Security & Compliance Skills
902 curated security and compliance skills for AI coding agents. Access control, vulnerability scanning, compliance audit - all license-verified.
Performing Malware Triage With Yara
Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-malware-triage-with-yara
Performing Memory Forensics With Volatility3
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-memory-forensics-with-volatility3
Performing Memory Forensics With Volatility3 Plugins
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-memory-forensics-with-volatility3-plugins
Performing Mobile App Certificate Pinning Bypass
Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-mobile-app-certificate-pinning-bypass
Performing Mobile Device Forensics With Cellebrite
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-mobile-device-forensics-with-cellebrite
Performing Network Forensics With Wireshark
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-forensics-with-wireshark
Performing Network Packet Capture Analysis
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-packet-capture-analysis
Performing Network Traffic Analysis With Tshark
Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-traffic-analysis-with-tshark
Performing Network Traffic Analysis With Zeek
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-traffic-analysis-with-zeek
Performing Nist Csf Maturity Assessment
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-nist-csf-maturity-assessment
Performing OAuth Scope Minimization Review
Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-oauth-scope-minimization-review
Performing Oil Gas Cybersecurity Assessment
This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-oil-gas-cybersecurity-assessment
Performing Open Source Intelligence Gathering
Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-open-source-intelligence-gathering
Performing OSINT with SpiderFoot
Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance,
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-osint-with-spiderfoot
Performing Ot Network Security Assessment
This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infrastructure.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-network-security-assessment
Performing Ot Vulnerability Assessment With Claroty
This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-vulnerability-assessment-with-claroty
Performing Ot Vulnerability Scanning Safely
Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-vulnerability-scanning-safely
Performing Packet Injection Attack
Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-packet-injection-attack
Performing Paste Site Monitoring for Credentials
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-paste-site-monitoring-for-credentials
Performing Phishing Simulation With Gophish
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-phishing-simulation-with-gophish
Performing Physical Intrusion Assessment
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-physical-intrusion-assessment
Performing Plc Firmware Security Analysis
This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampering.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-plc-firmware-security-analysis
Performing Post Quantum Cryptography Migration
Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-post-quantum-cryptography-migration
Performing Power Grid Cybersecurity Assessment
This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and related attacks.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-power-grid-cybersecurity-assessment
Performing Privacy Impact Assessment
'Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices,
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privacy-impact-assessment
Performing Privileged Account Access Review
Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privileged-account-access-review
Performing Privileged Account Discovery
Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privileged-account-discovery
Performing Privilege Escalation Assessment
Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privilege-escalation-assessment
Performing Privilege Escalation on Linux
Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privilege-escalation-on-linux
Performing Purple Team Atomic Testing
Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the ATT&CK matrix, and runs detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines. Activates for requests involving purple team exercises, atomic test execution, ATT&CK coverage assessment, detection engineering validation, or adversary emulation testing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-purple-team-atomic-testing
Performing Purple Team Exercise
Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-purple-team-exercise
Performing Ransomware Response
Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ransomware-response
Performing Ransomware Tabletop Exercise
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ransomware-tabletop-exercise
Performing Red Team Operations with Covenant C2
Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-red-team-with-covenant
Performing Red Team Phishing With Gophish
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-red-team-phishing-with-gophish
Performing S7comm Protocol Security Analysis
Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-s7comm-protocol-security-analysis
Performing Scada Hmi Security Assessment
Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-scada-hmi-security-assessment
Performing Sca Dependency Scanning With Snyk
This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-sca-dependency-scanning-with-snyk
Performing Second Order SQL Injection
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-second-order-sql-injection
Performing Security Headers Audit
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-security-headers-audit
Performing Serverless Function Security Review
Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-serverless-function-security-review
Performing Service Account Audit
Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-service-account-audit
Performing Service Account Credential Rotation
Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-service-account-credential-rotation
Performing Soap Web Service Security Testing
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soap-web-service-security-testing
Performing Soc2 Type2 Audit Preparation
Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soc2-type2-audit-preparation
Performing Soc Tabletop Exercise
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soc-tabletop-exercise
Performing Sqlite Database Forensics
Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-sqlite-database-forensics
Performing SSL Certificate Lifecycle Management
SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-certificate-lifecycle-management
Performing SSL Stripping Attack
Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-stripping-attack
Performing SSL Tls Inspection Configuration
Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-tls-inspection-configuration
Performing SSL Tls Security Assessment
Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-tls-security-assessment
Performing Ssrf Vulnerability Exploitation
Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169.254.169.254), internal port scanning via HTTP, URL scheme bypass techniques, and DNS rebinding detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssrf-vulnerability-exploitation
Performing Static Malware Analysis With Pe Studio
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-static-malware-analysis-with-pe-studio
Performing Steganography Detection
Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-steganography-detection
Performing Subdomain Enumeration With Subfinder
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-subdomain-enumeration-with-subfinder
Performing Supply Chain Attack Simulation
Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-supply-chain-attack-simulation
Performing Thick Client Application Penetration Test
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-thick-client-application-penetration-test
Performing Threat Emulation With Atomic Red Team
Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-emulation-with-atomic-red-team
Performing Threat Hunting With Elastic Siem
Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-hunting-with-elastic-siem
Performing Threat Hunting With Yara Rules
Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-hunting-with-yara-rules
Performing Threat Intelligence Sharing With Misp
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-intelligence-sharing-with-misp
Performing Threat Landscape Assessment For Sector
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-landscape-assessment-for-sector
Performing Threat Modeling With Owasp Threat Dragon
Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-modeling-with-owasp-threat-dragon
Performing Timeline Reconstruction With Plaso
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-timeline-reconstruction-with-plaso
Performing User Behavior Analytics
Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-user-behavior-analytics
Performing Vlan Hopping Attack
Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-vlan-hopping-attack
Performing Vulnerability Scanning With Nessus
Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-vulnerability-scanning-with-nessus
Performing Web Application Firewall Bypass
Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-firewall-bypass
Performing Web Application Penetration Test
Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses Burp Suite as the primary interception proxy alongside manual testing techniques to find flaws that automated scanners miss. Activates for requests involving web app pentest, OWASP testing, application security assessment, or web vulnerability testing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-penetration-test
Performing Web Application Scanning With Nikto
Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-scanning-with-nikto
Performing Web Application Vulnerability Triage
Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-vulnerability-triage
Performing Web Cache Deception Attack
Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-cache-deception-attack
Performing Web Cache Poisoning Attack
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-cache-poisoning-attack
Performing Wifi Password Cracking With Aircrack
Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wifi-password-cracking-with-aircrack
Performing Windows Artifact Analysis With Eric Zimmerman Tools
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools
Performing Wireless Network Penetration Test
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wireless-network-penetration-test
Performing Wireless Security Assessment With Kismet
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wireless-security-assessment-with-kismet
Performing Yara Rule Development For Detection
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-yara-rule-development-for-detection
Phi Deidentifier
Remove or mask PHI/PII from healthcare data using HIPAA Safe Harbor method. Use when creating test datasets, anonymizing for research, or preparing data for non-production environments.
by prshahbs/healthcare-claude-skills / .claude/skills/phi-deidentifier
Power BI Security and Row-Level Security Best Practices
Comprehensive Power BI Row-Level Security (RLS) and advanced security patterns implementation guide with dynamic security, best practices, and governance strategies.
by github/awesome-copilot / instructions/power-bi-security-rls-best-practices.instructions.md
Prioritizing Vulnerabilities With Cvss Scoring
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r
by mukul975/Anthropic-Cybersecurity-Skills / skills/prioritizing-vulnerabilities-with-cvss-scoring
Privacy Data Security
Design and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations. Use when the user asks about privacy notices, the Safeguards Rule, identity theft prevention programs, breach notification obligations, vendor security due diligence, incident response planning, data classification, or state privacy law compliance. Also trigger when users mention 'customer data was exposed', 'do we need to notify clients of a breach', 'cybersecurity exam prep', 'cloud vendor risk assessment', 'encrypting client data', 'BYOD security policy', 'Red Flags Rule', 'NY DFS 500 requirements', or ask how to handle a cybersecurity incident.
by JoelLewis/finance_skills / plugins/compliance/skills/privacy-data-security
Privacy Policy
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when creating a privacy policy, updating data protection documentation, or preparing for compliance.
by phuryn/pm-skills / pm-toolkit/skills/privacy-policy
Probe
Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For dynamic security testing, pentesting, or runtime vulnerability validation. Complements Sentinel static analysis.
by simota/agent-skills / probe
Processing Stix Taxii Feeds
Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.
by mukul975/Anthropic-Cybersecurity-Skills / skills/processing-stix-taxii-feeds
Profiling Threat Actor Groups
Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries. Activates for requests involving MITRE ATT&CK Groups, Mandiant APT profiles, CrowdStrike adversary naming, or sector-specific threat briefings.
by mukul975/Anthropic-Cybersecurity-Skills / skills/profiling-threat-actor-groups
Prompt Guard
Meta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ TPR, <1% FPR. Fast (<2ms GPU). Multilingual (8 languages). Deploy with HuggingFace or batch processing for RAG security.
by Orchestra-Research/AI-Research-SKILLs / 07-safety-alignment/prompt-guard
Protect MCP Setup
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool execution, or compliance-ready evidence of agent actions.
by wshobson/agents / plugins/protect-mcp/skills/protect-mcp-setup
Protocol Reverse Engineering
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
by wshobson/agents / plugins/reverse-engineering/skills/protocol-reverse-engineering
Qms Audit Expert
ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external audits, or managing an audit program.
by alirezarezvani/claude-skills / ra-qm-team/skills/qms-audit-expert
Quality Manager Qms Iso13485
ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design, documentation control, internal auditing, CAPA management, and certification support. Use when working with medical device quality systems, preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or building audit preparation programs. Useful for quality management, audit preparation, regulatory compliance, medical device documentation, and corrective action workflows.
by alirezarezvani/claude-skills / ra-qm-team/skills/quality-manager-qms-iso13485
Reconciliation
Design and operate reconciliation processes across portfolio management, custodian, and clearing systems. Use when building a daily position, cash, or transaction reconciliation process, investigating discrepancies between internal records and custodian records, diagnosing recurring break patterns from corporate actions or pricing differences, setting tolerance thresholds for position, cash, or market value matching, implementing three-way reconciliation, designing break investigation workflows with aging and escalation, normalizing multi-custodian feeds from Schwab, Fidelity, or Pershing, reconciling cost basis or accrued income, or preparing for examinations on books and records accuracy.
by JoelLewis/finance_skills / plugins/client-operations/skills/reconciliation
Recovering Deleted Files With Photorec
Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.
by mukul975/Anthropic-Cybersecurity-Skills / skills/recovering-deleted-files-with-photorec
Recovering From Ransomware Attack
Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
by mukul975/Anthropic-Cybersecurity-Skills / skills/recovering-from-ransomware-attack
Remediating S3 Bucket Misconfiguration
This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.
by mukul975/Anthropic-Cybersecurity-Skills / skills/remediating-s3-bucket-misconfiguration
Repomix Safe Mixer
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.
by daymade/claude-code-skills / repomix-safe-mixer
Researchers Security
Researches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subject involves cybersecurity incidents or threat actors.
by bitwize-music-studio/claude-ai-music-skills / skills/researchers-security
Reverse Engineering Android Malware With Jadx
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-android-malware-with-jadx
Reverse Engineering Dotnet Malware With Dnspy
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-dotnet-malware-with-dnspy
Reverse Engineering iOS App With Frida
Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-ios-app-with-frida