Skill Catalog
Browse 5,478 curated AI agent skills. No account needed.
Dependency Upgrade
Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing. Use when upgrading framework versions, updating major dependencies, or managing breaking changes in libraries.
by wshobson/agents / plugins/framework-migration/skills/dependency-upgrade
Dependency Vulnerability Scanning Skill
Scan repository dependencies for known vulnerabilities using the GitHub MCP Server's Dependabot toolset and the GitHub Advisory Database. Use when asked to check dependency security, audit lockfiles, or verify packages before merging.
by github/copilot-plugins / plugins/advanced-security/skills/dependency-scanning
Dependent Libraries (Preview)
Using dependent libraries in PCF components
by github/awesome-copilot / instructions/pcf-dependent-libraries.instructions.md
Deploy and Manage MCP-Based Agents
Skill converted from mcp-deploy-manage-agents.prompt.md
by github/awesome-copilot / skills/mcp-deploy-manage-agents
Deploying Active Directory Honeytokens
Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-active-directory-honeytokens
Deploying Cloudflare Access For Zero Trust
Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-cloudflare-access-for-zero-trust
Deploying Decoy Files For Ransomware Detection
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-decoy-files-for-ransomware-detection
Deploying Edr Agent With Crowdstrike
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-edr-agent-with-crowdstrike
Deploying Osquery For Endpoint Monitoring
Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-osquery-for-endpoint-monitoring
Deploying Palo Alto Prisma Access Zero Trust
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-palo-alto-prisma-access-zero-trust
Deploying Ransomware Canary Files
Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-ransomware-canary-files
Deploying Software Defined Perimeter
Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-software-defined-perimeter
Deploying Tailscale For Zero Trust Vpn
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
by mukul975/Anthropic-Cybersecurity-Skills / skills/deploying-tailscale-for-zero-trust-vpn
Deployment
Deploying Expo apps to iOS App Store, Android Play Store, web hosting, and API routes
by expo/skills / plugins/expo/skills/expo-deployment
Deployment Pipeline Design
Design multi-stage CI/CD pipelines with approval gates, security checks, and deployment orchestration. Use this skill when designing zero-downtime deployment pipelines, implementing canary rollout strategies, setting up multi-environment promotion workflows, or debugging failed deployment gates in CI/CD.
by wshobson/agents / plugins/cicd-automation/skills/deployment-pipeline-design
Deploy Model
Unified Azure OpenAI model deployment skill with intelligent intent-based routing. Handles quick preset deployments, fully customized deployments (version/SKU/capacity/RAI policy), and capacity discovery across regions and projects. USE FOR: deploy model, deploy gpt, create deployment, model deployment, deploy openai model, set up model, provision model, find capacity, check model availability, where can I deploy, best region for model, capacity analysis. DO NOT USE FOR: listing existing deployments (use foundry_models_deployments_list MCP tool), deleting deployments, agent creation (use agent/create), project creation (use project/create).
by microsoft/skills / .github/plugins/azure-skills/skills/microsoft-foundry/models/deploy-model
Deploy To Vercel
Deploy applications and websites to Vercel. Use when the user requests deployment actions like "deploy my app", "deploy and give me the link", "push this live", or "create a preview deployment".
by vercel-labs/agent-skills / skills/deploy-to-vercel
Depmap
Query the Cancer Dependency Map (DepMap) for cancer cell line gene dependency scores (CRISPR Chronos), drug sensitivity data, and gene effect profiles. Use for identifying cancer-specific vulnerabilities, synthetic lethal interactions, and validating oncology drug targets.
by K-Dense-AI/scientific-agent-skills / skills/depmap
DepMap — Cancer Dependency Map
Query the Cancer Dependency Map (DepMap) for cancer cell line gene dependency scores (CRISPR Chronos), drug sensitivity data, and gene effect profiles. Use for identifying cancer-specific vulnerabilities, synthetic lethal interactions, and validating oncology drug targets.
by K-Dense-AI/scientific-agent-skills / scientific-skills/depmap
Deposition Prep
Build a deposition outline for a witness — pull their documents from the eDiscovery platform, organize topics around the case theory, and surface impeachment material. Use when the user says "depo prep for [witness]", "build a depo outline", or "prepare for [name]'s deposition".
by anthropics/claude-for-legal / litigation-legal/skills/deposition-prep
Deprecation And Migration
Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when deciding whether to maintain or sunset existing code.
by addyosmani/agent-skills / skills/deprecation-and-migration
Design
Comprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG, Gemini 3.1 Pro), social photos (HTML→screenshot, multi-platform). Actions: design logo, create CIP, generate mockups, build slides, design banner, generate icon, create social photos, social media images, brand identity, design system. Platforms: Facebook, Twitter, LinkedIn, YouTube, Instagram, Pinterest, TikTok, Threads, Google Ads.
by nextlevelbuilder/ui-ux-pro-max-skill / .claude/skills/design
Design Brief Builder
Creates comprehensive design briefs for freelancers or agencies — project scope, brand guidelines, moodboard references via Brave Search, and deliverable specifications. Prerequisites: brave-search MCP.
by AgentArmory
Design Critique
Structured design critique and plan stress-testing. Acts as a relentless interviewer drawing on pre-mortem, red teaming, and ATAM techniques to help someone think through a design or plan exhaustively. Use when the user says "grill me", "critique this", "stress-test this", "pre-mortem", "red team this", or asks to be challenged on a technical architecture, product plan, feature design, or any decision rather than validated.
by psenger/ai-agent-skills / skills/design-critique
Designing Experiments
Design experiments and quasi-experiments before analysis. Use when choosing study design, treatment/control structure, outcomes, assumptions, validation plans after scientific experiment failure, or which of DiD, ITS, synthetic control, or regression discontinuity fits the research question. For fitting models or estimating effects on existing data, use performing-causal-analysis instead.
by foryourhealth111-pixel/Vibe-Skills / bundled/skills/designing-experiments
Design Md
Author/validate/export Google's DESIGN.md token spec files.
by NousResearch/hermes-agent / skills/creative/design-md
Design Md
Analyze Stitch projects and synthesize a semantic design system into DESIGN.md files
by sickn33/antigravity-awesome-skills / plugins/antigravity-awesome-skills-claude/skills/design-md
Design Patterns for Object-Oriented Programming for Clean Code
Best practices for applying Object-Oriented Programming (OOP) design patterns, including Gang of Four (GoF) patterns and SOLID principles, to ensure clean, maintainable, and scalable code.
by github/awesome-copilot / instructions/oop-design-patterns.instructions.md
Design System
Token architecture, component specifications, and slide generation. Three-layer tokens (primitive→semantic→component), CSS variables, spacing/typography scales, component specs, strategic slide creation. Use for design tokens, systematic design, brand-compliant presentations.
by nextlevelbuilder/ui-ux-pro-max-skill / .claude/skills/design-system
Design System Auditor
Design system accessibility auditor. Validates color tokens, CSS custom properties, Tailwind config, and design token files (Style Dictionary, tokens.json) for WCAG AA/AAA contrast compliance. Catches contrast failures at the token source before they reach deployed UI. Also validates focus ring tokens (WCAG 2.4.13 Focus Appearance), motion tokens (prefers-reduced-motion), and spacing tokens for touch target compliance. Supports MUI, Chakra UI, Radix, shadcn/ui, and Style Dictionary.
by Community-Access/accessibility-agents / codex-skills/design-system-auditor
Design System Patterns
Build scalable design systems with design tokens, theming infrastructure, and component architecture patterns. Use when creating design tokens, implementing theme switching, building component libraries, or establishing design system foundations.
by wshobson/agents / plugins/ui-design/skills/design-system-patterns
Design Taste Frontend
Anti-slop frontend skill for landing pages, portfolios, and redesigns. The agent reads the brief, infers the right design direction, and ships interfaces that do not look templated. Real design systems when applicable, audit-first on redesigns, strict pre-flight check.
by Leonxlnx/taste-skill / skills/taste-skill
Design Wizard
Interactive design wizard that guides through a complete frontend design process with discovery, aesthetic selection, and code generation. Use for creating distinctive, production-ready UI.
by davepoon/buildwithclaude / plugins/frontend-design-pro/skills/design-wizard
Desktop A11y Testing Coach
Desktop accessibility testing expert -- NVDA, JAWS, Narrator, VoiceOver screen readers, Accessibility Insights for Windows, automated UIA testing, keyboard-only testing, high contrast verification.
by Community-Access/accessibility-agents / codex-skills/desktop-a11y-testing-coach
Desktop Accessibility Specialist
Desktop application accessibility expert -- platform APIs (UI Automation, MSAA/IAccessible2, NSAccessibility), accessible control patterns, screen reader Name/Role/Value/State, focus management, high contrast, and custom widget accessibility.
by Community-Access/accessibility-agents / codex-skills/desktop-a11y-specialist
Detecting AI Model Prompt Injection Attacks
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models. The detector analyzes user inputs before they reach the LLM, flagging direct injections (system prompt overrides, role-play escapes, instruction hijacking) and indirect injections (encoded payloads, multi-language obfuscation, delimiter-based escapes). Based on the OWASP LLM Top 10 (LLM01:2025 Prompt Injection) and Simon Willison's prompt injection taxonomy. Activates for requests involving prompt injection detection, LLM input sanitization, AI security scanning, or prompt attack classification.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-ai-model-prompt-injection-attacks
Detecting Anomalies In Industrial Control Systems
This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-anomalies-in-industrial-control-systems
Detecting Anomalous Authentication Patterns
Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs. Activates for requests involving authentication anomaly detection, login behavior analysis, UEBA implementation, or suspicious sign-in investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-anomalous-authentication-patterns
Detecting API Enumeration Attacks
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-api-enumeration-attacks
Detecting Arp Poisoning In Network Traffic
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-arp-poisoning-in-network-traffic
Detecting Attacks On Historian Servers
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-attacks-on-historian-servers
Detecting Attacks On Scada Systems
This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly detection, and process data analytics to identify attacks that traditional IT security tools miss.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-attacks-on-scada-systems
Detecting AWS Cloudtrail Anomalies
Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-aws-cloudtrail-anomalies
Detecting AWS Credential Exposure With Trufflehog
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-aws-credential-exposure-with-trufflehog
Detecting AWS Guardduty Findings Automation
Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-aws-guardduty-findings-automation
Detecting AWS Iam Privilege Escalation
Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-aws-iam-privilege-escalation
Detecting Azure Lateral Movement
Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-azure-lateral-movement
Detecting Azure Service Principal Abuse
Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-azure-service-principal-abuse
Detecting Azure Storage Account Misconfigurations
Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-azure-storage-account-misconfigurations
Detecting Beaconing Patterns with Zeek
'Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-beaconing-patterns-with-zeek
Detecting Bluetooth Low Energy Attacks
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-bluetooth-low-energy-attacks
Detecting Broken Object Property Level Authorization
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-broken-object-property-level-authorization
Detecting Business Email Compromise
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-business-email-compromise
Detecting Business Email Compromise with AI
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-business-email-compromise-with-ai
Detecting Cloud Threats With Guardduty
This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-cloud-threats-with-guardduty
Detecting Command And Control Over DNS
Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development. Activates for requests involving DNS-based C2 detection, DNS tunnel identification, suspicious DNS traffic investigation, or DGA domain classification.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-command-and-control-over-dns
Detecting Compromised Cloud Credentials
Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-compromised-cloud-credentials
Detecting Container Drift At Runtime
Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-container-drift-at-runtime
Detecting Container Escape Attempts
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-container-escape-attempts
Detecting Container Escape With Falco Rules
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-container-escape-with-falco-rules
Detecting Credential Dumping Techniques
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-credential-dumping-techniques
Detecting Cryptomining In Cloud
This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-cryptomining-in-cloud
Detecting Data Anomalies
Investigate outliers, rare events, spikes, and suspicious records in datasets. Use as an explicit anomaly-analysis helper when you want concrete anomaly-detection workflow guidance, not generic data validation or end-to-end ML ownership.
by foryourhealth111-pixel/Vibe-Skills / bundled/skills/detecting-data-anomalies
Detecting Dcsync Attack In Active Directory
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-dcsync-attack-in-active-directory
Detecting Deepfake Audio In Vishing Attacks
Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generates confidence scores, and produces forensic reports. Activates for requests involving deepfake voice detection, vishing investigation, AI-generated speech analysis, voice cloning detection, or audio authenticity verification.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-deepfake-audio-in-vishing-attacks
Detecting Dll Sideloading Attacks
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-dll-sideloading-attacks
Detecting Dnp3 Protocol Anomalies
Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-dnp3-protocol-anomalies
Detecting DNS Exfiltration With DNS Query Analysis
Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-dns-exfiltration-with-dns-query-analysis
Detecting Email Account Compromise
Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-email-account-compromise
Detecting Email Forwarding Rules Attack
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-email-forwarding-rules-attack
Detecting Evasion Techniques In Endpoint Logs
Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-evasion-techniques-in-endpoint-logs
Detecting Exfiltration Over DNS With Zeek
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-exfiltration-over-dns-with-zeek
Detecting Fileless Attacks On Endpoints
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-fileless-attacks-on-endpoints
Detecting Fileless Malware Techniques
Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-fileless-malware-techniques
Detecting Golden Ticket Attacks In Kerberos Logs
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-golden-ticket-attacks-in-kerberos-logs
Detecting Golden Ticket Forgery
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-golden-ticket-forgery
Detecting Insider Data Exfiltration via DLP
'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-insider-data-exfiltration-via-dlp
Detecting Insider Threat Behaviors
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-insider-threat-behaviors
Detecting Insider Threat With Ueba
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-insider-threat-with-ueba
Detecting Kerberoasting Attacks
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-kerberoasting-attacks
Detecting Lateral Movement In Network
Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-lateral-movement-in-network
Detecting Lateral Movement With Splunk
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-lateral-movement-with-splunk
Detecting Lateral Movement With Zeek
Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-lateral-movement-with-zeek
Detecting Living Off The Land Attacks
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-living-off-the-land-attacks
Detecting Living Off The Land With Lolbas
Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-living-off-the-land-with-lolbas
Detecting Malicious Scheduled Tasks With Sysmon
Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-malicious-scheduled-tasks-with-sysmon
Detecting Mimikatz Execution Patterns
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-mimikatz-execution-patterns
Detecting Misconfigured Azure Storage
Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-misconfigured-azure-storage
Detecting Mobile Malware Behavior
Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-mobile-malware-behavior
Detecting Modbus Command Injection Attacks
Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and protocol deep packet inspection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-modbus-command-injection-attacks
Detecting Modbus Protocol Anomalies
This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for malformed Modbus frames. The skill leverages Zeek with Modbus protocol analyzers, Suricata IDS with OT rules, and custom Python-based detection using Markov chain models for normal Modbus transaction sequences.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-modbus-protocol-anomalies
Detecting Network Anomalies With Zeek
Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-network-anomalies-with-zeek
Detecting Network Scanning With Ids Signatures
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-network-scanning-with-ids-signatures
Detecting Ntlm Relay With Event Correlation
Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-ntlm-relay-with-event-correlation
Detecting OAuth Token Theft
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-oauth-token-theft
Detecting Pass The Hash Attacks
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-pass-the-hash-attacks
Detecting Pass-the-Ticket Attacks
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-pass-the-ticket-attacks
Detecting Port Scanning With Fail2ban
Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-port-scanning-with-fail2ban
Detecting Privilege Escalation Attempts
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-privilege-escalation-attempts
Detecting Privilege Escalation In Kubernetes Pods
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
by mukul975/Anthropic-Cybersecurity-Skills / skills/detecting-privilege-escalation-in-kubernetes-pods