Skip to main content

Skills in this repository

mukul975/Anthropic-Cybersecurity-Skills - Page 9

SkillsMP has collected 817 skills from mukul975/Anthropic-Cybersecurity-Skills. Open a skill to review its source and details.

mukul975/Anthropic-Cybersecurity-Skills

Showing 40 of 817 collected skills.

occupation
Information Security Analysts
description

Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for syslog/file-tailing/application logs and output routing to Elasticsearch,…

updated
occupation
Information Security Analysts
description

Builds an append-only log integrity chain using SHA-256 hash chaining, where each entry incorporates the previous entry's hash so tampering invalidates all subsequent hashes; covers log ingestion (syslog/JSON/plain text), chain verification, pinpoint tamper…

updated
occupation
Information Security Analysts
description

Implements microsegmentation with Akamai Guardicore Segmentation to map application dependencies, visualize east-west traffic flows, and create granular, least-privilege network policies across VMs, containers, bare metal, and cloud. Use when blocking lateral…

updated
occupation
Information Security Analysts
description

Deploys and configures Mimecast Targeted Threat Protection (TTP) modules -- URL Protect (click-time URL rewriting/analysis), Attachment Protect (sandbox detonation), Impersonation Protect (BEC/whaling detection), and Internal Email Protect -- for Microsoft…

updated
occupation
Information Security Analysts
description

Implements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), and supply chain risk (CIP-013),…

updated
occupation
Information Security Analysts
description

Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configuration to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices. Use when enforcing…

updated
occupation
Information Security Analysts
description

Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment, downloadable ACLs, and TrustSec Security Group Tags. Use when…

updated
occupation
Information Security Analysts
description

Deploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and logging integration. Use when deploying real-time inline…

updated
occupation
Information Security Analysts
description

Writes Kubernetes NetworkPolicy YAML (default-deny-all, DNS egress, namespace/pod selector rules) enforced via CNI plugins like Calico or Cilium to control ingress and egress traffic between pods, namespaces, and external endpoints. Use when implementing…

updated
occupation
Information Security Analysts
description

Implements OT network segmentation using VLANs, OT-aware firewalls, data diodes, and IEC 62443 zone/conduit architecture, with a traffic-baseline-driven design tool for migrating flat Purdue-model networks without disrupting operations. Use when segmenting a…

updated
occupation
Information Security Analysts
description

Designs and implements network segmentation using firewall security zones, VLANs, inter-zone ACLs, and workload-level microsegmentation to restrict east-west lateral movement and enforce least-privilege access. Use when architecting security zones, writing…

updated
occupation
Information Security Analysts
description

Queries Arkime (formerly Moloch) full packet capture via its API to search sessions, download PCAPs, detect C2 beaconing through connection interval/jitter stats, spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate issuers, using…

updated
occupation
Information Security Analysts
description

Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python pandas, computing hourly/daily volume distributions, per-host and protocol/port statistics, and top-talker profiles, then flags outliers via z-score and IQR anomaly…

updated
occupation
Information Security Analysts
description

Configures and deploys Palo Alto Networks next-generation firewalls end-to-end, covering App-ID application-aware policies, User-ID identity-based enforcement, zone-based security rules, SSL decryption for encrypted traffic visibility, and Content-ID threat…

updated
occupation
Information Security Analysts
description

Deploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego rules plus instantiated Constraints to validate, mutate, or deny resource requests at admission time. Use when enforcing policy-as-code admission…

updated
occupation
Information Security Analysts
description

Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP…

updated
occupation
Information Security Analysts
description

Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis, providing asset visibility, behavioral anomaly detection, protocol-aware monitoring, and vulnerability assessment across industrial control systems without disrupting operations.…

updated
occupation
Information Security Analysts
description

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles. Use…

updated
occupation
Information Security Analysts
description

Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Use when deploying passwordless…

updated
occupation
Information Security Analysts
description

Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators, covering WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentication, and migration from password-based systems aligned…

updated
occupation
Information Security Analysts
description

Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window…

updated
occupation
Information Security Analysts
description

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced authentication, and continuous monitoring controls introduced by…

updated
occupation
Information Security Analysts
description

Implement Kubernetes Pod Security Admission (PSA), the built-in admission controller stable since v1.25, to enforce Privileged, Baseline, and Restricted Pod Security Standards at the namespace level with enforce, audit, and warn modes, replacing the…

updated
occupation
Information Security Analysts
description

Implements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and…

updated
occupation
Information Security Analysts
description

Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure, covering vault architecture, session isolation, credential rotation policies, and integration with NIST 800-53 access…

updated
occupation
Information Security Analysts
description

Design and implement Privileged Access Workstations (PAWs) using the tiered administration model, with device hardening, device compliance enforcement via Microsoft Intune or Group Policy, just-in-time (JIT) access provisioning, and integration with PAM…

updated
occupation
Information Security Analysts
description

Implements privileged session monitoring and recording using PAM solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives, covering session recording configuration, keystroke logging, real-time monitoring, risk-based…

updated
occupation
Information Security Analysts
description

Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model, separating ICS networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise and enforcing strict traffic control through…

updated
occupation
Information Security Analysts
description

Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules, isolating backup credentials, and automating restore testing.…

updated
occupation
Information Security Analysts
description

Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g. WannaCry-style), and registry termination checks, then implements mutex vaccination and kill switch domain monitoring to stop ransomware…

updated
occupation
Information Security Analysts
description

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated vulnerability scanning across enterprise environments. Use when…

updated
occupation
Information Security Analysts
description

Harden Kubernetes RBAC by implementing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating external identity providers (OIDC). Use when reviewing or tightening…

updated
occupation
Information Security Analysts
description

Generates, stores, rotates, and manages RSA key pairs following NIST SP 800-57 guidelines, covering serialization formats (PEM, DER, PKCS#8), passphrase protection, and key strength validation. Use when creating or rotating RSA keys for signatures, key…

updated
occupation
Information Security Analysts
description

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls at the kernel level. Use when deploying Tetragon to detect or block…

updated
occupation
Information Security Analysts
description

Implement SAML 2.0 Single Sign-On using Okta as the Identity Provider, covering SP-initiated and IdP-initiated flows, attribute mapping, certificate management, SHA-256 signature enforcement, and Single Logout. Use when configuring Okta SAML SSO for an…

updated
occupation
Information Security Analysts
description

Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider. Use when automating account creation, attribute sync, or deactivation across downstream applications through Okta SCIM…

updated
occupation
Information Security Analysts
description

Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. Use when eliminating hardcoded credentials from…

updated
occupation
Information Security Analysts
description

Create, validate, and share STIX 2.1 threat intelligence objects (indicators, malware, campaigns, relationships, bundles) using the stix2 Python library, and publish them over TAXII 2.1. Use when building or exchanging structured threat intelligence, modeling…

updated
occupation
Information Security Analysts
description

Write multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1), and network connections (Sysmon Event 3) across hosts within…

updated
occupation
Information Security Analysts
description

Tune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines, and measuring precision/recall efficacy metrics. Use when a SOC…

updated
Showing 40 of 817 collected skills.