Skip to main content

Skills dans ce dépôt

mukul975/Anthropic-Cybersecurity-Skills - Page 20

SkillsMP a collecté 817 skills depuis mukul975/Anthropic-Cybersecurity-Skills. Ouvrez un skill pour examiner sa source et ses détails.

mukul975/Anthropic-Cybersecurity-Skills

Affichage de 40 skills collectés sur 817.

métier
Analystes en sécurité de l'information
description

Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 817.