Skip to main content

Skills dans ce dépôt

mukul975/Anthropic-Cybersecurity-Skills - Page 3

SkillsMP a collecté 817 skills depuis mukul975/Anthropic-Cybersecurity-Skills. Ouvrez un skill pour examiner sa source et ses détails.

mukul975/Anthropic-Cybersecurity-Skills

Affichage de 40 skills collectés sur 817.

métier
Analystes en sécurité de l'information
description

Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes, feeding the coerced NTLM auth into a relay against AD CS Web Enrollment (ESC8), LDAP (RBCD), or SMB. Use…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines that aggregate indicators from community and commercial…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Collect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and system state with documented chain of custody before they are lost. Use before isolating, shutting…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extract KRBTGT, Domain Admin, and service account hashes for Golden Ticket forging, typically with Mimikatz. Use in…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct external recon using OSINT techniques to map an organization's external attack surface without touching target systems, gathering DNS records, certificate transparency logs, search results, social media, code repositories, and breach databases into a…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to evaluate an organization's detection, prevention, and response against APT-style behavior. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing containment, analysis, eradication, and recovery procedures aligned to MITRE ATT&CK. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS tickets from LSASS memory on a compromised host and injecting them into another session to impersonate the ticket owner without knowing their password. Use during authorized…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide, and remediating affected accounts. Use when investigating a…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Design and execute a social engineering penetration test combining OSINT-driven target profiling with phishing, vishing, smishing, and physical pretexting campaigns using tools like GoPhish, the Social Engineer Toolkit (SET), and Evilginx to measure human…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Run a targeted spearphishing simulation for initial access by developing OSINT-derived pretexts, building payloads (HTML smuggling, macro docs, ISO/LNK, OneNote, QR codes), standing up look-alike-domain email infrastructure with SPF/DKIM/DMARC via GoPhish,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations (PAWs), administrative forest design, and authentication policy silos. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure AWS Verified Access to provide VPN-less zero trust network access to internal apps, combining identity trust providers (IAM Identity Center, Okta/OIDC), device posture providers (CrowdStrike, Jamf), Cedar policy authoring, and Terraform deployment.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL distribution points, OCSP responder configuration, and certificate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures Hardware Security Modules for cryptographic key storage using the PKCS#11 standard interface, covering key generation, signing, encryption, and key management on physical HSMs and SoftHSM2 for development. Use when protecting cryptographic keys so…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, including IAM bindings, Access Context Manager access levels, session/reauth settings, and…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding, and LDAP signing. Use when securing an LDAP or Active Directory environment against these attack…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures microsegmentation policies to enforce least-privilege workload-to-workload access using tools such as VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures. Use when designing or implementing network…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points, covering Duo Authentication Proxy setup, adaptive authentication policies, device trust assessment, and phishing-resistant WebAuthn/FIDO2 deployment…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths. Use when segmenting an enterprise network into isolated security zones,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, and scope design per OAuth 2.1. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures pfSense firewall rules, NAT policies, IPsec/OpenVPN tunnels, and traffic shaping to enforce network segmentation and control traffic between zones such as DMZ, internal, guest, and IoT. Use when deploying a pfSense perimeter or internal firewall,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Installs, configures, and tunes Snort 3 to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins. Use when deploying network-based intrusion detection at key boundaries, writing custom…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for high-throughput, protocol-aware traffic inspection (HTTP, TLS, DNS, SMB) and SIEM integration. Use when running Suricata in IDS or inline IPS mode…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures TLS 1.3 (RFC 8446) on servers, covering cipher suite and key-exchange group selection, and validates the resulting configuration with openssl s_client and testssl.sh. Use when deploying or hardening TLS 1.3 for secure communications, or when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring identity- and device-posture-based access policies, and integrating with IdPs. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or injection vulnerabilities regress. Use for continuous adversarial…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialogue rails, and LLM Guard input/output scanner pipelines as complementary runtime defenses that inspect and constrain LLM prompts and responses. Use when adding a production runtime…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deobfuscates malicious JavaScript found in phishing pages, web skimmers, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control-flow obfuscation to reveal the original malicious logic. Use when investigating a phishing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Systematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. Use during incident response or malware analysis when a PowerShell script…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement. Use when replacing VPN with Cloudflare One, exposing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Plants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bug URLs, AWS keys, documents, kubeconfigs) using Thinkst's open-source Canarytokens project and alerts via email or webhook when a token is touched. Use for high-fidelity intrusion…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys Palo Alto Networks Prisma Access for SASE-based zero trust network access, configuring GlobalProtect agents, ZTNA Connectors, security policy enforcement, and Strata Cloud Manager integration for unified management. Use when implementing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys and monitors ransomware canary files using Python's watchdog library, placing decoy files mimicking high-value targets (financial records, credentials, database exports) where ransomware enumerates first, and alerting via email, Slack, or syslog on…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. Use when building or hardening zero trust network…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys and configures Tailscale (or self-hosted Headscale) as a WireGuard-based zero trust mesh VPN, setting up identity-aware ACLs, exit nodes, subnet routers, and MagicDNS for encrypted peer-to-peer connectivity. Use when replacing traditional VPN servers…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt overrides, role-play escapes) and indirect injections (encoded…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 817.