analyzing-ransomware-network-indicators
Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
ソース情報
- リポジトリ
- mukul975/Anthropic-Cybersecurity-Skills
- ソースの最終更新活動
- 2026年8月2日 16:32
- 検出された SKILL.md の言語
- 英語
- スター
- 33,129
- フォーク
- 4,016
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
SKILL.md を表示中
- name
- analyzing-ransomware-network-indicators
- description
- Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
- domain
- cybersecurity
- subdomain
- threat-hunting
- tags
- ["ransomware","c2-beaconing","zeek","netflow","tor","exfiltration","network-forensics"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["File Metadata Consistency Validation","Certificate Analysis","Application Protocol Command Analysis","Content Format Conversion","File Content Analysis"]
- nist_csf
- ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"]
- mitre_attack
- ["T1071.001","T1573","T1048","T1567.002","T1486"]
- mitre_f3
- {"version":"1.1","tactics":["positioning","monetization"],"techniques":[{"id":"T1219","name":"Remote Access Tools","tactic":"positioning","source":"attack"},{"id":"F1018","name":"Convert to Cryptocurrency","tactic":"monetization","source":"f3"},{"id":"F1047","name":"Transfer of funds","tactic":"monetization","source":"f3"}]}