Skip to main content

이 저장소의 skills

mukul975/Anthropic-Cybersecurity-Skills - 6페이지

SkillsMP는 mukul975/Anthropic-Cybersecurity-Skills에서 817개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

mukul975/Anthropic-Cybersecurity-Skills

수집된 skill 817개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Exploits JWT algorithm confusion where the server's verification library trusts the alg named in the token header, by switching RS256 to HS256 (signing with the RSA public key as HMAC secret), setting alg to none, or injecting kid/jku/x5u headers to supply an…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/AES-encrypted hashes offline to recover service account credentials. Use during…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discovers and exploits mass assignment (autobinding) in REST APIs by injecting unexpected or hidden parameters (e.g. role, isAdmin, plan) into create/update requests, using Burp Suite Intruder, Arjun, and param-miner to find bindable fields on ORM-backed…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's ms17_010_eternalblue/ms17_010_psexec modules for exploitation. Use during…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploits the noPac Active Directory privilege-escalation chain (CVE-2021-42278 sAMAccountName spoofing plus CVE-2021-42287 KDC PAC confusion) using Impacket and secretsdump.py to escalate from a standard domain user to Domain Admin. Use when red-teaming or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and exploits NoSQL injection vulnerabilities in MongoDB, CouchDB, and similar databases to demonstrate authentication bypass, data extraction, and unauthorized access via crafted query operators. Use when pentesting APIs or web applications backed by…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection into Object.prototype. Use when assessing a JavaScript/Node.js…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that bypass rate limits, duplicate transactions, or overrun usage…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and exploits Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. Use when pentesting a web application that renders user input through a server-side…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploits PHP type juggling vulnerabilities caused by loose (==) comparison operators to bypass authentication, defeat hash verification via magic hashes, and manipulate application logic through type coercion. Use when pentesting PHP applications that compare…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather post-exploitation evidence, and confirm patch remediation. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploits the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol using Impacket to reset a domain controller's machine account password to empty, then runs DCSync via secretsdump.py to dump domain credentials. Use when red-teaming or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView). Use when performing digital…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. Use when analyzing a suspected or confirmed Agent Tesla…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. Use when performing memory forensics or incident response on an LSASS or full memory dump and you…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators (IPs, domains, URLs, PCAP indicators), host artifacts (file paths, registry keys, mutexes), and behavioral patterns, using tools like CyberChef, then…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy a Velociraptor server and agents, then author VQL (Velociraptor Query Language) artifacts and run them as fleet-wide hunts, on-demand forensic collections, or standalone offline collectors. Use when hunting a TTP across hundreds or thousands of…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Generate CycloneDX and SPDX SBOMs from container images and filesystems with Syft, correlate them to CVEs with Grype, and sign/attest them with Cosign. Use when you need a machine-readable dependency inventory for supply-chain risk, want to scan images or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and per-host/per-Event-ID metrics. Use during DFIR triage to turn raw…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Harden Dockerfiles, images, and container runtime settings against the CIS Docker Benchmark v1.8.0: non-root users, dropped capabilities, read-only rootfs, seccomp/AppArmor, and minimal multi-stage images, validated with docker-bench-security, Hadolint, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Harden the Docker daemon (dockerd) by configuring /etc/docker/daemon.json with user namespace remapping, TLS client authentication, seccomp profiles, and CIS Docker Benchmark controls such as icc, no-new-privileges, and live-restore. Use when securing a…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Baseline the EFI System Partition and hunt malicious EFI binaries such as ESPecter, BlackLotus, Bootkitty, and Glupteba by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and flagging anomalous non-EFI files or out-of-band bootloader…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log gaps, outputting colorized tables, CSV, or JSON. Use during…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect Cobalt Strike beacon command-and-control traffic using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP malleable C2 profile pattern matching, and beacon jitter/interval analysis, built with Zeek network logs,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for data exfiltration by analyzing Zeek and Suricata network telemetry for unusual data flows, DNS tunneling via large/frequent TXT queries, uploads to personal cloud storage, and encrypted-channel abuse, correlated against threat intel on destination…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon process-creation and file-system telemetry (Event ID 4688, Sysmon 1/11) for 7-Zip/RAR/tar archive creation, unusual temp or hidden folder access, and anomalous consolidation of files…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for DCOM-based lateral movement (MITRE ATT&CK T1021.003) by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects via Sysmon Event ID 1/3 correlation, WMI event analysis, and RPC endpoint mapper traffic on port 135. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All requests issued by non-domain-controller accounts. Use when hunting for DCSync credential…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using passive DNS history (SecurityTrails API), Route53/Azure…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects DNS tunneling and covert-channel data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, abnormally long query lengths, and unusual DNS record types (TXT/NULL/CNAME). Use when hunting for DNS-based data…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. Use when hunting for command-and-control traffic hidden behind legitimate CDN domains, or when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects WMI-based lateral movement (e.g. wmic process call create, Win32_Process.Create()) by analyzing Windows Event ID 4688 and Sysmon Event ID 1 for WmiPrvSE.exe spawning suspicious child processes like cmd.exe or powershell.exe, plus…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. "living off the cloud" tradecraft that blends in with normal cloud API and service activity. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and defense-evasion controls. Use when building LOLBins…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when reviewing endpoint process…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures, SMB signing status, and anomalous cross-domain authentication…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use when performing a broad persistence sweep during incident…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003) by monitoring the creation of WMI event filters, consumers, and filter-to-consumer bindings that trigger malicious code execution on system events. Use when investigating fileless,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10 (ProcessAccess) alongside EDR process telemetry. Use when hunting…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image File Execution Options (IFEO) debugger injection, and COM hijacking via CLSID overrides. Use when…

원문 언어: 영어

업데이트
수집된 skill 817개 중 40개를 표시합니다.