forensics▌
38 indexed skills · max 10 per page
analyzing-usb-device-connection-history
mukul975/Anthropic-Cybersecurity-Skills · analyzing-usb-device-connection-history
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
analyzing-prefetch-files-for-execution-history
mukul975/Anthropic-Cybersecurity-Skills · analyzing-prefetch-files-for-execution-history
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
analyzing-linux-system-artifacts
mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-system-artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
analyzing-powershell-empire-artifacts
mukul975/Anthropic-Cybersecurity-Skills · analyzing-powershell-empire-artifacts
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
performing-cloud-forensics-with-aws-cloudtrail
mukul975/Anthropic-Cybersecurity-Skills · performing-cloud-forensics-with-aws-cloudtrail
Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
performing-memory-forensics-with-volatility3
mukul975/Anthropic-Cybersecurity-Skills · performing-memory-forensics-with-volatility3
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
performing-network-forensics-with-wireshark
mukul975/Anthropic-Cybersecurity-Skills · performing-network-forensics-with-wireshark
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
implementing-cloud-trail-log-analysis
mukul975/Anthropic-Cybersecurity-Skills · implementing-cloud-trail-log-analysis
Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.
performing-network-traffic-analysis-with-zeek
mukul975/Anthropic-Cybersecurity-Skills · performing-network-traffic-analysis-with-zeek
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
extracting-credentials-from-memory-dump
mukul975/Anthropic-Cybersecurity-Skills · extracting-credentials-from-memory-dump
Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.