tag

data-exfiltration

8 indexed skills · max 10 per page

skills (8)

analyzing-usb-device-connection-history

mukul975/Anthropic-Cybersecurity-Skills · analyzing-usb-device-connection-history

0

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

analyzing-network-covert-channels-in-malware

mukul975/Anthropic-Cybersecurity-Skills · analyzing-network-covert-channels-in-malware

0

Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.

performing-insider-threat-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-insider-threat-investigation

0

Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection.

detecting-s3-data-exfiltration-attempts

mukul975/Anthropic-Cybersecurity-Skills · detecting-s3-data-exfiltration-attempts

0

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

investigating-insider-threat-indicators

mukul975/Anthropic-Cybersecurity-Skills · investigating-insider-threat-indicators

0

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

detecting-dns-exfiltration-with-dns-query-analysis

mukul975/Anthropic-Cybersecurity-Skills · detecting-dns-exfiltration-with-dns-query-analysis

0

Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.

hunting-for-data-exfiltration-indicators

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-data-exfiltration-indicators

0

Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.

hunting-for-dns-tunneling-with-zeek

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-dns-tunneling-with-zeek

0

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.