tag

detection

29 indexed skills · max 10 per page

skills (29)

performing-alert-triage-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-alert-triage-with-elastic-siem

0

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.

detecting-container-escape-with-falco-rules

mukul975/Anthropic-Cybersecurity-Skills · detecting-container-escape-with-falco-rules

0

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

detecting-process-injection-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-process-injection-techniques

0

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.

deploying-decoy-files-for-ransomware-detection

mukul975/Anthropic-Cybersecurity-Skills · deploying-decoy-files-for-ransomware-detection

0

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.

performing-dns-tunneling-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-dns-tunneling-detection

0

Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality. Uses scapy for packet capture analysis and statistical methods to distinguish legitimate DNS from covert channels. Use when hunting for data exfiltration.

performing-malware-hash-enrichment-with-virustotal

mukul975/Anthropic-Cybersecurity-Skills · performing-malware-hash-enrichment-with-virustotal

0

Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.

detecting-fileless-malware-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-fileless-malware-techniques

0

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination.

performing-lateral-movement-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-detection

0

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.

detecting-rootkit-activity

mukul975/Anthropic-Cybersecurity-Skills · detecting-rootkit-activity

0

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.

performing-container-escape-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-container-escape-detection

0

Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous capability assignments, and host path mounts using the kubernetes Python client. Identifies CVE-2022-0492 style escapes via cgroup abuse. Use when auditing container security posture or investigating escape attempts.

prevpage 1 / 3next