tag

forensics

38 indexed skills · max 10 per page

skills (38)

analyzing-ransomware-payment-wallets

mukul975/Anthropic-Cybersecurity-Skills · analyzing-ransomware-payment-wallets

0

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering.

performing-file-carving-with-foremost

mukul975/Anthropic-Cybersecurity-Skills · performing-file-carving-with-foremost

0

Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.

performing-malware-persistence-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-malware-persistence-investigation

0

Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.

performing-cloud-native-forensics-with-falco

mukul975/Anthropic-Cybersecurity-Skills · performing-cloud-native-forensics-with-falco

0

Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.

analyzing-windows-lnk-files-for-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-windows-lnk-files-for-artifacts

0

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

analyzing-linux-audit-logs-for-intrusion

mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-audit-logs-for-intrusion

0

Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.

analyzing-windows-registry-for-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-windows-registry-for-artifacts

0

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

analyzing-docker-container-forensics

mukul975/Anthropic-Cybersecurity-Skills · analyzing-docker-container-forensics

0

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

analyzing-email-headers-for-phishing-investigation

mukul975/Anthropic-Cybersecurity-Skills · analyzing-email-headers-for-phishing-investigation

0

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

collecting-volatile-evidence-from-compromised-host

mukul975/Anthropic-Cybersecurity-Skills · collecting-volatile-evidence-from-compromised-host

0

Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.

prevpage 3 / 4next