Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data.
Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data.
Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
Also in this package
Other skills from mukul975/anthropic-cybersecurity-skills · top by installs.
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Claude CodeNot declared
CursorNot declared
CodexNot declared
GitHub CopilotNot declared
WindsurfNot declared
Gemini CLINot declared
ClineNot declared
OpenCodeNot declared
Repository health
Stars32.4K
LicenseLICENSE
Default branchmain
Open issues20
Status
Active
Skill metadata
Parsed from SKILL.md frontmatter.
Version1.0
LicenseApache-2.0
Package contents
Files included with this skill beyond the listing page.
skill mdSKILL.md3,195 B
docsSUMMARY.md394 B
History
First seen on skills.sh
First recorded snapshot · 319 installs
SKILL.md
Analyzing Ransomware Network Indicators
Overview
Before and during ransomware execution, adversaries establish C2 channels, exfiltrate data, and download encryption keys. This skill analyzes Zeek conn.log and NetFlow data to detect beaconing patterns (regular-interval callbacks), connections to known TOR exit nodes, large outbound data transfers, and suspicious DNS activity associated with ransomware families.
When to Use
When investigating security incidents that require analyzing ransomware network indicators
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
Zeek conn.log files or NetFlow CSV/JSON exports
Python 3.8+ with standard library
TOR exit node list (fetched from Tor Project or threat intel feeds)
Optional: Known ransomware C2 IOC list
Steps
Parse Connection Logs — Ingest Zeek conn.log (TSV) or NetFlow records into structured format
Detect Beaconing Patterns — Calculate connection interval statistics (mean, stddev, coefficient of variation) to identify periodic callbacks
Check TOR Exit Node Connections — Cross-reference destination IPs against current TOR exit node list
Identify Data Exfiltration — Flag connections with unusually high outbound byte ratios to external IPs
Analyze DNS Patterns — Detect DGA-like domain queries and high-entropy subdomains
Score and Correlate — Apply composite risk scoring across all indicator types
Generate Report — Produce structured report with timeline and MITRE ATT&CK mapping
Expected Output
JSON report with beaconing detections and interval statistics
TOR exit node connection alerts
Data exfiltration flow analysis
Composite ransomware risk score with MITRE mapping (T1071, T1573, T1041)