Source

mukul975/anthropic-cybersecurity-skills

834 skills · 111.1K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
auditing-cloud-with-cis-benchmarks Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools l…
mukul975/anthropic-cybersecurity-skills
271
2
conducting-mobile-app-penetration-test Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security T…
mukul975/anthropic-cybersecurity-skills
271
3
Phishing Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and …
mukul975/anthropic-cybersecurity-skills
271
4
testing-for-host-header-injection Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache …
mukul975/anthropic-cybersecurity-skills
271
5
performing-web-application-firewall-bypass Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, a…
mukul975/anthropic-cybersecurity-skills
270
6
Account Access Removal Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous …
mukul975/anthropic-cybersecurity-skills
269
7
Structuring Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExp…
mukul975/anthropic-cybersecurity-skills
266
8
analyzing-threat-landscape-with-misp Query a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdo…
mukul975/anthropic-cybersecurity-skills
263
9
exploiting-server-side-request-forgery Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network r…
mukul975/anthropic-cybersecurity-skills
263
10
performing-web-application-scanning-with-nikto Runs Nikto, an open-source web server and web application scanner, to test over 7,000 potentially dangerous files/pro…
mukul975/anthropic-cybersecurity-skills
262
11
hardening-docker-containers-for-production >- Hardens Dockerfiles, images, and per-container runtime settings against the CIS Docker Benchmark v1.8.0: non-root …
mukul975/anthropic-cybersecurity-skills
260
12
analyzing-windows-event-logs-in-splunk Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escala…
mukul975/anthropic-cybersecurity-skills
259
13
performing-security-headers-audit Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or mis…
mukul975/anthropic-cybersecurity-skills
259
14
building-vulnerability-scanning-workflow Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, priorit…
mukul975/anthropic-cybersecurity-skills
258
15
exploiting-jwt-algorithm-confusion-attack >- Exploits JWT algorithm confusion where the server's verification library trusts the alg named in the token header,…
mukul975/anthropic-cybersecurity-skills
256
16
collecting-open-source-intelligence Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack c…
mukul975/anthropic-cybersecurity-skills
254
17
analyzing-windows-registry-for-artifacts Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, …
mukul975/anthropic-cybersecurity-skills
251
18
exploiting-websocket-vulnerabilities Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure me…
mukul975/anthropic-cybersecurity-skills
249
19
conducting-cloud-penetration-testing This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud env…
mukul975/anthropic-cybersecurity-skills
246
20
testing-mobile-api-authentication Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insec…
mukul975/anthropic-cybersecurity-skills
245
21
analyzing-usb-device-connection-history Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs, and setupapi.dev.log to reconstruct USB device…
mukul975/anthropic-cybersecurity-skills
244
22
analyzing-slack-space-and-file-system-artifacts Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or …
mukul975/anthropic-cybersecurity-skills
243
23
detecting-ai-model-prompt-injection-attacks Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-base…
mukul975/anthropic-cybersecurity-skills
242
24
auditing-azure-active-directory-configuration Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly …
mukul975/anthropic-cybersecurity-skills
241
25
analyzing-windows-prefetch-with-python Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution histo…
mukul975/anthropic-cybersecurity-skills
240
26
testing-for-xml-injection-vulnerabilities Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to ide…
mukul975/anthropic-cybersecurity-skills
240
27
auditing-gcp-iam-permissions Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service …
mukul975/anthropic-cybersecurity-skills
237
28
exploiting-broken-function-level-authorization Tests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, t…
mukul975/anthropic-cybersecurity-skills
237
29
analyzing-windows-lnk-files-for-artifacts Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifi…
mukul975/anthropic-cybersecurity-skills
232
30
exploiting-nosql-injection-vulnerabilities Detects and exploits NoSQL injection vulnerabilities in MongoDB, CouchDB, and similar databases to demonstrate authen…
mukul975/anthropic-cybersecurity-skills
232
31
building-devsecops-pipeline-with-gitlab-ci Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container sc…
mukul975/anthropic-cybersecurity-skills
231
32
exploiting-http-request-smuggling >- Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies betwe…
mukul975/anthropic-cybersecurity-skills
231
33
analyzing-windows-amcache-artifacts Parses the Windows Amcache.hve registry hive with Eric Zimmerman''s AmcacheParser and Timeline Explorer to extract ev…
mukul975/anthropic-cybersecurity-skills
229
34
auditing-tls-certificate-transparency-logs Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT d…
mukul975/anthropic-cybersecurity-skills
229
35
building-attack-pattern-library-from-cti-reports Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and…
mukul975/anthropic-cybersecurity-skills
228
36
conducting-full-scope-red-team-engagement Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, …
mukul975/anthropic-cybersecurity-skills
228
37
detecting-api-enumeration-attacks Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or U…
mukul975/anthropic-cybersecurity-skills
228
38
performing-csrf-attack-simulation Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit auth…
mukul975/anthropic-cybersecurity-skills
228
39
performing-threat-modeling-with-owasp-threat-dragon >- Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA,…
mukul975/anthropic-cybersecurity-skills
227
40
testing-for-email-header-injection Tests web application email functionality (contact forms, password reset, newsletter subscriptions) for CRLF/SMTP hea…
mukul975/anthropic-cybersecurity-skills
227
41
exploiting-oauth-misconfiguration Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token …
mukul975/anthropic-cybersecurity-skills
225
42
exploiting-template-injection-vulnerabilities Detects and exploits Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other…
mukul975/anthropic-cybersecurity-skills
225
43
analyzing-windows-shellbag-artifacts Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsin…
mukul975/anthropic-cybersecurity-skills
223
44
automating-ioc-enrichment Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR pla…
mukul975/anthropic-cybersecurity-skills
223
45
exploiting-race-condition-vulnerabilities Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder ex…
mukul975/anthropic-cybersecurity-skills
223
46
implementing-api-schema-validation-security Implements API schema validation using OpenAPI Specification and JSON Schema documents, enforced both at the API gate…
mukul975/anthropic-cybersecurity-skills
223
47
performing-ssrf-vulnerability-exploitation Tests web application URL parameters for Server-Side Request Forgery by probing cloud metadata endpoints (AWS/GCP/Azu…
mukul975/anthropic-cybersecurity-skills
223
48
Steal Web Session Cookie Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Devi…
mukul975/anthropic-cybersecurity-skills
221
49
exploiting-mass-assignment-in-rest-apis >- Discovers and exploits mass assignment (autobinding) in REST APIs by injecting unexpected or hidden parameters (e.…
mukul975/anthropic-cybersecurity-skills
220
50
performing-api-rate-limiting-bypass Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to m…
mukul975/anthropic-cybersecurity-skills
220
Page 3 · 834 total Previous Next