mukul975

mukul975/anthropic-cybersecurity-skills

748 resources in this repository

GitHub
🎯748
22,900

🎯Skills748

🎯acquiring-disk-image-with-dd-and-dcfldd🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains. Provides digital forensics guidance on acquiring disk images using dd and dcfldd tools for incident response and forensic investigations.

acquiring-disk-image-with-dd-and-dcfldd
🎯analyzing-api-gateway-access-logs🎯Skill

A cybersecurity skill for analyzing API gateway access logs, part of the Anthropic Cybersecurity Skills library of 754 production-grade skills across 26 security domains with MITRE ATT&CK and NIST framework mappings.

analyzing-api-gateway-access-logs
🎯analyzing-cyber-kill-chain🎯Skill

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify completed attack phases, evaluate defense successes/failures, and recommend controls for earlier attack interruption, with MITRE ATT&CK integration.

analyzing-cyber-kill-chain
🎯analyzing-email-headers-for-phishing-investigation🎯Skill

Parses and analyzes email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation with DNS lookup tools and threat intelligence integration.

analyzing-email-headers-for-phishing-investigation
🎯analyzing-android-malware-with-apktool🎯Skill

A cybersecurity skill teaching AI agents to analyze Android malware using APKTool for reverse engineering APK files, examining manifests, decompiled code, and identifying malicious behaviors.

analyzing-android-malware-with-apktool
🎯analyzing-browser-forensics-with-hindsight🎯Skill

A digital forensics skill for analyzing Chromium-based browser artifacts (Chrome, Edge, Brave, Opera) using Hindsight to extract and correlate browsing history, downloads, cookies, autofill data, saved passwords, and extensions into unified forensic timelines.

analyzing-browser-forensics-with-hindsight
🎯analyzing-docker-container-forensics🎯Skill

Guides investigating compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity, container escape attempts, and security misconfigurations.

analyzing-docker-container-forensics
🎯analyzing-cloud-storage-access-patterns🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides AI agents in analyzing cloud storage access patterns to identify unauthorized access, data exfiltration attempts, and misconfigured permissions across cloud environments.

analyzing-cloud-storage-access-patterns
🎯analyzing-certificate-transparency-for-phishing🎯Skill

A cybersecurity skill from a 754-skill library that teaches AI agents to analyze Certificate Transparency logs to detect and investigate phishing infrastructure.

analyzing-certificate-transparency-for-phishing
🎯analyzing-active-directory-acl-abuse🎯Skill

Detects dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths for security investigations.

analyzing-active-directory-acl-abuse
🎯analyzing-dns-logs-for-exfiltration🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, this skill focuses on analyzing DNS logs to detect potential data exfiltration patterns and threats.

analyzing-dns-logs-for-exfiltration
🎯analyzing-apt-group-with-mitre-navigator🎯Skill

Analyzes advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs. Supports detection gap analysis, multi-group comparison overlays, and generating actionable intelligence reports for detection engineering teams.

analyzing-apt-group-with-mitre-navigator
🎯analyzing-command-and-control-communication🎯Skill

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure for detection signature development and threat intelligence.

analyzing-command-and-control-communication
🎯analyzing-linux-audit-logs-for-intrusion🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides AI agents in analyzing Linux audit logs to detect intrusion attempts, suspicious activity, and security breaches across 26 security domains.

analyzing-linux-audit-logs-for-intrusion
🎯conducting-api-security-testing🎯Skill

Conducts security testing of REST, GraphQL, and gRPC APIs using the OWASP API Security Top 10 framework, combining Burp Suite interception with Postman collections to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic.

conducting-api-security-testing
🎯analyzing-network-traffic-with-wireshark🎯Skill

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, and support incident response on authorized network segments.

analyzing-network-traffic-with-wireshark
🎯analyzing-azure-activity-logs-for-threats🎯Skill

A cybersecurity skill from the largest open-source security skills library (754 skills across 26 domains), mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF frameworks for structured threat analysis with AI coding agents.

analyzing-azure-activity-logs-for-threats
🎯analyzing-indicators-of-compromise🎯Skill

Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority.

analyzing-indicators-of-compromise
🎯analyzing-bootkit-and-rootkit-samples🎯Skill

A cybersecurity skill for analyzing bootkit and advanced rootkit malware that infects MBR, VBR, or UEFI firmware. Covers boot sector acquisition, firmware analysis with UEFITool and chipsec, MBR disassembly, and kernel-level rootkit detection using Volatility, targeting nation-state level threats like APT28 and APT41.

analyzing-bootkit-and-rootkit-samples
🎯testing-api-security-with-owasp-top-10🎯Skill

An OWASP Top 10 API security testing skill from the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection with 754 skills across 26 security domains. Mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, and MITRE ATLAS.

testing-api-security-with-owasp-top-10
🎯analyzing-campaign-attribution-evidence🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks including Claude Code, Cursor, and Codex.

analyzing-campaign-attribution-evidence
🎯testing-for-xss-vulnerabilities🎯Skill

A cybersecurity skill for testing web applications against Cross-Site Scripting (XSS) vulnerabilities by injecting payloads into reflected, stored, and DOM-based contexts, with CSP bypass assessment and impact demonstration techniques for authorized penetration testing.

testing-for-xss-vulnerabilities
🎯performing-web-application-penetration-test🎯Skill

Guides systematic web application penetration testing following the OWASP WSTG methodology, covering authentication, authorization, input validation, session management, and business logic testing. Uses Burp Suite as the primary interception proxy alongside manual techniques to find vulnerabilities that automated scanners miss.

performing-web-application-penetration-test
🎯testing-jwt-token-security🎯Skill

A cybersecurity skill for assessing JWT (JSON Web Token) implementations during authorized penetration tests, covering algorithm confusion attacks, secret brute-forcing, token forgery, claim manipulation, and authorization bypass vulnerabilities.

testing-jwt-token-security
🎯analyzing-network-traffic-for-incidents🎯Skill

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts using Wireshark, Zeek, and NetFlow analysis techniques.

analyzing-network-traffic-for-incidents
🎯analyzing-ios-app-security-with-objection🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks including Claude Code, Cursor, and Codex.

analyzing-ios-app-security-with-objection
🎯analyzing-disk-image-with-autopsy🎯Skill

Guides comprehensive forensic analysis of disk images using Autopsy and The Sleuth Kit, covering file recovery, artifact examination, keyword searching, timeline analysis, and hash-based file identification for digital investigations.

analyzing-disk-image-with-autopsy
🎯analyzing-malicious-url-with-urlscan🎯Skill

A cybersecurity skill for analyzing malicious URLs using URLScan.io's scanning service. Provides procedures for safely investigating phishing URLs, credential harvesting pages, and malicious redirects by capturing screenshots, DOM content, HTTP transactions, and network connections in an isolated environment.

analyzing-malicious-url-with-urlscan
🎯analyzing-linux-kernel-rootkits🎯Skill

A cybersecurity skill for detecting Linux kernel rootkits by combining Volatility3 memory forensics plugins (check_syscall, lsmod, hidden_modules), live system scanning with rkhunter and chkrootkit, and /proc vs /sys cross-view discrepancy analysis. It produces a JSON report identifying syscall hooks, hidden kernel modules, modified IDT entries, and other rootkit artifacts.

analyzing-linux-kernel-rootkits
🎯analyzing-linux-system-artifacts🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks including Claude Code, Cursor, and Codex.

analyzing-linux-system-artifacts
🎯analyzing-network-traffic-of-malware🎯Skill

A cybersecurity skill for analyzing malware network traffic, part of a 754-skill library covering 26 security domains. Mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, and MITRE D3FEND for comprehensive threat analysis and compliance.

analyzing-network-traffic-of-malware
🎯analyzing-network-packets-with-scapy🎯Skill

A cybersecurity skill for analyzing network packets using Python's Scapy library, covering packet crafting, sending, sniffing, and dissection at granular protocol layers. Includes TCP/UDP/ICMP packet crafting, pcap file analysis, SYN scan implementation, DNS query analysis, and anomalous traffic pattern detection.

analyzing-network-packets-with-scapy
🎯analyzing-linux-elf-malware🎯Skill

A cybersecurity skill for analyzing malicious Linux ELF binaries β€” including botnets, cryptominers, ransomware, and rootkits β€” using static analysis, dynamic tracing, and reverse engineering tools like Ghidra, radare2, strace, and GDB. Covers threats targeting Linux servers, containers, and cloud infrastructure across x86_64 and ARM architectures.

analyzing-linux-elf-malware
🎯analyzing-kubernetes-audit-logs🎯Skill

A security skill for parsing Kubernetes API server audit logs in JSON format to detect threats such as exec-into-pod, unauthorized secret access, RBAC modifications, privileged pod creation, and anonymous API access. Intended for SOC analysts investigating cluster compromises or building Kubernetes-specific SIEM detection rules.

analyzing-kubernetes-audit-logs
🎯analyzing-golang-malware-with-ghidra🎯Skill

A cybersecurity skill that guides reverse engineering of Go-compiled malware using Ghidra, covering function recovery in stripped binaries with GoResolver, Go-specific string extraction, type reconstruction, and goroutine concurrency analysis.

analyzing-golang-malware-with-ghidra
🎯analyzing-cobalt-strike-beacon-configuration🎯Skill

Part of the Anthropic Cybersecurity Skills library β€” a collection of 754 production-grade skills spanning 26 security domains, mapped to five industry frameworks (MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF). This skill equips AI agents with expert-level guidance for analyzing Cobalt Strike beacon configurations.

analyzing-cobalt-strike-beacon-configuration
🎯analyzing-ethereum-smart-contract-vulnerabilities🎯Skill

A security skill for performing static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect vulnerabilities like reentrancy, integer overflow, and access control flaws before mainnet deployment. Covers running both tools, interpreting results, triaging findings by severity, and generating audit reports.

analyzing-ethereum-smart-contract-vulnerabilities
🎯analyzing-cobaltstrike-malleable-c2-profiles🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 production-grade skills across 26 security domains with mappings to five industry frameworks (MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF). This skill provides expert-level guidance for analyzing CobaltStrike Malleable C2 profiles as part of adversary emulation and threat detection workflows.

analyzing-cobaltstrike-malleable-c2-profiles
🎯testing-api-for-broken-object-level-authorization🎯Skill

Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities by systematically manipulating object identifiers to detect unauthorized access to other users' resources, covering OWASP API Security Top 10 risk API1:2023.

testing-api-for-broken-object-level-authorization
🎯testing-api-authentication-weaknesses🎯Skill

Tests API authentication mechanisms for weaknesses including broken token validation, missing endpoint auth, credential stuffing, token leakage, JWT flaws, and OAuth flow issues (OWASP API2:2023).

testing-api-authentication-weaknesses
🎯analyzing-malicious-pdf-with-peepdf🎯Skill

A cybersecurity skill for performing static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects, then generate actionable threat indicators.

analyzing-malicious-pdf-with-peepdf
🎯analyzing-web-server-logs-for-intrusion🎯Skill

Teaches AI agents to analyze web server logs for intrusion detection, part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains mapped to MITRE ATT&CK, NIST CSF 2.0, and three other industry frameworks.

analyzing-web-server-logs-for-intrusion
🎯exploiting-sql-injection-vulnerabilities🎯Skill

Guides identification and exploitation of SQL injection vulnerabilities during authorized penetration tests using manual techniques and sqlmap, covering error-based, union-based, blind boolean, and time-based blind injection across MySQL, PostgreSQL, MSSQL, and Oracle.

exploiting-sql-injection-vulnerabilities
🎯analyzing-heap-spray-exploitation🎯Skill

Detects and analyzes heap spray attacks in memory dumps using Volatility3 plugins, identifying NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.

analyzing-heap-spray-exploitation
🎯testing-cors-misconfiguration🎯Skill

A cybersecurity skill for identifying and exploiting Cross-Origin Resource Sharing misconfigurations during authorized penetration tests, covering origin reflection bypass, credential theft, and cross-domain data exfiltration techniques.

testing-cors-misconfiguration
🎯analyzing-network-flow-data-with-netflow🎯Skill

Part of the Anthropic Cybersecurity Skills library β€” a collection of 754 production-grade skills spanning 26 security domains, all mapped to five industry frameworks (MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF). This skill provides AI agents with expert-level guidance for analyzing network flow data using NetFlow.

analyzing-network-flow-data-with-netflow
🎯testing-for-broken-access-control🎯Skill

Systematically tests web applications for broken access control including privilege escalation, missing function-level checks, and insecure direct object references (OWASP A01:2021).

testing-for-broken-access-control
🎯analyzing-memory-dumps-with-volatility🎯Skill

Guides forensic analysis of RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, credential extraction, and YARA-based malware scanning across Windows, Linux, and macOS.

analyzing-memory-dumps-with-volatility
🎯analyzing-network-covert-channels-in-malware🎯Skill

Detects and analyzes covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and steganographic HTTP, using Python-based entropy analysis and traffic pattern detection to identify C2 infrastructure and data exfiltration attempts.

analyzing-network-covert-channels-in-malware
🎯analyzing-malware-behavior-with-cuckoo-sandbox🎯Skill

Guides AI agents through dynamic malware analysis using Cuckoo Sandbox, covering sample submission, real-time behavior monitoring, process activity analysis, and IOC extraction from behavioral reports.

analyzing-malware-behavior-with-cuckoo-sandbox
🎯testing-for-sensitive-data-exposure🎯Skill

A cybersecurity skill that provides structured workflows for identifying sensitive data exposure vulnerabilities during authorized penetration tests, covering API key leakage, PII in responses, insecure storage, secrets in source code, and unprotected data transmission. Mapped to MITRE ATT&CK, NIST CSF, and other security frameworks.

testing-for-sensitive-data-exposure
🎯testing-for-json-web-token-vulnerabilities🎯Skill

Tests JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation for authentication bypass.

testing-for-json-web-token-vulnerabilities
🎯analyzing-malware-sandbox-evasion-techniques🎯Skill

Analyzes behavioral reports from Cuckoo Sandbox and AnyRun to detect malware sandbox evasion techniques, including timing checks, VM artifact detection, sleep inflation, and user interaction monitoring, mapped to MITRE ATT&CK T1497 sub-techniques.

analyzing-malware-sandbox-evasion-techniques
🎯analyzing-threat-intelligence-feeds🎯Skill

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Supports ingesting CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, and enriching IOCs with campaign attribution.

analyzing-threat-intelligence-feeds
🎯analyzing-sbom-for-supply-chain-vulnerabilities🎯Skill

Parses CycloneDX and SPDX Software Bill of Materials to identify supply chain vulnerabilities by correlating components against the NVD CVE database, building dependency graphs, and generating compliance risk reports.

analyzing-sbom-for-supply-chain-vulnerabilities
🎯analyzing-macro-malware-in-office-documents🎯Skill

A cybersecurity skill for analyzing malicious VBA macros in Microsoft Office documents using olevba and oledump to extract download cradles, payload execution chains, persistence mechanisms, and anti-analysis techniques.

analyzing-macro-malware-in-office-documents
🎯analyzing-pdf-malware-with-pdfid🎯Skill

A cybersecurity skill for analyzing malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document.

analyzing-pdf-malware-with-pdfid
🎯analyzing-malware-family-relationships-with-malpedia🎯Skill

A skill for researching malware family relationships using the Malpedia API, covering family querying, variant evolution tracking, threat actor associations, and YARA rule extraction across 2,600+ documented malware families.

analyzing-malware-family-relationships-with-malpedia
🎯testing-oauth2-implementation-flaws🎯Skill

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF bypass, token leakage, scope escalation, and PKCE bypass.

testing-oauth2-implementation-flaws
🎯analyzing-malware-persistence-with-autoruns🎯Skill

Uses Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows.

analyzing-malware-persistence-with-autoruns
🎯analyzing-threat-actor-ttps-with-mitre-attack🎯Skill

A skill from the Anthropic Cybersecurity Skills library β€” the largest open-source cybersecurity skills collection for AI agents β€” offering 754 production-grade skills across 26 security domains, mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF.

analyzing-threat-actor-ttps-with-mitre-attack
🎯analyzing-lnk-file-and-jump-list-artifacts🎯Skill

A cybersecurity skill for analyzing Windows LNK file and Jump List forensic artifacts, part of the Anthropic cybersecurity skills collection for incident response and digital forensics.

analyzing-lnk-file-and-jump-list-artifacts
🎯conducting-network-penetration-test🎯Skill

Conducts comprehensive network penetration tests following PTES methodology, covering host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation.

conducting-network-penetration-test
🎯analyzing-ransomware-encryption-mechanisms🎯Skill

A cybersecurity agent skill from a library of 754 production-grade security skills, providing AI agents with structured knowledge for analyzing ransomware encryption mechanisms across 26 security domains.

analyzing-ransomware-encryption-mechanisms
🎯analyzing-office365-audit-logs-for-compromise🎯Skill

Analyzes Office 365 Unified Audit Logs via Microsoft Graph API to detect Business Email Compromise indicators, including suspicious inbox rule creation, email forwarding, mailbox delegation changes, and unauthorized OAuth consent grants.

analyzing-office365-audit-logs-for-compromise
🎯analyzing-powershell-script-block-logging🎯Skill

Part of a 754-skill cybersecurity library for AI agents spanning 26 security domains, mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF frameworks for structured security investigation guidance.

analyzing-powershell-script-block-logging
🎯analyzing-ransomware-network-indicators🎯Skill

A threat-hunting skill that identifies ransomware network indicators by analyzing Zeek conn.log and NetFlow data for C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and suspicious DNS activity with MITRE ATT&CK mapping.

analyzing-ransomware-network-indicators
🎯testing-for-xxe-injection-vulnerabilities🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that provides structured workflows for testing XML External Entity (XXE) injection vulnerabilities during authorized security assessments. Part of a 754-skill collection mapped to MITRE ATT&CK, NIST CSF, ATLAS, D3FEND, and NIST AI RMF frameworks.

testing-for-xxe-injection-vulnerabilities
🎯testing-api-for-mass-assignment-vulnerability🎯Skill

A large open-source cybersecurity skills library containing 754 structured skills across 26 security domains, designed to give AI agents the expertise of a senior security analyst. It covers penetration testing, threat detection, cloud security, incident response, and more, with mappings to NIST, MITRE ATT&CK, OWASP, and other frameworks across 26+ AI platforms.

testing-api-for-mass-assignment-vulnerability
🎯conducting-external-reconnaissance-with-osint🎯Skill

A cybersecurity skill that guides AI agents through external reconnaissance using OSINT techniques, covering DNS and subdomain enumeration, certificate transparency logs, social media profiling, code repository scanning, and breach database lookups to map an organization's attack surface without direct target interaction. It is designed for authorized penetration testing engagements and includes tooling guidance for Amass, theHarvester, Shodan, and other OSINT frameworks.

conducting-external-reconnaissance-with-osint
🎯analyzing-persistence-mechanisms-in-linux🎯Skill

Detects and analyzes Linux persistence mechanisms including crontab entries, systemd units, LD_PRELOAD hijacking, shell profile modifications, and SSH authorized_keys backdoors. Correlates findings with auditd logs to build installation timelines and produces risk-scored reports with MITRE ATT&CK mapping.

analyzing-persistence-mechanisms-in-linux
🎯auditing-aws-s3-bucket-permissions🎯Skill

Systematically audits AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured policies, and missing encryption using AWS CLI, S3audit, and Prowler.

auditing-aws-s3-bucket-permissions
🎯analyzing-memory-forensics-with-lime-and-volatility🎯Skill

A cybersecurity skill for performing Linux memory acquisition using LiME kernel module and forensic analysis with Volatility 3, including process listing, bash history extraction, network connection analysis, and kernel module inspection for incident response.

analyzing-memory-forensics-with-lime-and-volatility
🎯analyzing-ransomware-leak-site-intelligence🎯Skill

Part of a 754-skill cybersecurity library spanning 26 security domains, this skill provides structured knowledge for analyzing ransomware leak site intelligence following the agentskills.io standard.

analyzing-ransomware-leak-site-intelligence
🎯testing-for-host-header-injection🎯Skill

A cybersecurity skill for testing web applications against HTTP Host header injection vulnerabilities, covering password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation during authorized penetration tests.

testing-for-host-header-injection
🎯analyzing-powershell-empire-artifacts🎯Skill

Detects PowerShell Empire C2 framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, and known module signatures like Invoke-Mimikatz and Invoke-Kerberoast in Script Block Logging events.

analyzing-powershell-empire-artifacts
🎯testing-for-open-redirect-vulnerabilities🎯Skill

Identifies and tests open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft in authorized security testing.

testing-for-open-redirect-vulnerabilities
🎯analyzing-mft-for-deleted-file-recovery🎯Skill

A cybersecurity agent skill from a library of 754 production-grade security skills, providing AI agents with structured knowledge for analyzing NTFS Master File Table (MFT) records to recover deleted files in digital forensics investigations.

analyzing-mft-for-deleted-file-recovery
🎯analyzing-outlook-pst-for-email-forensics🎯Skill

Analyzes Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff and pst-utils for legal investigations and incident response.

analyzing-outlook-pst-for-email-forensics
🎯testing-for-business-logic-vulnerabilities🎯Skill

A cybersecurity skill for identifying flaws in application business logic β€” such as price manipulation, workflow bypass, and privilege escalation β€” that automated vulnerability scanners typically miss. It guides testers through mapping workflows, intercepting requests with Burp Suite, and testing rate-limited features like coupons and referral systems.

testing-for-business-logic-vulnerabilities
🎯testing-for-xss-vulnerabilities-with-burpsuite🎯Skill

A structured workflow for identifying and validating reflected, stored, and DOM-based XSS vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized penetration testing engagements.

testing-for-xss-vulnerabilities-with-burpsuite
🎯analyzing-threat-actor-ttps-with-mitre-navigator🎯Skill

A cybersecurity skill that maps advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using ATT&CK Navigator and the attackcti Python library. It queries STIX/TAXII data, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles.

analyzing-threat-actor-ttps-with-mitre-navigator
🎯collecting-open-source-intelligence🎯Skill

Collects and synthesizes open-source intelligence about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources and passive reconnaissance for authorized security assessments.

collecting-open-source-intelligence
🎯bypassing-authentication-with-forced-browsing🎯Skill

Guides discovering and accessing unprotected pages, APIs, and admin interfaces by enumerating URLs with ffuf during authorized penetration tests, validating that authentication is consistently enforced across all endpoints.

bypassing-authentication-with-forced-browsing
🎯analyzing-packed-malware-with-upx-unpacker🎯Skill

Identifies and unpacks UPX-packed and other packed malware samples to expose original executable code for static analysis, including handling of modified UPX headers.

analyzing-packed-malware-with-upx-unpacker
🎯analyzing-security-logs-with-splunk🎯Skill

A cybersecurity skill leveraging Splunk Enterprise Security and SPL for security incident investigation through log correlation, timeline reconstruction, and anomaly detection.

analyzing-security-logs-with-splunk
🎯analyzing-supply-chain-malware-artifacts🎯Skill

Investigates supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies through binary comparison, code signing verification, and dependency analysis to identify intrusion vectors.

analyzing-supply-chain-malware-artifacts
🎯building-incident-response-playbook🎯Skill

Designs structured incident response playbooks with step-by-step procedures aligned to NIST SP 800-61r3 and SANS PICERL frameworks, including decision trees and SOAR integration.

building-incident-response-playbook
🎯analyzing-typosquatting-domains-with-dnstwist🎯Skill

Detects typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate permutations and check DNS records, web page similarity via fuzzy hashing, and perceptual hashing.

analyzing-typosquatting-domains-with-dnstwist
🎯analyzing-prefetch-files-for-execution-history🎯Skill

Parses Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for digital forensics investigation.

analyzing-prefetch-files-for-execution-history
🎯analyzing-windows-event-logs-in-splunk🎯Skill

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK.

analyzing-windows-event-logs-in-splunk
🎯testing-for-xml-injection-vulnerabilities🎯Skill

A cybersecurity agent skill from a library of 754 production-grade security skills, equipping AI agents with structured knowledge for testing and identifying XML injection vulnerabilities across 26 security domains.

testing-for-xml-injection-vulnerabilities
🎯analyzing-tls-certificate-transparency-logs🎯Skill

Queries Certificate Transparency logs via crt.sh to detect phishing domains, unauthorized certificate issuance, and shadow IT β€” monitoring newly issued certificates for typosquatting using Levenshtein distance.

analyzing-tls-certificate-transparency-logs
🎯auditing-terraform-infrastructure-for-security🎯Skill

Audits Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies. Detects overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.

auditing-terraform-infrastructure-for-security
🎯analyzing-threat-landscape-with-misp🎯Skill

Analyzes the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to generate threat landscape reports with temporal analysis and MITRE ATT&CK technique mapping.

analyzing-threat-landscape-with-misp
🎯testing-websocket-api-security🎯Skill

Tests WebSocket API security by identifying vulnerabilities in real-time communication protocols including authentication bypass, injection attacks, and data leakage.

testing-websocket-api-security
🎯auditing-kubernetes-cluster-rbac🎯Skill

Audits Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

auditing-kubernetes-cluster-rbac
🎯performing-web-application-vulnerability-triage🎯Skill

Part of a 754-skill cybersecurity library for AI agents spanning 26 security domains, mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF frameworks for structured security investigation guidance.

performing-web-application-vulnerability-triage
🎯conducting-mobile-app-penetration-test🎯Skill

Conducts iOS and Android mobile app penetration testing following OWASP MASTG β€” covering static analysis of binaries, dynamic runtime analysis, and API security testing across the full mobile attack surface.

conducting-mobile-app-penetration-test
🎯auditing-cloud-with-cis-benchmarks🎯Skill

A skill for conducting cloud security audits using CIS (Center for Internet Security) benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with Prowler and ScoutSuite, remediating failures, and maintaining continuous compliance monitoring.

auditing-cloud-with-cis-benchmarks
🎯building-vulnerability-scanning-workflow🎯Skill

Builds structured vulnerability scanning workflows using Nessus, Qualys, and OpenVAS with CVSS-based prioritization, SIEM integration for scan result correlation, and SLA-driven remediation tracking dashboards.

building-vulnerability-scanning-workflow
🎯analyzing-ransomware-payment-wallets🎯Skill

A cybersecurity skill that traces ransomware cryptocurrency payment flows using blockchain analysis tools like Chainalysis Reactor and WalletExplorer, identifying wallet clusters, tracking funds through mixers and exchanges, and supporting law enforcement attribution.

analyzing-ransomware-payment-wallets
🎯testing-mobile-api-authentication🎯Skill

Tests authentication and authorization mechanisms in mobile APIs to identify broken auth, insecure tokens, session fixation, privilege escalation, and IDOR vulnerabilities.

testing-mobile-api-authentication
🎯analyzing-usb-device-connection-history🎯Skill

Digital forensics skill for investigating USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

analyzing-usb-device-connection-history
🎯exploiting-sql-injection-with-sqlmap🎯Skill

Guides detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests and CTF challenges.

exploiting-sql-injection-with-sqlmap
🎯analyzing-windows-registry-for-artifacts🎯Skill

A cybersecurity skill for digital forensics that guides extraction and analysis of Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise using tools like RegRipper and Registry Explorer.

analyzing-windows-registry-for-artifacts
🎯exploiting-server-side-request-forgery🎯Skill

Identifies and exploits SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests, covering webhooks, URL previews, and PDF generators.

exploiting-server-side-request-forgery
🎯testing-for-email-header-injection🎯Skill

A cybersecurity skill for testing web application email functionality against SMTP header injection vulnerabilities. Covers identifying injection points in contact forms, password resets, and sharing features, with step-by-step workflows using Burp Suite and CRLF injection techniques.

testing-for-email-header-injection
🎯exploiting-api-injection-vulnerabilities🎯Skill

Tests and identifies API injection vulnerabilities including SQL injection, NoSQL injection, and command injection in web application APIs for security assessment purposes.

exploiting-api-injection-vulnerabilities
🎯conducting-cloud-penetration-testing🎯Skill

A cybersecurity skill outlining methodologies for authorized penetration testing against AWS, Azure, and GCP cloud environments. Covers the shared responsibility model, cloud-specific attack tools like Pacu and ScoutSuite, IAM misconfiguration exploitation, SSRF to metadata services, and MITRE ATT&CK Cloud matrix-aligned reporting.

conducting-cloud-penetration-testing
🎯automating-ioc-enrichment🎯Skill

The largest open-source cybersecurity skills library for AI agents, covering 26 security domains with over 750 skills across 5 frameworks. Compatible with Claude Code, Gemini CLI, Codex CLI, Cursor, and other AI coding assistants for expert-level cybersecurity guidance.

automating-ioc-enrichment
🎯analyzing-windows-prefetch-with-python🎯Skill

Parses Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns in forensic investigations.

analyzing-windows-prefetch-with-python
🎯building-attack-pattern-library-from-cti-reports🎯Skill

Part of a 754-skill open-source cybersecurity library spanning 26 security domains, designed to give AI agents senior-analyst-level security expertise across threat intelligence, incident response, and cloud security.

building-attack-pattern-library-from-cti-reports
🎯performing-web-application-firewall-bypass🎯Skill

A cybersecurity skill for bypassing Web Application Firewall protections during penetration testing. Covers WAF fingerprinting with wafw00f, encoding/obfuscation techniques, HTTP method manipulation, parameter pollution, and payload delivery for SQL injection and XSS past WAF detection rules.

performing-web-application-firewall-bypass
🎯auditing-azure-active-directory-configuration🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents, covering 26 security domains with 754+ skills compatible with 5 frameworks and 26+ platforms.

auditing-azure-active-directory-configuration
🎯auditing-gcp-iam-permissions🎯Skill

Part of a 754-skill open-source cybersecurity library spanning 26 security domains, designed to give AI agents senior-analyst-level security expertise across threat intelligence, incident response, and cloud security.

auditing-gcp-iam-permissions
🎯conducting-full-scope-red-team-engagement🎯Skill

Plans and executes comprehensive MITRE ATT&CK-aligned red team engagements from reconnaissance through post-exploitation, evaluating an organization's detection, prevention, and response capabilities.

conducting-full-scope-red-team-engagement
🎯analyzing-windows-lnk-files-for-artifacts🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, spanning 754 skills across 26 security domains and compatible with Claude Code, Gemini CLI, Codex, and 26+ other platforms.

analyzing-windows-lnk-files-for-artifacts
🎯exploiting-idor-vulnerabilities🎯Skill

Cybersecurity skill for identifying and exploiting IDOR vulnerabilities during authorized penetration tests, covering access control validation across CRUD operations using Burp Suite and manual techniques.

exploiting-idor-vulnerabilities
🎯reverse-engineering-android-malware-with-jadx🎯Skill

A cybersecurity skill for reverse engineering malicious Android APK files using JADX decompiler, analyzing Java/Kotlin source code to identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks.

reverse-engineering-android-malware-with-jadx
🎯performing-web-application-scanning-with-nikto🎯Skill

A cybersecurity skill for performing web application scanning with Nikto, an open-source scanner that tests against 7,000+ potentially dangerous files, checks outdated server versions, and detects XSS, SQL injection, server misconfigurations, default credentials, and missing security headers.

performing-web-application-scanning-with-nikto
🎯analyzing-windows-amcache-artifacts🎯Skill

A digital forensics skill from a 754-skill cybersecurity library that guides AI agents through analyzing Windows Amcache artifacts for evidence of program execution, mapped to MITRE ATT&CK and other security frameworks.

analyzing-windows-amcache-artifacts
🎯analyzing-slack-space-and-file-system-artifacts🎯Skill

Examines NTFS file system artifacts including slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity for digital forensic investigations.

analyzing-slack-space-and-file-system-artifacts
🎯analyzing-windows-shellbag-artifacts🎯Skill

Part of the largest open-source cybersecurity skills library with 754+ skills across 26 security domains, enabling AI agents to assist with digital forensics, incident response, threat analysis, and more across 5 frameworks.

analyzing-windows-shellbag-artifacts
🎯building-incident-response-dashboard🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides AI agents through building incident response dashboards, covering breach containment, ransomware response, and IR playbooks aligned with NIST CSF and MITRE frameworks.

building-incident-response-dashboard
🎯auditing-tls-certificate-transparency-logs🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains, compatible with Claude Code, Cursor, Gemini CLI, GitHub Copilot, and other AI coding agents.

auditing-tls-certificate-transparency-logs
🎯exploiting-http-request-smuggling🎯Skill

Part of a 754-skill cybersecurity library covering 26 security domains, with mappings to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF.

exploiting-http-request-smuggling
🎯building-adversary-infrastructure-tracking-system🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with Claude Code, Cursor, Gemini CLI, Codex, and 26+ other platforms.

building-adversary-infrastructure-tracking-system
🎯conducting-internal-network-penetration-test🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains and compatible with five agent frameworks including Claude Code and Cursor.

conducting-internal-network-penetration-test
🎯exploiting-jwt-algorithm-confusion-attack🎯Skill

A cybersecurity skill from Anthropic Cybersecurity Skills (754 skills, 26 domains) that teaches AI agents how to identify and exploit JWT algorithm confusion vulnerabilities, mapped to MITRE ATT&CK and NIST CSF 2.0 frameworks.

exploiting-jwt-algorithm-confusion-attack
🎯exploiting-oauth-misconfiguration🎯Skill

A cybersecurity skill for identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations during authorized penetration tests, covering redirect URI manipulation, token leakage, and authorization code theft. Provides step-by-step workflows using Burp Suite for testing social login implementations and SSO flows.

exploiting-oauth-misconfiguration
🎯analyzing-uefi-bootkit-persistence🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with Claude Code, Gemini CLI, Codex CLI, GitHub Copilot, Cursor, and other AI coding agents.

analyzing-uefi-bootkit-persistence
🎯hardening-docker-containers-for-production🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents, covering 26 security domains with 754+ skills compatible with 5 frameworks and 26+ platforms.

hardening-docker-containers-for-production
🎯detecting-api-enumeration-attacks🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings (MITRE ATT&CK, NIST, etc.). Compatible with 26+ AI platforms including Claude Code, Cursor, and Copilot.

detecting-api-enumeration-attacks
🎯building-c2-infrastructure-with-sliver-framework🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with 5 framework mappings. This skill focuses on building C2 infrastructure with the Sliver framework for authorized security testing.

building-c2-infrastructure-with-sliver-framework
🎯detecting-ai-model-prompt-injection-attacks🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754+ skills across 26 security domains compatible with Claude Code, Cursor, Codex, and other agent frameworks.

detecting-ai-model-prompt-injection-attacks
🎯exploiting-websocket-vulnerabilities🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with support for five major agent frameworks.

exploiting-websocket-vulnerabilities
🎯building-threat-intelligence-platform🎯Skill

An open-source library of 754 production-grade cybersecurity skills spanning 26 security domains, designed to give AI agents the knowledge of a senior security analyst. Includes 5 framework mappings and supports 26+ AI platforms.

building-threat-intelligence-platform
🎯building-vulnerability-dashboard-with-defectdojo🎯Skill

An open-source library of 754 structured cybersecurity skills across 26 security domains, covering forensics, incident response, cloud security, and more, with mappings to MITRE ATT&CK, NIST, and other frameworks.

building-vulnerability-dashboard-with-defectdojo
🎯performing-web-cache-deception-attack🎯Skill

A cybersecurity skill for executing web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content. Covers Cloudflare cache behavior, cache key analysis, and CDN attack vectors.

performing-web-cache-deception-attack
🎯building-soc-playbook-for-ransomware🎯Skill

A cybersecurity skill for building SOC playbooks to handle ransomware incidents, from the Anthropic Cybersecurity Skills library covering 754 skills across 26 security domains. Provides structured workflows for incident response teams.

building-soc-playbook-for-ransomware
🎯configuring-oauth2-authorization-flow🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that covers OAuth2 authorization flow configuration, part of 754 production-grade skills across 26 security domains compatible with 26+ AI platforms.

configuring-oauth2-authorization-flow
🎯building-soc-escalation-matrix🎯Skill

A cybersecurity skill for designing SOC escalation matrices, from the largest open-source cybersecurity skills library with 754 skills across 26 security domains. It supports five industry frameworks and works with Claude Code, Cursor, Codex, and other AI agents.

building-soc-escalation-matrix
🎯building-detection-rules-with-sigma🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, providing threat detection, incident response, and security analysis capabilities for 26+ AI platforms.

building-detection-rules-with-sigma
🎯building-devsecops-pipeline-with-gitlab-ci🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, the largest open-source collection with 754+ skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Gemini CLI, Codex, Cursor, and 26+ other AI coding platforms.

building-devsecops-pipeline-with-gitlab-ci
🎯building-soc-metrics-and-kpi-tracking🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with mappings to 5 major frameworks. Compatible with Claude Code, Cursor, Gemini CLI, and 26+ other AI platforms.

building-soc-metrics-and-kpi-tracking
🎯building-threat-intelligence-feed-integration🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 production-grade skills across 26 security domains with mappings for 5 frameworks and compatibility with 26+ AI platforms.

building-threat-intelligence-feed-integration
🎯collecting-threat-intelligence-with-misp🎯Skill

A skill from the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 skills across 26 security domains, covering threat intelligence topics including MISP integration, STIX/TAXII feeds, and actor profiling.

collecting-threat-intelligence-with-misp
🎯building-automated-malware-submission-pipeline🎯Skill

A skill from the Anthropic Cybersecurity Skills library that provides structured workflows for building automated malware submission pipelines. Part of a 754-skill collection across 26 security domains, mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.

building-automated-malware-submission-pipeline
🎯exploiting-template-injection-vulnerabilities🎯Skill

The largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including template injection vulnerabilities, compatible with Claude Code, Codex, Gemini CLI, and other platforms.

exploiting-template-injection-vulnerabilities
🎯exploiting-race-condition-vulnerabilities🎯Skill

A cybersecurity skill from a 754-skill library spanning 26 security domains that teaches AI agents how to identify and exploit race condition vulnerabilities, mapped to MITRE ATT&CK and other frameworks.

exploiting-race-condition-vulnerabilities
🎯performing-web-cache-poisoning-attack🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains. Compatible with 5 frameworks and 26+ platforms, following the agentskills.io standard for Claude Code, Cursor, Codex, Gemini CLI, Copilot, and others.

performing-web-cache-poisoning-attack
🎯triaging-security-incident🎯Skill

A cybersecurity skill from the largest open-source security skills library for AI agents, covering 754 skills across 26 security domains including incident triaging, threat analysis, and security operations.

triaging-security-incident
🎯collecting-indicators-of-compromise🎯Skill

A cybersecurity agent skill for collecting indicators of compromise (IOCs), part of a 754-skill library spanning 26 security domains and 5 frameworks. Designed for security professionals using AI agents for threat detection, incident response, and security operations.

collecting-indicators-of-compromise
🎯building-threat-actor-profile-from-osint🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 26 security domains with 754+ skills. Provides guidance on building threat actor profiles from open-source intelligence (OSINT), compatible with Claude Code, Cursor, and other AI coding agents.

building-threat-actor-profile-from-osint
🎯building-detection-rule-with-splunk-spl🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, providing threat detection, digital forensics, and incident response capabilities compatible with 26+ AI platforms including Claude Code.

building-detection-rule-with-splunk-spl
🎯exploiting-nosql-injection-vulnerabilities🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 production-grade skills across 26 security domains with mappings to MITRE ATT&CK, NIST CSF, OWASP, and other frameworks.

exploiting-nosql-injection-vulnerabilities
🎯building-cloud-siem-with-sentinel🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, this skill covers building a cloud SIEM with Microsoft Sentinel. Compatible with Claude Code, Codex, Cursor, and 26+ AI platforms.

building-cloud-siem-with-sentinel
🎯performing-api-rate-limiting-bypass🎯Skill

A cybersecurity skill from Anthropic Cybersecurity Skills (754 skills, 26 domains) that teaches AI agents techniques for testing and bypassing API rate limiting controls, mapped to MITRE ATT&CK and NIST CSF 2.0 frameworks.

performing-api-rate-limiting-bypass
🎯performing-ssrf-vulnerability-exploitation🎯Skill

The largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks. Compatible with 26+ platforms including Claude Code, Cursor, and Gemini CLI for penetration testing, vulnerability assessment, and security analysis.

performing-ssrf-vulnerability-exploitation
🎯building-malware-incident-communication-template🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, the largest open-source collection with 754+ skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Gemini CLI, Codex, Cursor, and 26+ other AI coding platforms.

building-malware-incident-communication-template
🎯building-vulnerability-exception-tracking-system🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 structured skills across 26 security domains with mappings to MITRE ATT&CK, NIST, and 3 other frameworks. Compatible with Claude Code, Cursor, GitHub Copilot, and 26+ other AI platforms.

building-vulnerability-exception-tracking-system
🎯scanning-docker-images-with-trivy🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754+ skills across 26 security domains. Compatible with Claude Code, Cursor, Codex, Gemini CLI, and other platforms that support the Agent Skills specification.

scanning-docker-images-with-trivy
🎯implementing-secret-scanning-with-gitleaks🎯Skill

A cybersecurity skill for implementing secret scanning with Gitleaks, part of the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains and support for five agent frameworks.

implementing-secret-scanning-with-gitleaks
🎯performing-csrf-attack-simulation🎯Skill

A structured cybersecurity skill from a library of 754 production-grade security skills spanning 26 domains, designed to give AI coding agents the expertise of a senior security analyst across frameworks like MITRE ATT&CK and NIST.

performing-csrf-attack-simulation
🎯building-identity-governance-lifecycle-process🎯Skill

Part of the largest open-source cybersecurity skills library with 754 structured skills across 26 security domains, compatible with Claude Code, Cursor, and 26+ AI platforms via the Agent Skills specification.

building-identity-governance-lifecycle-process
🎯implementing-api-rate-limiting-and-throttling🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with mappings to five major frameworks. It covers everything from vulnerability scanning and incident response to cloud security and compliance.

implementing-api-rate-limiting-and-throttling
🎯exploiting-broken-function-level-authorization🎯Skill

Part of a library of 754 structured cybersecurity skills spanning 26 security domains, mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.

exploiting-broken-function-level-authorization
🎯building-incident-timeline-with-timesketch🎯Skill

Part of the largest open-source cybersecurity skills library covering 26 security domains and 754+ skills, this skill teaches AI agents to build incident timelines using Timesketch for forensic analysis.

building-incident-timeline-with-timesketch
🎯exploiting-insecure-deserialization🎯Skill

Part of a library of 754 production-grade cybersecurity skills spanning 26 security domains, each mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, and MITRE ATLAS, giving AI agents the security analysis capabilities of a senior analyst.

exploiting-insecure-deserialization
🎯performing-api-security-testing-with-postman🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with Claude Code, Cursor, Codex CLI, Gemini CLI, and other platforms.

performing-api-security-testing-with-postman
🎯building-red-team-c2-infrastructure-with-havoc🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754+ skills across 26 security domains including red teaming, incident response, and threat analysis. Compatible with Claude Code, Cursor, Gemini CLI, and other major agent platforms.

building-red-team-c2-infrastructure-with-havoc
🎯conducting-cloud-incident-response🎯Skill

Part of a comprehensive open-source cybersecurity skills library offering 754 skills spanning 26 security domains, from cloud incident response to threat analysis. Supports 5 frameworks and works with Claude Code, Codex CLI, Gemini CLI, and 26+ platforms.

conducting-cloud-incident-response
🎯conducting-wireless-network-penetration-test🎯Skill

A cybersecurity skill that guides AI agents through wireless network penetration testing workflows. Part of a library of 754 production-grade cybersecurity skills spanning 26 security domains for use with Claude Code, Cursor, and other AI agents.

conducting-wireless-network-penetration-test
🎯building-threat-hunt-hypothesis-framework🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains with support for five frameworks including Claude Code, Cursor, and Gemini CLI.

building-threat-hunt-hypothesis-framework
🎯conducting-internal-reconnaissance-with-bloodhound-ce🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings (MITRE ATT&CK, NIST, etc.). Compatible with 26+ AI platforms including Claude Code, Cursor, and GitHub Copilot.

conducting-internal-reconnaissance-with-bloodhound-ce
🎯building-ransomware-playbook-with-cisa-framework🎯Skill

A library of 754 production-grade cybersecurity skills spanning 26 security domains with 5 framework mappings, designed to give AI agents the security knowledge of a senior analyst.

building-ransomware-playbook-with-cisa-framework
🎯building-ioc-enrichment-pipeline-with-opencti🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library (754 skills, 26 domains) that teaches AI agents to build Indicator of Compromise enrichment pipelines using the OpenCTI threat intelligence platform, mapped to frameworks like MITRE ATT&CK and NIST CSF 2.0.

building-ioc-enrichment-pipeline-with-opencti
🎯conducting-phishing-incident-response🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including incident response, red teaming, penetration testing, endpoint security, and DevSecOps.

conducting-phishing-incident-response
🎯exploiting-prototype-pollution-in-javascript🎯Skill

Auto-generated security skill from trending appsec open-source projects on GitHub, providing installable SKILL.md playbooks that are updated every 30 minutes.

exploiting-prototype-pollution-in-javascript
🎯deobfuscating-javascript-malware🎯Skill

A cybersecurity agent skill from the Anthropic Cybersecurity Skills library (754 skills across 26 security domains) that guides the analysis and deobfuscation of JavaScript malware samples for security research and incident response.

deobfuscating-javascript-malware
🎯conducting-man-in-the-middle-attack-simulation🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains with support for 5 frameworks and 26+ compatible platforms.

conducting-man-in-the-middle-attack-simulation
🎯scanning-network-with-nmap-advanced🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with Claude Code, Cursor, Gemini CLI, Codex, and 26+ other platforms through five integrated frameworks.

scanning-network-with-nmap-advanced
🎯building-vulnerability-aging-and-sla-tracking🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, Cursor, and Gemini CLI.

building-vulnerability-aging-and-sla-tracking
🎯building-ioc-defanging-and-sharing-pipeline🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including threat intelligence, incident response, and IoC handling for five major frameworks.

building-ioc-defanging-and-sharing-pipeline
🎯exploiting-mass-assignment-in-rest-apis🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains. Compatible with 5 frameworks including Claude Code, Cursor, and Codex, following the agentskills.io standard.

exploiting-mass-assignment-in-rest-apis
🎯building-identity-federation-with-saml-azure-ad🎯Skill

Part of a comprehensive cybersecurity skills library with 754 production-grade skills across 26 security domains, including framework mappings for MITRE ATT&CK and NIST, compatible with Claude Code and 26+ AI platforms.

building-identity-federation-with-saml-azure-ad
🎯building-phishing-reporting-button-workflow🎯Skill

The largest open-source cybersecurity skills library for AI agents with 754 production-grade skills across 26 security domains and 5 framework mappings. Covers memory forensics, Sigma rules, cloud breach scoping, and more, compatible with 26+ AI platforms.

building-phishing-reporting-button-workflow
🎯building-threat-feed-aggregation-with-misp🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains. Compatible with 5 frameworks and 26+ platforms including Claude Code, Gemini CLI, and Cursor.

building-threat-feed-aggregation-with-misp
🎯conducting-malware-incident-response🎯Skill

A malware incident response skill from the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and compatible with 5 frameworks including Claude Code, Cursor, and GitHub Copilot.

conducting-malware-incident-response
🎯building-threat-intelligence-enrichment-in-splunk🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with five framework mappings. Compatible with 26+ AI platforms including Claude Code, Cursor, and GitHub Copilot.

building-threat-intelligence-enrichment-in-splunk
🎯performing-api-inventory-and-discovery🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with support for five agent frameworks.

performing-api-inventory-and-discovery
🎯performing-security-headers-audit🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains with support for Claude Code, Cursor, Codex, Gemini CLI, and other agent frameworks.

performing-security-headers-audit
🎯implementing-jwt-signing-and-verification🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains including cryptography, network security, and application security, compatible with Claude Code, Cursor, and other platforms.

implementing-jwt-signing-and-verification
🎯securing-github-actions-workflows🎯Skill

A production-grade cybersecurity skill from the largest open-source security skills library (754 skills across 26 domains), mapped to 5 frameworks including MITRE ATT&CK and NIST, compatible with Claude Code, Cursor, Gemini CLI, and 26+ AI platforms.

securing-github-actions-workflows
🎯conducting-domain-persistence-with-dcsync🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 production-grade skills across 26 security domains with mappings to 5 frameworks and compatibility with 26+ AI platforms.

conducting-domain-persistence-with-dcsync
🎯reverse-engineering-malware-with-ghidra🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains including vulnerability scanning, incident response, cloud security, and compliance frameworks for 26+ platforms.

reverse-engineering-malware-with-ghidra
🎯collecting-volatile-evidence-from-compromised-host🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains. This digital forensics skill teaches AI agents structured workflows for collecting volatile evidence from compromised hosts, following incident response playbooks mapped to MITRE ATT&CK frameworks.

collecting-volatile-evidence-from-compromised-host
🎯testing-android-intents-for-vulnerabilities🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Codex CLI, Gemini CLI, and 26+ other platforms following the agentskills.io specification.

testing-android-intents-for-vulnerabilities
🎯implementing-api-schema-validation-security🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 production-grade skills across 26 security domains and 5 framework mappings (NIST, MITRE ATT&CK, OWASP, CIS, ISO 27001). Compatible with 26+ AI platforms including Claude Code, Cursor, and Gemini.

implementing-api-schema-validation-security
🎯building-role-mining-for-rbac-optimization🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library (754+ skills across 26 security domains) that guides AI agents through role mining techniques to optimize Role-Based Access Control (RBAC) configurations.

building-role-mining-for-rbac-optimization
🎯conducting-pass-the-ticket-attack🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Cursor, Codex CLI, and 26+ agent platforms.

conducting-pass-the-ticket-attack
🎯reverse-engineering-ios-app-with-frida🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 structured skills across 26 security domains with mappings to five major frameworks including MITRE ATT&CK and NIST.

reverse-engineering-ios-app-with-frida
🎯exploiting-excessive-data-exposure-in-api🎯Skill

A cybersecurity skill focused on identifying and testing excessive data exposure vulnerabilities in APIs, from an open-source security skills library covering 26 security domains with over 750 skills across 5 frameworks.

exploiting-excessive-data-exposure-in-api
🎯performing-vulnerability-scanning-with-nessus🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks, compatible with Claude Code, Cursor, Codex, and other AI coding agents.

performing-vulnerability-scanning-with-nessus
🎯conducting-social-engineering-penetration-test🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library covering social engineering penetration testing. Part of 754 production-grade security skills spanning 26 domains with MITRE ATT&CK mappings, designed to give AI agents structured practitioner-level security knowledge.

conducting-social-engineering-penetration-test
🎯building-patch-tuesday-response-process🎯Skill

Part of a comprehensive open-source cybersecurity skills library with 754 skills across 26 security domains, providing AI agents with structured workflows for patch management, vulnerability response, and security operations. Supports Claude Code, Cursor, Codex, and other AI agent frameworks.

building-patch-tuesday-response-process
🎯performing-wifi-password-cracking-with-aircrack🎯Skill

A skill from the Anthropic Cybersecurity Skills library, the largest open-source collection of 754 cybersecurity skills across 26 security domains for AI agents, covering penetration testing, incident response, cloud security, and compliance.

performing-wifi-password-cracking-with-aircrack
🎯triaging-vulnerabilities-with-ssvc-framework🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings and compatibility with 26+ AI platforms.

triaging-vulnerabilities-with-ssvc-framework
🎯exploiting-deeplink-vulnerabilities🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library (754 skills across 26 domains) that teaches AI agents to identify and test deep link vulnerabilities in mobile applications, covering URL scheme hijacking and intent interception.

exploiting-deeplink-vulnerabilities
🎯scanning-containers-with-trivy-in-cicd🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library focused on container image scanning with Trivy in CI/CD pipelines. Part of 754 structured security skills across 26 domains including container security, K8s RBAC, and container forensics.

scanning-containers-with-trivy-in-cicd
🎯implementing-api-key-security-controls🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains. Compatible with 5 frameworks and 26+ platforms including Claude Code, Cursor, and other AI coding assistants.

implementing-api-key-security-controls
🎯exploiting-broken-link-hijacking🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and compatible with Claude Code, Gemini CLI, Cursor, Codex, and other coding agents.

exploiting-broken-link-hijacking
🎯exploiting-type-juggling-vulnerabilities🎯Skill

A cybersecurity skill from the largest open-source security skills library for AI agents, covering 754 skills across 26 domains. Every skill is mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF.

exploiting-type-juggling-vulnerabilities
🎯exploiting-insecure-data-storage-in-mobile🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with support for five agent frameworks including Claude Code and GitHub Copilot.

exploiting-insecure-data-storage-in-mobile
🎯validating-backup-integrity-for-recovery🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents. Covers 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms including Claude Code, Cursor, and GitHub Copilot.

validating-backup-integrity-for-recovery
🎯performing-api-fuzzing-with-restler🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including API security, cloud security, threat hunting, and incident response. Compatible with Claude Code, Cursor, Gemini CLI, and other agent platforms, it provides structured guidance for security operations and testing.

performing-api-fuzzing-with-restler
🎯detecting-attacks-on-scada-systems🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with Claude Code, Cursor, Gemini CLI, and 26+ other platforms, following the agentskills.io standard.

detecting-attacks-on-scada-systems
🎯conducting-memory-forensics-with-volatility🎯Skill

A cybersecurity skill that guides AI agents through memory forensics analysis using the Volatility framework. Part of the largest open-source cybersecurity skills library with 754+ skills across 26 security domains, compatible with Claude Code, Cursor, and other AI coding assistants.

conducting-memory-forensics-with-volatility
🎯conducting-post-incident-lessons-learned🎯Skill

Part of the largest open-source cybersecurity skills library with 754 structured skills across 26 security domains, providing AI agents with production-grade security knowledge following the agentskills.io standard and compatible with multiple AI platforms.

conducting-post-incident-lessons-learned
🎯performing-jwt-none-algorithm-attack🎯Skill

A cybersecurity skill from the Web Application Security domain, part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains including OWASP Top 10, covering five major AI agent frameworks.

performing-jwt-none-algorithm-attack
🎯tracking-threat-actor-infrastructure🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, the largest open-source security skills collection for AI agents with 754 skills across 26 security domains. Compatible with 5 frameworks and 26+ platforms including Claude Code.

tracking-threat-actor-infrastructure
🎯configuring-tls-1-3-for-secure-communications🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains with support for Claude Code, Cursor, Copilot, Gemini CLI, and 26+ platforms.

configuring-tls-1-3-for-secure-communications
🎯performing-soc2-type2-audit-preparation🎯Skill

Part of the largest open-source cybersecurity skills library (754 skills across 26 security domains), this skill guides AI agents through SOC 2 Type 2 audit preparation including control implementation, evidence gathering, and compliance verification.

performing-soc2-type2-audit-preparation
🎯executing-red-team-exercise🎯Skill

A cybersecurity skill for guiding red team exercises, part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains compatible with multiple AI agent frameworks.

executing-red-team-exercise
🎯triaging-security-incident-with-ir-playbook🎯Skill

A cybersecurity skill for triaging security incidents using IR playbooks, from a library of 754 production-grade skills across 26 security domains. Maps to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, and MITRE D3FEND.

triaging-security-incident-with-ir-playbook
🎯exploiting-vulnerabilities-with-metasploit-framework🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that provides AI agents with structured knowledge on using the Metasploit Framework for vulnerability exploitation, part of a 754-skill collection spanning 26 security domains.

exploiting-vulnerabilities-with-metasploit-framework
🎯executing-red-team-engagement-planning🎯Skill

An open-source library of 754 structured cybersecurity skills across 26 security domains, designed to give AI agents the knowledge of a senior security analyst with framework mappings for MITRE ATT&CK, NIST, and more.

executing-red-team-engagement-planning
🎯testing-ransomware-recovery-procedures🎯Skill

Part of a 754-skill open-source cybersecurity library covering 26 security domains, equipping AI agents with structured skills for threat detection, incident response, forensics, and security operations across 26+ AI platforms.

testing-ransomware-recovery-procedures
🎯detecting-anomalous-authentication-patterns🎯Skill

A cybersecurity skill for detecting anomalous authentication patterns, part of a large open-source library covering 754 skills across 26 security domains for AI agents including Claude Code, Cursor, and Gemini CLI.

detecting-anomalous-authentication-patterns
🎯performing-sca-dependency-scanning-with-snyk🎯Skill

An open-source cybersecurity skills library offering 754 skills across 26 security domains for AI agents, compatible with Claude Code, Cursor, Gemini CLI, and other major agent platforms.

performing-sca-dependency-scanning-with-snyk
🎯performing-threat-modeling-with-owasp-threat-dragon🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains and 5 frameworks, compatible with Claude Code, Cursor, and 26+ other platforms.

performing-threat-modeling-with-owasp-threat-dragon
🎯detecting-shadow-api-endpoints🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 production-grade skills across 26 security domains with mappings to five frameworks. Compatible with 26+ AI platforms including Claude Code.

detecting-shadow-api-endpoints
🎯hardening-docker-daemon-configuration🎯Skill

The largest open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, mapped to five major frameworks. Covers everything from memory forensics and Sigma rules to cloud breach scoping, giving AI agents the security knowledge of a senior analyst.

hardening-docker-daemon-configuration
🎯implementing-api-gateway-security-controls🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Cursor, and 26+ other platforms for security-focused development guidance.

implementing-api-gateway-security-controls
🎯detecting-sql-injection-via-waf-logs🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains and 5 frameworks. Covers threat detection, incident response, vulnerability analysis, cloud security, and more for platforms including Claude Code, Cursor, and Codex.

detecting-sql-injection-via-waf-logs
🎯conducting-spearphishing-simulation-campaign🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains and compatible with 5 major agent frameworks.

conducting-spearphishing-simulation-campaign
🎯performing-subdomain-enumeration-with-subfinder🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains. Teaches agents structured cybersecurity workflows compatible with 5 frameworks and 26+ AI platforms.

performing-subdomain-enumeration-with-subfinder
🎯extracting-browser-history-artifacts🎯Skill

Part of a 754-skill open-source cybersecurity library spanning 26 security domains, providing production-grade skills that give AI agents the capabilities of a senior security analyst across digital forensics, incident response, and threat detection.

extracting-browser-history-artifacts
🎯abusing-dpapi-for-credential-access🎯Skill

Skill

abusing-dpapi-for-credential-access
🎯detecting-broken-object-property-level-authorization🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains and 5 frameworks for detecting and addressing security vulnerabilities.

detecting-broken-object-property-level-authorization
🎯performing-directory-traversal-testing🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains and compatible with five frameworks including Claude Code, Cursor, and Codex.

performing-directory-traversal-testing
🎯conducting-social-engineering-pretext-call🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing structured guidance for security assessments, penetration testing, and defensive security operations.

conducting-social-engineering-pretext-call
🎯prioritizing-vulnerabilities-with-cvss-scoring🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including vulnerability assessment, compliance frameworks, and threat analysis, benchmarked at 96% accuracy across 625 test assertions.

prioritizing-vulnerabilities-with-cvss-scoring
🎯performing-graphql-security-assessment🎯Skill

Guides AI agents through GraphQL security assessments including query injection, introspection exposure, and authorization testing, as part of a comprehensive library of 754+ cybersecurity skills covering 26 security domains.

performing-graphql-security-assessment
🎯scanning-container-images-with-grype🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 production-grade skills across 26 security domains with 5 framework mappings, compatible with Claude Code, Cursor, and 26+ AI platforms.

scanning-container-images-with-grype
🎯exploiting-smb-vulnerabilities-with-metasploit🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, designed to give AI agents the capabilities of a senior security analyst.

exploiting-smb-vulnerabilities-with-metasploit
🎯implementing-secrets-scanning-in-ci-cd🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 production-grade skills across 26 security domains and 5 framework mappings. Compatible with Claude Code, Cursor, Codex, Gemini CLI, and 26+ other AI platforms.

implementing-secrets-scanning-in-ci-cd
🎯exploiting-ipv6-vulnerabilities🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 production-grade skills across 26 security domains, 5 framework mappings (MITRE ATT&CK, NIST, OWASP, CIS, ISO 27001), and support for 26+ AI platforms.

exploiting-ipv6-vulnerabilities
🎯implementing-api-security-posture-management🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks, compatible with Claude Code, Cursor, and other agent platforms.

implementing-api-security-posture-management
🎯detecting-oauth-token-theft🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with mappings to 5 frameworks (MITRE ATT&CK, NIST, and others). Compatible with Claude Code, Cursor, Codex, and 26+ other AI platforms.

detecting-oauth-token-theft
🎯implementing-api-abuse-detection-with-rate-limiting🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, this skill teaches API abuse detection with rate limiting across 26 security domains and 5 supported frameworks.

implementing-api-abuse-detection-with-rate-limiting
🎯securing-serverless-functions🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, Cursor, and Codex.

securing-serverless-functions
🎯configuring-network-segmentation-with-vlans🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 skills spanning 26 security domains and compatibility with 5 agent frameworks, covering areas from network security and incident response to compliance and threat intelligence.

configuring-network-segmentation-with-vlans
🎯performing-second-order-sql-injection🎯Skill

A cybersecurity skill for performing second-order SQL injection analysis, part of the largest open-source cybersecurity skills library for AI agents. The library includes 754 skills across 26 security domains and works with Claude Code, Cursor, Copilot, Gemini CLI, and other compatible platforms.

performing-second-order-sql-injection
🎯reverse-engineering-dotnet-malware-with-dnspy🎯Skill

A cybersecurity skill from a library of 754 production-grade skills across 26 security domains, providing AI agents with structured knowledge for reverse-engineering .NET malware using dnSpy.

reverse-engineering-dotnet-malware-with-dnspy
🎯securing-container-registry-images🎯Skill

Part of the Anthropic Cybersecurity Skills library, which contains 754 production-grade cybersecurity skills across 26 security domains with mappings to MITRE ATT&CK, NIST CSF, and other frameworks. Compatible with Claude Code, Cursor, and 26+ AI agent platforms.

securing-container-registry-images
🎯performing-content-security-policy-bypass🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains. Compatible with Claude Code, Cursor, Codex, Gemini CLI, and other agent frameworks.

performing-content-security-policy-bypass
🎯triaging-security-alerts-in-splunk🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 26 security domains with over 750 skills. It works across five frameworks and provides practical cybersecurity workflow guidance for security operations, threat analysis, and incident response.

triaging-security-alerts-in-splunk
🎯deobfuscating-powershell-obfuscated-malware🎯Skill

A CLI skill for the Meticulous tool that records user sessions and replays them to catch visual regressions, with support for global options and integration with the @alwaysmeticulous/cli package.

deobfuscating-powershell-obfuscated-malware
🎯configuring-host-based-intrusion-detection🎯Skill

Part of a 754-skill open-source cybersecurity library for AI agents, covering 26 security domains across 5 frameworks including Claude Code, with skills for security testing, vulnerability assessment, and defensive operations.

configuring-host-based-intrusion-detection
🎯performing-ssl-tls-security-assessment🎯Skill

A cybersecurity skill from a library of 754 production-grade skills across 26 security domains, providing AI agents with structured guidance for performing SSL/TLS security assessments.

performing-ssl-tls-security-assessment
🎯hardening-linux-endpoint-with-cis-benchmark🎯Skill

Part of an open-source cybersecurity skills library for AI agents with 754 skills spanning 26 security domains, designed for use across 5 frameworks and 26+ platforms.

hardening-linux-endpoint-with-cis-benchmark
🎯detecting-aws-credential-exposure-with-trufflehog🎯Skill

A personal skills directory for AI coding agents, compatible with 40+ agent platforms including Claude Code, Cursor, Codex, and others, with CLI-based installation for individual or bulk skill setup.

detecting-aws-credential-exposure-with-trufflehog
🎯exploiting-active-directory-with-bloodhound🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains with compatibility for Claude Code, Cursor, Codex, and other platforms.

exploiting-active-directory-with-bloodhound
🎯performing-android-app-static-analysis-with-mobsf🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides AI agents through Android app static analysis using MobSF, part of a 754-skill collection spanning 26 security domains with MITRE ATT&CK and NIST framework mappings.

performing-android-app-static-analysis-with-mobsf
🎯performing-clickjacking-attack-test🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains and compatible with Claude Code, Cursor, and 26+ agent platforms.

performing-clickjacking-attack-test
🎯configuring-pfsense-firewall-rules🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains and compatible with 5 major agent frameworks.

configuring-pfsense-firewall-rules
🎯exploiting-active-directory-certificate-services-esc1🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains. This skill covers exploiting Active Directory Certificate Services ESC1 vulnerabilities, compatible with Claude Code, Cursor, Gemini CLI, and other agent frameworks.

exploiting-active-directory-certificate-services-esc1
🎯exploiting-bgp-hijacking-vulnerabilities🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms.

exploiting-bgp-hijacking-vulnerabilities
🎯implementing-devsecops-security-scanning🎯Skill

A cybersecurity skill for implementing DevSecOps security scanning pipelines, part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains for AI agents.

implementing-devsecops-security-scanning
🎯securing-aws-iam-permissions🎯Skill

An open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains, compatible with Claude Code, Codex, Cursor, and other agent frameworks.

securing-aws-iam-permissions
🎯performing-http-parameter-pollution-attack🎯Skill

Part of a 754-skill open-source cybersecurity library for AI agents, covering 26 security domains across 5 frameworks including Claude Code, with skills for security testing, vulnerability assessment, and defensive operations.

performing-http-parameter-pollution-attack
🎯performing-network-traffic-analysis-with-tshark🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, covering areas from memory forensics to cloud breach investigation.

performing-network-traffic-analysis-with-tshark
🎯reverse-engineering-ransomware-encryption-routine🎯Skill

Part of a 754-skill open-source cybersecurity library spanning 26 security domains, this skill provides AI agents with structured guidance for reverse-engineering ransomware encryption routines. Compatible with Claude Code, Cursor, and other major AI coding assistants.

reverse-engineering-ransomware-encryption-routine
🎯achieving-cmmc-level-2-compliance🎯Skill

Skill

achieving-cmmc-level-2-compliance
🎯reverse-engineering-rust-malware🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library (754 skills across 26 domains), focused on reverse engineering Rust-compiled malware as part of the malware analysis domain covering static/dynamic analysis and sandboxing.

reverse-engineering-rust-malware
🎯performing-authenticated-vulnerability-scan🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains compatible with 5 frameworks and 26+ platforms.

performing-authenticated-vulnerability-scan
🎯configuring-certificate-authority-with-openssl🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including network defense, threat analysis, and compliance, compatible with five agent frameworks.

configuring-certificate-authority-with-openssl
🎯securing-api-gateway-with-aws-waf🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings. Covers incident response, cloud security, malware analysis, threat intelligence, and more, compatible with 26+ AI platforms.

securing-api-gateway-with-aws-waf
🎯remediating-s3-bucket-misconfiguration🎯Skill

Part of the Anthropic Cybersecurity Skills library with 754 skills across 26 security domains, this skill provides guidance on identifying and remediating S3 bucket misconfigurations to prevent unauthorized access and data exposure.

remediating-s3-bucket-misconfiguration
🎯performing-wireless-security-assessment-with-kismet🎯Skill

A cybersecurity skill from the largest open-source security skills library for AI agents, covering 754 skills across 26 security domains and compatible with Claude Code, Cursor, and other major agent platforms.

performing-wireless-security-assessment-with-kismet
🎯detecting-email-account-compromise🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Cursor, Gemini CLI, and other AI agent platforms for defensive security analysis and incident response tasks.

detecting-email-account-compromise
🎯monitoring-darkweb-sources🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains with support for 5 frameworks and 26+ platforms.

monitoring-darkweb-sources
🎯performing-blind-ssrf-exploitation🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains and 5 frameworks. Compatible with 26+ platforms including Claude Code, Cursor, and Codex for security auditing, penetration testing, and vulnerability assessment.

performing-blind-ssrf-exploitation
🎯scanning-kubernetes-manifests-with-kubesec🎯Skill

Part of a 754-skill cybersecurity library spanning 26 security domains and 5 framework mappings, providing production-grade security skills for AI agents across 26+ compatible platforms.

scanning-kubernetes-manifests-with-kubesec
🎯configuring-windows-defender-advanced-settings🎯Skill

Part of the Anthropic Cybersecurity Skills library with 754 production-grade skills across 26 security domains, this skill provides guidance on configuring Windows Defender advanced settings for AI-assisted security operations.

configuring-windows-defender-advanced-settings
🎯performing-osint-with-spiderfoot🎯Skill

A cybersecurity skill for performing open-source intelligence (OSINT) gathering with SpiderFoot, part of a 754-skill library spanning 26 security domains with mappings to MITRE ATT&CK, NIST CSF 2.0, and three other frameworks.

performing-osint-with-spiderfoot
🎯performing-ai-driven-osint-correlation🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides AI agents through open-source intelligence (OSINT) data correlation, supporting reconnaissance workflows aligned with the MITRE ATT&CK framework.

performing-ai-driven-osint-correlation
🎯exploiting-kerberoasting-with-impacket🎯Skill

The largest open-source cybersecurity skills library for AI agents, covering 26 security domains with over 750 skills and supporting five major agent frameworks for tasks like vulnerability assessment, penetration testing, and incident response.

exploiting-kerberoasting-with-impacket
🎯detecting-aws-iam-privilege-escalation🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents. The library covers MITRE ATT&CK tactics including privilege escalation, credential access, defense evasion, lateral movement detection, and persistence analysis for security-focused AI workflows.

detecting-aws-iam-privilege-escalation
🎯integrating-sast-into-github-actions-pipeline🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, which provides 754 production-grade security skills across 26 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, and three additional industry frameworks.

integrating-sast-into-github-actions-pipeline
🎯performing-graphql-introspection-attack🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with mappings to MITRE ATT&CK, OWASP, NIST, CIS, and PTES frameworks.

performing-graphql-introspection-attack
🎯hunting-credential-stuffing-attacks🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains compatible with Claude Code, Codex, Cursor, and other AI coding assistants.

hunting-credential-stuffing-attacks
🎯detecting-supply-chain-attacks-in-ci-cd🎯Skill

A cybersecurity skill from a library of 754 skills across 26 security domains, focused on detecting supply chain attacks in CI/CD pipelines using structured analysis aligned with MITRE ATT&CK and NIST frameworks.

detecting-supply-chain-attacks-in-ci-cd
🎯scanning-infrastructure-with-nessus🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains and 5 frameworks for use with Claude Code, Cursor, Codex, and other AI coding tools.

scanning-infrastructure-with-nessus
🎯extracting-credentials-from-memory-dump🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, the largest open-source collection with 754 skills across 26 security domains for AI agents. Compatible with 5 frameworks and 26+ platforms.

extracting-credentials-from-memory-dump
🎯performing-wireless-network-penetration-test🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms.

performing-wireless-network-penetration-test
🎯performing-container-security-scanning-with-trivy🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains. This skill focuses on container security scanning with Trivy and is compatible with five major agent frameworks.

performing-container-security-scanning-with-trivy
🎯exploiting-zerologon-vulnerability-cve-2020-1472🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source collection of 754 cybersecurity skills across 26 security domains for AI agents, compatible with Claude Code, Cursor, Codex CLI, and other platforms.

exploiting-zerologon-vulnerability-cve-2020-1472
🎯configuring-windows-event-logging-for-detection🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, compatible with Claude Code and 26+ AI platforms.

configuring-windows-event-logging-for-detection
🎯detecting-aws-cloudtrail-anomalies🎯Skill

A cybersecurity skill for detecting anomalies in AWS CloudTrail logs, part of the largest open-source cybersecurity skills library with 754+ skills across 26 security domains and 5 frameworks.

detecting-aws-cloudtrail-anomalies
🎯performing-active-directory-penetration-test🎯Skill

Guides AI agents through Active Directory penetration testing procedures, part of an open-source library of 754 cybersecurity skills mapped to five industry frameworks including MITRE ATT&CK and NIST CSF 2.0.

performing-active-directory-penetration-test
🎯performing-open-source-intelligence-gathering🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with support for five frameworks and 26+ compatible platforms including Claude Code, Cursor, and GitHub Copilot.

performing-open-source-intelligence-gathering
🎯configuring-microsegmentation-for-zero-trust🎯Skill

Part of a library of 754 production-grade cybersecurity skills spanning 26 security domains, designed to give AI agents the security knowledge of a senior analyst with framework mappings for MITRE ATT&CK, NIST, and more.

configuring-microsegmentation-for-zero-trust
🎯deploying-tailscale-for-zero-trust-vpn🎯Skill

A library of 754 production-grade cybersecurity skills spanning 26 security domains, compatible with 5 frameworks and over 26 AI platforms. Provides structured knowledge for AI agents to perform security analysis like a senior analyst.

deploying-tailscale-for-zero-trust-vpn
🎯performing-oauth-scope-minimization-review🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains including OAuth scope review, threat modeling, vulnerability assessment, and compliance auditing.

performing-oauth-scope-minimization-review
🎯performing-hash-cracking-with-hashcat🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including offensive testing, defensive analysis, and compliance, compatible with five major agent frameworks.

performing-hash-cracking-with-hashcat
🎯performing-mobile-app-certificate-pinning-bypass🎯Skill

Part of a production-grade cybersecurity skills library with 754 structured skills across 26 security domains, providing AI agents with senior analyst-level security capabilities including threat detection, incident response, and vulnerability analysis.

performing-mobile-app-certificate-pinning-bypass
🎯generating-threat-intelligence-reports🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 production-grade skills across 26 security domains with 5 framework mappings and compatibility with 26+ AI platforms.

generating-threat-intelligence-reports
🎯performing-network-forensics-with-wireshark🎯Skill

Teaches AI agents how to perform network forensics using Wireshark, part of a 754-skill open-source cybersecurity library covering 26 security domains and 5 framework mappings.

performing-network-forensics-with-wireshark
🎯performing-privilege-escalation-assessment🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 structured skills across 26 security domains with mappings to 5 major frameworks. Covers memory forensics, Sigma rules, cloud breach scoping, and more, compatible with 26+ AI platforms.

performing-privilege-escalation-assessment
🎯configuring-suricata-for-network-monitoring🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains including network monitoring, threat detection, incident response, and compliance frameworks.

configuring-suricata-for-network-monitoring
🎯exploiting-nopac-cve-2021-42278-42287🎯Skill

Part of a large open-source cybersecurity skills library with over 750 skills across 26 security domains, providing AI agents with structured knowledge for security assessments and vulnerability analysis.

exploiting-nopac-cve-2021-42278-42287
🎯containing-active-breach🎯Skill

Part of the Anthropic Cybersecurity Skills library, an open-source collection of 754 cybersecurity skills across 26 security domains, compatible with Claude Code, Cursor, and 26+ AI agent platforms.

containing-active-breach
🎯securing-kubernetes-on-cloud🎯Skill

A cybersecurity skill from a library of 754 skills across 26 security domains, providing structured guidance for securing Kubernetes clusters on cloud platforms with framework mappings to MITRE ATT&CK and NIST.

securing-kubernetes-on-cloud
🎯performing-privilege-escalation-on-linux🎯Skill

Guides AI agents through Linux privilege escalation techniques for security assessments, part of an open-source library of 754 cybersecurity skills mapped to five industry frameworks including MITRE ATT&CK and NIST CSF 2.0.

performing-privilege-escalation-on-linux
🎯performing-cryptographic-audit-of-application🎯Skill

An open-source cybersecurity skills library with 754 skills across 26 security domains, compatible with Claude Code, Cursor, Codex, and other AI coding agents through the Agent Skills standard.

performing-cryptographic-audit-of-application
🎯hunting-advanced-persistent-threats🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains compatible with 5 agent frameworks and 26+ platforms including Claude Code, Cursor, and Gemini CLI.

hunting-advanced-persistent-threats
🎯securing-remote-access-to-ot-environment🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, which provides 754 structured security skills across 26 domains for AI coding agents. Compatible with Claude Code, Cursor, Codex, and other Agent Skills-compatible platforms.

securing-remote-access-to-ot-environment
🎯securing-aws-lambda-execution-roles🎯Skill

Part of a comprehensive open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, designed to give AI agents the security analysis capabilities of a senior analyst across 5 framework mappings and 26+ AI platforms.

securing-aws-lambda-execution-roles
🎯securing-helm-chart-deployments🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains. Compatible with 5 agent frameworks and covers areas from network security and cloud hardening to threat hunting, incident response, and compliance auditing.

securing-helm-chart-deployments
🎯performing-container-image-hardening🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 production-grade skills spanning 26 security domains and 5 framework mappings. Compatible with over 26 AI platforms including Claude Code, Cursor, and GitHub Copilot.

performing-container-image-hardening
🎯configuring-ldap-security-hardening🎯Skill

An LDAP security hardening skill from the Anthropic Cybersecurity Skills library, which contains 754 structured cybersecurity skills across 26 security domains, mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, and MITRE D3FEND.

configuring-ldap-security-hardening
🎯performing-kubernetes-penetration-testing🎯Skill

Part of a large open-source cybersecurity skills library with over 750 skills across 26 security domains, designed for AI agents to perform security assessments and penetration testing tasks.

performing-kubernetes-penetration-testing
🎯implementing-api-security-testing-with-42crunch🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains and 5 frameworks, this skill focuses on implementing API security testing using the 42Crunch platform.

implementing-api-security-testing-with-42crunch
🎯detecting-arp-poisoning-in-network-traffic🎯Skill

A cybersecurity skill for detecting ARP poisoning in network traffic, part of a 754-skill library spanning 26 security domains with mappings to MITRE ATT&CK, NIST CSF 2.0, and three other industry frameworks.

detecting-arp-poisoning-in-network-traffic
🎯detecting-s3-data-exfiltration-attempts🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, giving AI agents senior analyst-level knowledge for incident response, threat detection, and cloud security.

detecting-s3-data-exfiltration-attempts
🎯performing-network-packet-capture-analysis🎯Skill

Part of a 754-skill cybersecurity library spanning 26 security domains, designed to give AI agents the security knowledge of a senior analyst. Includes structured skills for forensics, threat detection, cloud security, and more, compatible with Claude Code, Cursor, and 26+ AI platforms.

performing-network-packet-capture-analysis
🎯performing-graphql-depth-limit-attack🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that guides practitioners through GraphQL depth limit attack techniques for API security testing. Part of an API Security collection covering GraphQL, REST, OWASP API Top 10, and WAF bypass.

performing-graphql-depth-limit-attack
🎯deploying-cloudflare-access-for-zero-trust🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains compatible with 5 agent frameworks and 26+ platforms including Claude Code, Cursor, and Copilot.

deploying-cloudflare-access-for-zero-trust
🎯performing-docker-bench-security-assessment🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code.

performing-docker-bench-security-assessment
🎯performing-dark-web-monitoring-for-threats🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, covering areas from memory forensics and threat detection to cloud security.

performing-dark-web-monitoring-for-threats
🎯detecting-business-email-compromise🎯Skill

The largest open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, 5 framework mappings, and compatibility with 26+ AI platforms for giving AI agents senior analyst-level security capabilities.

detecting-business-email-compromise
🎯exploiting-constrained-delegation-abuse🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with mappings to five major security frameworks.

exploiting-constrained-delegation-abuse
🎯detecting-privilege-escalation-attempts🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source collection with 754 cybersecurity skills across 26 security domains and mappings to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF frameworks.

detecting-privilege-escalation-attempts
🎯configuring-hsm-for-key-storage🎯Skill

Part of the Anthropic Cybersecurity Skills library (754 skills across 26 security domains), falling under the Cryptography domain which covers TLS, certificate transparency, and key management for AI agents.

configuring-hsm-for-key-storage
🎯detecting-credential-dumping-techniques🎯Skill

Part of a large open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, designed for AI agents to perform security analysis and threat detection.

detecting-credential-dumping-techniques
🎯hardening-windows-endpoint-with-cis-benchmark🎯Skill

Skill

hardening-windows-endpoint-with-cis-benchmark
🎯detecting-container-escape-attempts🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills spanning 26 security domains and 5 framework mappings, compatible with Claude Code and 26+ AI platforms.

detecting-container-escape-attempts
🎯hunting-for-webshell-activity🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with multiple agent frameworks including Claude Code, Cursor, and OpenClaw.

hunting-for-webshell-activity
🎯detecting-email-forwarding-rules-attack🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, which provides 754 production-ready skills across 26 security domains for AI agents including Claude Code, Cursor, Codex, and Gemini CLI.

detecting-email-forwarding-rules-attack
🎯mapping-mitre-attack-techniques🎯Skill

Skill

mapping-mitre-attack-techniques
🎯performing-ssl-certificate-lifecycle-management🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754+ skills across 26 security domains and 5 frameworks for comprehensive security automation and analysis.

performing-ssl-certificate-lifecycle-management
🎯detecting-anomalies-in-industrial-control-systems🎯Skill

A cybersecurity skill for detecting anomalies in industrial control systems, part of the largest open-source cybersecurity skills library with 754+ skills across 26 security domains and 5 frameworks.

detecting-anomalies-in-industrial-control-systems
🎯detecting-typosquatting-packages-in-npm-pypi🎯Skill

Skill

detecting-typosquatting-packages-in-npm-pypi
🎯detecting-network-scanning-with-ids-signatures🎯Skill

Skill

detecting-network-scanning-with-ids-signatures
🎯configuring-active-directory-tiered-model🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including Active Directory tiered model configuration, with support for five security frameworks.

configuring-active-directory-tiered-model
🎯performing-external-network-penetration-test🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that provides structured playbooks for conducting external network penetration tests, with MITRE ATT&CK mappings and step-by-step workflows.

performing-external-network-penetration-test
🎯securing-container-registry-with-harbor🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains. Covers forensics, threat hunting, cloud security, compliance, and more, with mappings to five major security frameworks.

securing-container-registry-with-harbor
🎯correlating-threat-campaigns🎯Skill

A skill from Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms.

correlating-threat-campaigns
🎯detecting-dns-exfiltration-with-dns-query-analysis🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library, which provides 754+ skills across 26 security domains. Focuses on detecting DNS-based data exfiltration through DNS query pattern analysis for AI security agents.

detecting-dns-exfiltration-with-dns-query-analysis
🎯abusing-shadow-credentials-for-privesc🎯Skill

Skill

abusing-shadow-credentials-for-privesc
🎯configuring-aws-verified-access-for-ztna🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Cursor, and other AI coding assistants.

configuring-aws-verified-access-for-ztna
🎯detecting-compromised-cloud-credentials🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains. Compatible with 5 agent frameworks and 26+ platforms, covering areas from cloud security to incident response and threat hunting.

detecting-compromised-cloud-credentials
🎯implementing-llm-guardrails-for-security🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings, compatible with 26+ AI platforms including Claude Code, Cursor, and Codex.

implementing-llm-guardrails-for-security
🎯performing-ssl-tls-inspection-configuration🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with five frameworks and 26+ platforms for comprehensive security automation.

performing-ssl-tls-inspection-configuration
🎯integrating-dast-with-owasp-zap-in-pipeline🎯Skill

Skill

integrating-dast-with-owasp-zap-in-pipeline
🎯exploiting-ms17-010-eternalblue-vulnerability🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with 5 agent frameworks and 26+ platforms, benchmarked for practical security operations.

exploiting-ms17-010-eternalblue-vulnerability
🎯performing-privileged-account-discovery🎯Skill

An open-source library of 754 production-grade cybersecurity skills spanning 26 security domains, compatible with 26+ AI platforms and 5 security frameworks.

performing-privileged-account-discovery
🎯configuring-snort-ids-for-intrusion-detection🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains with support for five agent frameworks and 26+ platforms.

configuring-snort-ids-for-intrusion-detection
🎯performing-agentless-vulnerability-scanning🎯Skill

Provides structured workflows for performing vulnerability scans without deploying agents on target systems, covering scanning tools, patch prioritization, and CVSS assessment. Part of the Anthropic Cybersecurity Skills library with 754 skills across 26 security domains.

performing-agentless-vulnerability-scanning
🎯performing-ssl-stripping-attack🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains including network security, web application security, cloud security, and incident response. Compatible with five major agent frameworks and 26+ platforms.

performing-ssl-stripping-attack
🎯detecting-aws-guardduty-findings-automation🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains. Compatible with Claude Code, Cursor, Codex, Gemini CLI, and other agent frameworks.

detecting-aws-guardduty-findings-automation
🎯implementing-semgrep-for-custom-sast-rules🎯Skill

A skill from the Anthropic Cybersecurity Skills library, the largest open-source collection of cybersecurity skills for AI agents, covering 754 skills across 26 security domains and 5 compatible frameworks.

implementing-semgrep-for-custom-sast-rules
🎯performing-cloud-penetration-testing-with-pacu🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 skills across 26 security domains and compatibility with 5 agent frameworks.

performing-cloud-penetration-testing-with-pacu
🎯performing-red-team-phishing-with-gophish🎯Skill

A skill from the Anthropic Cybersecurity Skills library that guides AI agents through red team phishing campaigns using GoPhish, covering campaign setup, template creation, and result analysis across authorized security testing scenarios.

performing-red-team-phishing-with-gophish
🎯extracting-windows-event-logs-artifacts🎯Skill

Part of a comprehensive open-source cybersecurity skills library with 754 skills across 26 security domains for AI agents. Designed for use with Claude Code, Cursor, Codex, Gemini CLI, and other agent platforms, supporting five major agent frameworks.

extracting-windows-event-logs-artifacts
🎯performing-yara-rule-development-for-detection🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing YARA rule development capabilities for threat detection across 26 security domains with over 750 specialized skills.

performing-yara-rule-development-for-detection
🎯configuring-multi-factor-authentication-with-duo🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains. Compatible with Claude Code, Cursor, Windsurf, and other agent platforms, covering topics from multi-factor authentication to threat detection and incident response.

configuring-multi-factor-authentication-with-duo
🎯extracting-iocs-from-malware-samples🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with 5 agent frameworks and 26+ platforms including Claude Code, Cursor, and Gemini CLI.

extracting-iocs-from-malware-samples
🎯performing-threat-hunting-with-elastic-siem🎯Skill

A cybersecurity skill for performing threat hunting with structured playbooks, covering hypothesis-driven hunts, living-off-the-land detection, and behavioral analytics. Part of the largest open-source cybersecurity skills library with 754+ skills across 26 security domains.

performing-threat-hunting-with-elastic-siem
🎯performing-cve-prioritization-with-kev-catalog🎯Skill

A skill from the Anthropic Cybersecurity Skills library that guides AI agents through CVE prioritization using CISA's Known Exploited Vulnerabilities (KEV) catalog. Part of an open-source collection of 754 cybersecurity skills spanning 26 security domains.

performing-cve-prioritization-with-kev-catalog
🎯implementing-gdpr-data-protection-controls🎯Skill

Skill

implementing-gdpr-data-protection-controls
🎯detecting-attacks-on-historian-servers🎯Skill

A skill from the Anthropic Cybersecurity Skills library that provides AI agents with procedures for detecting attacks targeting historian servers in OT/ICS environments, covering protocols like Modbus, DNP3, and IEC 62443.

detecting-attacks-on-historian-servers
🎯hunting-for-anomalous-powershell-execution🎯Skill

Skill

hunting-for-anomalous-powershell-execution
🎯performing-endpoint-forensics-investigation🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with 5 agent frameworks and 26+ platforms including Claude Code, Cursor, and Gemini CLI.

performing-endpoint-forensics-investigation
🎯deploying-ransomware-canary-files🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with 5 agent frameworks and 26+ platforms.

deploying-ransomware-canary-files
🎯detecting-suspicious-oauth-application-consent🎯Skill

Skill

detecting-suspicious-oauth-application-consent
🎯performing-serverless-function-security-review🎯Skill

A serverless function security review skill from the largest open-source cybersecurity skills library, featuring 754 skills across 26 security domains compatible with Claude Code, Cursor, Codex, and other AI coding platforms.

performing-serverless-function-security-review
🎯intercepting-mobile-traffic-with-burpsuite🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains compatible with five agent frameworks including Claude Code and Cursor.

intercepting-mobile-traffic-with-burpsuite
🎯hunting-for-data-exfiltration-indicators🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains including threat hunting, incident response, and vulnerability analysis, compatible with Claude Code, Cursor, and other coding assistants.

hunting-for-data-exfiltration-indicators
🎯implementing-aes-encryption-for-data-at-rest🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains and compatible with 5 frameworks and 26+ platforms including Claude Code, Cursor, and other AI coding assistants.

implementing-aes-encryption-for-data-at-rest
🎯hunting-for-unusual-network-connections🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, Gemini CLI, and Codex.

hunting-for-unusual-network-connections
🎯detecting-azure-storage-account-misconfigurations🎯Skill

Skill

detecting-azure-storage-account-misconfigurations
🎯detecting-pass-the-hash-attacks🎯Skill

Skill

detecting-pass-the-hash-attacks
🎯performing-ios-app-security-assessment🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 skills across 26 security domains compatible with Claude Code, Cursor, and other AI coding assistants across 5 agent frameworks.

performing-ios-app-security-assessment
🎯detecting-lateral-movement-in-network🎯Skill

Skill

detecting-lateral-movement-in-network
🎯implementing-api-threat-protection-with-apigee🎯Skill

An open-source library of 754 production-grade cybersecurity skills for AI agents, covering 26 security domains including threat intelligence, incident response, and cloud security. Every skill is mapped to five industry frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF.

implementing-api-threat-protection-with-apigee
🎯performing-memory-forensics-with-volatility3🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 skills across 26 security domains and compatibility with 5 agent frameworks.

performing-memory-forensics-with-volatility3
🎯performing-binary-exploitation-analysis🎯Skill

Part of the Anthropic Cybersecurity Skills library, an open-source collection of 754 cybersecurity skills across 26 security domains, compatible with Claude Code, Cursor, and 26+ AI agent platforms.

performing-binary-exploitation-analysis
🎯detecting-cryptomining-in-cloud🎯Skill

Part of a library of 754 production-grade cybersecurity skills spanning 26 security domains and mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, and MITRE D3FEND, providing expert-level security guidance for AI agents.

detecting-cryptomining-in-cloud
🎯detecting-business-email-compromise-with-ai🎯Skill

A slide presentation framework built for AI agents where you describe your deck in natural language and the coding agent writes the React code, handling canvas scaling, navigation, hot reload, and present mode automatically.

detecting-business-email-compromise-with-ai
🎯hunting-for-dns-based-persistence🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains. Covers threat hunting, memory forensics, cloud breach scoping, and Sigma rules, compatible with Claude Code, Cursor, and 26+ AI platforms.

hunting-for-dns-based-persistence
🎯performing-red-team-with-covenant🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents, with 24 Red Teaming skills covering full-scope engagements, Active Directory attacks, and phishing simulation.

performing-red-team-with-covenant
🎯configuring-identity-aware-proxy-with-google-iap🎯Skill

Part of an open-source library of 754 cybersecurity skills for AI agents, spanning 26 security domains with 5 framework mappings. Provides structured, production-grade security knowledge compatible with 26+ AI platforms.

configuring-identity-aware-proxy-with-google-iap
🎯performing-mobile-device-forensics-with-cellebrite🎯Skill

Part of the largest open-source cybersecurity skills library with 754 production-grade skills across 26 security domains, providing AI agents with structured knowledge for penetration testing, incident response, and security operations.

performing-mobile-device-forensics-with-cellebrite
🎯performing-threat-hunting-with-yara-rules🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains with compatibility for 5 frameworks and 26+ platforms.

performing-threat-hunting-with-yara-rules
🎯detecting-deepfake-audio-in-vishing-attacks🎯Skill

Skill

detecting-deepfake-audio-in-vishing-attacks
🎯executing-phishing-simulation-campaign🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source collection with 754 production-grade cybersecurity skills across 26 security domains, compatible with 5 framework mappings and 26+ AI platforms including Claude Code and Cursor.

executing-phishing-simulation-campaign
🎯profiling-threat-actor-groups🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains. Compatible with 5 major frameworks and 26+ platforms for comprehensive security analysis, threat detection, and defensive operations.

profiling-threat-actor-groups
🎯securing-azure-with-microsoft-defender🎯Skill

A skill from the Anthropic Cybersecurity Skills library, an open-source collection providing 754 cybersecurity skills across 26 security domains for AI agents, compatible with 5 agent frameworks.

securing-azure-with-microsoft-defender
🎯securing-historian-server-in-ot-environment🎯Skill

Part of the Anthropic Cybersecurity Skills library, which provides 754 production-grade cybersecurity skills across 26 security domains to give AI agents senior analyst-level security capabilities on 26+ platforms.

securing-historian-server-in-ot-environment
🎯performing-user-behavior-analytics🎯Skill

A cybersecurity skill focused on user behavior analytics, part of the largest open-source security skills library covering 26 domains with 754 skills across 5 agent frameworks.

performing-user-behavior-analytics
🎯performing-authenticated-scan-with-openvas🎯Skill

Skill

performing-authenticated-scan-with-openvas
🎯detecting-dll-sideloading-attacks🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, with 754 skills across 26 security domains including endpoint security, red teaming, incident response, and penetration testing. Compatible with five major agent frameworks.

detecting-dll-sideloading-attacks
🎯detecting-insider-threat-behaviors🎯Skill

A cybersecurity skill from the largest open-source security skills library for AI agents, providing structured workflows for detecting insider threat behaviors, mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF frameworks.

detecting-insider-threat-behaviors
🎯performing-privacy-impact-assessment🎯Skill

The largest open-source cybersecurity skills library for AI agents, covering 26 security domains with 754 skills across 5 frameworks. Compatible with Claude Code, OpenClaw, Cursor, and 26+ other platforms.

performing-privacy-impact-assessment
🎯detecting-rootkit-activity🎯Skill

Skill

detecting-rootkit-activity
🎯detecting-azure-lateral-movement🎯Skill

Part of an open-source library of 754 cybersecurity skills for AI agents, covering 26 security domains including cloud security, network defense, and incident response. Compatible with Claude Code, Cursor, and 26+ other AI platforms.

detecting-azure-lateral-movement
🎯detecting-fileless-attacks-on-endpoints🎯Skill

Skill

detecting-fileless-attacks-on-endpoints
🎯performing-privileged-account-access-review🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains and support for 5 frameworks including Claude Code.

performing-privileged-account-access-review
🎯detecting-serverless-function-injection🎯Skill

Part of a 754-skill open-source cybersecurity library for AI agents covering 26 security domains including application security with OWASP Top 10 coverage. Includes mappings to MITRE ATT&CK, NIST CSF, and CIS Controls, compatible with 26+ AI platforms.

detecting-serverless-function-injection
🎯hunting-for-supply-chain-compromise🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains, mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.

hunting-for-supply-chain-compromise
🎯detecting-process-injection-techniques🎯Skill

Skill

detecting-process-injection-techniques
🎯performing-active-directory-vulnerability-assessment🎯Skill

An Active Directory vulnerability assessment skill from the largest open-source cybersecurity skills library, which provides 754 production-grade skills across 26 security domains compatible with 26+ AI platforms.

performing-active-directory-vulnerability-assessment
🎯performing-threat-landscape-assessment-for-sector🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains. Compatible with Claude Code, Cursor, Codex, Gemini CLI, and 20+ other agent platforms, with support for five major frameworks.

performing-threat-landscape-assessment-for-sector
🎯implementing-web-application-logging-with-modsecurity🎯Skill

Skill

implementing-web-application-logging-with-modsecurity
🎯detecting-port-scanning-with-fail2ban🎯Skill

Skill

detecting-port-scanning-with-fail2ban
🎯detecting-cloud-threats-with-guardduty🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754 production-grade skills across 26 security domains and 5 framework mappings. Compatible with Claude Code, Cursor, Codex, and 26+ other AI platforms.

detecting-cloud-threats-with-guardduty
🎯detecting-container-escape-with-falco-rules🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with 5 agent frameworks including Claude Code.

detecting-container-escape-with-falco-rules
🎯detecting-container-drift-at-runtime🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 26 security domains with over 754 skills. Compatible with five agent frameworks including Claude Code, Cursor, and Codex.

detecting-container-drift-at-runtime
🎯recovering-from-ransomware-attack🎯Skill

Skill

recovering-from-ransomware-attack
🎯performing-dns-enumeration-and-zone-transfer🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings, compatible with 26+ AI platforms including Claude Code and Cursor.

performing-dns-enumeration-and-zone-transfer
🎯performing-purple-team-exercise🎯Skill

The largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains and 5 frameworks. Compatible with 26+ platforms including Claude Code, Cursor, and other AI coding assistants.

performing-purple-team-exercise
🎯performing-supply-chain-attack-simulation🎯Skill

A skill from the Anthropic Cybersecurity Skills library, the largest open-source collection of cybersecurity skills for AI agents, covering 754 skills across 26 security domains and compatible with 5 frameworks and 26+ platforms.

performing-supply-chain-attack-simulation
🎯performing-arp-spoofing-attack-simulation🎯Skill

The largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains. Compatible with 26+ platforms and 5 frameworks for comprehensive security assessment and education.

performing-arp-spoofing-attack-simulation
🎯performing-active-directory-bloodhound-analysis🎯Skill

Part of the Anthropic Cybersecurity Skills library, the largest open-source collection of cybersecurity skills for AI agents, covering 754 skills across 26 security domains with support for multiple agent frameworks.

performing-active-directory-bloodhound-analysis
🎯implementing-github-advanced-security-for-code-scanning🎯Skill

Skill

implementing-github-advanced-security-for-code-scanning
🎯performing-soap-web-service-security-testing🎯Skill

Part of the Anthropic Cybersecurity Skills library with 754 production-grade skills across 26 security domains covering web application security, network security, malware analysis, threat hunting, cloud security, and more, with mappings to five industry frameworks.

performing-soap-web-service-security-testing
🎯performing-linux-log-forensics-investigation🎯Skill

Skill

performing-linux-log-forensics-investigation
🎯detecting-qr-code-phishing-with-email-security🎯Skill

Skill

detecting-qr-code-phishing-with-email-security
🎯hunting-for-unusual-service-installations🎯Skill

Skill

hunting-for-unusual-service-installations
🎯performing-aws-privilege-escalation-assessment🎯Skill

A CLI tool that scans your project to detect its tech stack and automatically installs curated AI coding skills tailored to your development environment.

performing-aws-privilege-escalation-assessment
🎯performing-firmware-malware-analysis🎯Skill

Skill

performing-firmware-malware-analysis
🎯detecting-golden-ticket-attacks-in-kerberos-logs🎯Skill

Skill

detecting-golden-ticket-attacks-in-kerberos-logs
🎯implementing-kubernetes-pod-security-standards🎯Skill

The largest open-source cybersecurity skills library for AI agents, with 754+ skills across 26 security domains. Compatible with multiple agent frameworks and platforms including Claude Code, Codex, and Cursor.

implementing-kubernetes-pod-security-standards
🎯performing-endpoint-vulnerability-remediation🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code.

performing-endpoint-vulnerability-remediation
🎯detecting-azure-service-principal-abuse🎯Skill

Part of the largest open-source cybersecurity skills library with 754 skills across 26 security domains, mapped to five industry frameworks including MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.

detecting-azure-service-principal-abuse
🎯performing-network-traffic-analysis-with-zeek🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains with mappings to ATT&CK, NIST CSF, ATLAS, D3FEND, and AI RMF frameworks.

performing-network-traffic-analysis-with-zeek
🎯performing-malware-triage-with-yara🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 production-grade skills across 26 security domains with 5 framework mappings. Compatible with 26+ AI platforms including Claude Code, providing structured knowledge for malware triage, incident response, and cloud security.

performing-malware-triage-with-yara
🎯detecting-dcsync-attack-in-active-directory🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents. Covers 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms.

detecting-dcsync-attack-in-active-directory
🎯performing-dns-tunneling-detection🎯Skill

Skill

performing-dns-tunneling-detection
🎯implementing-cloud-waf-rules🎯Skill

Skill

implementing-cloud-waf-rules
🎯performing-thick-client-application-penetration-test🎯Skill

Part of a library of 754 production-grade cybersecurity skills spanning 26 security domains, mapped to MITRE ATT&CK, NIST CSF 2.0, and three additional frameworks, providing structured penetration testing guidance for AI agents.

performing-thick-client-application-penetration-test
🎯performing-windows-artifact-analysis-with-eric-zimmerman-tools🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skill library with 754 production-grade skills spanning 26 security domains and 5 framework mappings. Equips AI agents with senior analyst-level security expertise for tasks like memory forensics, threat detection, and incident response.

performing-windows-artifact-analysis-with-eric-zimmerman-tools
🎯implementing-secrets-management-with-vault🎯Skill

Skill

implementing-secrets-management-with-vault
🎯performing-kubernetes-cis-benchmark-with-kube-bench🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains compatible with 5 agent frameworks, covering areas from Kubernetes security to SAST and cloud architecture.

performing-kubernetes-cis-benchmark-with-kube-bench
🎯performing-sqlite-database-forensics🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains, compatible with Claude Code, Cursor, Codex, and other AI coding assistants.

performing-sqlite-database-forensics
🎯performing-malware-hash-enrichment-with-virustotal🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains including malware analysis, digital forensics, threat intelligence, and SOC operations. Compatible with five major AI coding frameworks.

performing-malware-hash-enrichment-with-virustotal
🎯detecting-ransomware-precursors-in-network🎯Skill

Skill

detecting-ransomware-precursors-in-network
🎯performing-service-account-credential-rotation🎯Skill

Skill

performing-service-account-credential-rotation
🎯performing-active-directory-compromise-investigation🎯Skill

Skill

performing-active-directory-compromise-investigation
🎯hunting-for-command-and-control-beaconing🎯Skill

Skill

hunting-for-command-and-control-beaconing
🎯detecting-network-anomalies-with-zeek🎯Skill

Skill

detecting-network-anomalies-with-zeek
🎯detecting-kerberoasting-attacks🎯Skill

Skill

detecting-kerberoasting-attacks
🎯investigating-phishing-email-incident🎯Skill

Skill

investigating-phishing-email-incident
🎯performing-asset-criticality-scoring-for-vulns🎯Skill

Skill

performing-asset-criticality-scoring-for-vulns
🎯performing-dynamic-analysis-of-android-app🎯Skill

Skill

performing-dynamic-analysis-of-android-app
🎯detecting-bluetooth-low-energy-attacks🎯Skill

Part of a comprehensive open-source cybersecurity skills library with 754 skills across 26 security domains, providing AI agents with specialized knowledge for penetration testing, threat detection, and defensive security operations across multiple frameworks and platforms.

detecting-bluetooth-low-energy-attacks
🎯implementing-attack-surface-management🎯Skill

Part of a 754-skill cybersecurity library spanning 26 security domains, giving AI agents structured knowledge for memory forensics, Sigma rule detection, cloud breach scoping, and attack surface management across 5 framework mappings.

implementing-attack-surface-management
🎯implementing-network-access-control🎯Skill

Part of the largest open-source cybersecurity skills library, providing 754 production-grade skills across 26 security domains. Covers network access control implementation with compatibility for Claude Code and 26+ other AI platforms, mapped to five security frameworks.

implementing-network-access-control
🎯performing-vlan-hopping-attack🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that provides structured playbooks for VLAN hopping attack techniques used in network security assessments, with MITRE ATT&CK mappings and verification steps.

performing-vlan-hopping-attack
🎯performing-steganography-detection🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, covering 754 skills across 26 security domains and 5 frameworks. This skill focuses on steganography detection as part of a comprehensive security skill set compatible with Claude Code, Cursor, and other AI coding agents.

performing-steganography-detection
🎯performing-service-account-audit🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, featuring 754 skills across 26 security domains and 5 frameworks. Compatible with Claude Code, Cursor, and other AI coding assistants.

performing-service-account-audit
🎯implementing-zero-trust-network-access🎯Skill

Part of a 754-skill open-source cybersecurity library for AI agents covering 26 security domains including identity and access management with zero trust identity support. Includes mappings to MITRE ATT&CK, NIST CSF, and CIS Controls frameworks across 26+ compatible AI platforms.

implementing-zero-trust-network-access
🎯performing-ot-vulnerability-scanning-safely🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, offering 754 skills across 26 security domains with compatibility for 5 frameworks and 26+ platforms.

performing-ot-vulnerability-scanning-safely
🎯performing-packet-injection-attack🎯Skill

Part of the largest open-source cybersecurity skills library for AI agents, providing 754 structured skills across 26 security domains with mappings to five frameworks, compatible with 26+ AI platforms.

performing-packet-injection-attack
🎯implementing-zero-trust-in-cloud🎯Skill

Skill

implementing-zero-trust-in-cloud
🎯performing-aws-account-enumeration-with-scout-suite🎯Skill

Skill

performing-aws-account-enumeration-with-scout-suite
🎯attacking-oauth-with-device-code-phishing🎯Skill

Skill

attacking-oauth-with-device-code-phishing
🎯executing-active-directory-attack-simulation🎯Skill

The largest open-source cybersecurity skills library for AI agents, containing 754 skills across 26 security domains compatible with 5 agent frameworks and 26+ platforms.

executing-active-directory-attack-simulation
🎯implementing-dmarc-dkim-spf-email-security🎯Skill

Skill

implementing-dmarc-dkim-spf-email-security
🎯performing-ot-network-security-assessment🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing 754 production-grade skills across 26 security domains with 5 framework mappings and compatibility with 26+ AI platforms.

performing-ot-network-security-assessment
🎯detecting-mobile-malware-behavior🎯Skill

Skill

detecting-mobile-malware-behavior
🎯performing-power-grid-cybersecurity-assessment🎯Skill

Part of Anthropic Cybersecurity Skills, an open-source library of 754 cybersecurity skills for AI agents spanning 26 security domains. Compatible with 5 agent frameworks and over 26 platforms.

performing-power-grid-cybersecurity-assessment
🎯hunting-for-dns-tunneling-with-zeek🎯Skill

Skill

hunting-for-dns-tunneling-with-zeek
🎯performing-nist-csf-maturity-assessment🎯Skill

Skill

performing-nist-csf-maturity-assessment
🎯implementing-zero-trust-for-saas-applications🎯Skill

Skill

implementing-zero-trust-for-saas-applications
🎯performing-threat-emulation-with-atomic-red-team🎯Skill

Skill

performing-threat-emulation-with-atomic-red-team
🎯performing-plc-firmware-security-analysis🎯Skill

A cybersecurity skill from the Anthropic Cybersecurity Skills library that provides AI agents with expert-level knowledge for performing PLC firmware security analysis, part of a collection of 754 production-grade skills spanning 26 security domains compatible with 26+ AI platforms.

performing-plc-firmware-security-analysis
🎯hunting-for-data-staging-before-exfiltration🎯Skill

Skill

hunting-for-data-staging-before-exfiltration
🎯hunting-for-spearphishing-indicators🎯Skill

Skill

hunting-for-spearphishing-indicators
🎯detecting-rdp-brute-force-attacks🎯Skill

Skill

detecting-rdp-brute-force-attacks
🎯performing-static-malware-analysis-with-pe-studio🎯Skill

Skill

performing-static-malware-analysis-with-pe-studio
🎯hunting-for-persistence-mechanisms-in-windows🎯Skill

Skill

hunting-for-persistence-mechanisms-in-windows
🎯detecting-privilege-escalation-in-kubernetes-pods🎯Skill

Skill

detecting-privilege-escalation-in-kubernetes-pods
🎯implementing-aws-iam-permission-boundaries🎯Skill

Skill

implementing-aws-iam-permission-boundaries
🎯performing-kubernetes-etcd-security-assessment🎯Skill

Skill

performing-kubernetes-etcd-security-assessment
🎯hunting-for-registry-run-key-persistence🎯Skill

Skill

hunting-for-registry-run-key-persistence
🎯performing-kerberoasting-attack🎯Skill

The largest open-source cybersecurity skills library for AI agents, providing comprehensive security testing and analysis capabilities for defensive security workflows.

performing-kerberoasting-attack
🎯detecting-command-and-control-over-dns🎯Skill

Skill

detecting-command-and-control-over-dns
🎯performing-threat-intelligence-sharing-with-misp🎯Skill

Skill

performing-threat-intelligence-sharing-with-misp
🎯detecting-fileless-malware-techniques🎯Skill

Skill

detecting-fileless-malware-techniques
🎯detecting-beaconing-patterns-with-zeek🎯Skill

Part of Anthropic Cybersecurity Skills, the largest open-source cybersecurity skills library for AI agents with 754 skills across 26 security domains, compatible with 5 frameworks and 26+ platforms.

detecting-beaconing-patterns-with-zeek
🎯performing-ot-vulnerability-assessment-with-claroty🎯Skill

A cybersecurity skill from the largest open-source cybersecurity skills library for AI agents, covering vulnerability assessment techniques distilled from real-world security research and industry frameworks.

performing-ot-vulnerability-assessment-with-claroty
🎯performing-ip-reputation-analysis-with-shodan🎯Skill

Part of the Anthropic Cybersecurity Skills library, which provides 754 production-grade cybersecurity skills across 26 security domains to give AI agents senior analyst-level security capabilities on 26+ platforms.

performing-ip-reputation-analysis-with-shodan
🎯detecting-service-account-abuse🎯Skill

Skill

detecting-service-account-abuse
🎯implementing-threat-modeling-with-mitre-attack🎯Skill

Skill

implementing-threat-modeling-with-mitre-attack
🎯deploying-edr-agent-with-crowdstrike🎯Skill

Part of a 754-skill open-source cybersecurity library covering 26 security domains including endpoint detection, LOTL detection, fileless malware hunting, and persistence analysis across 5 framework mappings.

deploying-edr-agent-with-crowdstrike
🎯performing-phishing-simulation-with-gophish🎯Skill

Skill

performing-phishing-simulation-with-gophish
🎯hunting-for-suspicious-scheduled-tasks🎯Skill

Skill

hunting-for-suspicious-scheduled-tasks
🎯detecting-pass-the-ticket-attacks🎯Skill

Skill

detecting-pass-the-ticket-attacks
🎯performing-container-escape-detection🎯Skill

Skill

performing-container-escape-detection
🎯performing-ransomware-response🎯Skill

Skill

performing-ransomware-response
🎯deploying-active-directory-honeytokens🎯Skill

Skill

deploying-active-directory-honeytokens
🎯implementing-infrastructure-as-code-security-scanning🎯Skill

Skill

implementing-infrastructure-as-code-security-scanning
🎯deploying-osquery-for-endpoint-monitoring🎯Skill

Skill

deploying-osquery-for-endpoint-monitoring
🎯deploying-software-defined-perimeter🎯Skill

Skill

deploying-software-defined-perimeter
🎯performing-cloud-asset-inventory-with-cartography🎯Skill

Skill

performing-cloud-asset-inventory-with-cartography
🎯performing-malware-ioc-extraction🎯Skill

Skill

performing-malware-ioc-extraction
🎯performing-disk-forensics-investigation🎯Skill

Skill

performing-disk-forensics-investigation
🎯implementing-google-workspace-phishing-protection🎯Skill

Skill

implementing-google-workspace-phishing-protection
🎯detecting-ransomware-encryption-behavior🎯Skill

Skill

detecting-ransomware-encryption-behavior
🎯implementing-gdpr-data-subject-access-request🎯Skill

Skill

implementing-gdpr-data-subject-access-request
🎯hunting-for-lateral-movement-via-wmi🎯Skill

Skill

hunting-for-lateral-movement-via-wmi
🎯hunting-for-scheduled-task-persistence🎯Skill

Skill

hunting-for-scheduled-task-persistence
🎯hunting-for-domain-fronting-c2-traffic🎯Skill

Skill

hunting-for-domain-fronting-c2-traffic
🎯hunting-for-dcsync-attacks🎯Skill

Skill

hunting-for-dcsync-attacks
🎯performing-log-analysis-for-forensic-investigation🎯Skill

Skill

performing-log-analysis-for-forensic-investigation
🎯extracting-memory-artifacts-with-rekall🎯Skill

Skill

extracting-memory-artifacts-with-rekall
🎯detecting-process-hollowing-technique🎯Skill

Skill

detecting-process-hollowing-technique
🎯hunting-for-registry-persistence-mechanisms🎯Skill

Skill

hunting-for-registry-persistence-mechanisms
🎯performing-malware-persistence-investigation🎯Skill

Skill

performing-malware-persistence-investigation
🎯implementing-mitre-attack-coverage-mapping🎯Skill

Skill

implementing-mitre-attack-coverage-mapping
🎯hunting-for-process-injection-techniques🎯Skill

Skill

hunting-for-process-injection-techniques
🎯detecting-suspicious-powershell-execution🎯Skill

Skill

detecting-suspicious-powershell-execution
🎯detecting-shadow-it-cloud-usage🎯Skill

Skill

detecting-shadow-it-cloud-usage
🎯deploying-palo-alto-prisma-access-zero-trust🎯Skill

A zero trust deployment skill from the Anthropic Cybersecurity Skills library, the largest open-source cybersecurity skills collection for AI agents with 754 skills across 26 security domains. Part of the Zero Trust Architecture domain (13 skills) covering BeyondCorp, CISA maturity model, and microsegmentation approaches.

deploying-palo-alto-prisma-access-zero-trust
🎯auditing-mcp-servers-for-tool-poisoning🎯Skill

Skill

auditing-mcp-servers-for-tool-poisoning
🎯implementing-aqua-security-for-container-scanning🎯Skill

Skill

implementing-aqua-security-for-container-scanning
🎯implementing-end-to-end-encryption-for-messaging🎯Skill

Skill

implementing-end-to-end-encryption-for-messaging
🎯detecting-exfiltration-over-dns-with-zeek🎯Skill

Skill

detecting-exfiltration-over-dns-with-zeek
🎯hunting-for-living-off-the-cloud-techniques🎯Skill

Skill

hunting-for-living-off-the-cloud-techniques
🎯performing-ransomware-tabletop-exercise🎯Skill

Skill

performing-ransomware-tabletop-exercise
🎯performing-cloud-forensics-investigation🎯Skill

Skill

performing-cloud-forensics-investigation
🎯implementing-hashicorp-vault-dynamic-secrets🎯Skill

Skill

implementing-hashicorp-vault-dynamic-secrets
🎯detecting-modbus-command-injection-attacks🎯Skill

Skill

detecting-modbus-command-injection-attacks
🎯hunting-for-shadow-copy-deletion🎯Skill

Skill

hunting-for-shadow-copy-deletion
🎯detecting-evasion-techniques-in-endpoint-logs🎯Skill

Skill

detecting-evasion-techniques-in-endpoint-logs
🎯correlating-security-events-in-qradar🎯Skill

Skill

correlating-security-events-in-qradar
🎯performing-credential-access-with-lazagne🎯Skill

Skill

performing-credential-access-with-lazagne
🎯implementing-pci-dss-compliance-controls🎯Skill

Skill

implementing-pci-dss-compliance-controls
🎯performing-firmware-extraction-with-binwalk🎯Skill

Skill

performing-firmware-extraction-with-binwalk
🎯performing-active-directory-forest-trust-attack🎯Skill

Skill

performing-active-directory-forest-trust-attack
🎯performing-cloud-native-forensics-with-falco🎯Skill

Skill

performing-cloud-native-forensics-with-falco
🎯detecting-dnp3-protocol-anomalies🎯Skill

Skill

detecting-dnp3-protocol-anomalies
🎯performing-timeline-reconstruction-with-plaso🎯Skill

Skill

performing-timeline-reconstruction-with-plaso
🎯detecting-insider-threat-with-ueba🎯Skill

Skill

detecting-insider-threat-with-ueba
🎯performing-purple-team-atomic-testing🎯Skill

Skill

performing-purple-team-atomic-testing
🎯hunting-for-cobalt-strike-beacons🎯Skill

Skill

hunting-for-cobalt-strike-beacons
🎯performing-memory-forensics-with-volatility3-plugins🎯Skill

Skill

performing-memory-forensics-with-volatility3-plugins
🎯performing-cloud-log-forensics-with-athena🎯Skill

Skill

performing-cloud-log-forensics-with-athena
🎯detecting-ntlm-relay-with-event-correlation🎯Skill

Skill

detecting-ntlm-relay-with-event-correlation
🎯performing-fuzzing-with-aflplusplus🎯Skill

Skill

performing-fuzzing-with-aflplusplus
🎯detecting-insider-data-exfiltration-via-dlp🎯Skill

Skill

detecting-insider-data-exfiltration-via-dlp
🎯performing-lateral-movement-with-wmiexec🎯Skill

Skill

performing-lateral-movement-with-wmiexec
🎯hunting-for-persistence-via-wmi-subscriptions🎯Skill

Skill

hunting-for-persistence-via-wmi-subscriptions
🎯detecting-golden-ticket-forgery🎯Skill

Skill

detecting-golden-ticket-forgery
🎯hunting-for-lolbins-execution-in-endpoint-logs🎯Skill

Skill

hunting-for-lolbins-execution-in-endpoint-logs
🎯hunting-for-ntlm-relay-attacks🎯Skill

Skill

hunting-for-ntlm-relay-attacks
🎯detecting-living-off-the-land-with-lolbas🎯Skill

Skill

detecting-living-off-the-land-with-lolbas
🎯performing-adversary-in-the-middle-phishing-detection🎯Skill

Skill

performing-adversary-in-the-middle-phishing-detection
🎯hunting-for-beaconing-with-frequency-analysis🎯Skill

Skill

hunting-for-beaconing-with-frequency-analysis
🎯configuring-zscaler-private-access-for-ztna🎯Skill

Skill

configuring-zscaler-private-access-for-ztna
🎯processing-stix-taxii-feeds🎯Skill

Skill

processing-stix-taxii-feeds
🎯deploying-decoy-files-for-ransomware-detection🎯Skill

Skill

deploying-decoy-files-for-ransomware-detection
🎯detecting-living-off-the-land-attacks🎯Skill

Skill

detecting-living-off-the-land-attacks
🎯hunting-for-defense-evasion-via-timestomping🎯Skill

Skill

hunting-for-defense-evasion-via-timestomping
🎯implementing-endpoint-detection-with-wazuh🎯Skill

Skill

implementing-endpoint-detection-with-wazuh
🎯performing-soc-tabletop-exercise🎯Skill

Skill

performing-soc-tabletop-exercise
🎯implementing-network-policies-for-kubernetes🎯Skill

Skill

implementing-network-policies-for-kubernetes
🎯implementing-zero-knowledge-proof-for-authentication🎯Skill

Skill

implementing-zero-knowledge-proof-for-authentication
🎯assessing-vector-and-embedding-weaknesses🎯Skill

Skill

assessing-vector-and-embedding-weaknesses
🎯performing-paste-site-monitoring-for-credentials🎯Skill

Skill

performing-paste-site-monitoring-for-credentials
🎯extracting-config-from-agent-tesla-rat🎯Skill

Skill

extracting-config-from-agent-tesla-rat
🎯implementing-cloud-vulnerability-posture-management🎯Skill

Skill

implementing-cloud-vulnerability-posture-management
🎯performing-gcp-penetration-testing-with-gcpbucketbrute🎯Skill

Skill

performing-gcp-penetration-testing-with-gcpbucketbrute
🎯implementing-digital-signatures-with-ed25519🎯Skill

Skill

implementing-digital-signatures-with-ed25519
🎯implementing-iso-27001-information-security-management🎯Skill

Skill

implementing-iso-27001-information-security-management
🎯implementing-ddos-mitigation-with-cloudflare🎯Skill

Skill

implementing-ddos-mitigation-with-cloudflare
🎯performing-cloud-storage-forensic-acquisition🎯Skill

Skill

performing-cloud-storage-forensic-acquisition
🎯detecting-mimikatz-execution-patterns🎯Skill

Skill

detecting-mimikatz-execution-patterns
🎯hunting-for-dcom-lateral-movement🎯Skill

Skill

hunting-for-dcom-lateral-movement
🎯performing-false-positive-reduction-in-siem🎯Skill

Skill

performing-false-positive-reduction-in-siem
🎯detecting-stuxnet-style-attacks🎯Skill

Skill

detecting-stuxnet-style-attacks
🎯implementing-container-image-minimal-base-with-distroless🎯Skill

Skill

implementing-container-image-minimal-base-with-distroless
🎯performing-gcp-security-assessment-with-forseti🎯Skill

Skill

performing-gcp-security-assessment-with-forseti
🎯performing-physical-intrusion-assessment🎯Skill

Skill

performing-physical-intrusion-assessment
🎯performing-dynamic-analysis-with-any-run🎯Skill

Skill

performing-dynamic-analysis-with-any-run
🎯recovering-deleted-files-with-photorec🎯Skill

Skill

recovering-deleted-files-with-photorec
🎯implementing-vulnerability-management-with-greenbone🎯Skill

Skill

implementing-vulnerability-management-with-greenbone
🎯eradicating-malware-from-infected-systems🎯Skill

Skill

eradicating-malware-from-infected-systems
🎯performing-dmarc-policy-enforcement-rollout🎯Skill

Skill

performing-dmarc-policy-enforcement-rollout
🎯implementing-google-workspace-admin-security🎯Skill

Skill

implementing-google-workspace-admin-security
🎯implementing-ransomware-backup-strategy🎯Skill

Skill

implementing-ransomware-backup-strategy
🎯hunting-for-startup-folder-persistence🎯Skill

Skill

hunting-for-startup-folder-persistence
🎯implementing-anti-phishing-training-program🎯Skill

Skill

implementing-anti-phishing-training-program
🎯performing-scada-hmi-security-assessment🎯Skill

Skill

performing-scada-hmi-security-assessment
🎯hunting-for-living-off-the-land-binaries🎯Skill

Skill

hunting-for-living-off-the-land-binaries
🎯implementing-mobile-application-management🎯Skill

Skill

implementing-mobile-application-management
🎯detecting-spearphishing-with-email-gateway🎯Skill

Skill

detecting-spearphishing-with-email-gateway
🎯performing-post-quantum-cryptography-migration🎯Skill

Skill

performing-post-quantum-cryptography-migration
🎯detecting-malicious-scheduled-tasks-with-sysmon🎯Skill

Skill

detecting-malicious-scheduled-tasks-with-sysmon
🎯investigating-ransomware-attack-artifacts🎯Skill

Skill

investigating-ransomware-attack-artifacts
🎯implementing-kubernetes-network-policy-with-calico🎯Skill

Skill

implementing-kubernetes-network-policy-with-calico
🎯performing-cloud-native-threat-hunting-with-aws-detective🎯Skill

Skill

performing-cloud-native-threat-hunting-with-aws-detective
🎯detecting-lateral-movement-with-splunk🎯Skill

Skill

detecting-lateral-movement-with-splunk
🎯performing-cloud-incident-containment-procedures🎯Skill

Skill

performing-cloud-incident-containment-procedures
🎯auditing-foundry-smart-contract-security🎯Skill

Skill

auditing-foundry-smart-contract-security
🎯performing-automated-malware-analysis-with-cape🎯Skill

Skill

performing-automated-malware-analysis-with-cape
🎯implementing-code-signing-for-artifacts🎯Skill

Skill

implementing-code-signing-for-artifacts
🎯implementing-network-intrusion-prevention-with-suricata🎯Skill

Skill

implementing-network-intrusion-prevention-with-suricata
🎯auditing-entra-id-with-aadinternals🎯Skill

Skill

auditing-entra-id-with-aadinternals
🎯implementing-aws-config-rules-for-compliance🎯Skill

Skill

implementing-aws-config-rules-for-compliance
🎯performing-brand-monitoring-for-impersonation🎯Skill

Skill

performing-brand-monitoring-for-impersonation
🎯detecting-modbus-protocol-anomalies🎯Skill

Skill

detecting-modbus-protocol-anomalies
🎯implementing-rsa-key-pair-management🎯Skill

Skill

implementing-rsa-key-pair-management
🎯performing-bluetooth-security-assessment🎯Skill

Skill

performing-bluetooth-security-assessment
🎯conducting-cyber-risk-assessment-with-nist-800-30🎯Skill

Skill

conducting-cyber-risk-assessment-with-nist-800-30
🎯performing-deception-technology-deployment🎯Skill

Skill

performing-deception-technology-deployment
🎯implementing-pam-for-database-access🎯Skill

Skill

implementing-pam-for-database-access
🎯implementing-aws-security-hub🎯Skill

Skill

implementing-aws-security-hub
🎯implementing-threat-intelligence-lifecycle-management🎯Skill

Skill

implementing-threat-intelligence-lifecycle-management
🎯implementing-security-chaos-engineering🎯Skill

Skill

implementing-security-chaos-engineering
🎯implementing-google-workspace-sso-configuration🎯Skill

Skill

implementing-google-workspace-sso-configuration
🎯implementing-vulnerability-remediation-sla🎯Skill

Skill

implementing-vulnerability-remediation-sla
🎯evaluating-threat-intelligence-platforms🎯Skill

Skill

evaluating-threat-intelligence-platforms
🎯implementing-anti-ransomware-group-policy🎯Skill

Skill

implementing-anti-ransomware-group-policy
🎯implementing-rbac-hardening-for-kubernetes🎯Skill

Skill

implementing-rbac-hardening-for-kubernetes
🎯hunting-for-t1098-account-manipulation🎯Skill

Skill

hunting-for-t1098-account-manipulation
🎯detecting-misconfigured-azure-storage🎯Skill

Skill

detecting-misconfigured-azure-storage
🎯implementing-file-integrity-monitoring-with-aide🎯Skill

Skill

implementing-file-integrity-monitoring-with-aide
🎯implementing-network-segmentation-with-firewall-zones🎯Skill

Skill

implementing-network-segmentation-with-firewall-zones
🎯performing-oil-gas-cybersecurity-assessment🎯Skill

Skill

performing-oil-gas-cybersecurity-assessment
🎯benchmarking-kubernetes-with-kube-bench🎯Skill

Skill

benchmarking-kubernetes-with-kube-bench
🎯auditing-uefi-firmware-with-chipsec🎯Skill

Skill

auditing-uefi-firmware-with-chipsec
🎯implementing-gcp-vpc-firewall-rules🎯Skill

Skill

implementing-gcp-vpc-firewall-rules
🎯performing-cloud-forensics-with-aws-cloudtrail🎯Skill

Skill

performing-cloud-forensics-with-aws-cloudtrail
🎯implementing-policy-as-code-with-open-policy-agent🎯Skill

Skill

implementing-policy-as-code-with-open-policy-agent
🎯attacking-entra-id-with-roadtools🎯Skill

Skill

attacking-entra-id-with-roadtools
🎯implementing-cloud-security-posture-management🎯Skill

Skill

implementing-cloud-security-posture-management
🎯implementing-supply-chain-security-with-in-toto🎯Skill

Skill

implementing-supply-chain-security-with-in-toto
🎯auditing-kubernetes-rbac-privilege-escalation🎯Skill

Skill

auditing-kubernetes-rbac-privilege-escalation
🎯implementing-fuzz-testing-in-cicd-with-aflplusplus🎯Skill

Skill

implementing-fuzz-testing-in-cicd-with-aflplusplus
🎯performing-bandwidth-throttling-attack-simulation🎯Skill

Skill

performing-bandwidth-throttling-attack-simulation
🎯implementing-alert-fatigue-reduction🎯Skill

Skill

implementing-alert-fatigue-reduction
🎯implementing-pod-security-admission-controller🎯Skill

Skill

implementing-pod-security-admission-controller
🎯detecting-lateral-movement-with-zeek🎯Skill

Skill

detecting-lateral-movement-with-zeek
🎯implementing-privileged-session-monitoring🎯Skill

Skill

implementing-privileged-session-monitoring
🎯detecting-t1003-credential-dumping-with-edr🎯Skill

Skill

detecting-t1003-credential-dumping-with-edr
🎯performing-ioc-enrichment-automation🎯Skill

Skill

performing-ioc-enrichment-automation
🎯implementing-email-sandboxing-with-proofpoint🎯Skill

Skill

implementing-email-sandboxing-with-proofpoint
🎯implementing-endpoint-dlp-controls🎯Skill

Skill

implementing-endpoint-dlp-controls
🎯implementing-epss-score-for-vulnerability-prioritization🎯Skill

Skill

implementing-epss-score-for-vulnerability-prioritization
🎯implementing-cloud-workload-protection🎯Skill

Skill

implementing-cloud-workload-protection
🎯investigating-insider-threat-indicators🎯Skill

Skill

investigating-insider-threat-indicators
🎯detecting-wmi-persistence🎯Skill

Skill

detecting-wmi-persistence
🎯implementing-network-traffic-analysis-with-arkime🎯Skill

Skill

implementing-network-traffic-analysis-with-arkime
🎯implementing-identity-verification-for-zero-trust🎯Skill

Skill

implementing-identity-verification-for-zero-trust
🎯implementing-gcp-binary-authorization🎯Skill

Skill

implementing-gcp-binary-authorization
🎯implementing-network-access-control-with-cisco-ise🎯Skill

Skill

implementing-network-access-control-with-cisco-ise
🎯performing-s7comm-protocol-security-analysis🎯Skill

Skill

performing-s7comm-protocol-security-analysis
🎯implementing-aws-security-hub-compliance🎯Skill

Skill

implementing-aws-security-hub-compliance
🎯performing-entitlement-review-with-sailpoint-iiq🎯Skill

Skill

performing-entitlement-review-with-sailpoint-iiq
🎯performing-lateral-movement-detection🎯Skill

Skill

performing-lateral-movement-detection
🎯implementing-hardware-security-key-authentication🎯Skill

Skill

implementing-hardware-security-key-authentication
🎯implementing-honeypot-for-ransomware-detection🎯Skill

Skill

implementing-honeypot-for-ransomware-detection
🎯implementing-passwordless-auth-with-microsoft-entra🎯Skill

Skill

implementing-passwordless-auth-with-microsoft-entra
🎯performing-iot-security-assessment🎯Skill

Skill

performing-iot-security-assessment
🎯detecting-t1055-process-injection-with-sysmon🎯Skill

Skill

detecting-t1055-process-injection-with-sysmon
🎯implementing-cloud-dlp-for-data-protection🎯Skill

Skill

implementing-cloud-dlp-for-data-protection
🎯managing-cloud-identity-with-okta🎯Skill

Skill

managing-cloud-identity-with-okta
🎯performing-access-review-and-certification🎯Skill

Skill

performing-access-review-and-certification
🎯implementing-browser-isolation-for-zero-trust🎯Skill

Skill

implementing-browser-isolation-for-zero-trust
🎯implementing-mtls-for-zero-trust-services🎯Skill

Skill

implementing-mtls-for-zero-trust-services
🎯implementing-cisa-zero-trust-maturity-model🎯Skill

Skill

implementing-cisa-zero-trust-maturity-model
🎯detecting-t1548-abuse-elevation-control-mechanism🎯Skill

Skill

detecting-t1548-abuse-elevation-control-mechanism
🎯implementing-syslog-centralization-with-rsyslog🎯Skill

Skill

implementing-syslog-centralization-with-rsyslog
🎯implementing-attack-path-analysis-with-xm-cyber🎯Skill

Skill

implementing-attack-path-analysis-with-xm-cyber
🎯building-c2-redirector-infrastructure🎯Skill

Skill

building-c2-redirector-infrastructure
🎯implementing-runtime-application-self-protection🎯Skill

Skill

implementing-runtime-application-self-protection
🎯implementing-saml-sso-with-okta🎯Skill

Skill

implementing-saml-sso-with-okta
🎯implementing-disk-encryption-with-bitlocker🎯Skill

Skill

implementing-disk-encryption-with-bitlocker
🎯implementing-zero-standing-privilege-with-cyberark🎯Skill

Skill

implementing-zero-standing-privilege-with-cyberark
🎯implementing-image-provenance-verification-with-cosign🎯Skill

Skill

implementing-image-provenance-verification-with-cosign
🎯performing-hardware-security-module-integration🎯Skill

Skill

performing-hardware-security-module-integration
🎯implementing-application-whitelisting-with-applocker🎯Skill

Skill

implementing-application-whitelisting-with-applocker
🎯implementing-passwordless-authentication-with-fido2🎯Skill

Skill

implementing-passwordless-authentication-with-fido2
🎯implementing-immutable-backup-with-restic🎯Skill

Skill

implementing-immutable-backup-with-restic
🎯implementing-azure-ad-privileged-identity-management🎯Skill

Skill

implementing-azure-ad-privileged-identity-management
🎯implementing-vulnerability-sla-breach-alerting🎯Skill

Skill

implementing-vulnerability-sla-breach-alerting
🎯implementing-network-segmentation-for-ot🎯Skill

Skill

implementing-network-segmentation-for-ot
🎯implementing-patch-management-workflow🎯Skill

Skill

implementing-patch-management-workflow
🎯implementing-stix-taxii-feed-integration🎯Skill

Skill

implementing-stix-taxii-feed-integration
🎯implementing-soar-playbook-for-phishing🎯Skill

Skill

implementing-soar-playbook-for-phishing
🎯performing-file-carving-with-foremost🎯Skill

Skill

performing-file-carving-with-foremost
🎯building-super-timelines-with-plaso🎯Skill

Skill

building-super-timelines-with-plaso
🎯implementing-siem-use-cases-for-detection🎯Skill

Skill

implementing-siem-use-cases-for-detection
🎯implementing-siem-use-case-tuning🎯Skill

Skill

implementing-siem-use-case-tuning
🎯implementing-network-deception-with-honeypots🎯Skill

Skill

implementing-network-deception-with-honeypots
🎯implementing-ransomware-kill-switch-detection🎯Skill

Skill

implementing-ransomware-kill-switch-detection
🎯implementing-continuous-security-validation-with-bas🎯Skill

Skill

implementing-continuous-security-validation-with-bas
🎯performing-access-recertification-with-saviynt🎯Skill

Skill

performing-access-recertification-with-saviynt
🎯implementing-gcp-organization-policy-constraints🎯Skill

Skill

implementing-gcp-organization-policy-constraints
🎯performing-log-source-onboarding-in-siem🎯Skill

Skill

performing-log-source-onboarding-in-siem
🎯implementing-sigstore-for-software-signing🎯Skill

Skill

implementing-sigstore-for-software-signing
🎯implementing-network-traffic-baselining🎯Skill

Skill

implementing-network-traffic-baselining
🎯managing-intelligence-lifecycle🎯Skill

Skill

managing-intelligence-lifecycle
🎯implementing-conditional-access-policies-azure-ad🎯Skill

Skill

implementing-conditional-access-policies-azure-ad
🎯performing-indicator-lifecycle-management🎯Skill

Skill

performing-indicator-lifecycle-management
🎯implementing-data-loss-prevention-with-microsoft-purview🎯Skill

Skill

implementing-data-loss-prevention-with-microsoft-purview
🎯implementing-envelope-encryption-with-aws-kms🎯Skill

Skill

implementing-envelope-encryption-with-aws-kms
🎯implementing-zero-trust-dns-with-nextdns🎯Skill

Skill

implementing-zero-trust-dns-with-nextdns
🎯performing-insider-threat-investigation🎯Skill

Skill

performing-insider-threat-investigation
🎯implementing-cloud-trail-log-analysis🎯Skill

Skill

implementing-cloud-trail-log-analysis
🎯implementing-aws-macie-for-data-classification🎯Skill

Skill

implementing-aws-macie-for-data-classification
🎯implementing-honeytokens-for-breach-detection🎯Skill

Skill

implementing-honeytokens-for-breach-detection
🎯implementing-canary-tokens-for-network-intrusion🎯Skill

Skill

implementing-canary-tokens-for-network-intrusion
🎯implementing-siem-correlation-rules-for-apt🎯Skill

Skill

implementing-siem-correlation-rules-for-apt
🎯implementing-device-posture-assessment-in-zero-trust🎯Skill

Skill

implementing-device-posture-assessment-in-zero-trust
🎯implementing-aws-nitro-enclave-security🎯Skill

Skill

implementing-aws-nitro-enclave-security
🎯implementing-privileged-access-workstation🎯Skill

Skill

implementing-privileged-access-workstation
🎯implementing-diamond-model-analysis🎯Skill

Skill

implementing-diamond-model-analysis
🎯implementing-dragos-platform-for-ot-monitoring🎯Skill

Skill

implementing-dragos-platform-for-ot-monitoring
🎯implementing-memory-protection-with-dep-aslr🎯Skill

Skill

implementing-memory-protection-with-dep-aslr
🎯implementing-delinea-secret-server-for-pam🎯Skill

Skill

implementing-delinea-secret-server-for-pam
🎯implementing-privileged-access-management-with-cyberark🎯Skill

Skill

implementing-privileged-access-management-with-cyberark
🎯implementing-ebpf-security-monitoring🎯Skill

Skill

implementing-ebpf-security-monitoring
🎯implementing-conduit-security-for-ot-remote-access🎯Skill

Skill

implementing-conduit-security-for-ot-remote-access
🎯implementing-patch-management-for-ot-systems🎯Skill

Skill

implementing-patch-management-for-ot-systems
🎯performing-alert-triage-with-elastic-siem🎯Skill

Skill

performing-alert-triage-with-elastic-siem
🎯implementing-container-network-policies-with-calico🎯Skill

Skill

implementing-container-network-policies-with-calico
🎯implementing-ot-network-traffic-analysis-with-nozomi🎯Skill

Skill

implementing-ot-network-traffic-analysis-with-nozomi
🎯implementing-zero-trust-with-hashicorp-boundary🎯Skill

Skill

implementing-zero-trust-with-hashicorp-boundary
🎯implementing-identity-governance-with-sailpoint🎯Skill

Skill

implementing-identity-governance-with-sailpoint
🎯implementing-soar-playbook-with-palo-alto-xsoar🎯Skill

Skill

implementing-soar-playbook-with-palo-alto-xsoar
🎯implementing-ot-incident-response-playbook🎯Skill

Skill

implementing-ot-incident-response-playbook
🎯implementing-next-generation-firewall-with-palo-alto🎯Skill

Skill

implementing-next-generation-firewall-with-palo-alto
🎯analyzing-cobalt-strike-malleable-profiles🎯Skill

Skill

analyzing-cobalt-strike-malleable-profiles
🎯analyzing-phishing-email-headers🎯Skill

Skill

analyzing-phishing-email-headers
🎯building-cloud-security-posture-management🎯Skill

Skill

building-cloud-security-posture-management
🎯conducting-mobile-application-penetration-test🎯Skill

Skill

conducting-mobile-application-penetration-test
🎯conducting-cloud-infrastructure-penetration-test🎯Skill

Skill

conducting-cloud-infrastructure-penetration-test
🎯auditing-kubernetes-rbac-permissions🎯Skill

Skill

auditing-kubernetes-rbac-permissions
🎯performing-cloud-penetration-testing🎯Skill

Skill

performing-cloud-penetration-testing
🎯containing-active-security-breach🎯Skill

Skill

containing-active-security-breach
🎯implementing-mimecast-targeted-attack-protection🎯Skill

Skill

implementing-mimecast-targeted-attack-protection