Anthropic-Cybersecurity-Skills
by mukul975
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
About
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
Skill Analysis
Skills (762)
'Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,
powershellDetect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
jsonpythonsplyamlConfigure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory,
bashAutomate credential rotation for service accounts across Active Directory, cloud platforms, and application databases
powershellpythonIdentifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage,
bash'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation,
bash'Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
bashtomltsvyaml'Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to
bashjavascript'This skill guides organizations through implementing zero trust architecture in cloud environments following
bashyaml'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
bash'Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
bashpythonImplement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure
jsonkqlpythonsplParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract
'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and
bashpythonDetect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Recent Commits
- 0f429d02026-05-13Update README.mdMahipal
- 15b63712026-05-13Update README.mdMahipal
- 77d5d9d2026-04-26chore: auto-update index.jsonmukul975
- 812db442026-04-26Merge PR #44: Normalize tags in 3 skillsMahipal
- fcc73ea2026-04-26Merge PR #28: Add bulk skill metadata validation scriptMahipal
- fbc47b72026-04-21fix: replace word-split tags with domain-specific cybersecurity tagsclaude[bot]
- 888bbe42026-04-18Delete star.ymlMahipal
- c60cb4a2026-04-15Update star.ymlMahipal
- d5f3fa32026-04-15Update star.ymlMahipal
- 91a087a2026-04-15Update star.ymlMahipal