acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-network-traffic-for-incidents --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-network-traffic-for-incidentsContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
name: analyzing-network-traffic-for-incidents description: 'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. ' domain: cybersecurity subdomain: incident-response tags: - network-forensics - PCAP-analysis - Wireshark - Zeek - traffic-analysis mitre_attack: - T1071 - T1095 - T1573 - T1572 version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - RS.MA-01 - RS.MA-02 - RS.AN-03 - RC.RP-01
**Do not use** for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead.
Obtain the relevant traffic data for the investigation:
**Live Capture (if incident is active):**
# Capture on specific interface filtering by host tcpdump -i eth0 -w capture.pcap host 10.1.5.42 # Capture C2 traffic to specific external IP tcpdump -i eth0 -w c2_traffic.pcap host 185.220.101.42 # Capture with rotation (1GB files, keep 10) tcpdump -i eth0 -w capture_%Y%m%d%H%M.pcap -C 1000 -W 10
**From Existing Infrastructure:**
Detect command-and-control traffic patterns:
**Beaconing Detection (Zeek conn.log):**
# Extract connections to external IPs with regular intervals cat conn.log | zeek-cut ts id.orig_h id.resp_h id.resp_p duration orig_bytes resp_bytes \ | awk '$4 ~ /^185\.220/' | sort -t. -k1,1n -k2,2n
**Wireshark Beacon Analysis:**
# Filter for traffic to suspected C2 IP
ip.addr == 185.220.101.42
# Filter HTTPS traffic to non-standard ports
tcp.port != 443 && ssl
# Filter DNS queries for suspicious domains
dns.qry.name contains "evil" or dns.qry.name matches "^[a-z0-9]{32}\."
# Filter HTTP POST (common C2 check-in method)
http.request.method == "POST" && ip.dst == 185.220.101.42Beaconing characteristics to identify:
Trace adversary movement between internal systems:
Key protocols for lateral movement detection: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SMB (TCP 445): PsExec, file share access, ransomware propagation RDP (TCP 3389): Remote desktop sessions WinRM (TCP 5985): PowerShell remoting WMI (TCP 135): Remote command execution SSH (TCP 22): Linux lateral movement DCE/RPC (TCP 135): DCOM-based lateral movement
**Wireshark Filters for Lateral Movement:**
# SMB lateral movement smb2 && ip.src == 10.1.5.42 && ip.dst != 10.1.5.42 # RDP connections from compromised host tcp.dstport == 3389 && ip.src == 10.1.5.42 # Kerberos ticket requests (potential pass-the-ticket) kerberos.msg_type == 12 && ip.src == 10.1.5.42 # NTLM authentication (potential pass-the-hash) ntlmssp.auth.username && ip.src == 10.1.5.42
Identify unauthorized data transfers leaving the network:
# Identify large outbound transfers in Zeek conn.log cat conn.log | zeek-cut ts id.orig_h id.resp_h id.resp_p orig_bytes \ | awk '$5 > 100000000' | sort -t$'\t' -k5 -rn # DNS tunneling detection (high volume of TXT queries) cat dns.log | zeek-cut query qtype | grep TXT | cut -f1 \ | rev | cut -d. -f1,2 | rev | sort | uniq -c | sort -rn | head # Unusual protocol usage (ICMP tunneling, DNS over HTTPS) cat conn.log | zeek-cut proto id.resp_p orig_bytes | awk '$1 == "icmp" && $3 > 1000'
**Wireshark Exfiltration Filters:**
# Large HTTP POST uploads http.request.method == "POST" && tcp.len > 10000 # FTP data transfers ftp-data && ip.src == 10.0.0.0/8 # DNS with large TXT responses (tunneling) dns.resp.type == 16 && dns.resp.len > 200
Pull network-based indicators from traffic analysis:
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative