acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-ransomware-payment-wallets --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-ransomware-payment-walletsContext preview
The summary Claude sees to decide when to auto-load this skill.
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
name: analyzing-ransomware-payment-wallets description: 'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering. ' domain: cybersecurity subdomain: ransomware-defense tags: - ransomware - blockchain - cryptocurrency - forensics - threat-intelligence - bitcoin version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - PR.DS-11 - RS.MA-01 - RC.RP-01 - PR.IR-01
**Do not use** this skill for live payment interception or to interact directly with ransomware operators. All analysis should be passive and read-only against public blockchain data.
Parse the ransom note to identify the payment address(es):
Common address formats: Bitcoin (P2PKH): 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa (starts with 1) Bitcoin (P2SH): 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy (starts with 3) Bitcoin (Bech32): bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq (starts with bc1) Monero: 4... (95 characters, much harder to trace) Ethereum: 0x... (40 hex chars)
Retrieve all transactions associated with the wallet:
import requests
def get_wallet_transactions(address):
"""Query blockchain.com API for address transactions."""
url = f"https://blockchain.info/rawaddr/{address}"
resp = requests.get(url, timeout=30)
resp.raise_for_status()
data = resp.json()
return {
"address": address,
"n_tx": data.get("n_tx", 0),
"total_received_satoshi": data.get("total_received", 0),
"total_sent_satoshi": data.get("total_sent", 0),
"final_balance_satoshi": data.get("final_balance", 0),
"transactions": data.get("txs", []),
}Trace outputs from the ransom wallet to downstream addresses:
Fund Flow Analysis:
━━━━━━━━━━━━━━━━━━
Victim Payment ──► Ransom Wallet ──► Consolidation Wallet
├─► Mixer/Tumbler Service
├─► Exchange Deposit Address
└─► Peel Chain (sequential small outputs)
Key indicators:
- Consolidation: Multiple ransom payments aggregated into one wallet
- Peel chains: Sequential transactions with diminishing outputs
- Mixer usage: Funds sent to known mixer addresses (Wasabi, Samourai, ChipMixer)
- Exchange cashout: Deposits to known exchange wallets (Binance, Kraken hot wallets)Check addresses against known ransomware infrastructure:
# Check WalletExplorer for entity identification
def check_wallet_explorer(address):
url = f"https://www.walletexplorer.com/api/1/address?address={address}&caller=research"
resp = requests.get(url, timeout=30)
data = resp.json()
return {
"wallet_id": data.get("wallet_id"),
"label": data.get("label", "Unknown"),
"is_exchange": data.get("is_exchange", False),
}Compile findings into a structured intelligence report:
RANSOMWARE WALLET ANALYSIS REPORT ==================================== Ransom Address: bc1q...xyz Family Attribution: LockBit 3.0 (based on ransom note format) Total Received: 4.25 BTC ($178,500 at time of payment) Total Sent: 4.25 BTC (wallet fully drained) Number of Payments: 3 (likely 3 separate victims) FUND FLOW: Payment 1: 1.5 BTC → Consolidation wallet → Binance deposit Payment 2: 1.0 BTC → Wasabi Mixer → Unknown Payment 3: 1.75 BTC → Peel chain (12 hops) → OKX deposit CLUSTER ANALYSIS: Related wallets: 47 addresses identified in same cluster Total cluster volume: 156.3 BTC ($6.5M USD) First activity: 2024-01-15 Last activity: 2024-09-22
| Term | Definition | |------|------------| | **UTXO** | Unspent Transaction Output; the fundamental unit of Bitcoin that tracks ownership through a chain of transactions | | **Cluster Analysis** | Grouping multiple Bitcoin addres
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative