acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
$ npx -y skills add Mikaru0Mystic/sectinel --skill building-ransomware-playbook-with-cisa-framework --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/building-ransomware-playbook-with-cisa-frameworkContext preview
The summary Claude sees to decide when to auto-load this skill.
Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
name: building-ransomware-playbook-with-cisa-framework description: 'Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment. ' domain: cybersecurity subdomain: ransomware-defense tags: - ransomware - incident-response - CISA - playbook - compliance - NIST version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - PR.DS-11 - RS.MA-01 - RC.RP-01 - PR.IR-01
**Do not use** as a substitute for legal counsel regarding ransom payment decisions, breach notification timelines, or regulatory obligations specific to your jurisdiction.
Establish ransomware-specific defenses before an incident:
CISA Preparation Checklist: ━━━━━━━━━━━━━━━━━━━━━━━━━━ [ ] Maintain offline, encrypted backups tested for restoration [ ] Create and exercise a cyber incident response plan (IRP) [ ] Implement network segmentation between IT and OT networks [ ] Enable MFA on all remote access and privileged accounts [ ] Deploy endpoint detection and response (EDR) on all endpoints [ ] Disable or restrict RDP; require VPN for remote access [ ] Maintain a software/hardware asset inventory [ ] Apply patches within 48 hours for internet-facing systems [ ] Configure email filtering and disable macro execution by default [ ] Conduct regular phishing awareness training [ ] Implement application allowlisting (AppLocker/WDAC) [ ] Test backup restoration quarterly and document RTO/RPO
Identify ransomware indicators and assess scope:
Detection Indicators: ━━━━━━━━━━━━━━━━━━━━ - Mass file rename operations with new extensions (.locked, .encrypted) - Ransom notes appearing in directories (README.txt, DECRYPT.html) - Volume Shadow Copy deletion (vssadmin delete shadows) - Abnormal CPU usage from encryption processes - EDR/AV alerts for known ransomware signatures - Network connections to known C2 infrastructure - Unusual lateral movement via SMB or PsExec - Sysmon Event ID 11 (file creation) spikes Initial Analysis Steps (CISA): 1. Take system images and memory captures of affected devices 2. Identify patient zero and initial access vector 3. Determine the ransomware family (ID Ransomware, ransom note analysis) 4. Assess encryption scope: which systems, shares, and data are affected 5. Check if data exfiltration occurred (double extortion indicator)
Stop the spread and preserve evidence:
Immediate Containment (First 1-4 hours): ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1. Isolate affected systems from the network (disable NICs, VLAN quarantine) 2. If unable to disconnect, power down affected systems 3. Disable shared drives to prevent encryption spread 4. Reset credentials for compromised accounts (especially admin/service accounts) 5. Block known ransomware IOCs at firewall/proxy (C2 domains, IPs) 6. Preserve forensic evidence (memory dumps, disk images, logs) 7. Engage legal counsel and prepare breach notification if data exfiltrated Extended Containment: - Identify and patch the initial access vector (phishing, RDP, VPN vuln) - Audit all Active Directory accounts for persistence (scheduled tasks, services) - Check for backdoors or additional malware beyond the ransomware payload
Remove the threat and restore operations:
CISA Recovery Steps: ━━━━━━━━━━━━━━━━━━━ 1. Rebuild affected systems from known-clean images (do NOT decrypt in place) 2. Restore data from offline backups (verify backup integrity first) 3. Reset ALL passwords including service accounts, krbtgt (twice, 12h apart) 4. Scan restored systems with updated AV/EDR before reconnecting to network 5. Re-enable services in priority order based on business criticality 6. Monitor restored systems intensively for 72 hours for reinfection Recovery Priority Matrix: P1 (0-4h): Domain controllers, DNS, authentication infrastructure P2 (4-24h): Email, critical business applications, databases P3 (1-3d): File servers, departmental applications P4 (3-7d): Non-critical systems, development environments
Document lessons learned and improve defenses:
Post-Incident Report Template: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1. Executive summary: What happened, impact, resolution 2. Timeline: Detection to full recovery with timestamps 3. Root cause analysis: Initial access vector and propagation path 4. Scope: Number of systems, da
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative