acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
$ npx -y skills add Mikaru0Mystic/sectinel --skill deploying-decoy-files-for-ransomware-detection --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/deploying-decoy-files-for-ransomware-detectionContext preview
The summary Claude sees to decide when to auto-load this skill.
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
name: deploying-decoy-files-for-ransomware-detection description: 'Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption. ' domain: cybersecurity subdomain: ransomware-defense tags: - ransomware - detection - canary-files - honeytokens - deception - file-integrity version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - PR.DS-11 - RS.MA-01 - RC.RP-01 - PR.IR-01
**Do not use** decoy files as the sole ransomware defense. They are a detection mechanism, not a prevention mechanism, and should complement backups, EDR, and access controls.
Plan file placement for maximum detection coverage:
Canary File Placement Strategy: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Naming Convention: - Use names that sort FIRST and LAST alphabetically in each directory - Ransomware typically enumerates directories A-Z or Z-A - Examples: _AAAA_budget_2024.docx, ~zzzz_report_final.xlsx Placement Locations: - Root of every file share (\\server\share\_AAAA_canary.docx) - Desktop, Documents, Downloads on each endpoint - Department-specific shares (Finance, HR, Legal) - Backup staging directories - Home directories of high-privilege accounts File Types: - .docx, .xlsx, .pdf (most targeted by ransomware) - .sql, .bak (database files, high value) - Mix of file types to detect ransomware that targets specific extensions
Create decoy files with realistic content and metadata:
import os
import time
def create_canary_docx(filepath, content="Q4 Financial Summary - Confidential"):
"""Create a realistic .docx canary file using python-docx."""
from docx import Document
doc = Document()
doc.add_heading("Financial Report - CONFIDENTIAL", level=1)
doc.add_paragraph(content)
doc.add_paragraph(f"Generated: {time.strftime('%Y-%m-%d')}")
doc.save(filepath)
def create_canary_txt(filepath):
"""Create a simple text canary with known content for hash verification."""
content = "CANARY_TOKEN_DO_NOT_MODIFY\n"
content += f"Created: {time.strftime('%Y-%m-%dT%H:%M:%S')}\n"
content += "This file is monitored for unauthorized changes.\n"
with open(filepath, "w") as f:
f.write(content)Monitor canary files for any modification, rename, or deletion:
from watchdog.observers import Observer
from watchdog.events import FileSystemEventHandler
class CanaryHandler(FileSystemEventHandler):
def __init__(self, canary_paths, alert_callback):
self.canary_paths = set(canary_paths)
self.alert_callback = alert_callback
def on_modified(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("MODIFIED", event.src_path)
def on_deleted(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("DELETED", event.src_path)
def on_moved(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("RENAMED", event.src_path)Define automated responses when canary files are triggered:
Alert Response Matrix: ━━━━━━━━━━━━━━━━━━━━━ Event: Canary MODIFIED → Severity: CRITICAL → Action: Alert SOC, identify modifying process (PID), isolate endpoint Event: Canary DELETED → Severity: HIGH → Action: Alert SOC, check for ransomware note in same directory Event: Canary RENAMED (new extension added) → Severity: CRITICAL → Action: Alert SOC, check extension against known ransomware extensions → Automated: Kill modifying process, disable network interface Event: Multiple canaries triggered within 60 seconds → Severity: EMERGENCY → Action: Network-wide isolation, activate incident response plan
Test that canary files detect actual ransomware behavior:
# Simulate ransomware encryption (safe test - modifies canary content) echo "ENCRYPTED_BY_TEST" > /path/to/canary/_AAAA_budget.docx # Simulate ransomware rename (adds extension) mv /path/to/canary/report.xlsx /path/to/canary/report.xlsx.locked # Verify alerts were generated in SIEM/alerting system
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative