# cybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

- Tier: Indexed (plain plugin)
- Category: Security
- Page: https://www.flowy.sh/listings/mukul975-anthropic-cybersecurity-skills
- Source: https://github.com/mukul975/Anthropic-Cybersecurity-Skills
- Price: free and open source

## Summary
cybersecurity-skills is a Claude Code plugin with 200 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes abusing-dpapi-for-credential-access, abusing-shadow-credentials-for-privesc, achieving-cmmc-level-2-compliance. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.

## Install (Claude Code)
```
/plugin marketplace add mukul975/Anthropic-Cybersecurity-Skills
/plugin install cybersecurity-skills@anthropic-cybersecurity-skills
```

## Skills
- abusing-dpapi-for-credential-access
- abusing-shadow-credentials-for-privesc
- achieving-cmmc-level-2-compliance
- acquiring-disk-image-with-dd-and-dcfldd
- analyzing-active-directory-acl-abuse
- analyzing-android-malware-with-apktool
- analyzing-api-gateway-access-logs
- analyzing-apt-group-with-mitre-navigator
- analyzing-azure-activity-logs-for-threats
- analyzing-bootkit-and-rootkit-samples
- analyzing-browser-forensics-with-hindsight
- analyzing-campaign-attribution-evidence
- analyzing-certificate-transparency-for-phishing
- analyzing-cloud-storage-access-patterns
- analyzing-cobalt-strike-beacon-configuration
- analyzing-cobaltstrike-malleable-c2-profiles
- analyzing-command-and-control-communication
- analyzing-cyber-kill-chain
- analyzing-disk-image-with-autopsy
- analyzing-dns-logs-for-exfiltration
- analyzing-docker-container-forensics
- analyzing-email-headers-for-phishing-investigation
- analyzing-ethereum-smart-contract-vulnerabilities
- analyzing-golang-malware-with-ghidra
- analyzing-heap-spray-exploitation
- analyzing-indicators-of-compromise
- analyzing-ios-app-security-with-objection
- analyzing-kubernetes-audit-logs
- analyzing-linux-audit-logs-for-intrusion
- analyzing-linux-elf-malware
- analyzing-linux-kernel-rootkits
- analyzing-linux-system-artifacts
- analyzing-lnk-file-and-jump-list-artifacts
- analyzing-macro-malware-in-office-documents
- analyzing-malicious-pdf-with-peepdf
- analyzing-malicious-url-with-urlscan
- analyzing-malware-behavior-with-cuckoo-sandbox
- analyzing-malware-family-relationships-with-malpedia
- analyzing-malware-persistence-with-autoruns
- analyzing-malware-sandbox-evasion-techniques
- analyzing-memory-dumps-with-volatility
- analyzing-memory-forensics-with-lime-and-volatility
- analyzing-mft-for-deleted-file-recovery
- analyzing-network-covert-channels-in-malware
- analyzing-network-flow-data-with-netflow
- analyzing-network-packets-with-scapy
- analyzing-network-traffic-for-incidents
- analyzing-network-traffic-of-malware
- analyzing-network-traffic-with-wireshark
- analyzing-office365-audit-logs-for-compromise
- analyzing-outlook-pst-for-email-forensics
- analyzing-packed-malware-with-upx-unpacker
- analyzing-pdf-malware-with-pdfid
- analyzing-persistence-mechanisms-in-linux
- analyzing-powershell-empire-artifacts
- analyzing-powershell-script-block-logging
- analyzing-prefetch-files-for-execution-history
- analyzing-ransomware-encryption-mechanisms
- analyzing-ransomware-leak-site-intelligence
- analyzing-ransomware-network-indicators
- analyzing-ransomware-payment-wallets
- analyzing-sbom-for-supply-chain-vulnerabilities
- analyzing-security-logs-with-splunk
- analyzing-slack-space-and-file-system-artifacts
- analyzing-supply-chain-malware-artifacts
- analyzing-threat-actor-ttps-with-mitre-attack
- analyzing-threat-actor-ttps-with-mitre-navigator
- analyzing-threat-intelligence-feeds
- analyzing-threat-landscape-with-misp
- analyzing-tls-certificate-transparency-logs
- analyzing-typosquatting-domains-with-dnstwist
- analyzing-uefi-bootkit-persistence
- analyzing-usb-device-connection-history
- analyzing-web-server-logs-for-intrusion
- analyzing-windows-amcache-artifacts
- analyzing-windows-event-logs-in-splunk
- analyzing-windows-lnk-files-for-artifacts
- analyzing-windows-prefetch-with-python
- analyzing-windows-registry-for-artifacts
- analyzing-windows-shellbag-artifacts
- assessing-vector-and-embedding-weaknesses
- attacking-entra-id-with-roadtools
- attacking-oauth-with-device-code-phishing
- auditing-aws-s3-bucket-permissions
- auditing-azure-active-directory-configuration
- auditing-cloud-with-cis-benchmarks
- auditing-entra-id-with-aadinternals
- auditing-foundry-smart-contract-security
- auditing-gcp-iam-permissions
- auditing-kubernetes-cluster-rbac
- auditing-kubernetes-rbac-privilege-escalation
- auditing-mcp-servers-for-tool-poisoning
- auditing-terraform-infrastructure-for-security
- auditing-tls-certificate-transparency-logs
- auditing-uefi-firmware-with-chipsec
- automating-ioc-enrichment
- benchmarking-kubernetes-with-kube-bench
- building-adversary-infrastructure-tracking-system
- building-attack-pattern-library-from-cti-reports
- building-automated-malware-submission-pipeline
- building-c2-infrastructure-with-sliver-framework
- building-c2-redirector-infrastructure
- building-cloud-siem-with-sentinel
- building-detection-rule-with-splunk-spl
- building-detection-rules-with-sigma
- building-devsecops-pipeline-with-gitlab-ci
- building-identity-federation-with-saml-azure-ad
- building-identity-governance-lifecycle-process
- building-incident-response-dashboard
- building-incident-response-playbook
- building-incident-timeline-with-timesketch
- building-ioc-defanging-and-sharing-pipeline
- building-ioc-enrichment-pipeline-with-opencti
- building-malware-incident-communication-template
- building-patch-tuesday-response-process
- building-phishing-reporting-button-workflow
- building-ransomware-playbook-with-cisa-framework
- building-red-team-c2-infrastructure-with-havoc
- building-role-mining-for-rbac-optimization
- building-soc-escalation-matrix
- building-soc-metrics-and-kpi-tracking
- building-soc-playbook-for-ransomware
- building-super-timelines-with-plaso
- building-threat-actor-profile-from-osint
- building-threat-feed-aggregation-with-misp
- building-threat-hunt-hypothesis-framework
- building-threat-intelligence-enrichment-in-splunk
- building-threat-intelligence-feed-integration
- building-threat-intelligence-platform
- building-vulnerability-aging-and-sla-tracking
- building-vulnerability-dashboard-with-defectdojo
- building-vulnerability-exception-tracking-system
- building-vulnerability-scanning-workflow
- bypassing-authentication-with-forced-browsing
- coercing-authentication-with-coercer-petitpotam
- collecting-indicators-of-compromise
- collecting-open-source-intelligence
- collecting-threat-intelligence-with-misp
- collecting-volatile-evidence-from-compromised-host
- conducting-api-security-testing
- conducting-cloud-incident-response
- conducting-cloud-penetration-testing
- conducting-cyber-risk-assessment-with-nist-800-30
- conducting-domain-persistence-with-dcsync
- conducting-external-reconnaissance-with-osint
- conducting-full-scope-red-team-engagement
- conducting-internal-network-penetration-test
- conducting-internal-reconnaissance-with-bloodhound-ce
- conducting-malware-incident-response
- conducting-man-in-the-middle-attack-simulation
- conducting-memory-forensics-with-volatility
- conducting-mobile-app-penetration-test
- conducting-network-penetration-test
- conducting-pass-the-ticket-attack
- conducting-phishing-incident-response
- conducting-post-incident-lessons-learned
- conducting-social-engineering-penetration-test
- conducting-social-engineering-pretext-call
- conducting-spearphishing-simulation-campaign
- conducting-wireless-network-penetration-test
- configuring-active-directory-tiered-model
- configuring-aws-verified-access-for-ztna
- configuring-certificate-authority-with-openssl
- configuring-host-based-intrusion-detection
- configuring-hsm-for-key-storage
- configuring-identity-aware-proxy-with-google-iap
- configuring-ldap-security-hardening
- configuring-microsegmentation-for-zero-trust
- configuring-multi-factor-authentication-with-duo
- configuring-network-segmentation-with-vlans
- configuring-oauth2-authorization-flow
- configuring-pfsense-firewall-rules
- configuring-snort-ids-for-intrusion-detection
- configuring-suricata-for-network-monitoring
- configuring-tls-1-3-for-secure-communications
- configuring-windows-defender-advanced-settings
- configuring-windows-event-logging-for-detection
- configuring-zscaler-private-access-for-ztna
- containing-active-breach
- continuous-llm-red-teaming-with-promptfoo
- correlating-security-events-in-qradar
- correlating-threat-campaigns
- defending-llms-with-guardrails
- deobfuscating-javascript-malware
- deobfuscating-powershell-obfuscated-malware
- deploying-active-directory-honeytokens
- deploying-cloud-deception-with-decoy-resources
- deploying-cloudflare-access-for-zero-trust
- deploying-decoy-files-for-ransomware-detection
- deploying-edr-agent-with-crowdstrike
- deploying-honeytokens-and-canarytokens
- deploying-osquery-for-endpoint-monitoring
- deploying-palo-alto-prisma-access-zero-trust
- deploying-ransomware-canary-files
- deploying-software-defined-perimeter
- deploying-tailscale-for-zero-trust-vpn
- designing-adversary-engagement-with-mitre-engage
- detecting-ai-model-prompt-injection-attacks
- detecting-anomalies-in-industrial-control-systems
- detecting-anomalous-authentication-patterns

## FAQ

### What is cybersecurity-skills?
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

### How do I install cybersecurity-skills?
Run these in Claude Code: /plugin marketplace add mukul975/Anthropic-Cybersecurity-Skills then /plugin install cybersecurity-skills@anthropic-cybersecurity-skills. Then prompt normally.

### Does cybersecurity-skills auto-invoke its skills?
Not yet. It is indexed on Flowy as a plain plugin. Request auto-invocation on its page and Flowy will route its skills for you as you prompt.

### Is cybersecurity-skills free?
Yes. Flowy is free and open source, with nothing gated. You can read every skill in full before you install.
