abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-dns-logs-for-exfiltration --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-dns-logs-for-exfiltrationContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
name: analyzing-dns-logs-for-exfiltration description: 'Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls. ' domain: cybersecurity subdomain: soc-operations tags: - soc - dns - exfiltration - dns-tunneling - dga - c2-detection - splunk - threat-detection version: '1.0' author: mahipal license: Apache-2.0 atlas_techniques: - AML.T0024 - AML.T0056 - AML.T0086 nist_csf: - DE.CM-01 - DE.AE-02 - RS.MA-01 - DE.AE-06 mitre_attack: - T1048.003 - T1071.004 - T1567
Use this skill when:
**Do not use** for standard DNS troubleshooting or availability monitoring — this skill focuses on security-relevant DNS abuse detection.
DNS tunneling encodes data in subdomain labels, creating unusually long queries:
index=dns sourcetype="stream:dns" query_type IN ("A", "AAAA", "TXT", "CNAME", "MX")
| eval domain_parts = split(query, ".")
| eval subdomain = mvindex(domain_parts, 0, mvcount(domain_parts)-3)
| eval subdomain_str = mvjoin(subdomain, ".")
| eval subdomain_len = len(subdomain_str)
| eval tld = mvindex(domain_parts, -1)
| eval registered_domain = mvindex(domain_parts, -2).".".tld
| where subdomain_len > 50
| stats count AS queries, dc(query) AS unique_queries,
avg(subdomain_len) AS avg_subdomain_len,
max(subdomain_len) AS max_subdomain_len,
values(src_ip) AS sources
by registered_domain
| where queries > 20
| sort - avg_subdomain_len
| table registered_domain, queries, unique_queries, avg_subdomain_len, max_subdomain_len, sourcesDomain Generation Algorithms produce random-looking domains:
index=dns sourcetype="stream:dns" | eval domain_parts = split(query, ".") | eval sld = mvindex(domain_parts, -2) | eval sld_len = len(sld) | eval char_count = sld_len | eval vowels = len(replace(sld, "[^aeiou]", "")) | eval consonants = len(replace(sld, "[^bcdfghjklmnpqrstvwxyz]", "")) | eval digits = len(replace(sld, "[^0-9]", "")) | eval vowel_ratio = if(char_count > 0, vowels / char_count, 0) | eval digit_ratio = if(char_count > 0, digits / char_count, 0) | where sld_len > 12 AND (vowel_ratio < 0.2 OR digit_ratio > 0.3) | stats count AS queries, dc(query) AS unique_domains, values(src_ip) AS sources by query | where unique_domains > 10 | sort - queries
**Python-based Shannon Entropy Calculation for DNS queries:**
import math
from collections import Counter
def shannon_entropy(text):
"""Calculate Shannon entropy of a string"""
if not text:
return 0
counter = Counter(text.lower())
length = len(text)
entropy = -sum(
(count / length) * math.log2(count / length)
for count in counter.values()
)
return round(entropy, 4)
# Test with examples
normal_domain = "google" # Low entropy
dga_domain = "x8kj2m9p4qw7n" # High entropy
tunnel_subdomain = "aGVsbG8gd29ybGQ.evil.com" # Base64 encoded data
print(f"Normal: {shannon_entropy(normal_domain)}") # ~2.25
print(f"DGA: {shannon_entropy(dga_domain)}") # ~3.70
print(f"Tunnel: {shannon_entropy(tunnel_subdomain)}") # ~3.50
# Threshold: entropy > 3.5 for subdomain = likely tunneling/DGA**Splunk implementation of entropy scoring:**
index=dns sourcetype="stream:dns" | eval domain_parts = split(query, ".") | eval check_string = mvindex(domain_parts, 0) | eval check_len = len(check_string) | where check_len > 8 | eval chars = split(check_string, "") | stats count AS total_chars, dc(chars) AS unique_chars by query, src_ip, check_string, check_len | eval entropy_estimate = log(unique_chars, 2) * (unique_chars / check_len) | where entropy_estimate > 3.5 | stats count AS high_entropy_queries, dc(query) AS unique_queries by src_ip | where high_entropy_queries > 50 | sort - high_entropy_queries
Identify hosts generating abnormal DNS traffic:
index=dns sourcetype="stream:dns" earliest=-24h | bin _time span=1h | stats count AS queries, dc(query) AS unique_domains by src_ip, _time | eventstats avg(queries) AS avg_queries, stdev(queries) AS stdev_queries by src_ip | eval z_score = (queries - avg_queries) / stdev_queries | where z_score > 3 OR queries > 5000 | sort - z_score | table _time, src_ip, queries, unique_domains, avg_queries, z_score
**Detect TXT record abuse (common tunneling method):**
index=dns sourcetype="stream:dns" query_type="TXT"
| stats count AS txt_queries, dc(query) AS unique_txt_domains,
values(query) AS domains by src_ip
| where txt_queries > 100
| eval suspicion = case(
txt_queries > 1000, "CRITICAL — Likely DNS tunneling",
txt_queries > 500, "HIGH — Possible DNS tunneling",
txt_queries > 100, "MEDIUM — Unusual TXT volume"
)
| sort - txt_queries
| table src_ip, txt_queries, unique_txt_domains, su817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…