abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-network-traffic-for-incidents --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-network-traffic-for-incidentsContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
name: analyzing-network-traffic-for-incidents description: 'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. ' domain: cybersecurity subdomain: incident-response tags: - network-forensics - PCAP-analysis - Wireshark - Zeek - traffic-analysis mitre_attack: - T1071 - T1095 - T1573 - T1572 version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - RS.MA-01 - RS.MA-02 - RS.AN-03 - RC.RP-01
**Do not use** for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead.
Obtain the relevant traffic data for the investigation:
**Live Capture (if incident is active):**
# Capture on specific interface filtering by host tcpdump -i eth0 -w capture.pcap host 10.1.5.42 # Capture C2 traffic to specific external IP tcpdump -i eth0 -w c2_traffic.pcap host 185.220.101.42 # Capture with rotation (1GB files, keep 10) tcpdump -i eth0 -w capture_%Y%m%d%H%M.pcap -C 1000 -W 10
**From Existing Infrastructure:**
Detect command-and-control traffic patterns:
**Beaconing Detection (Zeek conn.log):**
# Extract connections to external IPs with regular intervals cat conn.log | zeek-cut ts id.orig_h id.resp_h id.resp_p duration orig_bytes resp_bytes \ | awk '$4 ~ /^185\.220/' | sort -t. -k1,1n -k2,2n
**Wireshark Beacon Analysis:**
# Filter for traffic to suspected C2 IP
ip.addr == 185.220.101.42
# Filter HTTPS traffic to non-standard ports
tcp.port != 443 && ssl
# Filter DNS queries for suspicious domains
dns.qry.name contains "evil" or dns.qry.name matches "^[a-z0-9]{32}\."
# Filter HTTP POST (common C2 check-in method)
http.request.method == "POST" && ip.dst == 185.220.101.42Beaconing characteristics to identify:
Trace adversary movement between internal systems:
Key protocols for lateral movement detection: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SMB (TCP 445): PsExec, file share access, ransomware propagation RDP (TCP 3389): Remote desktop sessions WinRM (TCP 5985): PowerShell remoting WMI (TCP 135): Remote command execution SSH (TCP 22): Linux lateral movement DCE/RPC (TCP 135): DCOM-based lateral movement
**Wireshark Filters for Lateral Movement:**
# SMB lateral movement smb2 && ip.src == 10.1.5.42 && ip.dst != 10.1.5.42 # RDP connections from compromised host tcp.dstport == 3389 && ip.src == 10.1.5.42 # Kerberos ticket requests (potential pass-the-ticket) kerberos.msg_type == 12 && ip.src == 10.1.5.42 # NTLM authentication (potential pass-the-hash) ntlmssp.auth.username && ip.src == 10.1.5.42
Identify unauthorized data transfers leaving the network:
# Identify large outbound transfers in Zeek conn.log cat conn.log | zeek-cut ts id.orig_h id.resp_h id.resp_p orig_bytes \ | awk '$5 > 100000000' | sort -t$'\t' -k5 -rn # DNS tunneling detection (high volume of TXT queries) cat dns.log | zeek-cut query qtype | grep TXT | cut -f1 \ | rev | cut -d. -f1,2 | rev | sort | uniq -c | sort -rn | head # Unusual protocol usage (ICMP tunneling, DNS over HTTPS) cat conn.log | zeek-cut proto id.resp_p orig_bytes | awk '$1 == "icmp" && $3 > 1000'
**Wireshark Exfiltration Filters:**
# Large HTTP POST uploads http.request.method == "POST" && tcp.len > 10000 # FTP data transfers ftp-data && ip.src == 10.0.0.0/8 # DNS with large TXT responses (tunneling) dns.resp.type == 16 && dns.resp.len > 200
Pull network-based indicators from traffic analysis:
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…