abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Auditing Terraform infrastructure-as-code for security misconfigurations
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-terraform-infrastructure-for-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/auditing-terraform-infrastructure-for-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Auditing Terraform infrastructure-as-code for security misconfigurations
name: auditing-terraform-infrastructure-for-security description: 'Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment. ' domain: cybersecurity subdomain: cloud-security tags: - cloud-security - terraform - infrastructure-as-code - checkov - tfsec - policy-as-code version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.IR-01 - ID.AM-08 - GV.SC-06 - DE.CM-01 mitre_attack: - T1078.004 - T1530 - T1190 - T1552.001 - T1580
**Do not use** for runtime security monitoring (use CSPM tools), for application security testing (use SAST/DAST tools), or for cloud configuration drift detection (use AWS Config or Azure Policy after deployment).
Run Checkov for comprehensive IaC security scanning with built-in and custom policies.
# Scan a Terraform directory checkov -d ./terraform/ --framework terraform # Scan with specific check categories checkov -d ./terraform/ --check CKV_AWS_18,CKV_AWS_19,CKV_AWS_20,CKV_AWS_21 # Scan and output results in JSON checkov -d ./terraform/ --output json > checkov-results.json # Scan a Terraform plan file for more accurate analysis terraform init && terraform plan -out=tfplan terraform show -json tfplan > tfplan.json checkov -f tfplan.json --framework terraform_plan # Skip specific checks with justification checkov -d ./terraform/ --skip-check CKV_AWS_145 \ --bc-api-key $BRIDGECREW_API_KEY # Scan Terraform modules checkov -d ./modules/ --framework terraform --compact # List all available checks checkov --list --framework terraform | grep CKV_AWS
Use tfsec for Terraform-native security analysis with detailed remediation guidance.
# Scan a Terraform directory tfsec ./terraform/ # Scan with minimum severity threshold tfsec ./terraform/ --minimum-severity HIGH # Output in JSON for CI/CD processing tfsec ./terraform/ --format json > tfsec-results.json # Scan with custom checks tfsec ./terraform/ --custom-check-dir ./custom-checks/ # Exclude specific rules tfsec ./terraform/ --exclude-downloaded-modules \ --exclude aws-s3-enable-bucket-logging # Scan and fail on specific severity tfsec ./terraform/ --minimum-severity CRITICAL --soft-fail # Generate SARIF output for GitHub Security tab tfsec ./terraform/ --format sarif > tfsec.sarif
Execute Terrascan for compliance checking against CIS, NIST, and SOC 2 frameworks.
# Scan Terraform against CIS AWS benchmark terrascan scan -t aws -i terraform -d ./terraform/ \ --policy-type aws --verbose # Scan against specific compliance frameworks terrascan scan -t aws -i terraform -d ./terraform/ \ --policy-type aws \ --categories "Compliance Validation" # Output in JSON terrascan scan -t aws -i terraform -d ./terraform/ \ --output json > terrascan-results.json # Scan a Terraform plan terrascan scan -t aws -i terraform \ --iac-file tfplan.json \ --iac-type tfplan # List available policies terrascan scan --list-policies -t aws
Write Rego policies for organization-specific security requirements.
# policy/aws_s3_encryption.rego
package terraform.aws.s3
deny[msg] {
resource := input.resource.aws_s3_bucket[name]
not resource.server_side_encryption_configuration
msg := sprintf("S3 bucket '%s' must have server-side encryption enabled", [name])
}
# policy/aws_iam_no_wildcards.rego
package terraform.aws.iam
deny[msg] {
resource := input.resource.aws_iam_policy[name]
statement := resource.policy.Statement[_]
statement.Action == "*"
statement.Effect == "Allow"
msg := sprintf("IAM policy '%s' must not use wildcard (*) actions", [name])
}
deny[msg] {
resource := input.resource.aws_iam_policy[name]
statement := resource.policy.Statement[_]
statement.Resource == "*"
statement.Effect == "Allow"
contains(statement.Action[_], "*")
msg := sprintf("IAM policy '%s' has overly permissive actions on wildcard resources", [name])
}
# policy/aws_no_public_ingress.rego
package terraform.aws.security_group
deny[msg] {
resource := input.resource.aws_security_group_rule[name]
resource.type == "ingress"
resource.cidr_blocks[_] == "0.0.0.0/0"
resource.from_port <= 22
resource.to_port >= 22
msg := sprintf("Security group rule '%s' allows SSH from 0.0.0.0/0", [name])
}# Evaluate Terraform plan against OPA policies terraform show -json tfplan | opa eval \ --data ./policy/ \ --input /dev/stdin \ "data.terraform.aws" \ --format pretty # Run Conftest for easier OPA policy testing conftest test tfplan.json --policy ./policy/ --output json
Add IaC security scanning as a mandatory CI/CD gate.
# GitHub Actions: Terraform security pipeline name: Terraform Secur
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…