abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Correlates disparate security incidents, IOCs, and adversary behaviors
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill correlating-threat-campaigns --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/correlating-threat-campaignsContext preview
The summary Claude sees to decide when to auto-load this skill.
Correlates disparate security incidents, IOCs, and adversary behaviors
name: correlating-threat-campaigns description: 'Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract shared indicators for improved detection. Use when multiple incidents exhibit overlapping indicators, when sector-wide attack campaigns require cross-organizational analysis, or when building campaign-level intelligence products. Activates for requests involving campaign analysis, incident clustering, cross-organizational IOC correlation, or MISP correlation engine. ' domain: cybersecurity subdomain: threat-intelligence tags: - campaign-analysis - correlation - MISP - ATT&CK - threat-actor - intrusion-set - clustering - CTI version: 1.0.0 author: team-cybersecurity license: Apache-2.0 nist_csf: - ID.RA-01 - ID.RA-05 - DE.CM-01 - DE.AE-02 mitre_attack: - T1566 - T1071.001 - T1587.001 - T1583.001 - T1588.002
Use this skill when:
**Do not use** this skill to force correlation based on weak signals — false campaign attribution misleads defenders and wastes resources on incorrect threat models.
Gather all candidate events for correlation from:
Normalize all events to STIX 2.1 schema with consistent timestamp (UTC), indicator types, and confidence scores. Ensure all indicators have source attribution and collection date.
Apply systematic pivot analysis across four dimensions:
**Infrastructure pivots**:
**Capability pivots**:
**Temporal pivots**:
**Victimology pivots**:
Apply weighted scoring for campaign attribution:
def calculate_campaign_confidence(events: list) -> float:
scores = []
# Infrastructure overlap (highest weight — most discriminating)
infra_overlap = count_shared_infra(events) / len(events)
scores.append(infra_overlap * 40)
# Capability overlap (high weight — TTPs are durable)
capability_overlap = count_shared_ttps(events) / len(events)
scores.append(capability_overlap * 35)
# Temporal proximity (moderate weight)
temporal_score = assess_temporal_clustering(events)
scores.append(temporal_score * 15)
# Victimology alignment (lower weight — many actors target same sector)
victim_score = assess_victim_pattern(events)
scores.append(victim_score * 10)
total = sum(scores)
if total >= 70: return "HIGH"
elif total >= 45: return "MEDIUM"
else: return "LOW"In OpenCTI or Maltego, construct campaign graph:
Label each relationship with evidence reference and confidence.
Structure the campaign report: 1. **Campaign name**: Assign descriptive codename based on targeting theme or tooling 2. **Timeline**: First/last observed dates with activity phases 3. **Attribution**: Suspected threat actor with confidence level 4. **Target profile**: Industry verticals, geographies, organization sizes 5. **TTPs summary**: ATT&CK Navigator heatmap for campaign-specific techniques 6. **Shared indicators**: IOCs that span multiple incidents (highest confidence for blocking) 7. **Detection guidance**: Sigma/YARA rules specific to this campaign
| Term | Definition | |------|-----------| | **Campaign** | STIX object representing a grouping of adversarial behaviors with common objectives over a defined time period | | **Intrusion Set** | STIX object grouping related intrusion activity by common objectives, even when actor identity is uncertain | | **Pivot** | Using a single data point (IOC, infrastructure, TTP) to discover related events or adversary artifacts | | **Clustering** | Machine learning or manual grouping of incidents based on feature similarity to identify campaign boundaries | | **Fal
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…