implementing-network-traffic-analysis-with-arkime
mukul975/Anthropic-Cybersecurity-Skills
This skill details the deployment and advanced querying techniques for Arkime (Moloch), enabling comprehensive full packet capture network traffic analysis. Users can leverage the Arkime API v3 to search connections, download PCAPs, detect sophisticated C2 beaconing, and analyze connection patterns and anomalies across DNS, HTTP, and TLS traffic. Essential for security monitoring and network forensics.