Login
Download
Skill UI
Browse and discover
16569+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
UI
, found
667
results
Default
Newest
Most Downloaded
Deploying Palo Alto Prisma Access Zero Trust
deploying-palo-alto-prisma-access-zero-trust
mukul975/Anthropic-Cybersecurity-Skills
282
A comprehensive guide for implementing enterprise-grade Security Access Service Edge (SASE) architectures using Palo Alto Networks Prisma Access. This skill covers configuring ZTNA connectors, GlobalProtect agents, security policies, and device posture checks (HIP) to provide unified, cloud-delivered security, replacing traditional VPNs and maintaining zero trust principles across remote and branch offices.
View Details
Deploying Software-Defined Perimeter for Zero Trust
deploying-software-defined-perimeter
mukul975/Anthropic-Cybersecurity-Skills
240
This skill provides a comprehensive guide to deploying a Software-Defined Perimeter (SDP) compliant with the CSA v2.0 specification. It details implementing core zero trust mechanisms, including Single Packet Authorization (SPA) and mutual TLS (mTLS), using a controller and gateway architecture. Use this when establishing invisible, identity-centric network access (dark cloud) to harden infrastructure, enforce strict zero trust policies, or meet advanced compliance requirements.
View Details
Tailscale Zero Trust Mesh VPN Deployment
deploying-tailscale-for-zero-trust-vpn
mukul975/Anthropic-Cybersecurity-Skills
214
This guide details deploying Tailscale (or self-hosted Headscale) to create a WireGuard-based zero trust mesh VPN. It establishes encrypted peer-to-peer connections between devices, eliminating the need for traditional VPN servers. Features include identity-aware Access Control Lists (ACLs), subnet routing, and secure connectivity for compliance-driven architectures. Use this when enforcing granular, identity-authenticated access control.
View Details
Detecting ARP Poisoning and Spoofing Attacks
detecting-arp-poisoning-in-network-traffic
mukul975/Anthropic-Cybersecurity-Skills
127
This guide provides comprehensive techniques for detecting Layer 2 ARP poisoning and spoofing attacks. It covers monitoring gratuitous ARP floods, tracking IP-to-MAC mapping changes, and identifying rogue devices. Techniques include deploying ARPWatch, configuring Dynamic ARP Inspection (DAI) on managed switches, and using advanced Wireshark filters or custom Python scripts for robust security monitoring and incident response.
View Details
Detecting Cloud Threats with GuardDuty
detecting-cloud-threats-with-guardduty
mukul975/Anthropic-Cybersecurity-Skills
240
A comprehensive guide for deploying and operationalizing Amazon GuardDuty. It provides continuous, intelligent threat detection across core AWS services including S3, EKS, and EC2 runtime monitoring. Use this skill to investigate suspicious activity, detect compromised credentials, or build automated incident response playbooks using EventBridge and Lambda for proactive security.
View Details
Detecting DCSync Attacks in Active Directory
detecting-dcsync-attack-in-active-directory
mukul975/Anthropic-Cybersecurity-Skills
317
This guide details comprehensive detection methods for DCSync attacks (MITRE T1003.006) in Active Directory. Attackers abuse legitimate directory replication protocols to extract sensitive password hashes. Detection relies on auditing Windows Event ID 4662 for unauthorized access attempts to critical Directory Service GUIDs, specifically flagging non-domain-controller accounts attempting replication calls. Essential for threat hunting and incident response.
View Details
Detecting DLL Sideloading Attacks
detecting-dll-sideloading-attacks
mukul975/Anthropic-Cybersecurity-Skills
207
A comprehensive guide for advanced threat hunting, focusing on detecting DLL side-loading and search-order hijacking (MITRE T1574). It instructs users to analyze Sysmon Event ID 7 logs, validate file signatures and hashes, and identify path anomalies to uncover APT persistence mechanisms. Essential for incident response and proactive threat detection in enterprise environments.
View Details
Detecting DNP3 Protocol Anomalies
detecting-dnp3-protocol-anomalies
mukul975/Anthropic-Cybersecurity-Skills
78
This tool detects critical anomalies in DNP3 communications used within SCADA and ICS environments. It employs deep packet inspection and machine learning to monitor for unauthorized control commands, protocol violations, firmware update attempts, and deviations from established network baselines. It is essential for securing critical infrastructure, such as energy grids and industrial control networks, and building robust anomaly-based Intrusion Detection Systems (IDS).
View Details
Detecting Compromised Email Accounts
detecting-email-account-compromise
mukul975/Anthropic-Cybersecurity-Skills
259
A comprehensive guide and analysis framework for detecting compromised Office 365 or Google Workspace email accounts. It focuses on analyzing unified audit logs and Azure AD sign-in logs to identify indicators of account takeover (ATO) or Business Email Compromise (BEC). Detection methods include monitoring impossible travel events, identifying malicious inbox rules (e.g., external forwarding or deletion rules), and analyzing suspicious Microsoft Graph API access patterns.
View Details
Detecting Malicious Email Forwarding Rules
detecting-email-forwarding-rules-attack
mukul975/Anthropic-Cybersecurity-Skills
266
This guide is designed for threat hunting, helping security teams proactively detect persistent unauthorized access methods. It focuses on identifying malicious inbox/mail-flow forwarding rules that adversaries establish after a compromise to maintain access to corporate communications, often associated with Business Email Compromise (BEC) or T1114 techniques. Use during incident response and proactive security assessments.
View Details
Detecting Kerberoasting Attacks in AD
detecting-kerberoasting-attacks
mukul975/Anthropic-Cybersecurity-Skills
243
A comprehensive guide for detecting Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests (Event ID 4769). This technique targets service accounts with Service Principal Names (SPNs), which are requested offline by attackers to crack service account passwords. Use this during threat hunting or incident response to scope MITRE T1558 credential access activities in Active Directory environments.
View Details
Detecting Mimikatz Credential Dumping Patterns
detecting-mimikatz-execution-patterns
mukul975/Anthropic-Cybersecurity-Skills
416
A comprehensive guide and workflow for detecting Mimikatz and similar credential-dumping activities. It utilizes command-line pattern matching, LSASS memory access signatures, binary indicators, and in-memory analysis. Ideal for threat hunting, scoping compromises during incident response, or validating detection coverage in purple team exercises using EDR/SIEM data.
View Details
Prev
1
2
3
...
8
9
10
11
12
13
14
...
54
55
56
Next
Language
简体中文
English