Anthropic-Cybersecurity-Skills
by mukul975
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
About
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
Skill Analysis
Skills (761)
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Manage...
Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify ...
pythonDeploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, cred...
>
bashyamlDetect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enu...
kqlpowershellsplDetect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifica...
bashgroovyyamlConfigure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill ...
Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and in...
bashyaml>
bashpython>
csvsplDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR p...
>-
bashpythonHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers,...
>
>
bashAuditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protecti...
bashConduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility secu...
bash
Recent Commits
- d388b312026-03-28Remove Product Hunt badge from READMEMahipal
- ac6abba2026-03-28Add Product Hunt badge to READMEMahipal
- 8dc2a4f2026-03-28chore: auto-update index.jsonmukul975
- 9fc237a2026-03-28Fix ESET AV false positive on AMSI bypass strings in skill docsmukul975
- 840049b2026-03-27chore: auto-update index.jsonmukul975
- b7bd6b12026-03-27Add skill: detecting-lateral-movement-with-zeek (fixes #5) (#29)Julio César Suástegui
- 93145652026-03-23docs: update release version from v1.0.0 to v1.1.0 in READMEmukul975
- c74a7542026-03-23docs: replace static contributors table with contrib.rocks auto-updating widgetmukul975
- f4e791c2026-03-23docs: remove fake contributor Systech2021-1952 from READMEmukul975
- 577f7952026-03-21docs: update skill count to 753 and domain count to 38 across all filesmukul975