
from Anthropic Cybersecurity Skills23,316
Detect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP profile matching, and timing analysis in Zeek/Su
Provides a practical detection workflow for identifying Cobalt Strike beacon callbacks in network traffic. The skill describes how to use Zeek logs, Suricata rules, and Python PCAP analysis to spot TLS certificate fingerprints, JA3/JA3S/JARM signatures, HTTP malleable profile patterns, and regular beacon timing with jitter. It combines these signals into a scored detection output for investigators and SOC analysts.
Use this skill during threat hunting, incident response, or monitoring validation when you suspect command-and-control (C2) activity or want to improve detection coverage for Cobalt Strike. It is useful for SOC playbooks, building IDS rules, and post-incident network forensics.
Based on repo and readme, this skill is compatible with threat-hunting and automation tooling and can be used by Claude Code, GitHub Copilot/Codex workflows, and CLI-based automation (Python scripts).
This skill has not been reviewed by our automated audit pipeline yet.
Analyzing Ransomware Leak Site Intelligence
Collect and analyze ransomware data-leak site (DLS) postings to extract victim, group, sector, and timeline intelligence for threat hunting and risk assessment.
Evaluating Threat Intelligence Platforms
Guides procurement, evaluation, and proof-of-concept testing for Threat Intelligence Platforms (MISP, OpenCTI, ThreatConnect, Anomali, EclecticIQ) based on inte
Performing Threat Modeling with OWASP Threat Dragon
Use OWASP Threat Dragon to create data-flow diagrams, apply STRIDE/LINDDUN threat classifications, and generate threat-model reports to guide secure design revi
Testing for XSS Vulnerabilities with Burp Suite
Guided workflow to identify, validate, and document reflected, stored, and DOM-based XSS using Burp Suite (scanner, repeater, intruder, DOM Invader).
Conducting Domain Persistence with DCSync
Guided procedures to identify DCSync-capable accounts and extract Active Directory credential hashes (KRBTGT, admin) for authorized red-team testing and validat
Testing for JSON Web Token (JWT) Vulnerabilities
Techniques and checks to find and exploit common JWT misconfigurations (alg none, alg confusion, kid/JKU injection, weak secrets).
NIST SP 800-30 Cyber Risk Assessment
Conducts comprehensive cybersecurity risk assessments using the NIST SP 800-30 Rev 1 methodology to identify threats, vulnerabilities, and impact.