Mukul975 Anthropic Cybersecurity Skills
合集@mukul9753.3万+开源协议: Apache-2.0
为国防承包商环境准备 CMMC 二级认证:界定 CUI 与 FCI 范围,在 14 个控制族中落实 NIST SP 800-171 Rev 2 的 110 项安…
performing-hardware-security-module-integration
@mukul975
编程协作开源协议: Apache-2.0
/**
* 通过 PKCS#11 接口使用 python-pkcs11 集成硬件安全模块(HSM),针对 SoftHSM2、AWS CloudHSM 或 YubiHSM2 …
*/performing-hash-cracking-with-hashcat
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用 Hashcat 破解口令哈希,涵盖哈希类型识别、字典/暴力/基于规则的
*/performing-http-parameter-pollution-attack
@mukul975
编程协作开源协议: Apache-2.0
/**
* 执行 HTTP 参数污染攻击,通过注入重复的请求参数来绕过输入验证、WAF 规则及其他安全控制,前提是前端和后端系统对重复参数的解析方式不同。在 Web 应用渗…
*/performing-ics-asset-discovery-with-claroty
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用 Claroty xDome 执行 ICS/OT 资产发现,结合被动监控与 Claroty Edge 主动查询,
*/performing-indicator-lifecycle-management
@mukul975
编程协作开源协议: Apache-2.0
/**
* 通过发现、富化/验证(VirusTotal、Shodan、被动 DNS)、部署到 SIEM/IDS 监控列表、命中率与误报监控、置信度衰减以及使用 MISP/O…
*/performing-initial-access-with-evilginx3
@mukul975
编程协作开源协议: Apache-2.0
/**
* 在红队演练期间,使用 EvilGinx3 中间人钓鱼框架执行经授权的初始访问,以捕获会话令牌并绕过多因素认证。
*/performing-insider-threat-investigation
@mukul975
编程协作开源协议: Apache-2.0
/**
* 调查涉及员工、承包商或受信任合作伙伴的内部威胁事件,这些人员滥用其被授权的访问权限来窃取数据、破坏系统或违反安全策略,综合运用数字取证、用户行为分析以及与 HR…
*/performing-ioc-enrichment-automation
@mukul975
流程自动化开源协议: Apache-2.0
/**
* 通过编排跨 VirusTotal、AbuseIPDB、Shodan、MISP 等情报源的查询,自动执行入侵指标(IOC)富化,提供上下文评分与处置建议。在告警分…
*/performing-ios-app-security-assessment
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用 Frida 进行动态插桩、Objection 进行运行时探测、绕过 SSL Pinning 以截获流量、提取 Keychain 进行凭据分析,
*/performing-iot-security-assessment
@mukul975
编程协作开源协议: Apache-2.0
/**
* 通过对硬件接口、固件、网络通信、云 API 以及配套移动应用的测试,对物联网设备及其生态系统开展全面的安全评估。测试人员使用固件提取与分析、通过 UART 和 …
*/performing-ip-reputation-analysis-with-shodan
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用 Shodan API 分析 IP 地址信誉,识别开放端口、运行服务、已知漏洞以及托管上下文,以支持威胁情报富化与事件分诊。
*/performing-jwt-none-algorithm-attack
@mukul975
编程协作开源协议: Apache-2.0
/**
* 执行并测试 JWT none 算法攻击,使用 PyJWT 配合拦截代理(Burp Suite/mitmproxy)构造将
*/performing-kerberoasting-attack
@mukul975
编程协作开源协议: Apache-2.0
/**
* 执行 Kerberoasting,这是一种后渗透技术,用于枚举 Active Directory 中具有服务主体名称(SPN)的服务账户,
*/performing-kubernetes-cis-benchmark-with-kube-bench
@mukul975
编程协作开源协议: Apache-2.0
/**
* 将 kube-bench 输出转化为完整的 CIS Kubernetes Benchmark 审计:对每个控制项解读 PASS/FAIL/WARN, 判断哪些失…
*/performing-kubernetes-etcd-security-assessment
@mukul975
设计多媒体开源协议: Apache-2.0
/**
* 评估支撑 Kubernetes 的 etcd 集群的安全态势:静态加密、对等端与客户端 TLS 传输、访问控制、备份加密以及网络隔离。在审计或加固控制平面、审查…
*/performing-kubernetes-penetration-testing
@mukul975
编程协作开源协议: Apache-2.0
/**
* 通过主动模拟针对 API server、kubelet、etcd、Pod、RBAC、网络策略和 Secrets 的攻击者技术,使用 kube-hunter、Ku…
*/performing-lateral-movement-detection
@mukul975
编程协作开源协议: Apache-2.0
/**
* 检测横向移动技术,包括 Pass-the-Hash、PsExec、WMI 执行、RDP 跳转以及基于 SMB 的扩散,通过在 SIEM 中关联 Windows …
*/performing-lateral-movement-with-wmiexec
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用基于 WMI 的远程执行技术跨 Windows 网络执行横向移动,包括 Impacket
*/performing-linux-log-forensics-investigation
@mukul975
编程协作开源协议: Apache-2.0
/**
* 对 Linux 系统日志进行取证调查,包括 syslog、auth.log、通过 journalctl 访问的
*/performing-log-analysis-for-forensic-investigation
@mukul975
编程协作开源协议: Apache-2.0
/**
* 在取证调查过程中,收集、解析并关联系统、应用和安全日志以重建事件并建立时间线。
*/performing-log-source-onboarding-in-siem
@mukul975
编程协作开源协议: Apache-2.0
/**
* 通过使用分层价值框架对数据源进行优先级排序、配置采集器、构建解析器、将字段归一化到通用模式(如 CIM),以及验证数据质量,对 SIEM 平台(Splunk、E…
*/performing-malware-hash-enrichment-with-virustotal
@mukul975
编程协作开源协议: Apache-2.0
/**
* 使用 VirusTotal API v3 对恶意软件文件哈希(MD5、SHA-1、SHA-256)进行富化,
*/performing-malware-ioc-extraction
@mukul975
编程协作开源协议: Apache-2.0
/**
* 恶意软件 IOC 提取是通过分析恶意软件来识别可操作的入侵指标的过程,包括文件哈希、网络指标(C2 域名、IP 地址、URL)、注册表
*/performing-malware-persistence-investigation
@mukul975
编程协作开源协议: Apache-2.0
/**
* 系统性地调查 Windows 和 Linux 系统上所有的持久化机制,以识别恶意软件如何在重启后存活并维持访问。
*/