tag

anomaly-detection

12 indexed skills · max 10 per page

skills (12)

hunting-for-unusual-network-connections

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-unusual-network-connections

0

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

implementing-network-traffic-baselining

mukul975/Anthropic-Cybersecurity-Skills · implementing-network-traffic-baselining

0

Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling

monitoring-scada-modbus-traffic-anomalies

mukul975/Anthropic-Cybersecurity-Skills · monitoring-scada-modbus-traffic-anomalies

0

Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic analysis, SCADA network monitoring, ICS anomaly detection, PLC security monitoring, or OT network threat detection.

implementing-ot-network-traffic-analysis-with-nozomi

mukul975/Anthropic-Cybersecurity-Skills · implementing-ot-network-traffic-analysis-with-nozomi

0

Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.

performing-user-behavior-analytics

mukul975/Anthropic-Cybersecurity-Skills · performing-user-behavior-analytics

0

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.

detecting-insider-threat-with-ueba

mukul975/Anthropic-Cybersecurity-Skills · detecting-insider-threat-with-ueba

0

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.

detecting-anomalies-in-industrial-control-systems

mukul975/Anthropic-Cybersecurity-Skills · detecting-anomalies-in-industrial-control-systems

0

This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.

detecting-aws-cloudtrail-anomalies

mukul975/Anthropic-Cybersecurity-Skills · detecting-aws-cloudtrail-anomalies

0

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

detecting-network-anomalies-with-zeek

mukul975/Anthropic-Cybersecurity-Skills · detecting-network-anomalies-with-zeek

0

Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.

detecting-dnp3-protocol-anomalies

mukul975/Anthropic-Cybersecurity-Skills · detecting-dnp3-protocol-anomalies

0

Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.

prevpage 1 / 2next