tag

deception

8 indexed skills · max 10 per page

skills (8)

deploying-decoy-files-for-ransomware-detection

mukul975/Anthropic-Cybersecurity-Skills · deploying-decoy-files-for-ransomware-detection

0

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.

implementing-canary-tokens-for-network-intrusion

mukul975/Anthropic-Cybersecurity-Skills · implementing-canary-tokens-for-network-intrusion

0

Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.

implementing-network-deception-with-honeypots

mukul975/Anthropic-Cybersecurity-Skills · implementing-network-deception-with-honeypots

0

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

implementing-deception-based-detection-with-canarytoken

mukul975/Anthropic-Cybersecurity-Skills · implementing-deception-based-detection-with-canarytoken

0

Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.

performing-deception-technology-deployment

mukul975/Anthropic-Cybersecurity-Skills · performing-deception-technology-deployment

0

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.

deploying-ransomware-canary-files

mukul975/Anthropic-Cybersecurity-Skills · deploying-ransomware-canary-files

0

Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.

deploying-active-directory-honeytokens

mukul975/Anthropic-Cybersecurity-Skills · deploying-active-directory-honeytokens

0

Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.

implementing-honeypot-for-ransomware-detection

mukul975/Anthropic-Cybersecurity-Skills · implementing-honeypot-for-ransomware-detection

0

Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Activates for requests involving ransomware honeypots, canary files, deception technology for ransomware, or early ransomware alerting.