tag

dfir

13 indexed skills · max 10 per page

skills (13)

analyzing-windows-shellbag-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-windows-shellbag-artifacts

0

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

building-incident-timeline-with-timesketch

mukul975/Anthropic-Cybersecurity-Skills · building-incident-timeline-with-timesketch

0

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.

performing-active-directory-compromise-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-compromise-investigation

0

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.

performing-cloud-forensics-with-aws-cloudtrail

mukul975/Anthropic-Cybersecurity-Skills · performing-cloud-forensics-with-aws-cloudtrail

0

Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.

implementing-velociraptor-for-ir-collection

mukul975/Anthropic-Cybersecurity-Skills · implementing-velociraptor-for-ir-collection

0

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.

performing-memory-forensics-with-volatility3-plugins

mukul975/Anthropic-Cybersecurity-Skills · performing-memory-forensics-with-volatility3-plugins

0

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

detecting-wmi-persistence

mukul975/Anthropic-Cybersecurity-Skills · detecting-wmi-persistence

0

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

analyzing-malicious-pdf-with-peepdf

mukul975/Anthropic-Cybersecurity-Skills · analyzing-malicious-pdf-with-peepdf

0

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

hunting-for-dcsync-attacks

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-dcsync-attacks

0

Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.

analyzing-mft-for-deleted-file-recovery

mukul975/Anthropic-Cybersecurity-Skills · analyzing-mft-for-deleted-file-recovery

0

Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.

prevpage 1 / 2next