killvxk

180 mods across 3 repositories, 197 stars between them.

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A Windows malware-analysis procedure that uses Sysinternals Autoruns to find programs configured to start automatically. Autoruns lists startup locations such as registry entries, services, scheduled tasks, drivers, and other system extensions.

43 4mo ago A 53 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A malware-analysis procedure for finding signs that a malicious program is trying to detect or avoid a security sandbox. A sandbox is an isolated environment used to run suspicious files safely; Cuckoo Sandbox and AnyRun produce reports about what those files do.

43 4mo ago A 60 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A procedure for examining a captured computer's RAM with Volatility, a memory-forensics tool. It helps investigate activity that may exist only in memory, such as hidden processes, injected code, network connections, or credentials.

43 4mo ago A 97 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide to finding covert communication channels in malware, where data is hidden inside ordinary DNS, ICMP, or HTTP traffic. Command and control means the connection malware uses to receive instructions; data exfiltration means stealing data from a system.

43 4mo ago A 59 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide to examining network traffic produced by malware, using packet captures and tools such as Wireshark, Zeek, and Suricata. A packet capture is a recorded copy of network communications.

43 4mo ago A 101 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide for using Wireshark and tshark to capture and inspect network packets. Packets are the small pieces of data sent across a network; the guide focuses on authorized troubleshooting and security investigations.

43 4mo ago B 58 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide to examining Outlook PST and OST files, which are files that store email and other Outlook data. It covers extracting messages, headers, attachments, deleted items, and related metadata for investigations.

43 4mo ago A 67 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide for examining a PDF’s internal structure to find malicious content without opening it in a PDF reader. It looks for JavaScript, automatic actions, exploit code, embedded files, and other suspicious objects.

43 4mo ago A 110 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide to finding ways attackers can make Linux programs or accounts start again automatically after a restart or login. It examines scheduled tasks, system services, shell startup files, injected libraries, and SSH keys.

43 4mo ago B 58 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide to reading the hidden metadata in email messages to check where they came from and whether the sender's identity was authenticated. SPF, DKIM, and DMARC are email checks that help verify sending domains and prevent spoofing.

43 4mo ago A 67 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide for finding PowerShell Empire traces in Windows event logs. PowerShell Empire is a post-compromise framework that attackers can use to control Windows systems after breaking in.

43 4mo ago A 69 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A guide for reading Windows PowerShell Script Block Logging records from EVTX event-log files. These records contain pieces of PowerShell scripts, including commands that may be encoded, hidden, or used to download malware.

43 4mo ago A 111 tokens original Apache-2.0

killvxk/cybersecurity-skills-zh

Skill Claude CodeCodex

A threat-intelligence workflow for monitoring ransomware data-leak sites, where criminal groups publish victim names or stolen-data samples to pressure payment. It focuses on collecting and analyzing information about ransomware activity.

43 4mo ago A 65 tokens original Apache-2.0