mukul975/Anthropic-Cybersecurity-Skills
Plugin Claude Code
818 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
177 tagged mitre-attack, measured the same way as everything else here.
mukul975/Anthropic-Cybersecurity-Skills
Plugin Claude Code
818 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
mukul975/Anthropic-Cybersecurity-Skills
Instructions file GitHub Copilot
Copilot instructions for mukul975/Anthropic-Cybersecurity-Skills, covering copilot instructions for anthropic-cybersecurity-skills, quick facts, repository structure, build & development and prerequisites.
mukul975/Anthropic-Cybersecurity-Skills
Instructions file CodexOpenCode
AGENTS.md instructions for mukul975/Anthropic-Cybersecurity-Skills, covering agents.md, what this repository is, reading a skill, changing a skill and writing a description.
mukul975/Anthropic-Cybersecurity-Skills
Skill Claude CodeCodex
Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback domains, dead drops). Use after reverse engineering reveals network traffic needing protocol analysis or when building…
Instructions file CodexOpenCode
AGENTS.md instructions for beenuar/AiSOC, covering learned user preferences and learned workspace facts.
killvxk/cybersecurity-skills-zh
Skill Claude CodeCodex
A cybersecurity workflow for using MITRE ATT&CK Navigator, a web tool for mapping how attackers operate, to analyze advanced persistent threat groups and their techniques.
CooperCyberCoffee/opencti_mcp_server
Instructions file
Claude Code instructions for CooperCyberCoffee/opencti_mcp_server, covering cooper cyber coffee opencti mcp server, project overview, recent features (v0.4.2), previous features (v0.4.1 and earlier) and development standards.
Instructions file GitHub Copilot
Instructions for meltedinhex/analyst-ai-pack, covering analystaipack — github copilot instructions, how to help in this repo, safety rules (do not violate) and authoring or editing a skill.
Instructions file CodexOpenCode
Instructions for meltedinhex/analyst-ai-pack, covering agents.md — using analystaipack as an ai agent, what this repo is, how to pick a skill, how to run a skill and or directly.
Skill Claude CodeCodex
Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on…
Skill Claude CodeCodex
Statically analyzes Linux ELF malware: ELF header and sections, dynamic symbols and imports, segment permissions, embedded strings, and packing indicators to infer capability without execution. Activates for requests to analyze an ELF binary, Linux malware, or shared object.
Skill Claude CodeCodex
Analyzes weaponized Windows shortcut (.lnk) files: parsing the shell link structure for the target command, arguments, icon, and working directory, and recovering hidden PowerShell/cmd payloads and embedded content used in phishing. Activates for requests to analyze a malicious LNK, parse a shortcut file, or extract a…
ayuksel-tenb/tenable-attack-mapper
Plugin Claude Code
Map Tenable Security Center findings to MITRE ATT&CK techniques and export a VPR-scored ATT&CK Navigator layer.
ayuksel-tenb/tenable-attack-mapper
Skill Claude CodeCodex
Clone the attack-navigator viewer, map this Security Center's open findings to MITRE ATT&CK, bring the viewer up, and open the VPR-scored ATT&CK matrix in the browser. Use when the user asks to show / open / visualize the ATT&CK matrix or their exposure, e.g. "open the attack matrix", "show me the ATT&CK matrix".
ayuksel-tenb/tenable-attack-mapper
Agent
Threat-informed vulnerability analyst. Maps Tenable Security Center findings to MITRE ATT&CK techniques and produces a VPR-scored Navigator layer. Use when the user asks which ATT&CK tactics/techniques to watch, which findings map to a technique, or to export an ATT&CK Navigator coverage layer.
Instructions file CodexOpenCode
Instructions for lidless-labs/mitre-mcp, covering repository guidance, definition of done, project shape, verification workflow and soc safety (hard prohibitions).
Instructions file
Instructions for haporfirio/cyberskills-hub, covering cyberskills documentation hub, instrucao de routing, role context, top-50 keywords and domain lookup.
Plugin Claude Code
Offline methodology engine and payload workshop for authorized penetration testing, CTF, security research, and education.
Instructions file CodexOpenCode
AGENTS.md instructions for cyanheads/pentest-mcp-server, covering developer protocol, core rules, patterns, tool (representative — pentestlookuptechnique) and server instructions.
Instructions file
Claude Code instructions for cyanheads/pentest-mcp-server, covering developer protocol, core rules, patterns, tool (representative — pentestlookuptechnique) and server instructions.
Skill Claude CodeCodex
Scaffold a new MCP tool definition. Use when the user asks to add a tool, create a new tool, or implement a new capability for the server.
Skill Claude CodeCodex
Design the tool surface, resources, and service layer for a new MCP server. Use when starting a new server, planning a major feature expansion, or when the user describes a domain/API they want to expose via MCP. Produces a design doc at docs/design.md that drives implementation.
Skill Claude CodeCodex
Ship a release end-to-end across every registry the project targets (npm, MCP Registry, GitHub Releases for .mcpb bundles, GHCR). Runs the final verification gate, pushes commits and tags, then publishes to each applicable destination. Assumes git wrapup (version bumps, changelog, commit, annotated tag) is already…
MCP server Claude CodeCodexCursor
Offline methodology engine for authorized penetration testing, CTF, and security research. Runs locally from the @cyanheads/pentest-mcp-server npm package. Needs 1 environment variable to run.
At most 3 mods per repository are shown here — the rest are on their repository pages: