817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
This repository provides 754 structured cybersecurity skill definitions organized across 26 security domains, designed to be loaded into AI agents via the agentskills.io open standard. Each skill is a machine-readable file containing methodology, tool guidance, and cross-framework identifiers covering MITRE ATT&CK v19.1, NIST CSF 2.0, MITRE ATLAS v5.4, MITRE D3FEND v1.3, and NIST AI RMF 1.0 simultaneously. A concrete example maps the skill `analyzing-network-traffic-of-malware` to ATT&CK technique T1071, NIST CSF category DE.CM, ATLAS technique AML.T0047, D3FEND technique D3-NTA, and AI RMF subcategory MEASURE-2.6 in a single file. The library installs via npx or git clone and works directly with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, and Gemini CLI. Security analysts, red teamers, and DevSecOps engineers building agentic workflows benefit most, as the skills cover domains including penetration testing, malware analysis, threat hunting, OSINT, incident response, and cloud security. The ATT&CK mappings are validated against the official mitreattack-python library with no revoked or deprecated technique IDs.
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Healthy fork ratio
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
git clone https://github.com/mukul975/Anthropic-Cybersecurity-Skills && cp Anthropic-Cybersecurity-Skills/*.md ~/.claude/agents/24 items en este repositorio
Create forensically sound bit-for-bit disk images using dd and dcfldd
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware samples using apktool
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
Analyze advanced persistent threat (APT) group techniques using MITRE
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
Analyzes bootkit and advanced rootkit malware that infects the Master
Analyze Chromium-based browser artifacts using Hindsight to extract browsing
Campaign attribution analysis involves systematically evaluating evidence
Monitor Certificate Transparency logs using crt.sh and Certstream to
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage
Extract and analyze Cobalt Strike beacon configuration from PE files
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike
Analyzes malware command-and-control (C2) communication protocols to
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
Perform comprehensive forensic analysis of disk images using Autopsy
Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
Investigate compromised Docker containers by analyzing images, layers,
Parse and analyze email headers to trace the origin of phishing emails,
Perform static and symbolic analysis of Solidity smart contracts using
Reverse engineer Go-compiled malware using Ghidra with specialized scripts
Detect and analyze heap spray attacks in memory dumps using Volatility3
Resumen de Subagents
<p align="center"> <img src="assets/banner.png" alt="Anthropic Cybersecurity Skills" width="100%"> </p> <div align="center"> # Anthropic Cybersecurity Skills ### The largest open-source cybersecurity skills library for AI agents [](https://mahipal.engineer/survey?utm_source=github_badge&utm_medium=readme&utm_campaign=gars2026) [](LICENSE) [](#whats-inside--29-security-domains) [](#six-frameworks-one-skill-library) [](https://ctid.mitre.org/fraud/) [](#whats-inside--29-security-domains) [](#compatible-platforms) [](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/stargazers) [](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/network/members) [](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/commits/main) [](https://agentskills.io) [](CONTRIBUTING.md) [](https://casky.ai/?utm_source=github&utm_medium=readme&utm_campaign=cohort_launch#waitlist) [](https://github.com/NousResearch/hermes-agent) **817 production-grade cybersecurity skills · 29 security domains · 6 framework mappings · 26+ AI platforms** [Get Started](#quick-start) · [What's Inside](#whats-inside--29-security-domains) · [Frameworks](#five-frameworks-one-skill-library) · [Platforms](#compatible-platforms) · [Contributing](#contributing) </div> --- > ⚠️ **Community Project** — This is an independent, community-created project. Not affiliated with Anthropic PBC. > > 🔐 **Authorized & lawful use only.** This library includes offensive and dual-use techniques (e.g. red-team C2, phishing simulation, exploitation) intended for **authorized penetration testing, security research, defense, and education**. Only use them against systems you own or have **explicit written permission** to test, and comply with all applicable laws and rules of engagement. You are solely responsible for how you use these skills. See [SECURITY.md](SECURITY.md) and [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md). ## Give any AI agent the security skills of a senior analyst A junior analyst knows which Volatility3 plugin to run on a suspicious memory dump, which Sigma rules catch Kerberoasting, and how to scope a cloud breach across three providers. **Your AI agent doesn't — unless you give it these skills.** This repo contains **817 structured cybersecurity skills** spanning **29 security domains**, each following the [agentskills.io](https://agentskills.io) open standard. Every skill is mapped to **six industry frameworks** — MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, NIST AI RMF, and the MITRE Fight Fraud Framework (F3) — making this the only open-source skills library with unified cross-framework coverage. Clone it, point your agent at it, and your next security investigation gets expert-level guidance in seconds. ## Six frameworks, one skill library No other open-source skills library maps every skill to all of these frameworks. One skill, six compliance checkboxes. | Framework | Version | Scope in this repo | What it maps | |---|---|---|---| | [MITRE ATT&CK](https://attack.mitre.org) | v19.1 | 15 tactics · 286 techniques | Adversary behaviors and TTPs | | [NIST CSF 2.0](https://www.nist.gov/cyberframework) | 2.0 | 6 functions · 22 categories | Organizational security posture | | [MITRE ATLAS](https://atlas.mitre.org) | v5.4 | 16 tactics · 84 techniques | AI/ML adversarial threats | | [MITRE D3FEND](https://d3fend.mitre.org) | v1.3 | 7 categories · 267 techniques | Defensive countermeasures | | [NIST AI RMF](https://airc.nist.gov/AI_RMF) | 1.0 | 4 functions · 72 subcategories | AI risk management | | [MITRE F3 (Fight Fraud Framework)](https://ctid.mitre.org/fraud/) | v1.1 (2026-04-09) | 8 tactics · 123 techniques · 94 fraud-relevant skills | Cyber-enabled financial fraud TTPs | **Example — a single skill maps across all six:** | Skill | ATT&CK | NIST CSF | ATLAS | D3FEND | AI RMF | F3 | |---|---|---|---|---|---|---| | `analyzing-network-traffic-of-malware` | T1071 | DE.CM | AML.T0047 | D3-NTA | MEASURE-2.6 | — | | `detecting-business-email-compromise` | T1566 | DE.AE | — | — | — | F1005.006 · monetization | ### 🆕 MITRE Fight Fraud Framework (F3) — 94 fraud-relevant skills [](https://ctid.mitre.org/fraud/) The **[MITRE Fight Fraud Framework (F3)](https://ctid.mitre.org/fraud/)** was released **April 9, 2026** by MITRE's Center for Threat-Informed Defense (CTID), co-developed with JPMorganChase, Citigroup, Lloyds Banking Group, Standard Chartered, CrowdStrike, Verizon Business, FS-ISAC, and others. It is an ATT&CK-compatible TTP catalog for **cyber-enabled financial fraud** — filling the gap ATT&CK leaves after initial compromise. F3 v1.1 adds **two fraud-specific tactics** that ATT&CK does not enumerate: - **Positioning** (`FA0001`) — actions taken after access to collect/manipulate data and prepare the fraud (synthetic-identity seeding, account warming, beneficiary setup, SIM-swap pre-positioning, banking-session hijack). - **Monetization** (`FA0002`) — converting stolen assets into usable funds (money-mule layering, APP fraud, crypto off-ramping, card cash-out, refund/chargeback abuse). Fraud-specific techniques use `F1XXX` IDs (e.g. `F1005.003` Add Beneficiary, `F1025.003` Wire Transfer, `F1007` Adversary-in-the-Browser); reused ATT&CK techniques keep their `T1XXX` IDs. Mappings live in each skill's `mitre_f3:` frontmatter block — all 123 F3 v1.1 technique IDs were verified against the upstream STIX bundle. See [`docs/mitre-f3-mapping.md`](docs/mitre-f3-mapping.md) for the schema. ### MITRE ATT&CK v19.1 — 754/754 skills mapped Every skill carries a `mitre_attack` frontmatter list validated against **MITRE ATT&CK v19.1** (the latest release) using the official `mitreattack-python` library — 286 distinct techniques across all 15 Enterprise tactics, plus ICS and Mobile techniques where relevant. Zero revoked or deprecated IDs. v19.1's restructured Defense Evasion (now split into **Stealth** and **Defense Impairment**) is reflected below. | Tactic | ID | Skills | |--------|----|--------| | Reconnaissance | TA0043 | 103 | | Resource Development | TA0042 | 22 | | Initial Access | TA0001 | 467 | | Execution | TA0002 | 350 | | Persistence | TA0003 | 444 | | Privilege Escalation | TA0004 | 464 | | Stealth | TA0005 | 442 | | Defense Impairment | TA0112 | 92 | | Credential Access | TA0006 | 202 | | Discovery | TA0007 | 237 | | Lateral Movement | TA0008 | 68 | | Collection | TA0009 | 172 | | Command and Control | TA0011 | 123 | | Exfiltration | TA0010 | 82 | | Impact | TA0040 | 50 | ## Quick start ```bash # Option 1: npx (recommended) npx skills add mukul975/Anthropic-Cybersecurity-Skills # Option 2: Git clone git clone https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git cd Anthropic-Cybersecurity-Skills ``` Works immediately with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI, and any [agentskills.io](https://agentskills.io)-compatible platform. ## 🌍 GARS-2026 — Global Agentic AI Readiness Survey I'm running a global academic study measuring how ready security professionals, developers, and enterprise teams actually are for agentic AI — MCP servers, tool calling, governance, and human-in-the-loop workflows. **If you use this repo, your response would be a genuinely valuable data point.** 📋 **Take the survey (10 min):** [Survey Link](https://mahipal.engineer/survey?utm_source=github_repo&utm_medium=readme&utm_campaign=gars2026) - 60 questions · Anonymous · Supervised by SRH Berlin - You get **50 Casky Tokens** for early access to [casky.ai](https://casky.ai) - Results published open access under CC-BY 4.0 ## 🚀 Try it on the Playground Experience Casky.ai hands-on — no setup required. **[→ Launch Playground on Casky.ai](https://casky.ai/?utm_source=github&utm_medium=readme&utm_campaign=cohort_launch#waitlist)** The playground lets you: - Run live cybersecurity skill exercises against real targets - See AI agents execute structured skills in real time - Explore MITRE ATT&CK mapped workflows interactively - Test threat hunting, DFIR, and penetration testing scenarios No installation. No configuration. Just open and start. ## Why this exists The cybersecurity workforce gap hit **4.8 million unfilled roles** globally in 2024 (ISC2). AI agents can help close that gap — but only if they have structured domain knowledge to work from. Today's agents can write code and search the web, but they lack the practitioner playbooks that turn a generic LLM into a capable security analyst. Existing security tool repos give you wordlists, payloads, or exploit code. None of them give an AI agent the structured decision-making workfl
Lo que la gente pregunta sobre Anthropic-Cybersecurity-Skills
¿Qué es mukul975/Anthropic-Cybersecurity-Skills?
+
mukul975/Anthropic-Cybersecurity-Skills es subagents para el ecosistema de Claude AI. 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0 Tiene 26.7k estrellas en GitHub y se actualizó por última vez 1mo ago.
¿Cómo se instala Anthropic-Cybersecurity-Skills?
+
Puedes instalar Anthropic-Cybersecurity-Skills clonando el repositorio (https://github.com/mukul975/Anthropic-Cybersecurity-Skills) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar mukul975/Anthropic-Cybersecurity-Skills?
+
Nuestro agente de seguridad ha analizado mukul975/Anthropic-Cybersecurity-Skills y le ha asignado un Trust Score de 100/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene mukul975/Anthropic-Cybersecurity-Skills?
+
mukul975/Anthropic-Cybersecurity-Skills es mantenido por mukul975. La última actividad registrada en GitHub es de 1mo ago, con 44 issues abiertos.
¿Hay alternativas a Anthropic-Cybersecurity-Skills?
+
Sí. En ClaudeWave puedes explorar subagents similares en /categories/agents, ordenados por popularidad o actividad reciente.
Despliega Anthropic-Cybersecurity-Skills en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/mukul975-anthropic-cybersecurity-skills)<a href="https://claudewave.com/repo/mukul975-anthropic-cybersecurity-skills"><img src="https://claudewave.com/api/badge/mukul975-anthropic-cybersecurity-skills" alt="Featured on ClaudeWave: mukul975/Anthropic-Cybersecurity-Skills" width="320" height="64" /></a>Más Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
The agent engineering platform.
Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.