Cybersecurity Skills skills
734+ cybersecurity skills — MITRE ATT&CK mapped, pentest, DFIR, threat intel, cloud security skills-hub.ai mirrors 818 skills from Cybersecurity Skills daily, every skill links back to its upstream GitHub source. Install with one command across Claude Code, Cursor, Codex, Windsurf, and any MCP-compatible tool.
Upstream: github.com/mukul975/Anthropic-Cybersecurity-Skills
Installing a Cybersecurity Skills skill
Pick a skill below, then run the install command for your AI coding tool. The skills-hub CLI writes the SKILL.md to the right directory and tracks the install in .skills.json so your team gets reproducible installs.
# Install a Cybersecurity Skills skill
npx @skills-hub-ai/cli install <skill-slug>
# Browse all Cybersecurity Skills skills via API
curl https://skills-hub.ai/api/v1/skills?source=cybersecurity-skills
# Browse all sources
open https://skills-hub.ai/sourcesTop Cybersecurity Skills skills
See all →The most-installed skills from Cybersecurity Skills, ranked by adoption.
01reverse-engineering-malware-with-ghidra
12 installsReverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to study internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Use when static or dynamic analysis flags suspicious functionality needing deeper code review, such as reversing C2 protocols, encryption algorithms, custom obfuscation, or a sample's exploit mechanism.
Buildfrom Cybersecurity Skills02reverse-engineering-ios-app-with-frida
7 installsReverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
Buildfrom Cybersecurity Skills03analyzing-network-traffic-for-incidents
7 installsAnalyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.
Buildfrom Cybersecurity Skills04performing-firmware-malware-analysis
6 installsAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Use for firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
Buildfrom Cybersecurity Skills05implementing-secrets-scanning-in-ci-cd
6 installsIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
Buildfrom Cybersecurity Skills06performing-firmware-extraction-with-binwalk
6 installsPerforms firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
Buildfrom Cybersecurity Skills07exploiting-insecure-deserialization
4 installsIdentifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.
Buildfrom Cybersecurity Skills08performing-osint-with-spiderfoot
2 installsAutomate OSINT collection with the SpiderFoot REST API and CLI (sf.py/spiderfoot-cli) across 200+ modules, selecting scan modes (footprint, investigate, passive) and parsing results for domains, IPs, emails, leaked credentials, and DNS records into a target intelligence profile. Use when mapping an organization's attack surface or profiling a target for threat intelligence.
Buildfrom Cybersecurity Skills09testing-oauth2-implementation-flaws
2 installsTests OAuth 2.0 and OpenID Connect implementations for authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass, using Burp Suite Professional and the EsPReSSO extension to probe the authorization server, client, and token handling. Use when assessing OAuth2/OIDC flows or SSO systems for misconfigurations enabling account takeover.
Buildfrom Cybersecurity Skills10performing-oil-gas-cybersecurity-assessment
2 installsConduct cybersecurity assessments of upstream, midstream, and downstream oil and gas operations, covering pipeline SCADA, refinery DCS, safety instrumented systems, and remote wellhead RTUs, and evaluate compliance with API 1164, TSA Pipeline Security Directives, and IEC 62443. Use when assessing a refinery, pipeline, or production facility or preparing for TSA/API compliance audits; not for IT-only or purely physical-security assessments.
Buildfrom Cybersecurity Skills11detecting-rootkit-activity
2 installsDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, and covert network connections using Volatility memory forensics, cross-view detection, and tools like GMER, rkhunter, chkrootkit, and RootkitRevealer. Use when standard tools (Task Manager, netstat, AV/EDR) show nothing abnormal but compromise is suspected.
Buildfrom Cybersecurity Skills12performing-disk-forensics-investigation
2 installsConduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination. Use when a security incident requires forensic analysis of persistent storage or when evidence must be preserved for legal or HR proceedings.
Buildfrom Cybersecurity Skills13monitoring-darkweb-sources
2 installsMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
Buildfrom Cybersecurity Skills14performing-ai-driven-osint-correlation
2 installsUse AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unified, confidence-scored intelligence profiles with link analysis. Use when raw OSINT data from multiple sources needs merging into one target profile or resolving identity linkage across platforms.
Buildfrom Cybersecurity Skills15performing-dynamic-analysis-of-android-app
2 installsPerforms runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis.
Buildfrom Cybersecurity Skills16performing-network-forensics-with-wireshark
2 installsCapture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control communications. Use when analyzing captured traffic from a security incident, reconstructing data exfiltration, or finding network indicators of compromise during malware analysis.
Buildfrom Cybersecurity Skills17performing-privilege-escalation-assessment
2 installsPerforms privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment.
Buildfrom Cybersecurity Skills18performing-file-carving-with-foremost
1 installsRecovers files from disk images and unallocated space using Foremost's header-footer signature carving, extracting evidence independent of the file system's state. Use during digital forensics investigations to carve deleted or fragmented files, such as documents, images, and archives, from raw disk images or unallocated space.
Buildfrom Cybersecurity Skills19extracting-browser-history-artifacts
1 installsExtracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView). Use when performing digital forensics or incident response on a disk image or live system and you need timeline evidence of a user's web activity.
Buildfrom Cybersecurity Skills20performing-arp-spoofing-attack-simulation
1 installsSimulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP Inspection, port security, and network monitoring detections. Use when testing whether switches, IDS/IPS, or a SIEM detect ARP spoofing under written authorization; do not use on production networks without explicit approval.
Buildfrom Cybersecurity Skills21exploiting-vulnerabilities-with-metasploit-framework
1 installsUses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather post-exploitation evidence, and confirm patch remediation. Use when performing vulnerability management validation, penetration testing, or post-patch verification and you need to prove real-world exploitability rather than rely on a scanner score alone.
Buildfrom Cybersecurity Skills22testing-websocket-api-security
1 installsTests WebSocket API implementations for missing upgrade-handshake authentication, Cross-Site WebSocket Hijacking (CSWSH), message injection, insufficient input validation, message-flooding DoS, and information leakage, using Burp Suite's WebSocket interception and the wscat CLI to craft malicious payloads. Use for real-time API penetration testing or CSWSH/authorization-bypass assessments on WebSocket channels.
Buildfrom Cybersecurity Skills23analyzing-bootkit-and-rootkit-samples
1 installsAnalyzes bootkit and advanced rootkit malware infecting the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware for below-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection. Use when compromise survives OS reinstallation or antivirus/EDR fails to detect malware despite clear infection signs.
Buildfrom Cybersecurity Skills24detecting-aws-guardduty-findings-automation
1 installsBuild automated AWS GuardDuty finding response pipelines using EventBridge and Lambda to trigger real-time incident response, automatically quarantine compromised resources, and route security notifications. Use when designing automated remediation playbooks for GuardDuty findings across VPC Flow Logs, CloudTrail, DNS, EKS, or S3 data events, or when reducing mean time to respond to cloud threats.
Buildfrom Cybersecurity Skills
About this source
skills-hub.ai mirrors skills from 90+ official GitHub repositories every day. Each imported skill is parsed from a SKILL.md file in the source repo, gets a security scan and quality score on import, and links back to its upstream source of truth.
Last sync: Sep 13, 2026, 4:48 PM (success).
Cybersecurity Skills skills, frequently asked
What are Cybersecurity Skills skills?
Cybersecurity Skills skills are AI coding skills published by Cybersecurity Skills (734+ cybersecurity skills — MITRE ATT&CK mapped, pentest, DFIR, threat intel, cloud security) and mirrored daily on skills-hub.ai. They are SKILL.md files that follow the open Agent Skills standard, so they work in Claude Code, Cursor, Codex CLI, Windsurf, Copilot, and any MCP-compatible tool.
How many Cybersecurity Skills skills are available?
skills-hub.ai indexes 818 skills from Cybersecurity Skills, synced daily from the upstream GitHub repository (https://github.com/mukul975/Anthropic-Cybersecurity-Skills).
How do I install a Cybersecurity Skills skill?
Run `npx @skills-hub-ai/cli install <skill-slug>` in your project. The CLI writes the SKILL.md to the right directory for your AI tool and adds it to your `.skills.json` lockfile so your team gets the same skills at the same versions.
Are these official Cybersecurity Skills skills?
Yes. Every skill from this source is mirrored from Cybersecurity Skills's own GitHub repository (https://github.com/mukul975/Anthropic-Cybersecurity-Skills). Each skill page links back to the upstream source of truth, so you can verify the original.