mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-20 06:20:58 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Standards and References - Agentless Vulnerability Scanning
|
||||
|
||||
## Tools and Platforms
|
||||
- Vuls (Open Source): https://vuls.io/
|
||||
- Microsoft Defender for Cloud Agentless: https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-agentless-data-collection
|
||||
- Tenable Agentless Discovery: https://www.tenable.com/cloud-security/capabilities/agentless-asset-vulnerability-discovery
|
||||
- Wiz Agentless VM: https://www.wiz.io/solutions/vulnerability-management
|
||||
- Datadog Agentless Scanning: https://www.datadoghq.com/blog/agentless-scanning/
|
||||
|
||||
## Industry Standards
|
||||
- **NIST SP 800-115**: Technical Guide to Information Security Testing and Assessment
|
||||
- **CIS Controls v8.1 Control 7.5**: Perform Automated Vulnerability Scans of Internal Assets
|
||||
- **PCI DSS v4.0 Req 11.3**: External and internal vulnerability scanning
|
||||
- **ISO 27001:2022 A.8.8**: Management of technical vulnerabilities
|
||||
|
||||
## Protocol Requirements
|
||||
| Protocol | Port | Auth Method | Use Case |
|
||||
|----------|------|-------------|----------|
|
||||
| SSH | 22 | Key-based or password | Linux/Unix scanning |
|
||||
| WinRM | 5985/5986 | NTLM/Kerberos | Windows scanning |
|
||||
| WMI | 135 + dynamic | NTLM | Windows legacy |
|
||||
| SNMP v3 | 161 | AuthPriv | Network devices |
|
||||
| Cloud APIs | 443 | IAM roles/keys | Cloud VMs |
|
||||
@@ -0,0 +1,52 @@
|
||||
# Workflows - Agentless Vulnerability Scanning
|
||||
|
||||
## Workflow 1: Multi-Protocol Scanning Pipeline
|
||||
|
||||
```
|
||||
┌──────────────────┐ ┌──────────────────┐ ┌──────────────────┐
|
||||
│ Asset Discovery │────>│ Classify by │────>│ Select Scanning │
|
||||
│ (CMDB/Network) │ │ OS / Platform │ │ Protocol │
|
||||
└──────────────────┘ └──────────────────┘ └──────────────────┘
|
||||
│
|
||||
┌──────────────┬──────────────┬─────────────────┘
|
||||
v v v
|
||||
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
|
||||
│ SSH Scan │ │ WinRM Scan │ │ Cloud API │
|
||||
│ (Linux) │ │ (Windows) │ │ Snapshot Scan│
|
||||
└──────────────┘ └──────────────┘ └──────────────┘
|
||||
│ │ │
|
||||
└──────────────┴──────────────┘
|
||||
│
|
||||
v
|
||||
┌──────────────────┐
|
||||
│ Normalize & │
|
||||
│ Correlate Results│
|
||||
└──────────────────┘
|
||||
```
|
||||
|
||||
## Workflow 2: Cloud Snapshot Scan Process
|
||||
|
||||
```
|
||||
For each cloud VM:
|
||||
1. Identify attached volumes (root + data)
|
||||
2. Create snapshot of root volume via cloud API
|
||||
3. Mount snapshot in isolated analysis environment
|
||||
4. Extract OS metadata (packages, configs, users)
|
||||
5. Compare against vulnerability databases (NVD, vendor)
|
||||
6. Generate findings with CVE mappings
|
||||
7. Delete temporary snapshot
|
||||
8. Report findings to central dashboard
|
||||
```
|
||||
|
||||
## Workflow 3: Credential Validation Before Scan
|
||||
|
||||
```
|
||||
Pre-Scan Credential Check:
|
||||
For each target:
|
||||
1. Test SSH/WinRM connectivity (TCP handshake)
|
||||
2. Authenticate with stored credentials
|
||||
3. Execute lightweight test command
|
||||
4. Verify sudo/admin privileges if required
|
||||
5. Log result: Success / Auth Failure / Network Error
|
||||
6. Only proceed with scan if credential test passes
|
||||
```
|
||||
Reference in New Issue
Block a user