mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-06 19:00:17 +03:00
Add folder anatomy (scripts/agent.py + references/api-reference.md) for 648 cybersecurity skills
Complete skill folder anatomy across all cybersecurity skills: - scripts/agent.py: 80-150 line Python agents using real libraries (impacket, boto3, azure-mgmt-*, kubernetes, pefile, yara, scapy, shodan, stix2, etc.) - references/api-reference.md: real API documentation with method signatures - LICENSE: MIT license for all skill folders
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
---
|
||||
name: detecting-sql-injection-via-waf-logs
|
||||
description: >-
|
||||
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection
|
||||
attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to
|
||||
identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks
|
||||
attack sources, correlates multi-stage injection attempts, and generates
|
||||
incident reports with OWASP classification.
|
||||
---
|
||||
|
||||
## Instructions
|
||||
|
||||
1. Install dependencies: `pip install requests`
|
||||
2. Collect WAF logs (ModSecurity audit log, AWS WAF JSON logs, or Cloudflare firewall events).
|
||||
3. Run the agent to parse and analyze:
|
||||
- Detect SQLi payloads via 15+ regex patterns
|
||||
- Classify attacks by OWASP injection type (classic, blind, time-based, UNION-based)
|
||||
- Identify persistent attackers by IP clustering
|
||||
- Correlate multi-request injection campaigns
|
||||
- Calculate attack success probability based on response codes
|
||||
|
||||
```bash
|
||||
python scripts/agent.py --log-file /var/log/modsec_audit.log --format modsecurity --output sqli_report.json
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
### ModSecurity SQLi Detection
|
||||
```
|
||||
Rule 942100 triggered: SQL Injection Attack Detected via libinjection
|
||||
URI: /api/users?id=1' UNION SELECT username,password FROM users--
|
||||
Source IP: 203.0.113.42 (47 requests in 5 minutes)
|
||||
Classification: UNION-based SQLi campaign
|
||||
```
|
||||
Reference in New Issue
Block a user