mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-14 20:05:22 +03:00
Production hardening: security fixes, code quality, 724 skills complete
- Fix 25 shell=True subprocess calls with list-based commands - Fix 49 verify=False in defensive skills (env-var override) - Add timeout to 231 HTTP/subprocess/socket calls - Fix 6 SQL injection patterns with whitelist validation - Replace 8 __import__() with standard imports - Remove 701 unused imports across 442 files - Add authorized-testing disclaimers to all offensive skills - Complete 11 incomplete skill directories - Expand 10 stub SKILL.md files with full content - Fix 2 YAML parse errors in frontmatter - Fix 5 pre-existing syntax errors - Convert 22 hardcoded paths/ports to environment variables - Back up 21 redundant skill pairs to .bak - Fix 2 global declaration errors - 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE) - 0 compile errors across all 724 agent.py files
This commit is contained in:
@@ -0,0 +1,86 @@
|
||||
# Phishing Email Header Analysis Report Template
|
||||
|
||||
## Report Information
|
||||
- **Analyst**: [Name]
|
||||
- **Date**: [YYYY-MM-DD]
|
||||
- **Case ID**: [CASE-XXXX]
|
||||
- **Classification**: [Phishing / Spear-phishing / BEC / Legitimate]
|
||||
|
||||
## Email Summary
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| From | |
|
||||
| To | |
|
||||
| Subject | |
|
||||
| Date Received | |
|
||||
| Message-ID | |
|
||||
|
||||
## Authentication Results
|
||||
| Check | Result | Domain | Notes |
|
||||
|---|---|---|---|
|
||||
| SPF | pass/fail/none | | |
|
||||
| DKIM | pass/fail/none | | |
|
||||
| DMARC | pass/fail/none | | |
|
||||
|
||||
## Sender Analysis
|
||||
| Field | Value | Match From? |
|
||||
|---|---|---|
|
||||
| From (header) | | N/A |
|
||||
| Return-Path (envelope) | | Yes/No |
|
||||
| Reply-To | | Yes/No |
|
||||
| X-Originating-IP | | |
|
||||
| X-Mailer | | |
|
||||
|
||||
## Routing Analysis
|
||||
| Hop | Server From | Server By | IP | Location | Time |
|
||||
|---|---|---|---|---|---|
|
||||
| 1 | | | | | |
|
||||
| 2 | | | | | |
|
||||
| 3 | | | | | |
|
||||
|
||||
## Indicators of Compromise (IOCs)
|
||||
### IP Addresses
|
||||
| IP | Source | Reputation | Location |
|
||||
|---|---|---|---|
|
||||
| | | | |
|
||||
|
||||
### Domains
|
||||
| Domain | Source | Age | Reputation |
|
||||
|---|---|---|---|
|
||||
| | | | |
|
||||
|
||||
### URLs
|
||||
| URL | Context | Status |
|
||||
|---|---|---|
|
||||
| | | |
|
||||
|
||||
## Phishing Indicators Found
|
||||
| # | Category | Description | Severity |
|
||||
|---|---|---|---|
|
||||
| 1 | | | |
|
||||
| 2 | | | |
|
||||
| 3 | | | |
|
||||
|
||||
## Risk Assessment
|
||||
- **Risk Score**: [0-100]
|
||||
- **Risk Level**: [CLEAN / LOW / MEDIUM / HIGH / CRITICAL]
|
||||
- **Confidence**: [Low / Medium / High]
|
||||
|
||||
## Recommended Actions
|
||||
- [ ] Block sender domain at email gateway
|
||||
- [ ] Add originating IP to blocklist
|
||||
- [ ] Submit IOCs to threat intelligence platform
|
||||
- [ ] Notify affected users
|
||||
- [ ] Check for similar messages in mail logs
|
||||
- [ ] Update email filtering rules
|
||||
- [ ] Report to anti-phishing databases (PhishTank, APWG)
|
||||
|
||||
## Evidence Chain
|
||||
| Item | Hash (SHA-256) | Description |
|
||||
|---|---|---|
|
||||
| Original .eml | | Raw email file |
|
||||
| Headers export | | Extracted headers |
|
||||
| Screenshots | | Visual evidence |
|
||||
|
||||
## Notes
|
||||
[Additional observations, context, or analysis notes]
|
||||
Reference in New Issue
Block a user