mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-21 12:10:59 +03:00
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):
- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
invocation, guardrails, model/data poisoning, system-prompt leakage,
embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration
Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2.5 KiB
2.5 KiB
Velociraptor Command and VQL Reference
The same velociraptor binary is server, client, and CLI. Behavior depends on the subcommand and --config.
Core subcommands
| Command | Description |
|---|---|
velociraptor config generate |
Print a default server config to stdout |
velociraptor config generate -i |
Interactive config wizard |
velociraptor --config server.config.yaml config client |
Derive client config |
velociraptor --config server.config.yaml user add <name> --role administrator |
Create GUI admin |
velociraptor --config server.config.yaml frontend -v |
Start server frontend + GUI |
velociraptor gui |
All-in-one local lab (server + frontend + local client) |
velociraptor --config client.config.yaml client -v |
Run as agent |
velociraptor --config client.config.yaml service install |
Install agent service (Windows) |
velociraptor query "<VQL>" |
Run an ad-hoc VQL query |
velociraptor artifacts list |
List artifacts |
velociraptor artifacts collect <Name> --output results.zip |
Collect an artifact locally |
velociraptor artifacts show <Name> |
Show an artifact definition |
Useful global flags
| Flag | Purpose |
|---|---|
--config <file> |
Path to config YAML |
-v / --verbose |
Verbose logging |
-q |
Alias usage with query |
--format json |
Output query results as JSON |
Common VQL plugins (data sources)
| Plugin | Returns |
|---|---|
pslist() |
Running processes (Pid, Name, CommandLine, ...) |
glob(globs=...) |
Files matching glob patterns |
parse_evtx(filename=...) |
Windows event log records |
registry(...) / read_reg_key() |
Registry keys/values |
netstat() |
Network connections |
wmi(query=...) |
WMI query results |
info() |
Host/system information |
execve(argv=...) |
Run an external command |
artifact_definitions() |
Enumerate loaded artifacts |
hunt(description=..., artifacts=...) |
Create a server-side hunt |
VQL query shape
SELECT <columns>
FROM <plugin>(<args>)
WHERE <condition> -- supports =~ for regex, AND/OR
ORDER BY <column>
LIMIT <n>
Custom artifact YAML structure
name: Custom.Category.Name
description: What it does.
parameters:
- name: param1
default: value
sources:
- query: |
SELECT * FROM plugin() WHERE col =~ param1
Default ports
| Service | Port |
|---|---|
| Frontend (client comms) | 8000 |
| Admin GUI | 8889 |