mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-22 04:30:59 +03:00
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):
- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
invocation, guardrails, model/data poisoning, system-prompt leakage,
embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration
Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
75 lines
2.5 KiB
Markdown
75 lines
2.5 KiB
Markdown
# Velociraptor Command and VQL Reference
|
|
|
|
The same `velociraptor` binary is server, client, and CLI. Behavior depends on the subcommand and `--config`.
|
|
|
|
## Core subcommands
|
|
|
|
| Command | Description |
|
|
|---------|-------------|
|
|
| `velociraptor config generate` | Print a default server config to stdout |
|
|
| `velociraptor config generate -i` | Interactive config wizard |
|
|
| `velociraptor --config server.config.yaml config client` | Derive client config |
|
|
| `velociraptor --config server.config.yaml user add <name> --role administrator` | Create GUI admin |
|
|
| `velociraptor --config server.config.yaml frontend -v` | Start server frontend + GUI |
|
|
| `velociraptor gui` | All-in-one local lab (server + frontend + local client) |
|
|
| `velociraptor --config client.config.yaml client -v` | Run as agent |
|
|
| `velociraptor --config client.config.yaml service install` | Install agent service (Windows) |
|
|
| `velociraptor query "<VQL>"` | Run an ad-hoc VQL query |
|
|
| `velociraptor artifacts list` | List artifacts |
|
|
| `velociraptor artifacts collect <Name> --output results.zip` | Collect an artifact locally |
|
|
| `velociraptor artifacts show <Name>` | Show an artifact definition |
|
|
|
|
## Useful global flags
|
|
|
|
| Flag | Purpose |
|
|
|------|---------|
|
|
| `--config <file>` | Path to config YAML |
|
|
| `-v` / `--verbose` | Verbose logging |
|
|
| `-q` | Alias usage with `query` |
|
|
| `--format json` | Output query results as JSON |
|
|
|
|
## Common VQL plugins (data sources)
|
|
|
|
| Plugin | Returns |
|
|
|--------|---------|
|
|
| `pslist()` | Running processes (Pid, Name, CommandLine, ...) |
|
|
| `glob(globs=...)` | Files matching glob patterns |
|
|
| `parse_evtx(filename=...)` | Windows event log records |
|
|
| `registry(...)` / `read_reg_key()` | Registry keys/values |
|
|
| `netstat()` | Network connections |
|
|
| `wmi(query=...)` | WMI query results |
|
|
| `info()` | Host/system information |
|
|
| `execve(argv=...)` | Run an external command |
|
|
| `artifact_definitions()` | Enumerate loaded artifacts |
|
|
| `hunt(description=..., artifacts=...)` | Create a server-side hunt |
|
|
|
|
## VQL query shape
|
|
|
|
```sql
|
|
SELECT <columns>
|
|
FROM <plugin>(<args>)
|
|
WHERE <condition> -- supports =~ for regex, AND/OR
|
|
ORDER BY <column>
|
|
LIMIT <n>
|
|
```
|
|
|
|
## Custom artifact YAML structure
|
|
|
|
```yaml
|
|
name: Custom.Category.Name
|
|
description: What it does.
|
|
parameters:
|
|
- name: param1
|
|
default: value
|
|
sources:
|
|
- query: |
|
|
SELECT * FROM plugin() WHERE col =~ param1
|
|
```
|
|
|
|
## Default ports
|
|
|
|
| Service | Port |
|
|
|---------|------|
|
|
| Frontend (client comms) | 8000 |
|
|
| Admin GUI | 8889 |
|