mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-30 16:06:52 +03:00
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):
- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
invocation, guardrails, model/data poisoning, system-prompt leakage,
embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration
Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2.9 KiB
2.9 KiB
Trivy — Command and Flag Reference
Scan Targets (subcommands)
| Command | Target | Example |
|---|---|---|
trivy image |
Container image (registry/tar) | trivy image alpine:3.19 |
trivy fs |
Local filesystem / project dir | trivy fs ./ |
trivy repository (repo) |
Git repository (local or remote URL) | trivy repo https://github.com/org/repo |
trivy config |
IaC / config misconfiguration | trivy config ./infra |
trivy sbom |
Existing SBOM (CycloneDX/SPDX) | trivy sbom sbom.cdx.json |
trivy kubernetes (k8s) |
Live Kubernetes cluster | trivy k8s --report summary cluster |
trivy vm |
VM image (AMI/EBS/VMDK) | trivy vm ami:ami-0123 |
trivy rootfs |
Extracted root filesystem | trivy rootfs /mnt/rootfs |
Key Flags
| Flag | Description |
|---|---|
--scanners vuln,misconfig,secret,license |
Select which scanners to run |
--severity LOW,MEDIUM,HIGH,CRITICAL |
Filter results by severity |
--exit-code <n> |
Exit code when matching results are found (gating) |
--ignore-unfixed |
Suppress vulnerabilities with no fixed version |
--format table|json|sarif|cyclonedx|spdx-json |
Output format |
--output <file> |
Write report to file |
--input <file> |
Scan an image tar instead of a registry ref |
--vuln-type os,library |
Limit vulnerability detection scope |
--image-config-scanners misconfig,secret |
Scan image build config/history |
--config-policy <dir> |
Custom Rego misconfig policy directory |
--policy-namespaces <ns> |
Rego policy namespaces to evaluate |
--download-db-only |
Pre-download vulnerability DB (caching/air-gap) |
--download-java-db-only |
Pre-download Java index DB |
--skip-dirs / --skip-files |
Exclude paths from scan |
--ignorefile <path> |
Path to .trivyignore (default .trivyignore) |
Output Formats
| Format | Use |
|---|---|
table |
Human-readable console (default) |
json |
Programmatic gating / parsing |
sarif |
GitHub code scanning / IDE ingestion |
cyclonedx |
CycloneDX SBOM |
spdx-json |
SPDX SBOM (JSON) |
github |
GitHub dependency snapshot |
.trivyignore Format
# One ID per line; supports CVE, AVD (misconfig), and secret rule IDs
CVE-2023-12345
AVD-AWS-0089
generic-api-key
GitHub Actions (trivy-action)
- uses: aquasecurity/trivy-action@master
with:
scan-type: 'image' # image | fs | config | repo | sbom
image-ref: 'myorg/app:1.4.0'
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'HIGH,CRITICAL'
ignore-unfixed: true
exit-code: '1'
External References
- Trivy Docs: https://trivy.dev/latest/docs/
- Configuration reference: https://trivy.dev/latest/docs/configuration/
- Misconfiguration scanning: https://trivy.dev/latest/docs/scanner/misconfiguration/
- SBOM: https://trivy.dev/latest/docs/supply-chain/sbom/