mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-20 14:30:59 +03:00
- Fix 25 shell=True subprocess calls with list-based commands - Fix 49 verify=False in defensive skills (env-var override) - Add timeout to 231 HTTP/subprocess/socket calls - Fix 6 SQL injection patterns with whitelist validation - Replace 8 __import__() with standard imports - Remove 701 unused imports across 442 files - Add authorized-testing disclaimers to all offensive skills - Complete 11 incomplete skill directories - Expand 10 stub SKILL.md files with full content - Fix 2 YAML parse errors in frontmatter - Fix 5 pre-existing syntax errors - Convert 22 hardcoded paths/ports to environment variables - Back up 21 redundant skill pairs to .bak - Fix 2 global declaration errors - 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE) - 0 compile errors across all 724 agent.py files
1.9 KiB
1.9 KiB
Phishing Email Header Analysis Report Template
Report Information
- Analyst: [Name]
- Date: [YYYY-MM-DD]
- Case ID: [CASE-XXXX]
- Classification: [Phishing / Spear-phishing / BEC / Legitimate]
Email Summary
| Field | Value |
|---|---|
| From | |
| To | |
| Subject | |
| Date Received | |
| Message-ID |
Authentication Results
| Check | Result | Domain | Notes |
|---|---|---|---|
| SPF | pass/fail/none | ||
| DKIM | pass/fail/none | ||
| DMARC | pass/fail/none |
Sender Analysis
| Field | Value | Match From? |
|---|---|---|
| From (header) | N/A | |
| Return-Path (envelope) | Yes/No | |
| Reply-To | Yes/No | |
| X-Originating-IP | ||
| X-Mailer |
Routing Analysis
| Hop | Server From | Server By | IP | Location | Time |
|---|---|---|---|---|---|
| 1 | |||||
| 2 | |||||
| 3 |
Indicators of Compromise (IOCs)
IP Addresses
| IP | Source | Reputation | Location |
|---|---|---|---|
Domains
| Domain | Source | Age | Reputation |
|---|---|---|---|
URLs
| URL | Context | Status |
|---|---|---|
Phishing Indicators Found
| # | Category | Description | Severity |
|---|---|---|---|
| 1 | |||
| 2 | |||
| 3 |
Risk Assessment
- Risk Score: [0-100]
- Risk Level: [CLEAN / LOW / MEDIUM / HIGH / CRITICAL]
- Confidence: [Low / Medium / High]
Recommended Actions
- Block sender domain at email gateway
- Add originating IP to blocklist
- Submit IOCs to threat intelligence platform
- Notify affected users
- Check for similar messages in mail logs
- Update email filtering rules
- Report to anti-phishing databases (PhishTank, APWG)
Evidence Chain
| Item | Hash (SHA-256) | Description |
|---|---|---|
| Original .eml | Raw email file | |
| Headers export | Extracted headers | |
| Screenshots | Visual evidence |
Notes
[Additional observations, context, or analysis notes]