Data & Analytics
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
-
mukul975 Bundle Analyzing Network Flow Data With NetflowParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns using the Python netflow library.
24.6k -
mukul975 Bundle Analyzing Network Traffic With WiresharkCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
24.6k -
mukul975 Bundle Exploiting API Injection VulnerabilitiesTests APIs for injection vulnerabilities including SQL, NoSQL, OS command, LDAP, and SSRF through parameters, headers, and request bodies.
24.6k -
mukul975 Bundle Exploiting SQL Injection VulnerabilitiesIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.
24.6k -
mukul975 Bundle Implementing Stix Taxii Feed IntegrationConsume and produce STIX/TAXII 2.1 cyber threat intelligence feeds using Python, including server discovery, collection polling, object parsing, and SIEM/TIP integration.
Audited 24.6k -
mukul975 Bundle Analyzing Outlook Pst For Email ForensicsAnalyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
24.6k -
mukul975 Bundle Analyzing Powershell Script Block LoggingParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.
24.6k -
mukul975 Bundle Analyzing Windows Lnk Files For ArtifactsParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
24.6k -
mukul975 Bundle Deploying Osquery For Endpoint MonitoringDeploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.
24.6k -
mukul975 Bundle Hunting For Unusual Service InstallationsDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
Audited 24.6k -
mukul975 Bundle Implementing Siem Use Cases For DetectionDesign, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
24.6k -
mukul975 Bundle Investigating Ransomware Attack ArtifactsIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
24.6k -
mukul975 Bundle Performing Red Team Phishing With GophishAutomates GoPhish phishing simulation campaigns using the Python gophish library to create email templates, configure SMTP profiles, import targets, launch campaigns, and analyze results for security awareness assessment.
24.6k -
mukul975 Bundle Analyzing Browser Forensics With HindsightExtract and analyze Chromium-based browser artifacts using Hindsight to reconstruct user web activity for forensic investigations.
24.6k -
mukul975 Bundle Analyzing Lnk File And Jump List ArtifactsAnalyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
24.6k -
mukul975 Bundle Building Incident Timeline With TimesketchBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
24.6k -
mukul975 Bundle Building Role Mining For Rbac OptimizationApply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
24.6k -
mukul975 Bundle Detecting Modbus Command Injection AttacksDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines.
24.6k -
mukul975 Bundle Implementing Cloud Dlp For Data ProtectionDiscover, classify, and protect sensitive data across cloud storage, databases, and data pipelines using Amazon Macie, Azure Information Protection, and Google Cloud DLP API.
24.6k -
mukul975 Bundle Implementing Log Integrity With BlockchainBuild an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes.
24.6k -
mukul975 Bundle Performing Cloud Log Forensics With AthenaQuery AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
24.6k -
mukul975 Bundle Performing Network Packet Capture AnalysisAnalyze network packet captures (PCAP/PCAPNG) using Wireshark, tshark, tcpdump, and Python to reconstruct communications, extract files, and identify malicious traffic.
24.6k -
mukul975 Bundle Performing Web Application Firewall BypassBypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
24.6k -
mukul975 Bundle Analyzing Macro Malware In Office DocumentsExtracts and analyzes malicious VBA macros, XLM macros, DDE, and remote template injections in Microsoft Office documents using olevba, oledump, and deobfuscation techniques to identify download cradles, payload execution, and persistence mechanisms.
24.6k -
mukul975 Bundle Detecting Anomalous Authentication PatternsDetects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs.
24.6k -
mukul975 Bundle Detecting Insider Data Exfiltration Via DlpDetects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs using pandas for behavioral analytics and statistical baselines.
24.6k -
mukul975 Bundle Generating Forensic Timelines With HayabusaGenerate Sigma-based forensic timelines from Windows EVTX files using Hayabusa for incident response triage.
24.6k -
mukul975 Bundle Implementing Siem Correlation Rules For AptDetect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
24.6k -
mukul975 Bundle Parsing Artifacts With Eric Zimmerman ToolsParse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
24.6k -
mukul975 Bundle Performing Firmware Extraction With BinwalkExtracts and analyzes firmware images using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis, recursive extraction, filesystem mounting, and string analysis for credential and configuration discovery.
24.6k -
mukul975 Bundle Performing Ics Asset Discovery With ClarotyDiscover and inventory ICS/OT assets using Claroty xDome, including passive monitoring, active queries, and integration with CMDB tools.
24.6k -
mukul975 Bundle Performing Network Forensics With WiresharkCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
24.6k -
mukul975 Bundle Securing Historian Server In Ot EnvironmentHardens and secures process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments, covering network placement, access control, data replication through DMZ, SQL injection prevention, and data integrity protection.
Audited 24.6k -
mukul975 Bundle Analyzing Cobalt Strike Beacon ConfigurationExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
24.6k -
mukul975 Bundle Analyzing Cobaltstrike Malleable C2 ProfilesParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
24.6k -
mukul975 Bundle Analyzing Malware Sandbox Evasion TechniquesDetect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
Audited 24.6k
Frequently asked questions
What are Data & Analytics agent skills?
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
Which Data & Analytics skills are most installed?
Popular Data & Analytics skills on SkillMD right now include analyzing-cobalt-strike-beacon-configuration, analyzing-browser-forensics-with-hindsight, deploying-osquery-for-endpoint-monitoring. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Data & Analytics skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.