conducting-malware-incident-response

mukul975/conducting-malware-incident-response · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.7 KB
  • 📁scripts
  • ⚙️agent.py 7.1 KB
  • 📄LICENSE 11.0 KB

Related

  1. building-soc-playbook-for-ransomware · mukul975 bundle
    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
    24.6k
    repo stars
  2. triaging-security-incident · mukul975 bundle
    Triages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
    24.6k
    repo stars
  3. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  4. hunting-for-webshell-activity · mukul975 bundle
    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
    24.6k
    repo stars
  5. hunting-for-unusual-network-connections · mukul975 bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    24.6k
    repo stars
  6. detecting-suspicious-powershell-execution · mukul975 bundle
    Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
    24.6k
    repo stars

Frequently asked questions

How do I install the conducting-malware-incident-response skill?

Run npx skillmds add mukul975/conducting-malware-incident-response in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the conducting-malware-incident-response skill do?

Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. It is listed under Security, Coding & Dev Tools, Incident Response on SkillMD.

Is conducting-malware-incident-response safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with conducting-malware-incident-response?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is conducting-malware-incident-response free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published conducting-malware-incident-response?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.