deploying-decoy-files-for-ransomware-detection

mukul975/deploying-decoy-files-for-ransomware-detection · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time using file integrity monitoring or OS-level watchdogs.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 3.1 KB
  • 📁scripts
  • ⚙️agent.py 9.2 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-honeypot-for-ransomware-detection · mukul975 bundle
    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.
    24.6k
    repo stars
  2. deploying-ransomware-canary-files · mukul975 bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection, triggering alerts via email, Slack, or syslog when decoy files are accessed.
    24.6k
    repo stars
  3. detecting-ransomware-encryption-behavior · mukul975 bundle
    Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics.
    24.6k
    repo stars
  4. implementing-deception-based-detection-with-canarytoken · mukul975 bundle
    Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
    24.6k
    repo stars
  5. implementing-honeytokens-for-breach-detection · mukul975 bundle
    Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection.
    24.6k
    repo stars
  6. performing-ransomware-response · mukul975 bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
    24.6k
    repo stars

Frequently asked questions

How do I install the deploying-decoy-files-for-ransomware-detection skill?

Run npx skillmds add mukul975/deploying-decoy-files-for-ransomware-detection in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the deploying-decoy-files-for-ransomware-detection skill do?

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time using file integrity monitoring or OS-level watchdogs. It is listed under Security, Coding & Dev Tools, Incident Response on SkillMD.

Is deploying-decoy-files-for-ransomware-detection safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with deploying-decoy-files-for-ransomware-detection?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is deploying-decoy-files-for-ransomware-detection free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published deploying-decoy-files-for-ransomware-detection?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.