implementing-honeypot-for-ransomware-detection

mukul975/implementing-honeypot-for-ransomware-detection · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. deploying-decoy-files-for-ransomware-detection · mukul975 bundle
    Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time using file integrity monitoring or OS-level watchdogs.
    24.6k
    repo stars
  2. performing-deception-technology-deployment · mukul975 bundle
    Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates.
    24.6k
    repo stars
  3. hunting-for-shadow-copy-deletion · mukul975 bundle
    Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
    24.6k
    repo stars
  4. recovering-from-ransomware-attack · mukul975 bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection.
    24.6k
    repo stars
  5. deploying-ransomware-canary-files · mukul975 bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection, triggering alerts via email, Slack, or syslog when decoy files are accessed.
    24.6k
    repo stars
  6. implementing-deception-based-detection-with-canarytoken · mukul975 bundle
    Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
    24.6k
    repo stars

Frequently asked questions

How do I install the implementing-honeypot-for-ransomware-detection skill?

Run npx skillmds add mukul975/implementing-honeypot-for-ransomware-detection in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-honeypot-for-ransomware-detection skill do?

Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. It is listed under Security, Coding & Dev Tools, Incident Response on SkillMD.

Is implementing-honeypot-for-ransomware-detection safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-honeypot-for-ransomware-detection?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-honeypot-for-ransomware-detection free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-honeypot-for-ransomware-detection?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.