external/anthropic-cybersecurity-skills/skills/hunting-for-data-exfiltration-indicators/SKILL.md
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.
npx skillsauth add seikaikyo/dash-skills hunting-for-data-exfiltration-indicatorsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Concept | Description | |---------|-------------| | T1041 | Exfiltration Over C2 Channel | | T1048 | Exfiltration Over Alternative Protocol | | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 | | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 | | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 | | T1567 | Exfiltration Over Web Service | | T1567.002 | Exfiltration to Cloud Storage | | T1052 | Exfiltration Over Physical Medium | | T1029 | Scheduled Transfer | | T1030 | Data Transfer Size Limits (staging) | | T1537 | Transfer Data to Cloud Account | | T1020 | Automated Exfiltration |
| Tool | Purpose | |------|---------| | Splunk | SIEM for data volume analysis and SPL queries | | Zeek | Network metadata for data flow analysis | | Microsoft Defender for Cloud Apps | CASB for cloud exfiltration | | Netskope | Cloud DLP and exfiltration detection | | Suricata | Network IDS for protocol anomaly detection | | RITA | DNS exfiltration and beacon detection | | ExtraHop | Network traffic analysis for data flow |
Hunt ID: TH-EXFIL-[DATE]-[SEQ]
Exfiltration Channel: [HTTP/DNS/Email/Cloud/USB]
Source: [Host/User]
Destination: [Domain/IP/Service]
Data Volume: [Bytes/MB/GB]
Time Period: [Start - End]
Protocol: [HTTPS/DNS/SMTP/SMB]
Files Involved: [Count/Types]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
tools
Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati
development
Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.
development
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
testing
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs