Token导航 LogoToken导航TokenDH.com
研究检索操作浏览器github未标认证来源可访问许可证需确认审计通过

hunting-for-data-exfiltration-indicators寻找数据泄露指标

Agent Skill

用于辅助数据整理、表格处理、CSV/Excel 分析、指标计算和图表准备。它适合让 Agent 清洗字段、汇总数据、发现异常、生成统计口径或把分析结果转成可读说明。使用时需要确认数据来源、字段含义和时间范围,避免把样本数据当全量事实;涉及敏感数据、导出文件或批量写回时,应先确认权限和脱敏边界。

总安装

214

周安装

9

GitHub Stars

5,933

下载量

75
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:hunting-for-data-exfiltration-indicators(寻找数据泄露指标)
来源仓库:https://github.com/mukul975/anthropic-cybersecurity-skills
仓库路径:skills/hunting-for-data-exfiltration-indicators
安装命令:
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill hunting-for-data-exfiltration-indicators
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill hunting-for-data-exfiltration-indicators

简介

hunting-for-data-exfiltration-indicators 用于辅助数据整理、表格分析和指标计算,适合清洗字段和发现异常。

  • 适用于数据分析、统计口径生成和图表准备,需确认数据来源和时间范围后再使用。
  • 可通过 npx skills add 从 GitHub 仓库安装,建议在脱敏前提下处理敏感数据。
  • 涉及导出文件或批量写回时,应先确认权限边界,避免误操作全量数据。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Hunting for Data Exfiltration Indicators

When to Use

  • When hunting for data theft in compromised environments
  • After detecting unusual outbound data volumes or patterns
  • When investigating potential insider threat data theft
  • During incident response to determine what data was stolen
  • When threat intel indicates data exfiltration campaigns targeting your sector

Prerequisites

  • Network proxy/firewall logs with byte-level data transfer metrics
  • DLP solution or CASB with cloud upload visibility
  • DNS query logs for DNS exfiltration detection
  • Email gateway logs for attachment monitoring
  • SIEM with data volume anomaly detection capabilities

Workflow

  1. Define Exfiltration Channels: Identify potential channels (HTTP/S uploads, DNS tunneling, email attachments, cloud storage, removable media, encrypted protocols).
  2. Baseline Normal Data Flows: Establish baseline outbound data transfer volumes per user, host, and destination over a 30-day window.
  3. Detect Volume Anomalies: Identify hosts or users transferring significantly more data than baseline to external destinations.
  4. Analyze Transfer Destinations: Check destination domains/IPs against threat intel, identify newly registered domains, personal cloud storage, and foreign infrastructure.
  5. Inspect Protocol Abuse: Look for DNS tunneling (large/frequent TXT queries), ICMP tunneling, or data hidden in allowed protocols.
  6. Correlate with File Access: Link exfiltration indicators to file access events on sensitive file shares, databases, or repositories.
  7. Report and Contain: Document findings with evidence, estimate data exposure, and recommend containment actions.

Key Concepts

ConceptDescription
T1041Exfiltration Over C2 Channel
T1048Exfiltration Over Alternative Protocol
T1048.001Exfiltration Over Symmetric Encrypted Non-C2
T1048.002Exfiltration Over Asymmetric Encrypted Non-C2
T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2
T1567Exfiltration Over Web Service
T1567.002Exfiltration to Cloud Storage
T1052Exfiltration Over Physical Medium
T1029Scheduled Transfer
T1030Data Transfer Size Limits (staging)
T1537Transfer Data to Cloud Account
T1020Automated Exfiltration

Tools & Systems

ToolPurpose
SplunkSIEM for data volume analysis and SPL queries
ZeekNetwork metadata for data flow analysis
Microsoft Defender for Cloud AppsCASB for cloud exfiltration
NetskopeCloud DLP and exfiltration detection
SuricataNetwork IDS for protocol anomaly detection
RITADNS exfiltration and beacon detection
ExtraHopNetwork traffic analysis for data flow

Common Scenarios

  1. Cloud Storage Exfiltration: User uploads sensitive documents to personal Google Drive or Dropbox via browser.
  2. DNS Tunneling: Malware exfiltrates data encoded in DNS subdomain queries to attacker-controlled nameserver.
  3. HTTPS Upload: Compromised system POSTs large data blobs to C2 server over encrypted HTTPS.
  4. Email Attachment Exfiltration: Insider forwards sensitive documents to personal email accounts.
  5. Staging and Compression: Adversary stages data in compressed archives before slow exfiltration to avoid detection.

Output Format

Hunt ID: TH-EXFIL-[DATE]-[SEQ]
Exfiltration Channel: [HTTP/DNS/Email/Cloud/USB]
Source: [Host/User]
Destination: [Domain/IP/Service]
Data Volume: [Bytes/MB/GB]
Time Period: [Start - End]
Protocol: [HTTPS/DNS/SMTP/SMB]
Files Involved: [Count/Types]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.98%
按下载量换算28

Claude

25.51%
按下载量换算19

Cursor

18.87%
按下载量换算14

Gemini CLI

8.68%
按下载量换算7

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

操作浏览器

该 Skill 可能涉及浏览器控制能力,使用时可能读取或操作网页内容,需要在受控环境中确认权限边界。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills