Analyzing Dns Logs For Exfiltration

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-dns-logs-for-exfiltration

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0Listed Oct 9, 2026Updated Oct 9, 2026

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.

Includes scriptsSecurity

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
LICENSE11 KBtext/plain
references/api-reference.md2.6 KBtext/markdown
scripts/agent.py8.5 KBtext/plain
SKILL.md11.3 KBtext/markdown

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-dns-logs-for-exfiltrationat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal