Analyzing Ransomware Network Indicators

SkillMonitoring & ops

analyzing-ransomware-network-indicators is a skill that guides an AI agent through analyzing Zeek conn.log and NetFlow data to find ransomware-related network activity. It detects C2 beaconing, TOR exit node connections, data exfiltration flows, and suspicious DNS patterns, then produces a scored report with a timeline and MITRE ATT&CK mappings. It is useful during threat hunting or incident response when investigating suspected pre-encryption exfiltration.

Use Analyzing Ransomware Network Indicators in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Analyzing Ransomware Network Indicators and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Analyzing Ransomware Network Indicators skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have Zeek conn.log files or NetFlow CSV/JSON exports available for the network period of interest.

Analyzing Ransomware Network IndicatorsStart free

What your AI can do with it

  • Parses Zeek conn.log (TSV) or NetFlow CSV/JSON records into a structured format
  • Detects C2 beaconing by computing connection interval statistics
  • Cross-references destination IPs against a current TOR exit node list
  • Flags connections with unusually high outbound byte ratios as data exfiltration
  • Detects DGA-like domain queries and high-entropy subdomains in DNS activity
  • Generates a JSON report with a timeline and MITRE ATT&CK mapping

Getting started

  1. Have Zeek conn.log files or NetFlow CSV/JSON exports available for the network period of interest.
  2. Install Python 3.8 or newer with the standard library.
  3. Obtain a TOR exit node list from the Tor Project or a threat intel feed.
  4. Optionally prepare a list of known ransomware C2 IOCs to enrich the analysis.
  5. Ask the agent to run the skill against the logs; it will score findings and return a JSON report.

What this skill tells your AI

The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/analyzing-ransomware-network-indicators/SKILL.md and read by ahel’s review.

Overview

Before and during ransomware execution, adversaries establish C2 channels, exfiltrate data, and download encryption keys. This skill analyzes Zeek conn.log and NetFlow data to detect beaconing patterns (regular-interval callbacks), connections to known TOR exit nodes, large outbound data transfers, and suspicious DNS activity associated with ransomware families.

When to Use

  • When investigating security incidents that require analyzing ransomware network indicators
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Zeek conn.log files or NetFlow CSV/JSON exports
  • Python 3.8+ with standard library
  • TOR exit node list (fetched from Tor Project or threat intel feeds)
  • Optional: Known ransomware C2 IOC list

Steps

  1. Parse Connection Logs — Ingest Zeek conn.log (TSV) or NetFlow records into structured format
  2. Detect Beaconing Patterns — Calculate connection interval statistics (mean, stddev, coefficient of variation) to identify periodic callbacks
  3. Check TOR Exit Node Connections — Cross-reference destination IPs against current TOR exit node list
  4. Identify Data Exfiltration — Flag connections with unusually high outbound byte ratios to external IPs
  5. Analyze DNS Patterns — Detect DGA-like domain queries and high-entropy subdomains
  6. Score and Correlate — Apply composite risk scoring across all indicator types
  7. Generate Report — Produce structured report with timeline and MITRE ATT&CK mapping

Expected Output

  • JSON report with beaconing detections and interval statistics
  • TOR exit node connection alerts
  • Data exfiltration flow analysis
  • Composite ransomware risk score with MITRE mapping (T1071, T1573, T1041)

Signals

GitHub stars
34k
Forks
4k
Last commit
Aug 2026

Questions

What log sources does it work with?
It ingests Zeek conn.log files in TSV format or NetFlow records exported as CSV or JSON.
What do I need before running it?
Zeek conn.log or NetFlow exports, Python 3.8+ with the standard library, and a TOR exit node list. A known ransomware C2 IOC list is optional.
Advanced
Item type
skill
Key
analyzing-ransomware-network-indicators-mukul975
Source
github.com/mukul975/anthropic-cybersecurity-skills