From cybersecurity-skills
Detects T1547.001 startup folder persistence by monitoring Windows startup directories, analyzing autoruns, and using watchdog for real-time filesystem monitoring.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:hunting-for-startup-folder-persistenceThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Attackers use Windows startup folders for persistence (MITRE ATT&CK T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder). Files placed in `%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup` or `C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup` execute automatically at user logon. This skill scans startup directories for suspicious files, monitors ...
Attackers use Windows startup folders for persistence (MITRE ATT&CK T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder). Files placed in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup or C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup execute automatically at user logon. This skill scans startup directories for suspicious files, monitors for real-time changes using Python watchdog, and analyzes file metadata to detect persistence implants.
watchdog, pefile (optional for PE analysis)npx claudepluginhub costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skillsDetects T1547.001 startup folder persistence by scanning Windows startup directories for suspicious files, analyzing autoruns entries, and real-time monitoring with Python watchdog.
Detects T1547.001 startup folder persistence by scanning startup directories for suspicious files, analyzing autoruns entries, and monitoring filesystem changes with Python watchdog.
Detects T1547.001 startup folder persistence by scanning startup directories for suspicious files, analyzing autoruns entries, and monitoring filesystem changes with Python watchdog.