From asi
Hunts for data exfiltration indicators via network traffic analysis, detecting unusual flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse. For threat hunting and incident response.
How this skill is triggered — by the user, by Claude, or both
Slash command
/asi:hunting-for-data-exfiltration-indicatorsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
- When hunting for data theft in compromised environments
| Concept | Description |
|---|---|
| T1041 | Exfiltration Over C2 Channel |
| T1048 | Exfiltration Over Alternative Protocol |
| T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 |
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 |
| T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 |
| T1567 | Exfiltration Over Web Service |
| T1567.002 | Exfiltration to Cloud Storage |
| T1052 | Exfiltration Over Physical Medium |
| T1029 | Scheduled Transfer |
| T1030 | Data Transfer Size Limits (staging) |
| T1537 | Transfer Data to Cloud Account |
| T1020 | Automated Exfiltration |
| Tool | Purpose |
|---|---|
| Splunk | SIEM for data volume analysis and SPL queries |
| Zeek | Network metadata for data flow analysis |
| Microsoft Defender for Cloud Apps | CASB for cloud exfiltration |
| Netskope | Cloud DLP and exfiltration detection |
| Suricata | Network IDS for protocol anomaly detection |
| RITA | DNS exfiltration and beacon detection |
| ExtraHop | Network traffic analysis for data flow |
Hunt ID: TH-EXFIL-[DATE]-[SEQ]
Exfiltration Channel: [HTTP/DNS/Email/Cloud/USB]
Source: [Host/User]
Destination: [Domain/IP/Service]
Data Volume: [Bytes/MB/GB]
Time Period: [Start - End]
Protocol: [HTTPS/DNS/SMTP/SMB]
Files Involved: [Count/Types]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
npx claudepluginhub plurigrid/asi --plugin asiHunts for data exfiltration indicators via network traffic analysis, detecting unusual flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse. For threat hunting and incident response.
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.
Hunts data exfiltration indicators via network traffic analysis, detecting anomalous data flows, DNS tunnels, cloud storage uploads, and encrypted channel abuse. For threat hunting in compromised environments.