defensive-file-upload
CommunityDetect file upload abuse and webshell activity.
Authorriparino
Version1.0.0
Installs0
System Documentation
What problem does it solve?
File upload abuse is a common attack vector against web applications. This skill helps identify malicious uploads and webshell activity by combining YARA signatures, logging analysis, and IOC mapping to enable rapid containment.
Core Features & Use Cases
- YARA-based webshell detection in upload directories and webroots.
- Sigma rules for HTTP requests to upload paths and file-creation events.
- KQL queries for MDE DeviceFileEvents and Web server logs to surface webshell activity.
- Use Case: SOC teams triage upload abuse incidents and DFIR accelerates investigations.
Quick Start
Inspect upload directories with a YARA scan, correlate with logs to confirm suspicious webshell activity, and begin containment.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: defensive-file-upload Download link: https://github.com/riparino/Claude-Cyber/archive/main.zip#defensive-file-upload Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.