# OT/ICS Security Skills in Anthropic's Cybersecurity Library: Complete Technical Reference

> Explore OT/ICS security skills covering asset discovery, segmentation, and incident response. This technical reference maps to MITRE ATT&CK and NIST CSF 2.0 frameworks.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: technical-reference
- Published: 2026-05-24

---

**The repository contains 28 specialized OT/ICS security skills organized around the Purdue Reference Model and IEC 62443, covering asset discovery, network segmentation, remote access hardening, and incident response, with each skill mapped to MITRE ATT&CK and NIST CSF 2.0 frameworks.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository provides a dedicated collection of operational technology (OT) and industrial control system (ICS) security modules. These 28 self-contained skills enable AI agents and security practitioners to implement defense-in-depth strategies across the complete lifecycle of industrial control system protection, from Level 0 field devices to Level 5 enterprise networks.

## Core OT/ICS Security Capabilities by Category

The skills are organized into functional domains aligned with the **Purdue Reference Model** and **IEC 62443** concepts of zones, conduits, and defense-in-depth.

### Remote Access and Conduit Security

- **`securing-remote-access-to-ot-environment`**: Defined in [`skills/securing-remote-access-to-ot-environment/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/securing-remote-access-to-ot-environment/SKILL.md), this module designs jump-server architectures with DMZ segregation, MFA enforcement, and co-attendance controls for operators and vendors. The [`references/api-reference.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/api-reference.md) file contains specific API endpoints for automation.
- **`implementing-conduit-security-for-ot-remote-access`**: Applies IEC 62443 zones-and-conduits modeling with strict access policies and data-flow documentation.

### Network Segmentation and Architecture

- **`implementing-purdue-model-network-segmentation`**: Located at [`skills/implementing-purdue-model-network-segmentation/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/implementing-purdue-model-network-segmentation/SKILL.md), this skill builds Purdue-level zones (Level 0-5) and includes Terraform snippets for automated firewall and VLAN deployment.

### Asset Discovery and Inventory

- **`performing-ics-asset-discovery-with-claroty`**: Uses Claroty xDome passive sensors to enumerate OT devices and map protocol usage, creating comprehensive asset inventories without disrupting operations.

### Vulnerability Assessment and Patch Management

- **`performing-ot-vulnerability-assessment-with-claroty`**: Prioritizes findings against IEC 62443 and NIST CSF controls.
- **`performing-ot-vulnerability-scanning-safely`**: Implements passive banner grabbing and protocol-specific queries (e.g., Modbus Read Holding Registers) instead of intrusive port scans that could crash PLCs.
- **`implementing-patch-management-for-ot-systems`**: Defines safe patch cycles for devices that cannot tolerate reboots, leveraging out-of-band updates tracked against NIST CSF PR controls.

### Network Monitoring and Protocol Analysis

- **`monitoring-scada-modbus-traffic-anomalies`**: Captures Modbus-TCP traffic with function-code frequency baselining to detect rogue masters. The skill includes [`skills/monitoring-scada-modbus-traffic-anomalies/scripts/modbus_monitor.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/monitoring-scada-modbus-traffic-anomalies/scripts/modbus_monitor.py) for packet extraction.
- **`implementing-dragos-platform-for-ot-monitoring`**: Deploys Dragos sensors for real-time analytics and SIEM integration.
- **`performing-s7comm-protocol-security-analysis`**: Decodes S7 COTP and PDU structures to identify unsafe function codes in Siemens environments.

### System Hardening and Data Protection

- **`securing-historian-server-in-ot-environment`**: Hardens OSIsoft PI and Ignition historians by isolating them in Level 3.5, enforcing one-way data diodes, and applying role-based ACLs.
- **`implementing-ics-firewall-with-tofino`**: Deploys Tofino ASIC firewalls with whitelisting capabilities for Modbus and DNP3 function codes.
- **`performing-scada-hmi-security-assessment`**: Reviews HMI configurations, tests for insecure protocols, and validates patch levels.

### Incident Response and Threat Intelligence

- **`implementing-ot-incident-response-playbook`**: Tailors the SANS PICERL framework for PLC/SCADA outages with containment steps specific to safety systems.
- **`performing-threat-landscape-assessment-for-sector`**: Maps sector-specific threat actors to MITRE ATT&CK TTP libraries.

Additional skills cover DNP3 protocol hardening, PLC firmware integrity verification, OT-focused SOC metrics, and safety-aware scanning methodologies.

## Framework Alignment and Skill Structure

Each OT/ICS skill follows a standardized anatomy defined in the repository README. The [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) front-matter includes machine-readable metadata with `domain: "ot-ics"` and explicit mappings to five major frameworks:

- **MITRE ATT&CK** for adversarial technique coverage
- **NIST CSF 2.0** for risk management alignment
- **MITRE ATLAS** for AI system threats
- **MITRE D3FEND** for defensive countermeasures
- **NIST AI RMF** for artificial intelligence risk

The metadata structure enables AI agents to automatically select appropriate skills by querying tags like `remote-access` or `protocol-analysis`. Each skill contains **When-to-Use** triggers, **Prerequisites** (e.g., `nmap`, `Modbus-py`, `Dragos`), step-by-step **Workflow** commands, and **Verification** criteria such as "no unauthorized Modbus writes observed for 24 hours."

## Practical Implementation Examples

### Installing and Executing OT/ICS Skills

Install the complete skill library using the Node.js package manager:

```bash

# Recommended one-liner – adds the whole Anthropic Skills collection

npx skills add mukul975/Anthropic-Cybersecurity-Skills

```

Execute a specific OT security skill with parameterized inputs:

```bash

# Search for OT/ICS skills by domain tag

skills search --domain ot-ics --tag remote-access

# Execute the remote access hardening skill

skills run securing-remote-access-to-ot-environment \
  --param vpn_endpoint="vpn.corp.example.com" \
  --param dmz_subnet="10.10.20.0/24"

```

The workflow automatically validates VPN connectivity, deploys a hardened jump-server VM using embedded Terraform scripts, configures firewall rules restricting OT device access to the jump-host, enables Duo MFA, and generates a Remote-Access Security Report in the `assets/` directory.

### Python Integration for Modbus Monitoring

Embed traffic monitoring capabilities into broader automation pipelines:

```python
import subprocess
import json

# Launch the Modbus traffic monitor wrapper

result = subprocess.run(
    ["skills", "run", "monitoring-scada-modbus-traffic-anomalies",
     "--param", "interface=eth0",
     "--output", "json"],
    capture_output=True, text=True)

alerts = json.loads(result.stdout)
for alert in alerts:
    print(f"⚠️  {alert['timestamp']} – {alert['description']}")

```

This invokes [`modbus_monitor.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/modbus_monitor.py) from the skill's `scripts/` directory, which captures packets, extracts function-code statistics, and returns structured JSON alerts suitable for SIEM ingestion.

## Summary

- **28 specialized skills** cover the complete OT/ICS security lifecycle from discovery through remediation
- **Purdue Model alignment** ensures proper segmentation across Level 0-5 architectures
- **Framework integration** provides native mapping to MITRE ATT&CK, NIST CSF 2.0, and IEC 62443 standards
- **Executable workflows** include Terraform automation, Python monitoring scripts, and verification checklists
- **AI-ready structure** with machine-readable metadata enables autonomous skill selection based on domain tags and threat context

## Frequently Asked Questions

### How many OT/ICS security skills are available in the repository?

The repository contains **28 individual skills** dedicated to OT/ICS security. Each skill functions as a self-contained module with front-matter metadata, reference documentation, and optional helper scripts located in respective `skills/` subdirectories.

### Which industrial cybersecurity frameworks do these skills support?

The skills map to five major frameworks: **MITRE ATT&CK** for threat intelligence, **NIST CSF 2.0** for cybersecurity risk management, **MITRE ATLAS** for AI system security, **MITRE D3FEND** for defensive countermeasures, and **IEC 62443** for zones and conduits architecture. Framework mappings are stored in each skill's [`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md) file.

### Can these skills be executed programmatically by AI agents?

Yes, each skill follows a standardized anatomy with machine-readable front-matter containing `name`, `description`, `domain: "ot-ics"`, and framework tags. This structure allows AI agents to parse [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) files and automatically trigger appropriate workflows using the `skills run` CLI interface or direct Python import of helper scripts.

### What specific tools and platforms are referenced in the OT/ICS skills?

The skills reference industry-standard OT security platforms including **Claroty xDome** for passive asset discovery, **Dragos** for threat monitoring and analytics, **Tofino ASIC** firewalls for protocol enforcement, and **OSIsoft PI/Ignition** historians for data protection. Prerequisites for each tool are documented in the respective skill's [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) under the Prerequisites section.