Analyzes proxy, DNS query, and netflow logs using Python pandas to detect Shadow IT: unauthorized SaaS/cloud services. Aggregates traffic by domain, classifies SaaS categories, scores risks, generates JSON reports.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
影子 IT(Shadow IT)是指员工未经 IT 部门批准而使用的未授权 SaaS 应用程序和云服务。本 skill 通过分析代理日志、DNS 查询日志和防火墙/网络流数据,识别未授权的云服务使用,将发现的域名分类至已知 SaaS 类别,测量数据传输量,并根据安全状况和合规要求标记高风险服务。
Detects shadow IT by analyzing proxy logs, DNS queries, and netflow data with Python pandas; classifies SaaS domains, flags unauthorized services, scores risks, generates reports. For SOC threat hunting and compliance audits.
Detects shadow IT cloud usage by analyzing proxy, DNS query, and netflow logs with Python pandas for domain classification, traffic volumes, and risk scoring.
Audits shadow IT and SaaS usage via Zscaler Z-Insights: discovers unsanctioned apps, assesses risk scores, monitors CASB usage, tracks data transfers, inventories IoT devices. For security team shadow IT queries.
Share bugs, ideas, or general feedback.
影子 IT(Shadow IT)是指员工未经 IT 部门批准而使用的未授权 SaaS 应用程序和云服务。本 skill 通过分析代理日志、DNS 查询日志和防火墙/网络流数据,识别未授权的云服务使用,将发现的域名分类至已知 SaaS 类别,测量数据传输量,并根据安全状况和合规要求标记高风险服务。
pandas、tldextract