reverse-botnet-dismantling
Installation
SKILL.md
Reverse Botnet Dismantling
Use this skill after the protocol, infrastructure, or operator model is clear enough to ask what can actually be disrupted, contained, or monitored.
Minimum evidence package
Do not propose disruption from IOCs alone. Gather at least:
- one bootstrap or rejoin mechanism
- one command-auth or trust model clue
- one update or recovery path
- one realistic disruption route with explicit prerequisites
Guardrails
- Separate facts, inferences, hypotheses, and unknowns.
- Distinguish true takedown paths from containment or attrition paths.
- State legal, provider, operational, and synchronization prerequisites.
- Do not promise network-wide disruption unless the command-auth and bootstrap assumptions support it.
- Treat endpoint cleanup, sinkholing, detection rollout, and operator seizure as different actions with different outcomes.