Serafim — Ransomware Resilience & Backup Security Engineer AI Skill
Instant download · 30-day money-back guarantee. Pay once, keep forever — no subscription. Refund policy
Make ransomware survivable: immutable backups an attacker cannot reach, a tested recovery sequence, and an honest recovery-time answer for the board.
- Immutable, air-gapped backup design with a separate identity plane
- Tested RTO and RPO, restore rehearsal and clean room recovery
- Active Directory forest recovery as the critical path
- Early encryption detection and backup tampering alerts
Organisations whose recovery plan is a backup product and a hope, who need the recovery sequence proven before it is needed.A ransomware resilience and backup security engineer bills $155+/hr, this is one file, yours forever.
Drop Serafim into Claude and get a resilience engineer who starts from the fact that most ransomware victims had backups and lost them anyway.
Serafim makes ransomware survivable: backup architecture an attacker holding domain admin cannot destroy, built on 3-2-1-1-0 with immutability, object lock, WORM, air gap and a separate identity plane for the backup system; recovery time and recovery point objectives tested rather than declared; restore rehearsal at realistic scale and the isolated recovery environment or clean room; Active Directory forest recovery as the long pole in every enterprise recovery; hypervisor, SaaS and Microsoft 365 backup gaps; early detection of encryption behaviour through canary files, honeypot shares, entropy and volume anomalies, shadow copy deletion and backup job tampering; segmentation and credential hardening of the backup estate itself; playbook execution from containment through recovery sequencing; the extortion and data-leak dimension where restoring solves nothing; and giving the board an honest recovery estimate instead of the vendor's number.
What you get
- →Immutable, air-gapped backup design with a separate identity plane
- →Tested RTO and RPO, restore rehearsal and clean room recovery
- →Active Directory forest recovery as the critical path
- →Early encryption detection and backup tampering alerts
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Serafim builds the answer. Includes a full worked example so you see exactly what you get.
# Serafim - Ransomware Resilience & Backup Security Engineer You are Serafim, a senior ransomware resilience and backup security engineer. You assume the attacker will reach the backup system, and you design so it still recovers. ## How you work 1. Ask how the backups get destroyed, then close that path first 2. Separate the backup identity plane from production entirely 3. Make copies immutable and prove it, do not trust the setting 4. Rehearse restores at real scale; Active Directory recovery leads 5. Give recovery times measured in a test, never quoted from a datasheet Test recovery in an isolated environment. Restoring does not resolve data-leak extortion; treat that separately.
Excerpt from the actual file you'll download.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot — whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required. No subscription. Pay once, keep forever.
Works with every major AI chat.
Drop the file into your AI's system prompt, Project instructions, or custom instructions. No setup. No code. No vendor lock-in.
- Claude
- ChatGPT
- Gemini
- Grok
- Copilot
Works with any AI chat that accepts a system prompt or custom instructions.
Ready to specialise your AI?
One drop-in file. Pay once, keep forever — works with Claude & ChatGPT.