All authors

Claude Skills by 26zl
github.com/26zl510 skills6 installs902 views
- Performing Fuzzing With Aflplusplus'Perform coverage-guided fuzzing of compiled binaries using AFL++ (AmericanVotes: 0GitHub stars: 65
- Performing Gcp Penetration Testing With GcpbucketbrutePerform GCP security testing using GCPBucketBrute for storage bucketVotes: 0GitHub stars: 65
- Performing Graphql Introspection Attack'Performs GraphQL introspection attacks to extract the full API schemaVotes: 0GitHub stars: 65
- Performing Hardware Security Module IntegrationIntegrate Hardware Security Modules (HSMs) using PKCS#11 interface forVotes: 0GitHub stars: 65
- Performing Hash Cracking With HashcatHash cracking is an essential skill for penetration testers and securityVotes: 0GitHub stars: 65
- Performing Http Parameter Pollution AttackExecute HTTP Parameter Pollution attacks to bypass input validation,Votes: 0GitHub stars: 65
- Performing Ics Asset Discovery With Claroty'Perform comprehensive ICS/OT asset discovery using Claroty xDome platform,Votes: 0GitHub stars: 65
- Performing Indicator Lifecycle ManagementIndicator lifecycle management tracks IOCs from initial discovery throughVotes: 0GitHub stars: 65
- Performing Initial Access With Evilginx3Perform authorized initial access using EvilGinx3 adversary-in-the-middleVotes: 0GitHub stars: 65
- Performing Insider Threat Investigation'Investigates insider threat incidents involving employees, contractors,Votes: 0GitHub stars: 65
- Performing Jwt None Algorithm AttackExecute and test the JWT none algorithm attack to bypass signature verificationVotes: 0GitHub stars: 65
- Performing Kerberoasting AttackKerberoasting is a post-exploitation technique that targets service accountsVotes: 0GitHub stars: 65
- Sap Erp Security AssessmentUse for SAP and ERP security assessments, S/4HANA, NetWeaver, ABAP, HANA DB, RFC trust, SAP Gateway, ICM, transports, default users, authorization roles, SoD, patching, and business-critical ERP control review.Votes: 0GitHub stars: 65
- Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.Votes: 0GitHub stars: 65
- Add ToolUse when adding a new cybersecurity tool to this installer. Walks through editing the right module file, adding to tools_config.json, running validators, and syncing MCP server data if needed. Triggers on phrases like "add tool", "add <toolname>", "register a new tool", "include X in the installer".Votes: 0GitHub stars: 65
- Ai Llm Security ReviewUse for AI/LLM security assessments, prompt injection, RAG security, agent/tool permissioning, model supply chain, LLM red teaming, AI governance, eval design, data leakage, jailbreak testing, and secure AI application review.Votes: 0GitHub stars: 65
- Ai Threat TestingOffensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.Votes: 0GitHub stars: 65
- Analyzing Android Malware With ApktoolPerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java sourceVotes: 0GitHub stars: 65
- Analyzing Cobalt Strike Beacon ConfigurationExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,Votes: 0GitHub stars: 65
- Analyzing Disk Image With AutopsyPerform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, andVotes: 0GitHub stars: 65
- Analyzing Email Headers For Phishing InvestigationParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identifyVotes: 0GitHub stars: 65
- Analyzing Ethereum Smart Contract VulnerabilitiesPerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,Votes: 0GitHub stars: 65
- Analyzing Ios App Security With Objection'Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit thatVotes: 0GitHub stars: 65
- Analyzing Macro Malware In Office Documents'Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify downloadVotes: 0GitHub stars: 65
- Analyzing Malicious Pdf With PeepdfPerform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,Votes: 0GitHub stars: 65
- Analyzing Mft For Deleted File RecoveryAnalyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT recordVotes: 0GitHub stars: 65
- Analyzing Network Packets With ScapyCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, andVotes: 0GitHub stars: 65
- Analyzing Network Traffic With Wireshark'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,Votes: 0GitHub stars: 65
- Blockchain SecuritySmart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract security.Votes: 0GitHub stars: 65
- Bounty ApiUse when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".Votes: 0GitHub stars: 65
- Bounty MobileUse when bug-bountying an Android (APK) or iOS (IPA) app. Covers static + dynamic analysis, Frida hooking, certificate pinning bypass, deep link / intent abuse, IPC, secrets in bundles. Triggers on "bounty mobile", "android app", "ios app", "apk analysis", "frida".Votes: 0GitHub stars: 65
- Bounty ReconUse at the start of a bug bounty engagement. Provides scope-aware recon methodology — passive enumeration, subdomain discovery, asset attribution, tech stack fingerprinting, content discovery. Respects scope and program rules. Triggers on "bounty recon", "subdomain enum", "attack surface map", "h1 recon", "bug bounty start".Votes: 0GitHub stars: 65
- Bounty WebUse during the testing phase of a web application bug bounty. Provides OWASP-aligned attack catalog, payload sources, and tool ordering for SQLi, XSS, SSRF, SSTI, IDOR, auth, race conditions, file upload, deserialization. Triggers on "bounty web", "test this app", "web app testing", "h1 web target".Votes: 0GitHub stars: 65
- Building C2 Infrastructure With Sliver FrameworkBuild and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework withVotes: 0GitHub stars: 65
- Building Detection Rules With Sigma'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platformsVotes: 0GitHub stars: 65
- Building Red Team C2 Infrastructure With HavocDeploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,Votes: 0GitHub stars: 65
- Building Role Mining For Rbac OptimizationApply bottom-up and top-down role mining techniques to discover optimalVotes: 0GitHub stars: 65
- Building Soc Escalation MatrixBuild a structured SOC escalation matrix defining severity tiers, responseVotes: 0GitHub stars: 65
- Building Soc Playbook For Ransomware'Builds a structured SOC incident response playbook for ransomware attacksVotes: 0GitHub stars: 65
- Building Threat Actor Profile From OsintBuild comprehensive threat actor profiles using open-source intelligenceVotes: 0GitHub stars: 65
- Building Threat Feed Aggregation With MispDeploy MISP (Malware Information Sharing Platform) to aggregate, correlate,Votes: 0GitHub stars: 65
- Building Threat Hunt Hypothesis FrameworkBuild a systematic threat hunt hypothesis framework that transforms threatVotes: 0GitHub stars: 65
- Building Threat Intelligence Enrichment In SplunkBuild automated threat intelligence enrichment pipelines in Splunk EnterpriseVotes: 0GitHub stars: 65
- Building Threat Intelligence PlatformBuilding a Threat Intelligence Platform (TIP) involves deploying andVotes: 0GitHub stars: 65
- Building Vulnerability Aging And Sla TrackingImplement a vulnerability aging dashboard and SLA tracking system toVotes: 0GitHub stars: 65
- Building Vulnerability Dashboard With DefectdojoDeploy DefectDojo as a centralized vulnerability management dashboardVotes: 0GitHub stars: 65
- Building Vulnerability Exception Tracking SystemBuild a vulnerability exception and risk acceptance tracking system withVotes: 0GitHub stars: 65
- CodeqlScans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.Votes: 0GitHub stars: 65
- Collecting Threat Intelligence With MispMISP (Malware Information Sharing Platform) is an open-source threatVotes: 0GitHub stars: 65
- Collecting Volatile Evidence From Compromised HostCollect volatile forensic evidence from a compromised system followingVotes: 0GitHub stars: 65