All authors

Claude Skills by 26zl
github.com/26zl510 skills6 installs902 views
- Detecting Broken Object Property Level AuthorizationDetect and test for OWASP API3:2023 Broken Object Property Level AuthorizationVotes: 0GitHub stars: 65
- Authorization GateUse as the pre-flight authorization check before any offensive, intrusive, or simulation activity — pentest, red team, exploitation, phishing simulation, wireless attacks, social engineering, C2, scanning a target you don't own. Confirms written authorization, scope boundaries, lawful basis, and target ownership before a single packet is sent, and defines the hard refusals (mass targeting, supply-chain compromise, malicious evasion). Run this gate at the top of any offensive or simulation wor...Votes: 0GitHub stars: 65
- Bb MethodologyUse at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."Votes: 0GitHub stars: 65
- Bug BountyComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (prompt injection, indirec...Votes: 0GitHub stars: 65
- Constant Time AnalysisDetects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering division on secrets, secret-dependent branches, or constant-time programming questions in C, C++, Go, Rust, Swift, Java, Kotlin, C#, PHP, JavaScript, TypeScript, Python, or Ruby.Votes: 0GitHub stars: 65
- Credential AttackPassword spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated hunt chain pattern. Use when assessing whether credential attack is worth running on a target, picking the right mode, or recovering from common pitfalls.Votes: 0GitHub stars: 65
- Detecting Business Email Compromise With AiDeploy AI and NLP-powered detection systems to identify business emailVotes: 0GitHub stars: 65
- Detecting Business Email CompromiseBusiness Email Compromise (BEC) is a sophisticated fraud scheme whereVotes: 0GitHub stars: 65
- Detecting Cloud Threats With Guardduty'This skill teaches security teams how to deploy and operationalize AmazonVotes: 0GitHub stars: 65
- Detecting Command And Control Over Dns'Detects command-and-control (C2) communications tunneled through DNSVotes: 0GitHub stars: 65
- Detecting Compromised Cloud Credentials'Detecting compromised cloud credentials across AWS, Azure, and GCP byVotes: 0GitHub stars: 65
- Detecting Container Drift At RuntimeDetect unauthorized modifications to running containers by monitoringVotes: 0GitHub stars: 65
- Detecting Container Escape AttemptsContainer escape is a critical attack technique where an adversary breaksVotes: 0GitHub stars: 65
- Detecting Container Escape With Falco RulesDetect container escape attempts in real-time using Falco runtime securityVotes: 0GitHub stars: 65
- Detecting Credential Dumping TechniquesDetect LSASS credential dumping, SAM database extraction, and NTDS.ditVotes: 0GitHub stars: 65
- Detecting Cryptomining In Cloud'This skill teaches security teams how to detect and respond to unauthorizedVotes: 0GitHub stars: 65
- Detecting Dcsync Attack In Active DirectoryDetect DCSync attacks where adversaries abuse Active Directory replicationVotes: 0GitHub stars: 65
- Detecting Deepfake Audio In Vishing Attacks'Detects AI-generated deepfake audio used in voice phishing (vishing)Votes: 0GitHub stars: 65
- Detecting Dll Sideloading AttacksDetect DLL side-loading attacks where adversaries place malicious DLLsVotes: 0GitHub stars: 65
- Detecting Dnp3 Protocol Anomalies'Detect anomalies in DNP3 (Distributed Network Protocol 3) communicationsVotes: 0GitHub stars: 65
- Detecting Dns Exfiltration With Dns Query AnalysisDetect data exfiltration through DNS tunneling by analyzing query entropy,Votes: 0GitHub stars: 65
- Detecting Email Account CompromiseDetect compromised O365 and Google Workspace email accounts by analyzingVotes: 0GitHub stars: 65
- Detecting Email Forwarding Rules AttackDetect malicious email forwarding rules created by adversaries to maintainVotes: 0GitHub stars: 65
- Detecting Exfiltration Over Dns With ZeekDetect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropyVotes: 0GitHub stars: 65
- Detecting Fileless Malware Techniques'Detects and analyzes fileless malware that operates entirely in memoryVotes: 0GitHub stars: 65
- Detecting Golden Ticket Attacks In Kerberos LogsDetect Golden Ticket attacks in Active Directory by analyzing KerberosVotes: 0GitHub stars: 65
- Detecting Golden Ticket ForgeryDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769Votes: 0GitHub stars: 65
- Detecting Insider Threat BehaviorsDetect insider threat behavioral indicators including unusual data access,Votes: 0GitHub stars: 65
- Detecting Insider Threat With UebaImplement User and Entity Behavior Analytics using Elasticsearch/OpenSearchVotes: 0GitHub stars: 65
- Detecting Kerberoasting AttacksDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGSVotes: 0GitHub stars: 65
- Detecting Lateral Movement With SplunkDetect adversary lateral movement across networks using Splunk SPL queriesVotes: 0GitHub stars: 65
- Detecting Living Off The Land With LolbasDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse includingVotes: 0GitHub stars: 65
- Detecting Mimikatz Execution PatternsDetect Mimikatz execution through command-line patterns, LSASS accessVotes: 0GitHub stars: 65
- Detecting Misconfigured Azure Storage'Detecting misconfigured Azure Storage accounts including publicly accessibleVotes: 0GitHub stars: 65
- Detecting Mobile Malware Behavior'Detects and analyzes malicious behavior in mobile applications throughVotes: 0GitHub stars: 65
- Detecting Modbus Command Injection Attacks'Detect command injection attacks against Modbus TCP/RTU protocol inVotes: 0GitHub stars: 65
- Detecting Modbus Protocol Anomalies'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communicationsVotes: 0GitHub stars: 65
- Detecting Network Anomalies With Zeek'Deploys and configures Zeek (formerly Bro) network security monitorVotes: 0GitHub stars: 65
- Detecting Ntlm Relay With Event Correlation'Detect NTLM relay attacks through Windows Security Event correlationVotes: 0GitHub stars: 65
- Detecting Oauth Token Theft'Detects and responds to OAuth token theft and replay attacks in cloudVotes: 0GitHub stars: 65
- Detecting Pass The Hash AttacksDetect Pass-the-Hash attacks by analyzing NTLM authentication patterns,Votes: 0GitHub stars: 65
- Detecting Pass The Ticket AttacksDetect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows EventVotes: 0GitHub stars: 65
- Detecting Privilege Escalation AttemptsDetect privilege escalation attempts including token manipulation, UACVotes: 0GitHub stars: 65
- Detecting Privilege Escalation In Kubernetes PodsDetect and prevent privilege escalation in Kubernetes pods by monitoringVotes: 0GitHub stars: 65
- Detecting Process Hollowing TechniqueDetect process hollowing (T1055.012) by analyzing memory-mapped sections,Votes: 0GitHub stars: 65
- Detecting Qr Code Phishing With Email SecurityDetect and prevent QR code phishing (quishing) attacks that bypass traditionalVotes: 0GitHub stars: 65
- Detecting Ransomware Encryption Behavior'Detects ransomware encryption activity in real time using entropy analysis,Votes: 0GitHub stars: 65
- Detecting Ransomware Precursors In Network'Detects early-stage ransomware indicators in network traffic beforeVotes: 0GitHub stars: 65
- Detecting Rdp Brute Force AttacksDetect RDP brute force attacks by analyzing Windows Security Event LogsVotes: 0GitHub stars: 65
- Detecting Rootkit Activity'Detects rootkit presence on compromised systems by identifying hiddenVotes: 0GitHub stars: 65