All authors

Claude Skills by 26zl
github.com/26zl510 skills6 installs902 views
- Detecting Service Account AbuseDetect abuse of service accounts through anomalous interactive logons,Votes: 0GitHub stars: 65
- Detecting Shadow Api EndpointsDiscover and inventory shadow API endpoints that operate outside documentedVotes: 0GitHub stars: 65
- Detecting Shadow It Cloud UsageDetect unauthorized SaaS and cloud service usage (shadow IT) by analyzingVotes: 0GitHub stars: 65
- Detecting Spearphishing With Email GatewaySpearphishing targets specific individuals using personalized, researchedVotes: 0GitHub stars: 65
- Detecting Stuxnet Style Attacks'This skill covers detecting sophisticated cyber-physical attacks thatVotes: 0GitHub stars: 65
- Detecting Supply Chain Attacks In Ci Cd'Scans GitHub Actions workflows and CI/CD pipeline configurations forVotes: 0GitHub stars: 65
- Detecting Suspicious Powershell ExecutionDetect suspicious PowerShell execution patterns including encoded commands,Votes: 0GitHub stars: 65
- Detecting T1003 Credential Dumping With EdrDetect OS credential dumping techniques targeting LSASS memory, SAM database,Votes: 0GitHub stars: 65
- Detecting T1055 Process Injection With SysmonDetect process injection techniques (T1055) including classic DLL injection,Votes: 0GitHub stars: 65
- Detecting T1548 Abuse Elevation Control MechanismDetect abuse of elevation control mechanisms including UAC bypass, sudoVotes: 0GitHub stars: 65
- Detecting Wmi PersistenceDetect WMI event subscription persistence by analyzing Sysmon Event IDsVotes: 0GitHub stars: 65
- DfirDigital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. Use when investigating security incidents, analyzing Sherlocks, or performing threat hunting on provided evidence files.Votes: 0GitHub stars: 65
- Differential ReviewPerforms security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.Votes: 0GitHub stars: 65
- Dimensional AnalysisAnnotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol, offchain code, or other blockchain-related codebase with arithmetic. Prevents dimensional mismatches and catches formula bugs early.Votes: 0GitHub stars: 65
- Eradicating Malware From Infected SystemsSystematically remove malware, backdoors, and attacker persistence mechanismsVotes: 0GitHub stars: 65
- Evidence HygieneSanitize security evidence before sharing, reporting, or writing up findings. Use for bug bounty reports, guided MCP assessments, pentest/DFIR notes, screenshots, HAR files, curl commands, request/response logs, PoC output, terminal transcripts, writeups, and any evidence that may contain cookies, bearer tokens, API keys, session IDs, PII, customer data, credentials, internal hostnames, or excessive exploit output.Votes: 0GitHub stars: 65
- Executing Phishing Simulation Campaign'Executes authorized phishing simulation campaigns to assess an organization''sVotes: 0GitHub stars: 65
- Executing Red Team Engagement PlanningRed team engagement planning is the foundational phase that defines scope,Votes: 0GitHub stars: 65
- Executing Red Team Exercise'Executes comprehensive red team exercises that simulate real-world adversaryVotes: 0GitHub stars: 65
- Exploiting Api Injection Vulnerabilities'Tests APIs for injection vulnerabilities including SQL injection, NoSQLVotes: 0GitHub stars: 65
- Exploiting Broken Function Level Authorization'Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilitiesVotes: 0GitHub stars: 65
- Exploiting Broken Link HijackingDiscover and exploit broken link hijacking vulnerabilities by identifyingVotes: 0GitHub stars: 65
- Exploiting Constrained Delegation AbuseExploit Kerberos Constrained Delegation misconfigurations in Active DirectoryVotes: 0GitHub stars: 65
- Exploiting Excessive Data Exposure In Api'Tests APIs for excessive data exposure where endpoints return more dataVotes: 0GitHub stars: 65
- Exploiting Idor VulnerabilitiesIdentifying and exploiting Insecure Direct Object Reference vulnerabilitiesVotes: 0GitHub stars: 65
- Exploiting Kerberoasting With ImpacketPerform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for ActiveVotes: 0GitHub stars: 65
- Exploiting Mass Assignment In Rest ApisDiscover and exploit mass assignment vulnerabilities in REST APIs toVotes: 0GitHub stars: 65
- Exploiting Nopac Cve 2021 42278 42287Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountNameVotes: 0GitHub stars: 65
- Exploiting Template Injection VulnerabilitiesDetecting and exploiting Server-Side Template Injection (SSTI) vulnerabilitiesVotes: 0GitHub stars: 65
- Exploiting Type Juggling VulnerabilitiesExploit PHP type juggling vulnerabilities caused by loose comparisonVotes: 0GitHub stars: 65
- Exploiting Vulnerabilities With Metasploit FrameworkThe Metasploit Framework is the world's most widely used penetrationVotes: 0GitHub stars: 65
- Exploiting Zerologon Vulnerability Cve 2020 1472Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controllerVotes: 0GitHub stars: 65
- Extracting Browser History ArtifactsExtract and analyze browser history, cookies, cache, downloads, and bookmarksVotes: 0GitHub stars: 65
- Extracting Config From Agent Tesla RatExtract embedded configuration from Agent Tesla RAT samples includingVotes: 0GitHub stars: 65
- Extracting Windows Event Logs ArtifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw,Votes: 0GitHub stars: 65
- Finding TriageUse to triage a single security finding — from a scanner (SAST/DAST/SCA), an audit, a pentest report, a bug bounty submission, a CVE advisory, or a threat hunt — into a defensible disposition with the required evidence. Produces a ticket-ready writeup: Fixed, Deferred, Accepted Risk, or False Positive. Use when normalizing findings across different sources, deciding whether something is real and reachable, assigning contextual severity, or building an audit trail that survives review six mont...Votes: 0GitHub stars: 65
- Fp CheckSystematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug.Votes: 0GitHub stars: 65
- Grc Compliance Privacy ProgramUse for governance, risk, compliance, privacy, audit readiness, control mapping, SOC 2, ISO 27001, NIST CSF, CIS, GDPR, legal/regulatory scoping, policy evidence, vendor risk, and security program maturity work.Votes: 0GitHub stars: 65
- Guided AssessmentPick and run the right MCP tools for an authorized security task. Default companion mode auto-detects the workflow/problem type, classifies target/finding input, returns triage gates, recommended skills, reporting next steps, selects from all modules/profiles, recommends the next command, and guides step-by-step; opt-in autonomous starts an auto-solver loop over the full MCP toolchain via run_tool/run_pipeline/run_script, including AI-created scoped helper scripts when tools/pipelines are not...Votes: 0GitHub stars: 65
- Hardening Docker Containers For ProductionHardening Docker containers for production involves applying securityVotes: 0GitHub stars: 65
- Hardening Docker Daemon ConfigurationHarden the Docker daemon by configuring daemon.json with user namespaceVotes: 0GitHub stars: 65
- Hunting Credential Stuffing Attacks'Detects credential stuffing attacks by analyzing authentication logsVotes: 0GitHub stars: 65
- Hunting For Data Staging Before ExfiltrationDetect data staging activity before exfiltration by monitoring for archiveVotes: 0GitHub stars: 65
- Hunting For Dcom Lateral Movement'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application,Votes: 0GitHub stars: 65
- Hunting For Dcsync AttacksDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorizedVotes: 0GitHub stars: 65
- Hunting For Dns Based PersistenceHunt for DNS-based persistence mechanisms including DNS hijacking, danglingVotes: 0GitHub stars: 65
- Hunting For Dns Tunneling With ZeekDetect DNS tunneling and data exfiltration by analyzing Zeek dns.logVotes: 0GitHub stars: 65
- Hunting For Domain Fronting C2 TrafficDetect domain fronting C2 traffic by analyzing SNI vs HTTP Host headerVotes: 0GitHub stars: 65
- Hunting For Lateral Movement Via WmiDetect WMI-based lateral movement by analyzing Windows Event ID 4688Votes: 0GitHub stars: 65
- Hunting For Living Off The Cloud TechniquesHunt for adversary abuse of legitimate cloud services for C2, data staging,Votes: 0GitHub stars: 65