All authors

Claude Skills by andycungkrinx91
github.com/andycungkrinx91126 skills0 installs17 views
- Anbu SkillStandard Operating Procedures for backend development, bug fixing, DevOps, infrastructure deployment, and security hardening.Votes: 0GitHub stars: 9
- Abusing Dpapi For Credential AccessExtract DPAPI-protected secrets such as credentials and browser data offline and online.Votes: 0GitHub stars: 9
- Abusing Shadow Credentials For PrivescTake over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.Votes: 0GitHub stars: 9
- Analyzing Certificate Transparency For PhishingMonitor Certificate Transparency logs using crt.sh and Certstream toVotes: 0GitHub stars: 9
- Analyzing Email Headers For Phishing InvestigationParse and analyze email headers to trace the origin of phishing emails,Votes: 0GitHub stars: 9
- Analyzing Indicators Of Compromise'Analyzes indicators of compromise (IOCs) including IP addresses, domains,Votes: 0GitHub stars: 9
- Analyzing Linux Elf Malware'Analyzes malicious Linux ELF (Executable and Linkable Format) binariesVotes: 0GitHub stars: 9
- Analyzing Ransomware Encryption Mechanisms'Analyzes encryption algorithms, key management, and file encryptionVotes: 0GitHub stars: 9
- Analyzing Ransomware Leak Site IntelligenceMonitor and analyze ransomware group data leak sites (DLS) to track victimVotes: 0GitHub stars: 9
- Analyzing Ransomware Payment Wallets'Traces ransomware cryptocurrency payment flows using blockchain analysisVotes: 0GitHub stars: 9
- Analyzing Tls Certificate Transparency Logs'Queries Certificate Transparency logs via crt.sh and pycrtsh to detectVotes: 0GitHub stars: 9
- Analyzing Typosquatting Domains With DnstwistDetect typosquatting, homograph phishing, and brand impersonation domainsVotes: 0GitHub stars: 9
- Attacking Entra Id With RoadtoolsEnumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.Votes: 0GitHub stars: 9
- Attacking Oauth With Device Code PhishingRun OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.Votes: 0GitHub stars: 9
- Auditing Entra Id With AadinternalsRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.Votes: 0GitHub stars: 9
- Auditing Kubernetes Cluster Rbac'Auditing Kubernetes cluster RBAC configurations to identify overly permissiveVotes: 0GitHub stars: 9
- Auditing Kubernetes Rbac Privilege EscalationFind over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.Votes: 0GitHub stars: 9
- Benchmarking Kubernetes With Kube BenchRun CIS Kubernetes Benchmark checks and remediate findings with kube-bench.Votes: 0GitHub stars: 9
- Building C2 Redirector InfrastructureArchitect redirectors with nginx and Apache, malleable profiles, and OPSECVotes: 0GitHub stars: 9
- Building Identity Federation With Saml Azure AdEstablish SAML 2.0 identity federation between on-premises Active DirectoryVotes: 0GitHub stars: 9
- Building Identity Governance Lifecycle Process'Builds comprehensive identity governance and lifecycle management processesVotes: 0GitHub stars: 9
- Building Phishing Reporting Button WorkflowImplement a phishing report button in email clients with automated triageVotes: 0GitHub stars: 9
- Building Ransomware Playbook With Cisa Framework'Builds a structured ransomware incident response playbook aligned withVotes: 0GitHub stars: 9
- Coercing Authentication With Coercer PetitpotamTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.Votes: 0GitHub stars: 9
- Conducting Phishing Incident Response'Responds to phishing incidents by analyzing reported emails, extractingVotes: 0GitHub stars: 9
- Conducting Social Engineering Penetration TestDesign and execute a social engineering penetration test including phishing,Votes: 0GitHub stars: 9
- Conducting Spearphishing Simulation CampaignSpearphishing simulation is a targeted social engineering attack vectorVotes: 0GitHub stars: 9
- Configuring Identity Aware Proxy With Google Iap'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-requestVotes: 0GitHub stars: 9
- Configuring Ldap Security HardeningHarden LDAP directory services against common attacks including credentialVotes: 0GitHub stars: 9
- Configuring Oauth2 Authorization FlowConfigure secure OAuth 2.0 authorization flows including AuthorizationVotes: 0GitHub stars: 9
- Deploying Honeytokens And CanarytokensPlant canarytokens and honey credentials and alert on breach.Votes: 0GitHub stars: 9
- Deploying Ransomware Canary Files'Deploys and monitors ransomware canary files across critical directoriesVotes: 0GitHub stars: 9
- Detecting Aws Credential Exposure With Trufflehog'Detecting exposed AWS credentials in source code repositories, CI/CDVotes: 0GitHub stars: 9
- Detecting Business Email CompromiseBusiness Email Compromise (BEC) is a sophisticated fraud scheme whereVotes: 0GitHub stars: 9
- Detecting Compromised Cloud Credentials'Detecting compromised cloud credentials across AWS, Azure, and GCP byVotes: 0GitHub stars: 9
- Detecting Container Runtime Threats With FalcoWrite and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.Votes: 0GitHub stars: 9
- Detecting Credential Dumping TechniquesDetect LSASS credential dumping, SAM database extraction, and NTDS.ditVotes: 0GitHub stars: 9
- Detecting Deepfake Audio In Vishing Attacks'Detects AI-generated deepfake audio used in voice phishing (vishing)Votes: 0GitHub stars: 9
- Detecting Oauth Token Theft'Detects and responds to OAuth token theft and replay attacks in cloudVotes: 0GitHub stars: 9
- Detecting Qr Code Phishing With Email SecurityDetect and prevent QR code phishing (quishing) attacks that bypass traditionalVotes: 0GitHub stars: 9
- Detecting Ransomware Encryption Behavior'Detects ransomware encryption activity in real time using entropy analysis,Votes: 0GitHub stars: 9
- Detecting Spearphishing With Email GatewaySpearphishing targets specific individuals using personalized, researchedVotes: 0GitHub stars: 9
- Detecting T1003 Credential Dumping With EdrDetect OS credential dumping techniques targeting LSASS memory, SAM database,Votes: 0GitHub stars: 9
- Emulating Cloud Attacks With Stratus Red TeamDetonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validateVotes: 0GitHub stars: 9
- Escaping Containers To HostExploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.Votes: 0GitHub stars: 9
- Exploiting Adcs With CertipyEnumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.Votes: 0GitHub stars: 9
- Exploiting Aws With PacuUse Pacu modules for AWS privilege escalation, persistence, and backdooring.Votes: 0GitHub stars: 9
- Exploiting Http Request SmugglingDetecting and exploiting HTTP request smuggling vulnerabilities causedVotes: 0GitHub stars: 9
- Exploiting Jwt Algorithm Confusion Attack'Exploits JWT algorithm confusion vulnerabilities where the server''sVotes: 0GitHub stars: 9
- Exploiting Kerberoasting With ImpacketPerform Kerberoasting attacks using Impacket's GetUserSPNs to extractVotes: 0GitHub stars: 9