All authors

Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repo753 skills0 installs1,069 views
- Extracting Iocs From Malware SamplesExtracts indicators of compromise (IOCs) from malware samples, includingVotes: 0GitHub stars: 67
- Extracting Memory Artifacts With Rekall'Uses Rekall memory forensics framework to analyze memory dumps for processVotes: 0GitHub stars: 67
- Extracting Windows Event Logs ArtifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw,Votes: 0GitHub stars: 67
- Generating Threat Intelligence Reports'Generates structured cyber threat intelligence reports at strategic,Votes: 0GitHub stars: 67
- Hardening Docker Containers For ProductionHardens Dockerfiles, images, and per-container runtime settings against the CIS Docker Benchmark v1.8.0: non-root users, dropped capabilities, read-only root filesystem, seccomp and AppArmor profiles, and minimal multi-stage builds, validated with docker-bench-security, Hadolint, and Dockle. Use when preparing a container or Dockerfile for production, or auditing images and runtime flags against CIS Docker controls. Keywords: Dockerfile, USER, --cap-drop, read-only rootfs, seccomp, AppArmor, ...Votes: 0GitHub stars: 67
- Hardening Docker Daemon ConfigurationHardens the Docker daemon (dockerd) through /etc/docker/daemon.json with user namespace remapping, TLS client authentication, seccomp profiles, and CIS Docker Benchmark controls such as icc, no-new-privileges, and live-restore. Use when securing a Docker host's daemon to prevent privilege escalation, breakout, or lateral movement, or when auditing daemon settings against CIS requirements. Keywords: dockerd, daemon.json, userns-remap, no-new-privileges, icc, live-restore, TLS socket. Do not us...Votes: 0GitHub stars: 67
- Hardening Linux Endpoint With Cis Benchmark'Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu,Votes: 0GitHub stars: 67
- Hardening Windows Endpoint With Cis Benchmark'Hardens Windows endpoints using CIS (Center for Internet Security) BenchmarkVotes: 0GitHub stars: 67
- Hunting Advanced Persistent Threats'Proactively hunts for Advanced Persistent Threat (APT) activity withinVotes: 0GitHub stars: 67
- Hunting Credential Stuffing Attacks'Detects credential stuffing attacks by analyzing authentication logsVotes: 0GitHub stars: 67
- Hunting For Anomalous Powershell Execution'Hunt for malicious PowerShell activity by analyzing Script Block LoggingVotes: 0GitHub stars: 67
- Hunting For Beaconing With Frequency AnalysisIdentify command-and-control beaconing patterns in network traffic byVotes: 0GitHub stars: 67
- Hunting For Cobalt Strike BeaconsDetect Cobalt Strike beacon command-and-control traffic using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP malleable C2 profile pattern matching, and beacon jitter/interval analysis, built with Zeek network logs, Suricata IDS rules, and Python PCAP analysis. Use when hunting for Cobalt Strike beacon callbacks in network traffic or building detection rules for this C2 framework.Votes: 0GitHub stars: 67
- Hunting For Command And Control BeaconingDetect C2 beaconing patterns in network traffic using frequency analysis,Votes: 0GitHub stars: 67
- Hunting For Data Exfiltration IndicatorsHunt for data exfiltration by analyzing Zeek and Suricata network telemetry for unusual data flows, DNS tunneling via large/frequent TXT queries, uploads to personal cloud storage, and encrypted-channel abuse, correlated against threat intel on destination domains. Use when hunting for data theft in a compromised environment, investigating unusual outbound data volumes, or determining what data was stolen during incident response.Votes: 0GitHub stars: 67
- Hunting For Data Staging Before ExfiltrationDetect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon process-creation and file-system telemetry (Event ID 4688, Sysmon 1/11) for 7-Zip/RAR/tar archive creation, unusual temp or hidden folder access, and anomalous consolidation of files from multiple directories. Use when hunting for pre-exfiltration staging behavior, building detection rules for archiver abuse, or validating monitoring coverage for T1074.Votes: 0GitHub stars: 67
- Hunting For Dcom Lateral Movement'Hunt for DCOM-based lateral movement (MITRE ATT&CK T1021.003) by detectingVotes: 0GitHub stars: 67
- Hunting For Dcsync AttacksDetect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All requests issued by non-domain-controller accounts. Use when hunting for DCSync credential theft, after detecting Mimikatz-class tooling, or during incident response and purple-team exercises involving Active Directory replication abuse.Votes: 0GitHub stars: 67
- Hunting For Defense Evasion Via Timestomping'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATIONVotes: 0GitHub stars: 67
- Hunting For Dns Based PersistenceHunts for DNS-based persistence mechanisms such as DNS hijacking, danglingVotes: 0GitHub stars: 67
- Hunting For Dns Tunneling With ZeekDetects DNS tunneling and covert-channel data exfiltration by analyzingVotes: 0GitHub stars: 67
- Hunting For Domain Fronting C2 TrafficDetects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-headerVotes: 0GitHub stars: 67
- Hunting For Lateral Movement Via WmiDetects WMI-based lateral movement (e.g. wmic process call create,Votes: 0GitHub stars: 67
- Hunting For Living Off The Cloud TechniquesHunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP,Votes: 0GitHub stars: 67
- Hunting For Living Off The Land BinariesProactively hunts for adversary abuse of legitimate, signed system binariesVotes: 0GitHub stars: 67
- Hunting For Lolbins Execution In Endpoint LogsHunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITREVotes: 0GitHub stars: 67
- Hunting For Ntlm Relay AttacksDetects NTLM relay attacks (MITRE T1557.001) by analyzing Windows EventVotes: 0GitHub stars: 67
- Hunting For Persistence Mechanisms In WindowsSystematically hunts for adversary persistence mechanisms across WindowsVotes: 0GitHub stars: 67
- Hunting For Persistence Via Wmi SubscriptionsHunts for adversary persistence via WMI event subscriptions (MITRE T1546.003)Votes: 0GitHub stars: 67
- Hunting For Process Injection TechniquesDetects process injection techniques (MITRE T1055) — includingVotes: 0GitHub stars: 67
- Hunting For Registry Persistence MechanismsHunts for registry-based persistence mechanisms (MITRE T1547) in WindowsVotes: 0GitHub stars: 67
- Hunting For Registry Run Key PersistenceDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzingVotes: 0GitHub stars: 67
- Hunting For Scheduled Task PersistenceRuns a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual scheduling patterns. Use when hunting for scheduled-task persistence, after threat intel flags related campaigns, during incident response, or when alerts fire on schtasks/at.exe activity.Votes: 0GitHub stars: 67
- Hunting For Shadow Copy DeletionRuns a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. Use when hunting for ransomware preparation or anti-forensics activity, after threat intel flags active campaigns, or when alerts trigger on shadow-copy deletion commands.Votes: 0GitHub stars: 67
- Hunting For Spearphishing IndicatorsHunt for spearphishing campaign indicators across email logs, endpointVotes: 0GitHub stars: 67
- Hunting For Startup Folder PersistenceDetects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for real-time filesystem monitoring. Use when hunting for malware or implants that survive reboot via startup-folder placement, or when validating autoruns/EDR findings against known-good startup baselines.Votes: 0GitHub stars: 67
- Hunting For Supply Chain CompromiseRuns a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts. Use when hunting after threat intel flags a compromised vendor/dependency, scoping a build-pipeline compromise, or reviewing update/build integrity.Votes: 0GitHub stars: 67
- Hunting For Suspicious Scheduled TasksHunts for adversary persistence and execution via Windows scheduled tasks (T1053.005) by analyzing Security Event ID 4698 task-creation events, suspicious task properties, and unusual execution patterns from schtasks.exe/at.exe. Use after detecting schtasks or at.exe in process creation logs, during incident response to enumerate persistence on compromised hosts, or when Event ID 4698 fires for an unusual task.Votes: 0GitHub stars: 67
- Hunting For T1098 Account ManipulationHunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4738, 4728, 4732, 4756, 4670, and 5136. Use when investigating suspected privilege persistence in Active Directory, after detecting anomalous group/credential changes, or during incident response to trace account tampering.Votes: 0GitHub stars: 67
- Hunting For Unusual Network ConnectionsRuns a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and unusual connection frequencies from endpoints. Use when hunting for beaconing/C2 traffic, after threat intel flags suspicious infrastructure, or when alerts fire on anomalous connections.Votes: 0GitHub stars: 67
- Hunting For Unusual Service InstallationsDetects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms via Sysmon/EDR telemetry. Use when hunting for new-service persistence after a suspected compromise, when Event ID 7045 fires for an unfamiliar service, or during incident response to enumerate service-based persistence on Windows hosts.Votes: 0GitHub stars: 67
- Hunting For Webshell ActivityRuns a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server processes, and anomalous HTTP request patterns. Use when hunting for web shells after a public-facing app compromise, when EDR/SIEM alerts fire on webserver process anomalies, or during incident response on internet-facing infrastructure.Votes: 0GitHub stars: 67
- Implementing Aes Encryption For Data At RestGuides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Use when deploying or configuring encryption for data at rest, establishing controls to meet compliance requirements, or reviewing an implementation during a security assessment.Votes: 0GitHub stars: 67
- Implementing Alert Fatigue Reduction'Implements strategies to reduce SOC alert fatigue by tuning detectionVotes: 0GitHub stars: 67
- Implementing Anti Phishing Training ProgramGuides designing, deploying, and measuring an anti-phishing security awareness program - baseline phishing simulations, interactive training modules, just-in-time learning, and metric tracking - using platforms like KnowBe4, Proofpoint Security Awareness, or Cofense. Use when building or maturing a phishing awareness program, establishing training controls for compliance, or measuring phishing susceptibility and reporting rates over time.Votes: 0GitHub stars: 67
- Implementing Anti Ransomware Group Policy'Configures Windows Group Policy Objects to block ransomware executionVotes: 0GitHub stars: 67
- Implementing Api Abuse Detection With Rate LimitingImplements API abuse detection using token bucket, sliding window, andVotes: 0GitHub stars: 67
- Implementing Api Gateway Security Controls'Configures API gateways such as Kong, AWS API Gateway, Azure APIM,Votes: 0GitHub stars: 67
- Implementing Api Key Security Controls'Implements secure API key generation with sufficient entropy, server-sideVotes: 0GitHub stars: 67
- Implementing Api Rate Limiting And Throttling'Implements API rate limiting and throttling with token bucket, slidingVotes: 0GitHub stars: 67