All authors

Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repo753 skills0 installs1,069 views
- Implementing Zero Knowledge Proof For AuthenticationImplements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.Votes: 0GitHub stars: 67
- Implementing Zero Standing Privilege With CyberarkDeploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.Votes: 0GitHub stars: 67
- Implementing Zero Trust Dns With NextdnsConfigure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME cloaking, and enforces organizational DNS policy across endpoints. Use when deploying DNS-layer threat blocking and acceptable-use enforcement, or when extending zero trust controls (including Windows 11 Zero Trust DNS) to the DNS resolution path.Votes: 0GitHub stars: 67
- Implementing Zero Trust For Saas ApplicationsSecures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity verification and device compliance. Use when adding MFA/device-compliance conditional access, discovering shadow IT, governing OAuth consent grants, or applying session controls to sensitive SaaS data.Votes: 0GitHub stars: 67
- Implementing Zero Trust In CloudGuides zero trust implementation across AWS, Azure, and GCP per NIST SP 800-207 and BeyondCorp principles, covering identity-centric access, micro-segmentation, continuous verification, device trust assessment, and Identity-Aware Proxy deployment. Use when migrating from perimeter security to identity-centric access, removing VPN dependency, or designing micro-segmentation for multi-cloud workloads.Votes: 0GitHub stars: 67
- Implementing Zero Trust Network Access With ZscalerConfigures Zero Trust Network Access using Zscaler Private Access (ZPA) to broker identity-based, context-aware connections between authenticated users and internal applications through the Zscaler Zero Trust Exchange, without placing users on the corporate network. Use when replacing traditional VPN architectures with ZTNA, or when brokering secure per-application access for remote and hybrid users via Zscaler.Votes: 0GitHub stars: 67
- Implementing Zero Trust Network AccessConfigures Zero Trust Network Access (ZTNA) in AWS, Azure, and GCP using identity-aware proxies, micro-segmentation, and continuous verification with conditional access policies, replacing VPN-based access with BeyondCorp-style architectures. Use when replacing VPN remote access with identity-based controls, limiting lateral movement via micro-segmentation, or exposing cloud workloads to authenticated users without public internet exposure.Votes: 0GitHub stars: 67
- Implementing Zero Trust With BeyondcorpConfigures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network attributes, and auditing the resulting policies for compliance. Use when eliminating perimeter/VPN trust for GCP resources or internal apps, or when setting up identity- and device-posture-based access controls on Google Cloud.Votes: 0GitHub stars: 67
- Implementing Zero Trust With Hashicorp BoundaryInstalls and configures HashiCorp Boundary as a default-deny, identity-aware proxy for infrastructure access, including controller/worker setup, Vault-backed credential brokering, session recording, and OIDC/LDAP auth across an org/project scope hierarchy. Use when replacing VPN or direct network access with just-in-time, credential-less Boundary sessions, or standing up Boundary controllers and workers.Votes: 0GitHub stars: 67
- Integrating Dast With Owasp Zap In PipelineIntegrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation, scan policy tuning, and DAST quality gates. Use when testing running web apps or REST/GraphQL APIs for XSS, SQLi, CSRF, and auth/authz flaws, or when SAST alone is insufficient and runtime DAST is required for compliance or release gating.Votes: 0GitHub stars: 67
- Integrating Sast Into Github Actions PipelineIntegrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and merge-blocking quality gates for high-severity findings. Use when adding automated code vulnerability detection to CI, enforcing consistent SAST org-wide, or producing SOC 2/PCI DSS/NIST SSDF compliance evidence.Votes: 0GitHub stars: 67
- Intercepting Mobile Traffic With Burpsuite'Intercepts and analyzes HTTP/HTTPS traffic from mobile applicationsVotes: 0GitHub stars: 67
- Investigating Insider Threat Indicators'Investigates insider threat indicators including data exfiltration attempts,Votes: 0GitHub stars: 67
- Investigating Phishing Email Incident'Investigates phishing email incidents from initial user report throughVotes: 0GitHub stars: 67
- Investigating Ransomware Attack ArtifactsForensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options. Use immediately after discovering ransomware encryption, when scoping the incident forensically, or when documenting evidence for law enforcement and insurance claims.Votes: 0GitHub stars: 67
- Managing Cloud Identity With OktaImplement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and enforce adaptive access policies on device posture and risk signals. Use when standing up Okta SSO, rolling out FastPass MFA, automating identity lifecycle, or building risk-based conditional access for cloud environments.Votes: 0GitHub stars: 67
- Managing Intelligence Lifecycle'Manages the end-to-end cyber threat intelligence lifecycle from planningVotes: 0GitHub stars: 67
- Mapping Mitre Attack Techniques'Maps observed adversary behaviors, security alerts, and detection rulesVotes: 0GitHub stars: 67
- Monitoring Darkweb Sources'Monitors dark web forums, marketplaces, paste sites, and ransomwareVotes: 0GitHub stars: 67
- Monitoring Scada Modbus Traffic Anomalies'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalousVotes: 0GitHub stars: 67
- Performing Access Recertification With SaviyntConfigure and execute access recertification campaigns in Saviynt EnterpriseVotes: 0GitHub stars: 67
- Performing Access Review And CertificationDesigns and runs access review and certification campaigns-scoping,Votes: 0GitHub stars: 67
- Performing Active Directory Bloodhound AnalysisUse BloodHound and SharpHound (or AzureHound) to enumerate Active DirectoryVotes: 0GitHub stars: 67
- Performing Active Directory Compromise InvestigationInvestigate Active Directory compromise by analyzing authentication logs,Votes: 0GitHub stars: 67
- Performing Active Directory Forest Trust AttackEnumerate and audit Active Directory forest trust relationships usingVotes: 0GitHub stars: 67
- Performing Active Directory Penetration TestConduct a focused Active Directory penetration test using BloodHound,Votes: 0GitHub stars: 67
- Performing Active Directory Vulnerability AssessmentAssess Active Directory security posture using PingCastle, BloodHound,Votes: 0GitHub stars: 67
- Performing Adversary In The Middle Phishing DetectionDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacksVotes: 0GitHub stars: 67
- Performing Agentless Vulnerability ScanningConfigure and execute agentless vulnerability scanning using networkVotes: 0GitHub stars: 67
- Performing Ai Driven Osint CorrelationUse AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFootVotes: 0GitHub stars: 67
- Performing Alert Triage With Elastic SiemPerform systematic alert triage in Elastic Security SIEM—classifying,Votes: 0GitHub stars: 67
- Performing Android App Static Analysis With Mobsf'Performs automated static analysis of Android applications using MobileVotes: 0GitHub stars: 67
- Performing Api Fuzzing With Restler'Uses Microsoft RESTler to perform stateful REST API fuzzing: compilesVotes: 0GitHub stars: 67
- Performing Api Inventory And Discovery'Performs API inventory and discovery to identify all API endpoints inVotes: 0GitHub stars: 67
- Performing Api Rate Limiting Bypass'Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp)Votes: 0GitHub stars: 67
- Performing Api Security Testing With Postman'Uses Postman to build structured API security test collections coveringVotes: 0GitHub stars: 67
- Performing Arp Spoofing Attack Simulation'Simulates ARP spoofing/cache-poisoning attacks in authorized lab orVotes: 0GitHub stars: 67
- Performing Asset Criticality Scoring For VulnsBuild a multi-factor asset criticality scoring model—incorporating dataVotes: 0GitHub stars: 67
- Performing Authenticated Scan With OpenvasConfigure and execute authenticated (credentialed) vulnerability scans using OpenVAS/GreenboneVotes: 0GitHub stars: 67
- Performing Authenticated Vulnerability ScanPlan and run authenticated (credentialed) vulnerability scans with scanners such asVotes: 0GitHub stars: 67
- Performing Automated Malware Analysis With CapeDeploy and operate the CAPEv2 malware sandbox (a Cuckoo derivative) to run samples in aVotes: 0GitHub stars: 67
- Performing Aws Account Enumeration With Scout SuiteRun the agentless, open-source ScoutSuite tool (via pip install and the `scout` CLI)Votes: 0GitHub stars: 67
- Performing Aws Privilege Escalation Assessment'Performing authorized privilege escalation assessments in AWS environmentsVotes: 0GitHub stars: 67
- Performing Bandwidth Throttling Attack Simulation'Simulate bandwidth throttling and network degradation attacks using tc,Votes: 0GitHub stars: 67
- Performing Binary Exploitation Analysis'Analyze ELF binaries for memory-corruption vulnerabilities and build proof-of-conceptVotes: 0GitHub stars: 67
- Performing Blind Ssrf ExploitationDetect and exploit blind Server-Side Request Forgery (SSRF) using out-of-bandVotes: 0GitHub stars: 67
- Performing Bluetooth Security AssessmentAssess Bluetooth Low Energy (BLE) device security using Python's bleak asyncioVotes: 0GitHub stars: 67
- Performing Brand Monitoring For ImpersonationMonitor for brand impersonation attacks across domains, social media,Votes: 0GitHub stars: 67
- Performing Clickjacking Attack TestTesting web applications for clickjacking vulnerabilities by assessingVotes: 0GitHub stars: 67
- Performing Cloud Asset Inventory With CartographyRun Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database,Votes: 0GitHub stars: 67