All authors

Claude Skills by mukul975
github.com/mukul9751,113 skills6 installs1,639 views
- Analyzing Pdf Malware With Pdfid'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,Votes: 0GitHub stars: 31,965
- Analyzing Persistence Mechanisms In LinuxDetect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOADVotes: 0GitHub stars: 31,965
- Analyzing Powershell Empire ArtifactsDetect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,Votes: 0GitHub stars: 31,965
- Analyzing Powershell Script Block LoggingParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encodedVotes: 0GitHub stars: 31,965
- Analyzing Prefetch Files For Execution HistoryParse Windows Prefetch files to determine program execution history including run counts, timestamps, and referencedVotes: 0GitHub stars: 31,965
- Analyzing Ransomware Encryption Mechanisms'Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families toVotes: 0GitHub stars: 31,965
- Analyzing Ransomware Leak Site IntelligenceMonitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligenceVotes: 0GitHub stars: 31,965
- Analyzing Ransomware Network IndicatorsIdentify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltrationVotes: 0GitHub stars: 31,965
- Analyzing Ransomware Payment Wallets'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,Votes: 0GitHub stars: 31,965
- Analyzing Sbom For Supply Chain Vulnerabilities'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilitiesVotes: 0GitHub stars: 31,965
- Analyzing Security Logs With Splunk'Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidentsVotes: 0GitHub stars: 31,965
- Analyzing Slack Space And File System ArtifactsExamine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden dataVotes: 0GitHub stars: 31,965
- Analyzing Supply Chain Malware ArtifactsInvestigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,Votes: 0GitHub stars: 31,965
- Analyzing Threat Actor Ttps With Mitre AttackMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)Votes: 0GitHub stars: 31,965
- Analyzing Threat Actor Ttps With Mitre Navigator'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK frameworkVotes: 0GitHub stars: 31,965
- Analyzing Threat Intelligence Feeds'Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,Votes: 0GitHub stars: 31,965
- Analyzing Threat Landscape With MispAnalyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,Votes: 0GitHub stars: 31,965
- Analyzing Tls Certificate Transparency Logs'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificateVotes: 0GitHub stars: 31,965
- Analyzing Typosquatting Domains With DnstwistDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutationsVotes: 0GitHub stars: 31,965
- Analyzing Uefi Bootkit Persistence'Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System PartitionVotes: 0GitHub stars: 31,965
- Analyzing Usb Device Connection HistoryInvestigate USB device connection history from Windows registry, event logs, and setupapi logs to track removableVotes: 0GitHub stars: 31,965
- Analyzing Web Server Logs For IntrusionParse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal,Votes: 0GitHub stars: 31,965
- Analyzing Windows Amcache Artifacts'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, applicationVotes: 0GitHub stars: 31,965
- Analyzing Windows Event Logs In Splunk'Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilegeVotes: 0GitHub stars: 31,965
- Analyzing Windows Lnk Files For ArtifactsParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiersVotes: 0GitHub stars: 31,965
- Analyzing Windows Prefetch With PythonParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,Votes: 0GitHub stars: 31,965
- Analyzing Windows Registry For ArtifactsExtract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, andVotes: 0GitHub stars: 31,965
- Analyzing Windows Shellbag ArtifactsAnalyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removableVotes: 0GitHub stars: 31,965
- Auditing Aws S3 Bucket Permissions'Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,Votes: 0GitHub stars: 31,965
- Auditing Azure Active Directory Configuration'Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,Votes: 0GitHub stars: 31,965
- Auditing Cloud With Cis Benchmarks'This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS,Votes: 0GitHub stars: 31,965
- Auditing Gcp Iam Permissions'Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,Votes: 0GitHub stars: 31,965
- Auditing Kubernetes Cluster Rbac'Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerousVotes: 0GitHub stars: 31,965
- Auditing Terraform Infrastructure For Security'Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, andVotes: 0GitHub stars: 31,965
- Auditing Tls Certificate Transparency Logs'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomainsVotes: 0GitHub stars: 31,965
- Automating Ioc Enrichment'Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context usingVotes: 0GitHub stars: 31,965
- Building Adversary Infrastructure Tracking SystemBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOISVotes: 0GitHub stars: 31,965
- Building Attack Pattern Library From Cti ReportsExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based libraryVotes: 0GitHub stars: 31,965
- Building Automated Malware Submission Pipeline'Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints andVotes: 0GitHub stars: 31,965
- Building C2 Infrastructure With Sliver FrameworkBuild and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework withVotes: 0GitHub stars: 31,965
- Building Cloud Siem With Sentinel'This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized securityVotes: 0GitHub stars: 31,965
- Building Detection Rule With Splunk SplBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identifyVotes: 0GitHub stars: 31,965
- Building Detection Rules With Sigma'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platformsVotes: 0GitHub stars: 31,965
- Building Devsecops Pipeline With Gitlab CiDesign and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,Votes: 0GitHub stars: 31,965
- Building Identity Federation With Saml Azure AdEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID)Votes: 0GitHub stars: 31,965
- Building Identity Governance Lifecycle Process'Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation,Votes: 0GitHub stars: 31,965
- Building Incident Response Dashboard'Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadershipVotes: 0GitHub stars: 31,965
- Building Incident Response Playbook'Designs and documents structured incident response playbooks that define step-by-step procedures for specificVotes: 0GitHub stars: 31,965
- Building Incident Timeline With TimesketchBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-sourceVotes: 0GitHub stars: 31,965
- Building Ioc Defanging And Sharing PipelineBuild an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharingVotes: 0GitHub stars: 31,965