All authors

Claude Skills by mukul975
github.com/mukul9751,113 skills6 installs1,639 views
- Exploiting Websocket VulnerabilitiesTesting WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecureVotes: 0GitHub stars: 31,965
- Exploiting Zerologon Vulnerability Cve 2020 1472Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controllerVotes: 0GitHub stars: 31,965
- Extracting Browser History ArtifactsExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and EdgeVotes: 0GitHub stars: 31,965
- Extracting Config From Agent Tesla RatExtract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials,Votes: 0GitHub stars: 31,965
- Extracting Credentials From Memory DumpExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps usingVotes: 0GitHub stars: 31,965
- Extracting Iocs From Malware Samples'Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs,Votes: 0GitHub stars: 31,965
- Extracting Memory Artifacts With Rekall'Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VADVotes: 0GitHub stars: 31,965
- Extracting Windows Event Logs ArtifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateralVotes: 0GitHub stars: 31,965
- Generating Threat Intelligence Reports'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailoredVotes: 0GitHub stars: 31,965
- Hardening Docker Containers For ProductionHardening Docker containers for production involves applying security best practices aligned with CIS DockerVotes: 0GitHub stars: 31,965
- Hardening Docker Daemon ConfigurationHarden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootlessVotes: 0GitHub stars: 31,965
- Hardening Linux Endpoint With Cis Benchmark'Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface,Votes: 0GitHub stars: 31,965
- Hardening Windows Endpoint With Cis Benchmark'Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attackVotes: 0GitHub stars: 31,965
- Hunting Advanced Persistent Threats'Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-drivenVotes: 0GitHub stars: 31,965
- Hunting Credential Stuffing Attacks'Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,Votes: 0GitHub stars: 31,965
- Hunting For Anomalous Powershell Execution'Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (EventVotes: 0GitHub stars: 31,965
- Hunting For Beaconing With Frequency AnalysisIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,Votes: 0GitHub stars: 31,965
- Hunting For Cobalt Strike BeaconsDetect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARMVotes: 0GitHub stars: 31,965
- Hunting For Command And Control BeaconingDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputationVotes: 0GitHub stars: 31,965
- Hunting For Data Exfiltration IndicatorsHunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloudVotes: 0GitHub stars: 31,965
- Hunting For Data Staging Before ExfiltrationDetect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual tempVotes: 0GitHub stars: 31,965
- Hunting For Dcom Lateral Movement'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindowsVotes: 0GitHub stars: 31,965
- Hunting For Dcsync AttacksDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requestsVotes: 0GitHub stars: 31,965
- Hunting For Defense Evasion Via Timestomping'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestampsVotes: 0GitHub stars: 31,965
- Hunting For Dns Based PersistenceHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,Votes: 0GitHub stars: 31,965
- Hunting For Dns Tunneling With ZeekDetect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessiveVotes: 0GitHub stars: 31,965
- Hunting For Domain Fronting C2 TrafficDetect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificateVotes: 0GitHub stars: 31,965
- Hunting For Lateral Movement Via WmiDetect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 forVotes: 0GitHub stars: 31,965
- Hunting For Living Off The Cloud TechniquesHunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuseVotes: 0GitHub stars: 31,965
- Hunting For Living Off The Land BinariesProactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads whileVotes: 0GitHub stars: 31,965
- Hunting For Lolbins Execution In Endpoint LogsHunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logsVotes: 0GitHub stars: 31,965
- Hunting For Ntlm Relay AttacksDetect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifyingVotes: 0GitHub stars: 31,965
- Hunting For Persistence Mechanisms In WindowsSystematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,Votes: 0GitHub stars: 31,965
- Hunting For Persistence Via Wmi SubscriptionsHunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMIVotes: 0GitHub stars: 31,965
- Hunting For Process Injection TechniquesDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injectionVotes: 0GitHub stars: 31,965
- Hunting For Registry Persistence MechanismsHunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, andVotes: 0GitHub stars: 31,965
- Hunting For Registry Run Key PersistenceDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registryVotes: 0GitHub stars: 31,965
- Hunting For Scheduled Task PersistenceHunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious taskVotes: 0GitHub stars: 31,965
- Hunting For Shadow Copy DeletionHunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoringVotes: 0GitHub stars: 31,965
- Hunting For Spearphishing IndicatorsHunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detectVotes: 0GitHub stars: 31,965
- Hunting For Startup Folder PersistenceDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,Votes: 0GitHub stars: 31,965
- Hunting For Supply Chain CompromiseHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,Votes: 0GitHub stars: 31,965
- Hunting For Suspicious Scheduled TasksHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspiciousVotes: 0GitHub stars: 31,965
- Hunting For T1098 Account ManipulationHunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, groupVotes: 0GitHub stars: 31,965
- Hunting For Unusual Network ConnectionsHunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standardVotes: 0GitHub stars: 31,965
- Hunting For Unusual Service InstallationsDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for EventVotes: 0GitHub stars: 31,965
- Hunting For Webshell ActivityHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspiciousVotes: 0GitHub stars: 31,965
- Implementing Aes Encryption For Data At RestAES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protectVotes: 0GitHub stars: 31,965
- Implementing Alert Fatigue Reduction'Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts,Votes: 0GitHub stars: 31,965
- Implementing Anti Phishing Training ProgramSecurity awareness training is the human layer of phishing defense. An effective anti-phishing training programVotes: 0GitHub stars: 31,965