All authors

Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146962 skills2 installs1,412 views
- Performing Api Fuzzing With RestlerUses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies betweenVotes: 0GitHub stars: 4
- Performing Api Inventory And DiscoveryPerforms API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester usesVotes: 0GitHub stars: 4
- Performing Api Rate Limiting BypassTests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttlingVotes: 0GitHub stars: 4
- Performing Api Security Testing With PostmanUses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws,Votes: 0GitHub stars: 4
- Performing Graphql Depth Limit AttackExecute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.Votes: 0GitHub stars: 4
- Performing Graphql Introspection AttackPerforms GraphQL introspection attacks to Şunu çıkar: full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspectionVotes: 0GitHub stars: 4
- Performing Jwt None Algorithm AttackExecute and Şunu test et: JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.Votes: 0GitHub stars: 4
- Performing Soap Web Service Security TestingPerform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.Votes: 0GitHub stars: 4
- Testing Api Authentication WeaknessesTests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, tokenVotes: 0GitHub stars: 4
- Testing Api For Broken Object Level AuthorizationTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulatingVotes: 0GitHub stars: 4
- Testing Api For Mass Assignment VulnerabilityTests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have Erişim: by including additional parameters in API requests. TheVotes: 0GitHub stars: 4
- Testing Oauth2 Implementation FlawsTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation,Votes: 0GitHub stars: 4
- Testing Websocket Api SecurityTests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocketVotes: 0GitHub stars: 4
- Analyzing Ethereum Smart Contract VulnerabilitiesPerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to tespit etmereentrancy, integer overflow, access control, and other vulnerability classes before Dağıt:mentVotes: 0GitHub stars: 4
- Analyzing Cloud Storage Access Patternstespit etmeabnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads,Votes: 0GitHub stars: 4
- Analyzing Office365 Audit Logs For CompromiseParse Office 365 Unified Audit Logs via Microsoft Graph API to tespit etmeemail forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.Votes: 0GitHub stars: 4
- Auditing Aws S3 Bucket PermissionsSystematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI,Votes: 0GitHub stars: 4
- Auditing Azure Active Directory ConfigurationAuditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, andVotes: 0GitHub stars: 4
- Auditing Cloud With Cis Benchmarksbu skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, runningVotes: 0GitHub stars: 4
- Auditing Gcp Iam PermissionsAuditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI,Votes: 0GitHub stars: 4
- Auditing Kubernetes Cluster RbacAuditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation pathsVotes: 0GitHub stars: 4
- Auditing Terraform Infrastructure For SecurityAuditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to tespit etmeoverly permissive IAM policies, public resource exposure,Votes: 0GitHub stars: 4
- Building Cloud Siem With Sentinelbu skill covers Dağıt:ing Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion,Votes: 0GitHub stars: 4
- Conducting Cloud Penetration Testingbu skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testingVotes: 0GitHub stars: 4
- Detecting Aws Cloudtrail Anomaliestespit etmeunusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorizedVotes: 0GitHub stars: 4
- Detecting Aws Credential Exposure With TrufflehogTespit etme exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native Tespit mechanisms to prevent credentialVotes: 0GitHub stars: 4
- Detecting Aws Guardduty Findings AutomationAutomate AWS GuardDuty threat Tespit Bul:ings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notificationVotes: 0GitHub stars: 4
- Detecting Aws Iam Privilege Escalationtespit etmeAWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violationsVotes: 0GitHub stars: 4
- Detecting Azure Lateral Movementtespit etmelateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation,Votes: 0GitHub stars: 4
- Detecting Azure Service Principal Abusetespit etmeand Araştır: Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.Votes: 0GitHub stars: 4
- Detecting Azure Storage Account MisconfigurationsAudit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions usingVotes: 0GitHub stars: 4
- Detecting Cloud Threats With Guarddutybu skill teaches security teams how to Dağıt: and operationalize Amazon GuardDuty for continuous threat Tespit across AWS accounts and workloads. It covers enabling protection plans forVotes: 0GitHub stars: 4
- Detecting Compromised Cloud CredentialsTespit etme compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuseVotes: 0GitHub stars: 4
- Detecting Cryptomining In Cloudbu skill teaches security teams how to tespit etmeand respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through computeVotes: 0GitHub stars: 4
- Detecting Misconfigured Azure StorageTespit etme misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network accessVotes: 0GitHub stars: 4
- Detecting Oauth Token Thefttespit etme (s) and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomalyVotes: 0GitHub stars: 4
- Detecting S3 Data Exfiltration AttemptsTespit etme data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty Bul:ings, Amazon Macie alerts, and S3 access patterns to identify unauthorizedVotes: 0GitHub stars: 4
- Detecting Serverless Function Injectiontespit etme (s) and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtimeVotes: 0GitHub stars: 4
- Detecting Shadow It Cloud Usagetespit etmeunauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.Votes: 0GitHub stars: 4
- Detecting Suspicious Oauth Application Consenttespit etmerisky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.Votes: 0GitHub stars: 4
- Implementing Aws Config Rules For ComplianceImplementing AWS Config rules for continuous compliance monitoring of AWS resources, Dağıt:ing managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediationVotes: 0GitHub stars: 4
- Implementing Aws Macie For Data ClassificationImplement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials Tespit.Votes: 0GitHub stars: 4
- Implementing Aws Nitro Enclave SecurityImplements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communicationVotes: 0GitHub stars: 4
- Implementing Aws Security Hub ComplianceImplementing AWS Security Hub to aggregate security Bul:ings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridgeVotes: 0GitHub stars: 4
- Implementing Aws Security Hubbu skill covers Dağıt:ing AWS Security Hub as a centralized cloud security posture management platform that aggregates Bul:ings from GuardDuty, Denetle:or, Macie, and third-party tools. ItVotes: 0GitHub stars: 4
- Implementing Azure Defender For CloudImplementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations,Votes: 0GitHub stars: 4
- Implementing Cloud Dlp For Data ProtectionImplementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage,Votes: 0GitHub stars: 4
- Implementing Cloud Security Posture ManagementImplementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite,Votes: 0GitHub stars: 4
- Implementing Cloud Trail Log AnalysisImplementing AWS CloudTrail log analysis for security monitoring, threat Tespit, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorizedVotes: 0GitHub stars: 4
- Implementing Cloud Waf Rulesbu skill covers Dağıt:ing and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuringVotes: 0GitHub stars: 4