All authors

Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146962 skills2 installs1,412 views
- Implementing Cloud Workload ProtectionImplements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly Tespit, and file integrity checking on EC2/GCE instances. Scans forVotes: 0GitHub stars: 4
- Implementing Gcp Binary AuthorizationImplement GCP Binary Authorization to enforce Dağıt:-time security controls that ensure only trusted, attested container images are Dağıtılmış to Google Kubernetes Engine and Cloud Run.Votes: 0GitHub stars: 4
- Implementing Gcp Organization Policy ConstraintsImplement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization,Votes: 0GitHub stars: 4
- Implementing Gcp Vpc Firewall RulesImplementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitorVotes: 0GitHub stars: 4
- Implementing Secrets Management With Vaultbu skill covers Dağıt:ing HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption,Votes: 0GitHub stars: 4
- Implementing Zero Trust In Cloudbu skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric accessVotes: 0GitHub stars: 4
- Implementing Zero Trust Network AccessImplementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, andVotes: 0GitHub stars: 4
- Managing Cloud Identity With Oktabu skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, Dağıt:ing phishing- resistant MFA with OktaVotes: 0GitHub stars: 4
- Performing Aws Account Enumeration With Scout SuitePerform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and Şunu üret:ctionable security reports.Votes: 0GitHub stars: 4
- Performing Aws Privilege Escalation AssessmentPerforming authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, PrincipalVotes: 0GitHub stars: 4
- Performing Cloud Asset Inventory With CartographyPerform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS,Votes: 0GitHub stars: 4
- Performing Cloud Forensics With Aws CloudtrailPerform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.Votes: 0GitHub stars: 4
- Performing Cloud Log Forensics With AthenaUses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for Tespit etmeVotes: 0GitHub stars: 4
- Performing Cloud Native Forensics With FalcoUses Falco YAML rules for runtime threat Tespit in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages FalcoVotes: 0GitHub stars: 4
- Performing Cloud Native Threat Hunting With Aws DetectiveHunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty Bul:ing correlation, and automated entity profiling across IAM users, EC2 instances,Votes: 0GitHub stars: 4
- Performing Cloud Penetration Testing With PacuPerforming authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting,Votes: 0GitHub stars: 4
- Performing Gcp Penetration Testing With GcpbucketbrutePerform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditingVotes: 0GitHub stars: 4
- Performing Gcp Security Assessment With ForsetiPerforming comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storageVotes: 0GitHub stars: 4
- Performing Serverless Function Security ReviewPerforming security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables,Votes: 0GitHub stars: 4
- Remediating S3 Bucket Misconfigurationbu skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 BlockVotes: 0GitHub stars: 4
- Securing Api Gateway With Aws WafSecuring API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputationVotes: 0GitHub stars: 4
- Securing Aws Iam Permissionsbu skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permissionVotes: 0GitHub stars: 4
- Securing Aws Lambda Execution RolesSecuring AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validateVotes: 0GitHub stars: 4
- Securing Azure With Microsoft Defenderbu skill instructs security practitioners on Dağıt:ing Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It coversVotes: 0GitHub stars: 4
- Securing Container Registry ImagesSecuring container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and buildingVotes: 0GitHub stars: 4
- Securing Kubernetes On Cloudbu skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls,Votes: 0GitHub stars: 4
- Securing Serverless Functionsbu skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerabilityVotes: 0GitHub stars: 4
- Implementing Gdpr Data Protection ControlsThe General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. ThisVotes: 0GitHub stars: 4
- Implementing Iso 27001 Information Security ManagementISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). bu skill covers theVotes: 0GitHub stars: 4
- Implementing Pci Dss Compliance ControlsPCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirementsVotes: 0GitHub stars: 4
- Performing Nist Csf Maturity AssessmentThe NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect,Votes: 0GitHub stars: 4
- Performing Soc2 Type2 Audit PreparationAutomates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testingVotes: 0GitHub stars: 4
- Analyzing Kubernetes Audit LogsParses Kubernetes API server audit logs (JSON lines) to tespit etmeexec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat Tespit rulesVotes: 0GitHub stars: 4
- Detecting Container Drift At Runtimetespit etmeunauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.Votes: 0GitHub stars: 4
- Detecting Container Escape AttemptsContainer escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Tespit involves monitoring for escapeVotes: 0GitHub stars: 4
- Detecting Container Escape With Falco Rulestespit etmecontainer escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.Votes: 0GitHub stars: 4
- Detecting Privilege Escalation In Kubernetes Podstespit etmeand prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.Votes: 0GitHub stars: 4
- Hardening Docker Containers For ProductionHardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforceVotes: 0GitHub stars: 4
- Hardening Docker Daemon ConfigurationHarden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.Votes: 0GitHub stars: 4
- Implementing Container Image Minimal Base With DistrolessReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.Votes: 0GitHub stars: 4
- Implementing Container Network Policies With CalicoEnforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.Votes: 0GitHub stars: 4
- Implementing Image Provenance Verification With CosignSign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.Votes: 0GitHub stars: 4
- Implementing Kubernetes Network Policy With CalicoImplement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.Votes: 0GitHub stars: 4
- Implementing Kubernetes Pod Security StandardsPod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into KubernetesVotes: 0GitHub stars: 4
- Implementing Network Policies For KubernetesKubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined withVotes: 0GitHub stars: 4
- Implementing Opa Gatekeeper For Policy EnforcementEnforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.Votes: 0GitHub stars: 4
- Implementing Pod Security Admission ControllerImplement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.Votes: 0GitHub stars: 4
- Implementing Rbac Hardening For KubernetesHarden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.Votes: 0GitHub stars: 4
- Implementing Runtime Security With TetragonImplement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat Tespit and policy enforcement.Votes: 0GitHub stars: 4
- Implementing Supply Chain Security With In TotoImplement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.Votes: 0GitHub stars: 4