All authors

Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146962 skills2 installs1,412 views
- Conducting Cloud Incident ResponseResponds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisitionVotes: 0GitHub stars: 4
- Conducting Malware Incident ResponseResponds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers theVotes: 0GitHub stars: 4
- Conducting Memory Forensics With VolatilityPerforms memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incidentVotes: 0GitHub stars: 4
- Conducting Phishing Incident ResponseResponds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediatingVotes: 0GitHub stars: 4
- Conducting Post Incident Lessons LearnedFacilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.Votes: 0GitHub stars: 4
- Containing Active BreachExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using networkVotes: 0GitHub stars: 4
- Detecting Email Account Compromisetespit etmecompromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via MicrosoftVotes: 0GitHub stars: 4
- Eradicating Malware From Infected SystemsSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.Votes: 0GitHub stars: 4
- Implementing Velociraptor For Ir CollectionDağıt: and configure Velociraptor for scalable endpoint forensic artifact collection incident response sırasında using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, andVotes: 0GitHub stars: 4
- Performing Active Directory Compromise InvestigationAraştır: Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateralVotes: 0GitHub stars: 4
- Performing Cloud Incident Containment ProceduresExecute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictionsVotes: 0GitHub stars: 4
- Performing Disk Forensics InvestigationConducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such asVotes: 0GitHub stars: 4
- Performing Insider Threat InvestigationAraştır:s insider threat incidents involving employees, contractors, or trusted partners who misuse authorized Erişim: steal data, sabotage systems, or violate security policies. CombinesVotes: 0GitHub stars: 4
- Performing Ransomware ResponseExecutes a structured ransomware incident response from initial Tespit through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransomVotes: 0GitHub stars: 4
- Testing Ransomware Recovery ProceduresTest and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizationalVotes: 0GitHub stars: 4
- Triaging Security Incident With Ir PlaybookClassify and prioritize security incidents using structured IR playbooks to Belirle: severity, assign response teams, and initiate appropriate response procedures.Votes: 0GitHub stars: 4
- Triaging Security IncidentPerforms initial triage of security incidents to Belirle: severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type,Votes: 0GitHub stars: 4
- Validating Backup Integrity For RecoveryValidate backup integrity through cryptographic hash verification, automated restore testing, corruption Tespit, and recoverability checks to ensure backups are reliable for disaster recoveryVotes: 0GitHub stars: 4
- Analyzing Android Malware With ApktoolPerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest Denetle:ion, and suspiciousVotes: 0GitHub stars: 4
- Analyzing Bootkit And Rootkit SamplesAnalyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers bootVotes: 0GitHub stars: 4
- Analyzing Cobalt Strike Beacon ConfigurationExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.Votes: 0GitHub stars: 4
- Analyzing Cobaltstrike Malleable C2 ProfilesParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, tespit etmeevasion techniques, and generate network Tespit signatures.Votes: 0GitHub stars: 4
- Analyzing Command And Control CommunicationAnalyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocolVotes: 0GitHub stars: 4
- Analyzing Golang Malware With GhidraReverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.Votes: 0GitHub stars: 4
- Analyzing Heap Spray Exploitationtespit etmeand analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual addressVotes: 0GitHub stars: 4
- Analyzing Linux Elf MalwareAnalyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure.Votes: 0GitHub stars: 4
- Analyzing Macro Malware In Office DocumentsAnalyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques.Votes: 0GitHub stars: 4
- Analyzing Malicious Pdf With PeepdfPerform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.Votes: 0GitHub stars: 4
- Analyzing Malware Behavior With Cuckoo SandboxExecutes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. GeneratesVotes: 0GitHub stars: 4
- Analyzing Malware Persistence With AutorunsUse Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows systems.Votes: 0GitHub stars: 4
- Analyzing Malware Sandbox Evasion Techniquestespit etmesandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction Tespit, and sleep inflation patterns from Cuckoo/AnyRun behavioralVotes: 0GitHub stars: 4
- Analyzing Memory Dumps With VolatilityAnalyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.Votes: 0GitHub stars: 4
- Analyzing Network Covert Channels In Malwaretespit etmeand analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.Votes: 0GitHub stars: 4
- Analyzing Network Traffic Of MalwareAnalyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movementVotes: 0GitHub stars: 4
- Analyzing Packed Malware With Upx UnpackerIdentifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headersVotes: 0GitHub stars: 4
- Analyzing Pdf Malware With PdfidAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Belirle:s the attackVotes: 0GitHub stars: 4
- Analyzing Ransomware Encryption MechanismsAnalyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recoveryVotes: 0GitHub stars: 4
- Analyzing Supply Chain Malware ArtifactsAraştır: supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.Votes: 0GitHub stars: 4
- Deobfuscating Javascript MalwareDeobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscationVotes: 0GitHub stars: 4
- Deobfuscating Powershell Obfuscated MalwareSystematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.Votes: 0GitHub stars: 4
- Detecting Fileless Malware Techniquestespit etme (s) and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) withoutVotes: 0GitHub stars: 4
- Detecting Process Injection Techniquestespit etme (s) and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics,Votes: 0GitHub stars: 4
- Detecting Rootkit Activitytespit etme (s) rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics,Votes: 0GitHub stars: 4
- Extracting Config From Agent Tesla RatExtract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.Votes: 0GitHub stars: 4
- Extracting Iocs From Malware SamplesExtracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioralVotes: 0GitHub stars: 4
- Malware TechniquesProvides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for maVotes: 0GitHub stars: 4
- Performing Automated Malware Analysis With CapeDağıt: and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.Votes: 0GitHub stars: 4
- Performing Dynamic Analysis With Any RunPerforms interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic,Votes: 0GitHub stars: 4
- Performing Firmware Malware AnalysisAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystemVotes: 0GitHub stars: 4
- Performing Malware Triage With YaraPerforms rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspiciousVotes: 0GitHub stars: 4