All authors

Claude Skills by nexuslinkproductions
github.com/nexuslinkproductions1,031 skills11 installs2,544 views
- Cyber Auditing Azure Active Directory ConfigurationAuditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.Votes: 0GitHub stars: 2
- Cyber Auditing Cloud With Cis BenchmarksThis skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP.Votes: 0GitHub stars: 2
- Cyber Auditing Entra Id With AadinternalsRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.Votes: 0GitHub stars: 2
- Cyber Auditing Foundry Smart Contract Security>- Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and arithmetic bugs BEFORE deploying to an EVM chain. Also enforces key hygiene (no plaintext private keys,Votes: 0GitHub stars: 2
- Cyber Auditing Gcp Iam PermissionsAuditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.Votes: 0GitHub stars: 2
- Cyber Auditing Kubernetes Cluster RbacAuditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.Votes: 0GitHub stars: 2
- Cyber Auditing Kubernetes Rbac Privilege EscalationFind over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.Votes: 0GitHub stars: 2
- Cyber Auditing Mcp Servers For Tool PoisoningScan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.Votes: 0GitHub stars: 2
- Cyber Auditing Terraform Infrastructure For SecurityAuditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.Votes: 0GitHub stars: 2
- Cyber Auditing Tls Certificate Transparency LogsMonitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requestVotes: 0GitHub stars: 2
- Cyber Auditing Uefi Firmware With ChipsecUse Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.Votes: 0GitHub stars: 2
- Cyber Automating Ioc EnrichmentAutomates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated enrichment workflows integrated with SIEM alerts, email submission pipelines, or bulk IOC processing from threat feeds. Activates for requests invVotes: 0GitHub stars: 2
- Cyber Benchmarking Kubernetes With Kube BenchRun CIS Kubernetes Benchmark checks and remediate findings with kube-bench.Votes: 0GitHub stars: 2
- Cyber Building Adversary Infrastructure Tracking SystemBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.Votes: 0GitHub stars: 2
- Cyber Building Attack Pattern Library From Cti ReportsExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.Votes: 0GitHub stars: 2
- Cyber Building Automated Malware Submission PipelineBuilds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.Votes: 0GitHub stars: 2
- Cyber Building C2 Infrastructure With Sliver FrameworkBuild and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.Votes: 0GitHub stars: 2
- Cyber Building C2 Redirector InfrastructureArchitect redirectors with nginx and Apache, malleable profiles, and OPSEC for resilient C2.Votes: 0GitHub stars: 2
- Cyber Building Cloud Siem With SentinelThis skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.Votes: 0GitHub stars: 2
- Cyber Building Detection Rule With Splunk SplBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.Votes: 0GitHub stars: 2
- Cyber Building Detection Rules With SigmaBuilds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.Votes: 0GitHub stars: 2
- Cyber Building Devsecops Pipeline With Gitlab CiDesign and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.Votes: 0GitHub stars: 2
- Cyber Building Identity Federation With Saml Azure AdEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.Votes: 0GitHub stars: 2
- Cyber Building Identity Governance Lifecycle ProcessBuilds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design.Votes: 0GitHub stars: 2
- Cyber Building Incident Response DashboardBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.Votes: 0GitHub stars: 2
- Cyber Building Incident Response PlaybookDesigns and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, resVotes: 0GitHub stars: 2
- Cyber Building Incident Timeline With TimesketchBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.Votes: 0GitHub stars: 2
- Cyber Building Ioc Defanging And Sharing PipelineBuild an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.Votes: 0GitHub stars: 2
- Cyber Building Ioc Enrichment Pipeline With OpenctiOpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using OVotes: 0GitHub stars: 2
- Cyber Building Malware Incident Communication TemplateBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.Votes: 0GitHub stars: 2
- Cyber Building Patch Tuesday Response ProcessEstablish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.Votes: 0GitHub stars: 2
- Cyber Building Phishing Reporting Button WorkflowImplement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.Votes: 0GitHub stars: 2
- Cyber Bypassing Authentication With Forced Browsing[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.Votes: 0GitHub stars: 2
- Cyber Coercing Authentication With Coercer PetitpotamTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.Votes: 0GitHub stars: 2
- Cyber Collecting Indicators Of CompromiseSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, coVotes: 0GitHub stars: 2
- Cyber Collecting Open Source IntelligenceCollects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly avVotes: 0GitHub stars: 2
- Cyber Collecting Threat Intelligence With MispMISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threatVotes: 0GitHub stars: 2
- Cyber Collecting Volatile Evidence From Compromised HostCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.Votes: 0GitHub stars: 2
- Cyber Conducting Api Security TestingConducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests inVotes: 0GitHub stars: 2
- Cyber Conducting Cloud Incident ResponseResponds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Activates for requests involving cloud incident response, AWS security incident, Azure compromise, GCP breach, cloud forensics, or cloud identity compromise.Votes: 0GitHub stars: 2
- Cyber Conducting Cloud Penetration TestingThis skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK CloudVotes: 0GitHub stars: 2
- Cyber Conducting Cyber Risk Assessment With Nist 800 30>- Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a matuVotes: 0GitHub stars: 2
- Cyber Conducting Domain Persistence With DcsyncPerform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.Votes: 0GitHub stars: 2
- Cyber Conducting External Reconnaissance With OsintConducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records, certificate transparency logs, search engines, social media, code repositories, and data breach databases to build a comprehensive target profiVotes: 0GitHub stars: 2
- Cyber Conducting Full Scope Red Team EngagementPlan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.Votes: 0GitHub stars: 2
- Cyber Conducting Internal Network Penetration TestExecute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.Votes: 0GitHub stars: 2
- Cyber Conducting Internal Reconnaissance With Bloodhound CeConduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.Votes: 0GitHub stars: 2
- Cyber Conducting Malware Incident ResponseResponds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment, analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal, worm containment, malware triage, orVotes: 0GitHub stars: 2
- Cyber Conducting Man In The Middle Attack SimulationSimulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities.Votes: 0GitHub stars: 2
- Cyber Conducting Memory Forensics With VolatilityPerforms memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigatVotes: 0GitHub stars: 2