All authors

Claude Skills by nuroctane
github.com/nuroctane628 skills1 installs644 views
- Reviewing Signatures Permit And Eip712Review EIP-712, permit, and custom signatures: replay, chainId, nonce, deadline, ecrecover address(0), malleability, encodePacked collisions. Use for permits, listings, votes, and bridge attestations.Votes: 0GitHub stars: 3
- Reviewing Solana ProgramsReview Solana/SVM programs: missing signer, account confusion, arbitrary CPI, PDA bumps, sysvar spoof, close/reinit, Token-2022 hooks. Use for Anchor/native programs and SVM L2s. Lawful/in-scope only.Votes: 0GitHub stars: 3
- Reviewing Token Standard PitfallsReview ERC-20/721/1155 integration footguns: fee-on-transfer, rebasing, missing return, approve race, weird decimals, ERC-777/721 hooks. Use whenever a protocol talks to arbitrary tokens.Votes: 0GitHub stars: 3
- Reviewing Upgradeable ProxiesReview upgradeable Solidity proxies (UUPS, transparent, beacon) for storage-layout clashes, unprotected initialize, missing initializer lock, and implementation suicide. Use before shipping or auditing proxies.Votes: 0GitHub stars: 3
- Reviewing With Solodit And SwcManual smart-contract review against Solodit historical findings and SWC weakness IDs by protocol type (vault, AMM, bridge, governance). Use after static analysis, before writing a contest report.Votes: 0GitHub stars: 3
- Sc ResearchRouter for whitehat smart-contract security research. Use for DeFi audits, Immunefi/Code4rena/Cantina/Sherlock contests, invariants, oracles, proxies, bridges, lending, AMMs, vaults, and responsible disclosure. Lawful/in-scope only. Never load the whole pack.Votes: 0GitHub stars: 3
- Static Analysis Slither Aderyn Semgrep WakeRun and triage Slither, Aderyn, Semgrep Solidity rules, and Wake on a Foundry/Hardhat repo. Use as the fast static layer before invariants. Complements auditing-foundry-smart-contract-security.Votes: 0GitHub stars: 3
- Triaging And Deduping FindingsDedupe and rank Slither/Aderyn/Mythril/fuzz hits: (file, line), SWC, exploitability x funds, false positives, known issues. Use before writing a contest report.Votes: 0GitHub stars: 3
- Writing Foundry Invariant HandlersWrite Foundry invariant tests with handler contracts, ghost variables, and actor rotation. Use when a vault, AMM, or any value-moving Solidity contract only has unit tests.Votes: 0GitHub stars: 3
- Acquiring Disk Image With Dd And DcflddCreate forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.Votes: 0GitHub stars: 3
- Analyzing Android Malware With ApktoolPerform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.Votes: 0GitHub stars: 3
- Analyzing Apt Group With Mitre NavigatorQuery ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.Votes: 0GitHub stars: 3
- Analyzing Bootkit And Rootkit Samples'Analyzes bootkit and advanced rootkit malware infecting the MasterVotes: 0GitHub stars: 3
- Analyzing Browser Forensics With HindsightParse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.Votes: 0GitHub stars: 3
- Analyzing Campaign Attribution EvidenceSystematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.Votes: 0GitHub stars: 3
- Analyzing Cloud Storage Access PatternsDetect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.Votes: 0GitHub stars: 3
- Analyzing Cobaltstrike Malleable C2 ProfilesParse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.Votes: 0GitHub stars: 3
- Analyzing Command And Control Communication'Analyzes malware C2 communication over HTTP, HTTPS, DNS, and customVotes: 0GitHub stars: 3
- Analyzing Disk Image With AutopsyPerform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.Votes: 0GitHub stars: 3
- Analyzing Docker Container ForensicsInvestigate compromised Docker containers by analyzing images, layers,Votes: 0GitHub stars: 3
- Analyzing Email Headers For Phishing InvestigationParse and analyze email headers (Received chain, Return-Path, Message-ID)Votes: 0GitHub stars: 3
- Analyzing Golang Malware With GhidraReverse engineer Go-compiled malware in Ghidra by parsing Go buildinfoVotes: 0GitHub stars: 3
- Analyzing Kubernetes Audit LogsParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rule...Votes: 0GitHub stars: 3
- Analyzing Linux Elf Malware'Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,Votes: 0GitHub stars: 3
- Analyzing Linux Kernel RootkitsDetect kernel-level rootkits in Linux memory dumps using Volatility3Votes: 0GitHub stars: 3
- Analyzing Linux System ArtifactsExamine Linux system artifacts (auth logs, cron/systemd persistence,Votes: 0GitHub stars: 3
- Analyzing Lnk File And Jump List ArtifactsAnalyze Windows LNK shortcut files and Jump List artifacts with LECmd,Votes: 0GitHub stars: 3
- Analyzing Malicious Pdf With PeepdfPerform static analysis of malicious PDF documents using peepdf, pdfid,Votes: 0GitHub stars: 3
- Analyzing Malware Behavior With Cuckoo Sandbox'Detonate malware samples in Cuckoo Sandbox to observe runtime behaviorVotes: 0GitHub stars: 3
- Analyzing Malware Family Relationships With MalpediaQuery the Malpedia API to look up malware family aliases and namingVotes: 0GitHub stars: 3
- Analyzing Malware Persistence With AutorunsUse Sysinternals Autoruns to systematically enumerate and analyze malwareVotes: 0GitHub stars: 3
- Analyzing Malware Sandbox Evasion TechniquesDetect sandbox and VM evasion techniques in malware samples by analyzingVotes: 0GitHub stars: 3
- Analyzing Mft For Deleted File RecoveryAnalyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,Votes: 0GitHub stars: 3
- Analyzing Network Covert Channels In MalwareDetect and analyze covert communication channels used by malware, includingVotes: 0GitHub stars: 3
- Analyzing Network Packets With ScapyUse Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.Votes: 0GitHub stars: 3
- Analyzing Outlook Pst For Email ForensicsParse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.Votes: 0GitHub stars: 3
- Analyzing Packed Malware With Upx Unpacker'Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or when preparing a packed binary for disassembly in Ghidra or IDA.Votes: 0GitHub stars: 3
- Analyzing Persistence Mechanisms In LinuxScan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.Votes: 0GitHub stars: 3
- Analyzing Powershell Empire ArtifactsDetect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.Votes: 0GitHub stars: 3
- Analyzing Prefetch Files For Execution HistoryParse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.Votes: 0GitHub stars: 3
- Analyzing Ransomware Leak Site IntelligenceSafely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or building proactive defense reporting from double-extortion leak-site activity.Votes: 0GitHub stars: 3
- Analyzing Ransomware Network IndicatorsIdentify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.Votes: 0GitHub stars: 3
- Analyzing Ransomware Payment Wallets'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.Votes: 0GitHub stars: 3
- Analyzing Sbom For Supply Chain Vulnerabilities'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSONVotes: 0GitHub stars: 3
- Analyzing Slack Space And File System ArtifactsExamine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.Votes: 0GitHub stars: 3
- Analyzing Supply Chain Malware ArtifactsInvestigate supply chain attack artifacts including trojanized softwareVotes: 0GitHub stars: 3
- Analyzing Threat Actor Ttps With Mitre AttackSystematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.Votes: 0GitHub stars: 3
- Analyzing Threat Actor Ttps With Mitre Navigator'Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group''s techniques, building Navigator coverage heatmaps, or assessing technique coverage gaps against a specific threat actor.Votes: 0GitHub stars: 3
- Analyzing Threat Landscape With MispQuery a MISP (Malware Information Sharing Platform) instance via PyMISPVotes: 0GitHub stars: 3
- Analyzing Typosquatting Domains With DnstwistGenerate domain permutations with dnstwist and check DNS resolutionVotes: 0GitHub stars: 3