All authors

Claude Skills by Undermybelt
github.com/Undermybelt1,299 skills6 installs3,292 views
- Sspcs Schdld TasksHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspiciousVotes: 0GitHub stars: 9
- Ssrf Vuln ExplttTest for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,Votes: 0GitHub stars: 9
- Startup Folder PrsstnDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,Votes: 0GitHub stars: 9
- Static Malware Ana Pe St'Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine fileVotes: 0GitHub stars: 9
- Stgngr DtctnDetect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncoverVotes: 0GitHub stars: 9
- Stix Taxii Feed IntgrtSTIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)Votes: 0GitHub stars: 9
- Stix Taxii Feeds'Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-nativeVotes: 0GitHub stars: 9
- Stuxnet Style Attacks'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifyingVotes: 0GitHub stars: 9
- Supp Chai Atta Ci Cd'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinnedVotes: 0GitHub stars: 9
- Supp Chai Malw ArtfInvestigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,Votes: 0GitHub stars: 9
- Supply Chain Attack SmltSimulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,Votes: 0GitHub stars: 9
- Supply Chain CmprmsHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,Votes: 0GitHub stars: 9
- Supply Chain Sec TotoImplement software supply chain integrity verification for container builds using the in-toto framework to createVotes: 0GitHub stars: 9
- Suricata Net Mon'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules forVotes: 0GitHub stars: 9
- Syslog Cntrlz RsyslogConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. GeneratesVotes: 0GitHub stars: 9
- T1003 Crdntl Dumping EdrDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentialsVotes: 0GitHub stars: 9
- T1055 Proc Injctn SysmonDetect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injectionVotes: 0GitHub stars: 9
- T1098 Account MnpltnHunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, groupVotes: 0GitHub stars: 9
- T154 Abus Elvt Cont MchnDetect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulationVotes: 0GitHub stars: 9
- Taxii Server OpntxDeploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence usingVotes: 0GitHub stars: 9
- Tcktng System Incdnt'Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive forVotes: 0GitHub stars: 9
- Template Injctn VulnsDetecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,Votes: 0GitHub stars: 9
- Thick Client App PntrtnConduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,Votes: 0GitHub stars: 9
- Thre Acto Ttps Mitr AttaMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)Votes: 0GitHub stars: 9
- Thre Acto Ttps Mitr Nvgt'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK frameworkVotes: 0GitHub stars: 9
- Thre Hunt Hypt FrmwBuild a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, andVotes: 0GitHub stars: 9
- Thre Inte Enrc SpluBuild automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modularVotes: 0GitHub stars: 9
- Thre Mode Mitr Atta'Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,Votes: 0GitHub stars: 9
- Thre Mode Owas Thre DragUse OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,Votes: 0GitHub stars: 9
- Threat Actor Groups'Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectivesVotes: 0GitHub stars: 9
- Threat Actor Prof OsintBuild comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversaryVotes: 0GitHub stars: 9
- Threat Emltn Atomic Red'Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.Votes: 0GitHub stars: 9
- Threat Feed Aggrgt MispDeploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligenceVotes: 0GitHub stars: 9
- Threat Hunt Elastic Siem'Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and TimelineVotes: 0GitHub stars: 9
- Threat Hunt Yara Rules'Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystemsVotes: 0GitHub stars: 9
- Threat Intel Feed Intgrt'Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threatVotes: 0GitHub stars: 9
- Threat Intel Feeds'Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,Votes: 0GitHub stars: 9
- Threat Intel Lfcycl MgmtImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis,Votes: 0GitHub stars: 9
- Threat Intel MispMISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,Votes: 0GitHub stars: 9
- Threat Intel PlatformBuilding a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unifiedVotes: 0GitHub stars: 9
- Threat Intel Reports'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailoredVotes: 0GitHub stars: 9
- Threat Intel Sharing MisUse PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,Votes: 0GitHub stars: 9
- Threat Lndscp Assssm SecConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attackVotes: 0GitHub stars: 9
- Threat Lndscp MispAnalyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,Votes: 0GitHub stars: 9
- Timeline Rcnstr PlasoBuild comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems,Votes: 0GitHub stars: 9
- Tls 1 3 Sec CmmnctTLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvementsVotes: 0GitHub stars: 9
- Tls Cert Trnspr Logs'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificateVotes: 0GitHub stars: 9
- Tlscl Zero Trust VpnDeploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,Votes: 0GitHub stars: 9
- Tracking Threat ActorThreat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-controlVotes: 0GitHub stars: 9
- Type Juggling VulnsExploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumventVotes: 0GitHub stars: 9