All authors
26zl avatar

Claude Skills by 26zl

github.com/26zl
48 skillsA× 40B× 5C× 1D× 21 installs297 views
Configuring Windows Event Logging For DetectionA

'Configures Windows Event Logging with advanced audit policies to generate

ai-agentsgoshell
0
12
Configuring Zscaler Private Access For ZtnaB

'Configuring Zscaler Private Access (ZPA) to replace traditional VPN

securityrustbash
0
12
Containing Active BreachA

'Executes containment strategies to stop active adversary operations

securitygoshell
0
12
Correlating Security Events In QradarA

'Correlates security events in IBM QRadar SIEM using AQL (Ariel Query

ai-agentsgobash
0
12
Correlating Threat CampaignsA

'Correlates disparate security incidents, IOCs, and adversary behaviors

ai-agentspythongo
0
12
Ctf CryptoA

Use when solving a CTF cryptography challenge — RSA, AES, classical ciphers, ECC, hash crypto, PRNGs, or unknown ciphertext. Provides a decision tree, attack catalog, and tool ordering specific to this installer's crypto module. Triggers on "ctf crypto", "rsa challenge", "aes ctr", "decrypt", "crypto category".

ai-agentspythongo
0
12
Ctf ForensicsA

Use when solving CTF forensics challenges — disk images, memory dumps, PCAPs, log analysis, file carving, deleted file recovery, NTFS/ext4 artifacts. Triggers on "ctf forensics", "memory dump", "pcap analysis", "disk image", "file carving", "log forensics".

ai-agentspythongo
0
12
Ctf PwnA

Use when solving binary exploitation / pwn CTF challenges — buffer overflows, ROP, format strings, heap, kernel pwn. Provides a decision tree, exploit primitive catalog, and uses pwntools via the run_script(venv="pwntools") MCP path. Triggers on "ctf pwn", "binary exploit", "rop", "buffer overflow", "format string", "heap challenge".

ai-agentspythongo
0
12
Ctf RevA

Use when solving a CTF reverse engineering challenge — stripped binaries, packed binaries, anti-debug, custom VMs, .NET/Java decomp, Android dex, obfuscated JS, ELF/PE/Mach-O analysis. Provides workflow and tool ordering from the reversing module. Triggers on "ctf rev", "reversing", "reverse engineer", "decompile", "stripped binary".

ai-agentspythonrust
0
12
Ctf StegoA

Use when solving steganography CTF challenges — hidden data in images (PNG/JPG/BMP), audio (WAV/MP3), video, or text. Triggers on "ctf stego", "steganography", "hidden in image", "audio stego", "lsb".

ai-agentspythongo
0
12
Ctf WebB

Use when solving a CTF web challenge — SQLi, XSS, SSRF, SSTI, IDOR, auth bypass, file upload, deserialization, prototype pollution, race conditions, JWT attacks. Provides a decision tree and tool stack from this installer's web module. Triggers on "ctf web", "web challenge", "sqli", "xss", "ssti", "ssrf", "jwt".

ai-agentsgojava
0
12
Cve Poc GeneratorA

CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.

ai-agentspythongit
0
12
Deobfuscating Javascript MalwareA

'Deobfuscates malicious JavaScript code used in web-based attacks, phishing

ai-agentsjavascriptpython
0
12
Deobfuscating Powershell Obfuscated MalwareA

Systematically deobfuscate multi-layer PowerShell malware using AST analysis,

ai-agentspythonshell
0
12
Deploying Active Directory HoneytokensA

'Deploys deception-based honeytokens in Active Directory including fake

securitypythongo
0
12
Deploying Cloudflare Access For Zero TrustB

'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust

securityrustgo
0
12
Deploying Decoy Files For Ransomware DetectionA

'Deploys canary files (honeytokens) across file systems to detect ransomware

ai-agentspythongo
0
12
Deploying Edr Agent With CrowdstrikeB

'Deploys and configures CrowdStrike Falcon EDR agents across enterprise

ai-agentsgoshell
0
12
Deploying Osquery For Endpoint MonitoringA

'Deploys and configures osquery for real-time endpoint monitoring using

securityrustgo
0
12
Deploying Palo Alto Prisma Access Zero TrustA

'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust

ai-agentsrustgo
0
12
Deploying Ransomware Canary FilesA

'Deploys and monitors ransomware canary files across critical directories

ai-agentspythontesting
0
12
Deploying Software Defined PerimeterA

Deploy a Software-Defined Perimeter using the CSA v2.0 specification

securitypythonrust
0
12
Deploying Tailscale For Zero Trust VpnD

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN

securityrustgo
0
12
Detecting Ai Model Prompt Injection AttacksC

'Detects prompt injection attacks targeting LLM-based applications using

ai-agentspythongo
0
12
Detecting Anomalies In Industrial Control SystemsA

'This skill covers deploying anomaly detection systems for industrial

ai-agentspythongo
0
12
Detecting Anomalous Authentication PatternsA

'Detects anomalous authentication patterns using UEBA analytics, statistical

ai-agentspythongo
0
12
Detecting Api Enumeration AttacksA

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation

securitypythonaws
0
12
Detecting Arp Poisoning In Network TrafficB

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection,

ai-agentspythonrust
0
12
Detecting Attacks On Historian ServersA

'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,

securitypythongo
0
12
Detecting Attacks On Scada SystemsA

'This skill covers detecting cyber attacks targeting Supervisory Control

securitypythongo
0
12
Detecting Aws Cloudtrail AnomaliesA

Detect unusual API call patterns in AWS CloudTrail logs using boto3,

ai-agentspythonaws
0
12
Detecting Aws Credential Exposure With TrufflehogD

'Detecting exposed AWS credentials in source code repositories, CI/CD

securitypythongo
0
12
Detecting Aws Guardduty Findings AutomationA

Automate AWS GuardDuty threat detection findings processing using EventBridge

ai-agentspythongo
0
12
Detecting Aws Iam Privilege EscalationA

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining

ai-agentspythonaws
0
12
Detecting Azure Lateral MovementA

Detect lateral movement in Azure AD/Entra ID environments using Microsoft

ai-agentsazureapi
0
12
Detecting Azure Service Principal AbuseA

Detect and investigate Azure service principal abuse including privilege

securityshellazure
0
12
Detecting Azure Storage Account MisconfigurationsA

Audit Azure Blob and ADLS storage accounts for public access exposure,

ai-agentspythonazure
0
12
Detecting Beaconing Patterns With ZeekA

'Performs statistical analysis of Zeek conn.log connection intervals

ai-agentspythontesting
0
12
Detecting Bluetooth Low Energy AttacksA

'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including

securitypythongo
0
12
Detecting Broken Object Property Level AuthorizationA

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization

securitypythontesting
0
12
Sap Erp Security AssessmentA

Use for SAP and ERP security assessments, S/4HANA, NetWeaver, ABAP, HANA DB, RFC trust, SAP Gateway, ICM, transports, default users, authorization roles, SoD, patching, and business-critical ERP control review.

ai-agentsrustrails
0
11
Semgrep Rule CreatorA

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

ai-agentspythonrust
0
11
Insecure DefaultsA

Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.

securitygobash
0
7
Iot Embedded Hardware Security AssessmentA

Use for IoT, embedded, firmware, hardware security, UART/JTAG/SWD, bootloader, secure boot, OTA update, radio protocol, device cloud, mobile companion app, and embedded Linux assessment work.

securityrailstesting
0
7
Karpathy GuidelinesA

Behavioral coding-agent guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.

ai-agentsgorefactoring
0
7
Mainframe Security AssessmentA

Use for mainframe, z/OS, RACF, ACF2, Top Secret, CICS, IMS, DB2, JCL, JES, APF libraries, USS, TN3270, privileged dataset, and legacy enterprise security assessment work.

securityrailstesting
0
7
Mcp Sync CheckA

Use when the MCP server may be out of sync with bash sources after editing tools_db.py, profiles.py, lib/common.sh MODULE_DESCRIPTIONS, lib/installers.sh ALL_DOCKER_IMAGES, or scripts/verify.sh _PIPX_BIN_NAMES. Triggers on "check mcp sync", "validate mcp", "is the python in sync".

ai-agentspythonbash
0
7
Module ScaffoldA

Use when creating a brand new module file in modules/ for a new tool category. Generates the boilerplate with correct array prefix, install_module_<name>() function, and ensures it integrates with install.sh, profiles, and MCP server. Triggers on "new module", "add a module for X", "scaffold module".

ai-agentspythongo
0
7