
Claude Skills by 26zl
github.com/26zl'Perform coverage-guided fuzzing of compiled binaries using AFL++ (American
Perform GCP security testing using GCPBucketBrute for storage bucket
'Performs GraphQL introspection attacks to extract the full API schema
Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for
Hash cracking is an essential skill for penetration testers and security
Execute HTTP Parameter Pollution attacks to bypass input validation,
'Perform comprehensive ICS/OT asset discovery using Claroty xDome platform,
Indicator lifecycle management tracks IOCs from initial discovery through
Perform authorized initial access using EvilGinx3 adversary-in-the-middle
'Investigates insider threat incidents involving employees, contractors,
Execute and test the JWT none algorithm attack to bypass signature verification
Kerberoasting is a post-exploitation technique that targets service accounts
Use for SAP and ERP security assessments, S/4HANA, NetWeaver, ABAP, HANA DB, RFC trust, SAP Gateway, ICM, transports, default users, authorization roles, SoD, patching, and business-critical ERP control review.
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
Use when adding a new cybersecurity tool to this installer. Walks through editing the right module file, adding to tools_config.json, running validators, and syncing MCP server data if needed. Triggers on phrases like "add tool", "add <toolname>", "register a new tool", "include X in the installer".
Use for AI/LLM security assessments, prompt injection, RAG security, agent/tool permissioning, model supply chain, LLM red teaming, AI governance, eval design, data leakage, jailbreak testing, and secure AI application review.
Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,
'Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that
'Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,
Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record
Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and
'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,
Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract security.
Use when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".
Use when bug-bountying an Android (APK) or iOS (IPA) app. Covers static + dynamic analysis, Frida hooking, certificate pinning bypass, deep link / intent abuse, IPC, secrets in bundles. Triggers on "bounty mobile", "android app", "ios app", "apk analysis", "frida".
Use at the start of a bug bounty engagement. Provides scope-aware recon methodology — passive enumeration, subdomain discovery, asset attribution, tech stack fingerprinting, content discovery. Respects scope and program rules. Triggers on "bounty recon", "subdomain enum", "attack surface map", "h1 recon", "bug bounty start".
Use during the testing phase of a web application bug bounty. Provides OWASP-aligned attack catalog, payload sources, and tool ordering for SQLi, XSS, SSRF, SSTI, IDOR, auth, race conditions, file upload, deserialization. Triggers on "bounty web", "test this app", "web app testing", "h1 web target".
Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with
'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,
Apply bottom-up and top-down role mining techniques to discover optimal
Build a structured SOC escalation matrix defining severity tiers, response
'Builds a structured SOC incident response playbook for ransomware attacks
Build comprehensive threat actor profiles using open-source intelligence
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate,
Build a systematic threat hunt hypothesis framework that transforms threat
Build automated threat intelligence enrichment pipelines in Splunk Enterprise
Building a Threat Intelligence Platform (TIP) involves deploying and
Implement a vulnerability aging dashboard and SLA tracking system to
Deploy DefectDojo as a centralized vulnerability management dashboard
Build a vulnerability exception and risk acceptance tracking system with
Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.
MISP (Malware Information Sharing Platform) is an open-source threat
Collect volatile forensic evidence from a compromised system following