
Claude Skills by 26zl
github.com/26zlPerform DCSync attacks to replicate Active Directory credentials and
'Conducts external reconnaissance using Open Source Intelligence (OSINT)
Plan and execute a comprehensive red team engagement covering reconnaissance
Conduct internal Active Directory reconnaissance using BloodHound Community
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen
'Responds to phishing incidents by analyzing reported emails, extracting
Design and execute a social engineering penetration test including phishing,
Plan and execute authorized vishing (voice phishing) pretext calls to
Spearphishing simulation is a targeted social engineering attack vector
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
Configure AWS Verified Access to provide VPN-less zero trust network
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy,
Hardware Security Modules (HSMs) are tamper-resistant physical devices
'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request
Harden LDAP directory services against common attacks including credential
Configure microsegmentation policies to enforce least-privilege workload-to-workload
Deploy Cisco Duo multi-factor authentication across enterprise applications,
'Designs and implements VLAN-based network segmentation on managed switches
Configure secure OAuth 2.0 authorization flows including Authorization
'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic
'Installs, configures, and tunes Snort 3 intrusion detection system to
'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets,
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security
'Configuring Zscaler Private Access (ZPA) to replace traditional VPN
Use when solving a CTF cryptography challenge — RSA, AES, classical ciphers, ECC, hash crypto, PRNGs, or unknown ciphertext. Provides a decision tree, attack catalog, and tool ordering specific to this installer's crypto module. Triggers on "ctf crypto", "rsa challenge", "aes ctr", "decrypt", "crypto category".
Use when solving CTF forensics challenges — disk images, memory dumps, PCAPs, log analysis, file carving, deleted file recovery, NTFS/ext4 artifacts. Triggers on "ctf forensics", "memory dump", "pcap analysis", "disk image", "file carving", "log forensics".
Use when solving binary exploitation / pwn CTF challenges — buffer overflows, ROP, format strings, heap, kernel pwn. Provides a decision tree, exploit primitive catalog, and uses pwntools via the run_script(venv="pwntools") MCP path. Triggers on "ctf pwn", "binary exploit", "rop", "buffer overflow", "format string", "heap challenge".
Use when solving a CTF reverse engineering challenge — stripped binaries, packed binaries, anti-debug, custom VMs, .NET/Java decomp, Android dex, obfuscated JS, ELF/PE/Mach-O analysis. Provides workflow and tool ordering from the reversing module. Triggers on "ctf rev", "reversing", "reverse engineer", "decompile", "stripped binary".
Use when solving steganography CTF challenges — hidden data in images (PNG/JPG/BMP), audio (WAV/MP3), video, or text. Triggers on "ctf stego", "steganography", "hidden in image", "audio stego", "lsb".
Use when solving a CTF web challenge — SQLi, XSS, SSRF, SSTI, IDOR, auth bypass, file upload, deserialization, prototype pollution, race conditions, JWT attacks. Provides a decision tree and tool stack from this installer's web module. Triggers on "ctf web", "web challenge", "sqli", "xss", "ssti", "ssrf", "jwt".
CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.
'Deobfuscates malicious JavaScript code used in web-based attacks, phishing
Systematically deobfuscate multi-layer PowerShell malware using AST analysis,
'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust
'Deploys canary files (honeytokens) across file systems to detect ransomware
'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust
'Deploys and monitors ransomware canary files across critical directories
Deploy a Software-Defined Perimeter using the CSA v2.0 specification
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN
'Detects prompt injection attacks targeting LLM-based applications using
'This skill covers deploying anomaly detection systems for industrial
'Detects anomalous authentication patterns using UEBA analytics, statistical
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection,
'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,
Detect unusual API call patterns in AWS CloudTrail logs using boto3,
'Detecting exposed AWS credentials in source code repositories, CI/CD
Automate AWS GuardDuty threat detection findings processing using EventBridge
Detect and investigate Azure service principal abuse including privilege
Audit Azure Blob and ADLS storage accounts for public access exposure,