All authors
andycungkrinx91 avatar

Claude Skills by andycungkrinx91

github.com/andycungkrinx91
695 skillsA× 563B× 84C× 24D× 18F× 60 installs5 views
Anbu SkillB

Standard Operating Procedures for backend development, bug fixing, DevOps, infrastructure deployment, and security hardening.

devopspythonrust
0
9
Abusing Dpapi For Credential AccessA

Extract DPAPI-protected secrets such as credentials and browser data offline and online.

securitypythongo
0
9
Abusing Shadow Credentials For PrivescA

Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.

securitypythonrust
0
9
Analyzing Certificate Transparency For PhishingA

Monitor Certificate Transparency logs using crt.sh and Certstream to

devopspythonrust
0
9
Analyzing Email Headers For Phishing InvestigationB

Parse and analyze email headers to trace the origin of phishing emails,

developmentjavascriptpython
0
9
Analyzing Indicators Of CompromiseA

'Analyzes indicators of compromise (IOCs) including IP addresses, domains,

devopspythonrust
0
9
Analyzing Linux Elf MalwareC

'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries

devopspythongo
0
9
Analyzing Ransomware Encryption MechanismsA

'Analyzes encryption algorithms, key management, and file encryption

businesspythongo
0
9
Analyzing Ransomware Leak Site IntelligenceA

Monitor and analyze ransomware group data leak sites (DLS) to track victim

securitypythongit
0
9
Analyzing Ransomware Payment WalletsA

'Traces ransomware cryptocurrency payment flows using blockchain analysis

blockchainpythonreact
0
9
Analyzing Tls Certificate Transparency LogsA

'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect

devopspythontesting
0
9
Analyzing Typosquatting Domains With DnstwistA

Detect typosquatting, homograph phishing, and brand impersonation domains

devopspythongo
0
9
Attacking Entra Id With RoadtoolsA

Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.

securitypythonbash
0
9
Attacking Oauth With Device Code PhishingB

Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.

securitypythonrust
0
9
Auditing Entra Id With AadinternalsA

Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.

securityrustgo
0
9
Auditing Kubernetes Cluster RbacB

'Auditing Kubernetes cluster RBAC configurations to identify overly permissive

devopspythonbash
0
9
Auditing Kubernetes Rbac Privilege EscalationC

Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.

securitygobash
0
9
Benchmarking Kubernetes With Kube BenchA

Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.

devopsgobash
0
9
Building C2 Redirector InfrastructureA

Architect redirectors with nginx and Apache, malleable profiles, and OPSEC

devopspythonrust
0
9
Building Identity Federation With Saml Azure AdA

Establish SAML 2.0 identity federation between on-premises Active Directory

devopsrustshell
0
9
Building Identity Governance Lifecycle ProcessA

'Builds comprehensive identity governance and lifecycle management processes

securitypythonrust
0
9
Building Phishing Reporting Button WorkflowA

Implement a phishing report button in email clients with automated triage

devopsrustgo
0
9
Building Ransomware Playbook With Cisa FrameworkA

'Builds a structured ransomware incident response playbook aligned with

securitypythongo
0
9
Coercing Authentication With Coercer PetitpotamA

Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.

securitypythonbash
0
9
Conducting Phishing Incident ResponseA

'Responds to phishing incidents by analyzing reported emails, extracting

securityrustgo
0
9
Conducting Social Engineering Penetration TestA

Design and execute a social engineering penetration test including phishing,

securityrustgo
0
9
Conducting Spearphishing Simulation CampaignA

Spearphishing simulation is a targeted social engineering attack vector

devopspythongo
0
9
Configuring Identity Aware Proxy With Google IapA

'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request

securitypythonrust
0
9
Configuring Ldap Security HardeningA

Harden LDAP directory services against common attacks including credential

securitypythontesting
0
9
Configuring Oauth2 Authorization FlowA

Configure secure OAuth 2.0 authorization flows including Authorization

securitypythontesting
0
9
Deploying Honeytokens And CanarytokensF

Plant canarytokens and honey credentials and alert on breach.

devopspythonrust
0
9
Deploying Ransomware Canary FilesA

'Deploys and monitors ransomware canary files across critical directories

businesspythontesting
0
9
Detecting Aws Credential Exposure With TrufflehogD

'Detecting exposed AWS credentials in source code repositories, CI/CD

devopspythongo
0
9
Detecting Business Email CompromiseA

Business Email Compromise (BEC) is a sophisticated fraud scheme where

businessrustgo
0
9
Detecting Compromised Cloud CredentialsA

'Detecting compromised cloud credentials across AWS, Azure, and GCP by

developmentpythonrust
0
9
Detecting Container Runtime Threats With FalcoD

Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.

devopsshellbash
0
9
Detecting Credential Dumping TechniquesA

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit

securitypythondatabase
0
9
Detecting Deepfake Audio In Vishing AttacksA

'Detects AI-generated deepfake audio used in voice phishing (vishing)

businesspythongo
0
9
Detecting Oauth Token TheftA

'Detects and responds to OAuth token theft and replay attacks in cloud

securityrustgo
0
9
Detecting Qr Code Phishing With Email SecurityA

Detect and prevent QR code phishing (quishing) attacks that bypass traditional

developmentrustgo
0
9
Detecting Ransomware Encryption BehaviorA

'Detects ransomware encryption activity in real time using entropy analysis,

devopspythonshell
0
9
Detecting Spearphishing With Email GatewayA

Spearphishing targets specific individuals using personalized, researched

securityrustsecurity
0
9
Detecting T1003 Credential Dumping With EdrA

Detect OS credential dumping techniques targeting LSASS memory, SAM database,

securitygogit
0
9
Emulating Cloud Attacks With Stratus Red TeamB

Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate

devopspythongo
0
9
Escaping Containers To HostD

Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.

securityshellbash
0
9
Exploiting Adcs With CertipyA

Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.

securitypythongo
0
9
Exploiting Aws With PacuC

Use Pacu modules for AWS privilege escalation, persistence, and backdooring.

securitypythonrust
0
9
Exploiting Http Request SmugglingA

Detecting and exploiting HTTP request smuggling vulnerabilities caused

securitypythongo
0
9
Exploiting Jwt Algorithm Confusion AttackB

'Exploits JWT algorithm confusion vulnerabilities where the server''s

securitypythonrust
0
9
Exploiting Kerberoasting With ImpacketA

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract

securityshellbash
0
9