
Claude Skills by andycungkrinx91
github.com/andycungkrinx91Standard Operating Procedures for backend development, bug fixing, DevOps, infrastructure deployment, and security hardening.
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
Monitor Certificate Transparency logs using crt.sh and Certstream to
Parse and analyze email headers to trace the origin of phishing emails,
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
'Analyzes encryption algorithms, key management, and file encryption
Monitor and analyze ransomware group data leak sites (DLS) to track victim
'Traces ransomware cryptocurrency payment flows using blockchain analysis
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
Detect typosquatting, homograph phishing, and brand impersonation domains
Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.
Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
'Auditing Kubernetes cluster RBAC configurations to identify overly permissive
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
Architect redirectors with nginx and Apache, malleable profiles, and OPSEC
Establish SAML 2.0 identity federation between on-premises Active Directory
'Builds comprehensive identity governance and lifecycle management processes
Implement a phishing report button in email clients with automated triage
'Builds a structured ransomware incident response playbook aligned with
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
'Responds to phishing incidents by analyzing reported emails, extracting
Design and execute a social engineering penetration test including phishing,
Spearphishing simulation is a targeted social engineering attack vector
'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request
Harden LDAP directory services against common attacks including credential
Configure secure OAuth 2.0 authorization flows including Authorization
Plant canarytokens and honey credentials and alert on breach.
'Deploys and monitors ransomware canary files across critical directories
'Detecting exposed AWS credentials in source code repositories, CI/CD
Business Email Compromise (BEC) is a sophisticated fraud scheme where
'Detecting compromised cloud credentials across AWS, Azure, and GCP by
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit
'Detects AI-generated deepfake audio used in voice phishing (vishing)
'Detects and responds to OAuth token theft and replay attacks in cloud
Detect and prevent QR code phishing (quishing) attacks that bypass traditional
'Detects ransomware encryption activity in real time using entropy analysis,
Spearphishing targets specific individuals using personalized, researched
Detect OS credential dumping techniques targeting LSASS memory, SAM database,
Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate
Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
Use Pacu modules for AWS privilege escalation, persistence, and backdooring.
Detecting and exploiting HTTP request smuggling vulnerabilities caused
'Exploits JWT algorithm confusion vulnerabilities where the server''s
Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract