
Claude Skills by andycungkrinx91
github.com/andycungkrinx91Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit
'Detects AI-generated deepfake audio used in voice phishing (vishing)
'Detects and responds to OAuth token theft and replay attacks in cloud
Detect and prevent QR code phishing (quishing) attacks that bypass traditional
'Detects ransomware encryption activity in real time using entropy analysis,
Spearphishing targets specific individuals using personalized, researched
Detect OS credential dumping techniques targeting LSASS memory, SAM database,
Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate
Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
Use Pacu modules for AWS privilege escalation, persistence, and backdooring.
Detecting and exploiting HTTP request smuggling vulnerabilities caused
'Exploits JWT algorithm confusion vulnerabilities where the server''s
Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract
MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB,
Detect and exploit JavaScript prototype pollution vulnerabilities on
Detect and exploit race condition vulnerabilities in web applications
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote
Extract cached credentials, password hashes, Kerberos tickets, and authentication
Produce Sigma-based EVTX timelines and summaries with Hayabusa.
Detect Cobalt Strike beacon network activity using default TLS certificate
Hunt for data exfiltration through network traffic analysis, detecting
Security awareness training is the human layer of phishing defense. An
'Configures Windows Group Policy Objects (GPO) to prevent ransomware
Configure Microsoft Entra Privileged Identity Management to enforce just-in-time
'Implements Delinea Secret Server for privileged access management (PAM)
'Implements comprehensive Google Workspace security hardening including
Configure Google Workspace advanced phishing and malware protection settings
Configure SAML 2.0 single sign-on for Google Workspace with a third-party
'Implements HashiCorp Vault dynamic secrets engines for database credentials,
Deploy SailPoint IdentityNow or IdentityIQ for identity governance and
Implement continuous identity verification for zero trust using phishing-resistant
Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment
Deploy privileged access management for database systems including Oracle,
'Implements passwordless authentication using Microsoft Entra ID with
Deploy CyberArk Privileged Access Management to discover, vault, rotate,
'Designs and implements a ransomware-resilient backup strategy following
'Detects and exploits ransomware kill switch mechanisms including mutex-based
Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider
Implement automated user provisioning and deprovisioning using SCIM 2.0
Automate phishing incident response using Splunk SOAR REST API to create
Implement HashiCorp Boundary for identity-aware zero trust infrastructure
Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, and offboard securely. Use when an organization needs to assess a new vendor before onboarding, when st...
Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
Inventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
Use NetExec for SMB, WinRM, LDAP, and MSSQL enumeration, password spraying,
Deploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary emulation.