
Claude Skills by andycungkrinx91
github.com/andycungkrinx91Deploy privileged access management for database systems including Oracle,
'Implements passwordless authentication using Microsoft Entra ID with
Deploy CyberArk Privileged Access Management to discover, vault, rotate,
'Designs and implements a ransomware-resilient backup strategy following
'Detects and exploits ransomware kill switch mechanisms including mutex-based
Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider
Implement automated user provisioning and deprovisioning using SCIM 2.0
Automate phishing incident response using Splunk SOAR REST API to create
Implement HashiCorp Boundary for identity-aware zero trust infrastructure
Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, and offboard securely. Use when an organization needs to assess a new vendor before onboarding, when st...
Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
Inventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
Use NetExec for SMB, WinRM, LDAP, and MSSQL enumeration, password spraying,
Deploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary emulation.
Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
Run MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
Configure and execute access recertification campaigns in Saviynt Enterprise
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks
'Performs entitlement review and access certification campaigns using
'Performs OAuth 2.0 scope minimization review to identify over-permissioned
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials,
GoPhish is an open-source phishing simulation framework used by security
'Executes a structured ransomware incident response from initial detection
'Plans and facilitates tabletop exercises simulating ransomware incidents
Automate GoPhish phishing simulation campaigns using the Python gophish
Automate credential rotation for service accounts across Active Directory,
Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
'Executes structured recovery from a ransomware incident following NIST
Run ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
Reverse engineer ransomware encryption routines to identify cryptographic
Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
'This skill guides practitioners through hardening AWS Identity and Access
Test and validate ransomware recovery procedures including backup restore
Threat actor infrastructure tracking involves monitoring and mapping
Run targeted forensic artifact collection and module parsing with KAPE.
Validate backup integrity through cryptographic hash verification, automated
Standard Operating Procedures for web research, documentation lookup, evidence synthesis with citations.
Standard Operating Procedures for read-only codebase exploration, symbol search, dependency mapping, code tracing, code review, architecture analysis, technical research, source evaluation, and evidence-based reporting.
Standard Operating Procedures and router for premium UI development, design match comparison, component architecture, and 3D web experiences.
Standard Operating Procedures for architecture decisions, security audits, deep code analysis, risk assessment, and critical problem solving.
Use when the user requests diagrams, flowcharts, architecture diagrams, ER diagrams, UML / sequence / class diagrams, SysML / MBSE diagrams (block definition, internal block, requirement, parametric), BPMN business process diagrams, swimlane / cross-functional flowcharts, network topology, cloud architecture from Terraform or Kubernetes manifests, ML/DL model figures (Transformer/CNN/LSTM), mind maps, or any visualization. Also use proactively when explaining systems with 3+ components, compl...
Guidelines and instructions for maintaining, extending, and debugging the Konoha MCP Tools Orchestrator, MCP middleware, and multi-archetype website builder across 7 coding clients (Antigravity IDE/CLI, Cursor, Claude Code, OpenCode, Command Code, Codex, Pi/pi.dev).
Standard Operating Procedures and router for MCP task triage, subagent selection, and orchestration.
Standard Operating Procedures for technical writing, README creation, API specifications, runbooks, and documentation updates.
Standard Operating Procedures for backend development, bug fixing, DevOps, infrastructure deployment, and security hardening.
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
Monitor Certificate Transparency logs using crt.sh and Certstream to
Parse and analyze email headers to trace the origin of phishing emails,