
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repoCreate forensically sound bit-for-bit disk images using dd and dcfldd
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware samples using apktool
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
Analyze advanced persistent threat (APT) group techniques using MITRE
'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
'Analyzes bootkit and advanced rootkit malware that infects the Master
Analyze Chromium-based browser artifacts using Hindsight to extract browsing
Campaign attribution analysis involves systematically evaluating evidence
Monitor Certificate Transparency logs using crt.sh and Certstream to
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage
Extract and analyze Cobalt Strike beacon configuration from PE files
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike
'Analyzes malware command-and-control (C2) communication protocols to
'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
Perform comprehensive forensic analysis of disk images using Autopsy
'Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
Investigate compromised Docker containers by analyzing images, layers,
Parse and analyze email headers to trace the origin of phishing emails,
Perform static and symbolic analysis of Solidity smart contracts using
Reverse engineer Go-compiled malware using Ghidra with specialized scripts
Detect and analyze heap spray attacks in memory dumps using Volatility3
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
'Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,
'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
Detect kernel-level rootkits in Linux memory dumps using Volatility3
Examine Linux system artifacts including auth logs, cron jobs, shell
Analyze Windows LNK shortcut files and Jump List artifacts to establish
'Analyzes malicious VBA macros embedded in Microsoft Office documents
Perform static analysis of malicious PDF documents using peepdf, pdfid,
URLScan.io is a free service for scanning and analyzing suspicious URLs.
'Executes malware samples in Cuckoo Sandbox to observe runtime behavior
Use the Malpedia platform and API to research malware family relationships,
Use Sysinternals Autoruns to systematically identify and analyze malware
Detect sandbox evasion techniques in malware samples by analyzing timing
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Analyze the NTFS Master File Table ($MFT) to recover metadata and content
Detect and analyze covert communication channels used by malware including
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Craft, send, sniff, and dissect network packets using Scapy for protocol
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
'Analyzes network traffic generated by malware during sandbox execution
'Captures and analyzes network packet data using Wireshark and tshark
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Analyze Microsoft Outlook PST and OST files for email forensic evidence
'Identifies and unpacks UPX-packed and other packed malware samples to
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to