All authors
costrict-plugins-repo avatar

Claude Skills by costrict-plugins-repo

github.com/costrict-plugins-repo
818 skillsA× 697B× 83C× 17D× 12F× 90 installs64 views
Implementing Patch Management WorkflowA

Patch management is the systematic process of identifying, testing, deploying,

devopspythongo
0
67
Implementing Pci Dss Compliance ControlsA

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives

securitygotesting
0
67
Implementing Pod Security Admission ControllerA

Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via AdmissionConfiguration, exemptions for usernames, runtime classes and namespaces, version pinning, and troubleshooting pods the controller rejected. Use when wiring PSA up on a cluster, setting cluster-wide default enforcement, exempting system namespaces, debugging why a pod was rejected or why enforcement is not f...

devopsbashnode
0
67
Implementing Policy As Code With Open Policy AgentA

'Implements policy-as-code enforcement with Open Policy Agent (OPA)

devopsgobash
0
67
Implementing Privileged Access Management With CyberarkA

Deploy CyberArk Privileged Access Management to discover, vault, rotate,

securitypythonsql
0
67
Implementing Privileged Access WorkstationA

Design and implement Privileged Access Workstations (PAWs) using the

securitypythonrust
0
67
Implementing Privileged Session MonitoringD

'Implements privileged session monitoring and recording using PAM

securitypythonshell
0
67
Implementing Proofpoint Email Security GatewayA

Deploy and configure Proofpoint Email Protection as a secure email gateway

securitygotesting
0
67
Implementing Purdue Model Network SegmentationA

'Implement network segmentation based on the Purdue Enterprise Reference

businesspythonrust
0
67
Implementing Ransomware Backup StrategyA

'Designs a ransomware-resilient backup strategy using the 3-2-1-1-0

devopsrustgo
0
67
Implementing Ransomware Kill Switch DetectionA

'Analyzes ransomware kill switch mechanisms, including mutex-based execution

devopspythongo
0
67
Implementing Rapid7 Insightvm For ScanningA

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines,

securitypythonshell
0
67
Implementing Rbac Hardening For KubernetesA

Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC identity provider. Use when tightening cluster access control, removing excessive ClusterRoleBindings, or hardening service-account permissions against escalation and lateral movement. Keywords: RBAC, Role, ClusterRole, RoleBinding, least privilege, service account, OIDC, cluster-admin. Do not use fo...

securitygobash
0
67
Implementing Rsa Key Pair ManagementA

Generates, stores, rotates, and manages RSA key pairs following NIST

securitypythongo
0
67
Implementing Runtime Application Self ProtectionA

Deploy Runtime Application Self-Protection (RASP) agents to detect and

securitypythongo
0
67
Implementing Runtime Security With TetragonB

Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage...

devopsgobash
0
67
Implementing Saml Sso With OktaA

Implement SAML 2.0 Single Sign-On using Okta as the Identity Provider,

securitypythongo
0
67
Implementing Scim Provisioning With OktaA

Implement automated user lifecycle provisioning and deprovisioning using

securitypythonreact
0
67
Implementing Secret Scanning With GitleaksA

'This skill covers implementing Gitleaks for detecting and preventing

devopspythongo
0
67
Implementing Secrets Management With VaultB

'Deploy HashiCorp Vault for centralized secrets management, covering dynamic

devopsrustbash
0
67
Implementing Secrets Scanning In Ci CdA

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked

devopspythongit
0
67
Implementing Security Chaos EngineeringA

'Implements security chaos engineering experiments that deliberately

testingpythontesting
0
67
Implementing Security Information Sharing With Stix2A

'Create, validate, and share STIX 2.1 threat intelligence objects (indicators,

testingpythongo
0
67
Implementing Security Monitoring With DatadogB

'Implements security monitoring using Datadog Cloud SIEM, Cloud Security

devopspythongo
0
67
Implementing Semgrep For Custom Sast RulesA

Write custom Semgrep SAST rules in YAML to detect application-specific

devopsjavascripttypescript
0
67
Implementing Siem Correlation Rules For AptA

Write multi-event correlation rules in Splunk SPL and Sigma format that

securitypythongo
0
67
Implementing Siem Use Case TuningA

Tune SIEM detection rules in Splunk and Elastic to reduce false positives

businesspythongo
0
67
Implementing Siem Use Cases For DetectionA

'Implements SIEM detection use cases by designing correlation rules,

devopspythongo
0
67
Implementing Sigstore For Software SigningA

'Implements Sigstore-based software signing and verification using Cosign

devopspythonrust
0
67
Implementing Soar Automation With PhantomA

'Implements Security Orchestration, Automation, and Response (SOAR) workflows

securitypythonrust
0
67
Implementing Soar Playbook For PhishingA

Automates phishing incident response by calling the Splunk SOAR (Phantom)

toolspythonapi
0
67
Implementing Soar Playbook With Palo Alto XsoarA

Build automated incident response playbooks in Cortex XSOAR (Demisto)

devopsjavascriptpython
0
67
Implementing Stix Taxii Feed IntegrationA

Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and

securitypythonrust
0
67
Implementing Supply Chain Security With In TotoA

Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadata, verifying before deployment, enforcing at Kubernetes admission, and integrating with SLSA. Use when attesting CI/CD pipeline steps, proving an image followed the approved build process, or enforcing provenance at admission. Keywords: in-toto, layout, link metadata, step, inspection, SLSA, prov...

devopspythongo
0
67
Implementing Syslog Centralization With RsyslogA

Configure rsyslog for centralized log collection with TLS encryption,

securitypythonbash
0
67
Implementing Taxii Server With OpentaxiiA

Deploy and configure a TAXII 2.1 server (Medallion) with Docker, publish

devopspythonrust
0
67
Implementing Threat Intelligence Lifecycle ManagementA

Build out a full CTI program around the six-phase threat intelligence

securitypythongo
0
67
Implementing Threat Modeling With Mitre AttackA

'Implements threat modeling using the MITRE ATT&CK framework to map adversary

businesspythonshell
0
67
Implementing Ticketing System For IncidentsA

'Implements an integrated incident ticketing system connecting SIEM alerts

securitypythongo
0
67
Implementing Usb Device Control PolicyA

'Implements USB device control policies to restrict unauthorized removable

devopsgoshell
0
67
Implementing Velociraptor For Ir CollectionA

Deploy and configure Velociraptor for scalable endpoint forensic artifact

devopspythongo
0
67
Implementing Vulnerability Management With GreenboneA

Deploy and operate Greenbone/OpenVAS vulnerability management using the

securitypythonapi
0
67
Implementing Vulnerability Remediation SlaA

Design a vulnerability remediation SLA program covering asset tiering,

businesspythongo
0
67
Implementing Vulnerability Sla Breach AlertingA

Build an automated SLA breach alerting system for vulnerability remediation,

databasespythongo
0
67
Implementing Web Application Logging With ModsecurityA

Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web

devopssqlsecurity
0
67
Implementing Zero Knowledge Proof For AuthenticationA

Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.

securitypythontesting
0
67
Implementing Zero Standing Privilege With CyberarkA

Deploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.

devopsrustgo
0
67
Implementing Zero Trust Dns With NextdnsB

Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME cloaking, and enforces organizational DNS policy across endpoints. Use when deploying DNS-layer threat blocking and acceptable-use enforcement, or when extending zero trust controls (including Windows 11 Zero Trust DNS) to the DNS resolution path.

devopsrustgo
0
67
Implementing Zero Trust For Saas ApplicationsA

Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity verification and device compliance. Use when adding MFA/device-compliance conditional access, discovering shadow IT, governing OAuth consent grants, or applying session controls to sensitive SaaS data.

devopsrustgo
0
67
Implementing Zero Trust In CloudA

Guides zero trust implementation across AWS, Azure, and GCP per NIST SP 800-207 and BeyondCorp principles, covering identity-centric access, micro-segmentation, continuous verification, device trust assessment, and Identity-Aware Proxy deployment. Use when migrating from perimeter security to identity-centric access, removing VPN dependency, or designing micro-segmentation for multi-cloud workloads.

securityrustgo
0
67