
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repoDetect and analyze Linux persistence mechanisms including crontab entries,
Detect PowerShell Empire framework artifacts in Windows event logs by
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
Parse Windows Prefetch files to determine program execution history including
'Analyzes encryption algorithms, key management, and file encryption
Monitor and analyze ransomware group data leak sites (DLS) to track victim
Identify ransomware network indicators including C2 beaconing patterns,
'Traces ransomware cryptocurrency payment flows using blockchain analysis
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
'Leverages Splunk Enterprise Security and SPL (Search Processing Language)
Examine file system slack space, MFT entries, USN journal, and alternate
Investigate supply chain attack artifacts including trojanized software
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,
'Map advanced persistent threat (APT) group tactics, techniques, and
'Analyzes structured and unstructured threat intelligence feeds to extract
Analyze the threat landscape using MISP (Malware Information Sharing
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
Detect typosquatting, homograph phishing, and brand impersonation domains
'Analyzes UEFI bootkit persistence mechanisms including firmware implants
Investigate USB device connection history from Windows registry, event
Parse Apache and Nginx access logs to detect SQL injection attempts,
'Parses and analyzes the Windows Amcache.hve registry hive to extract
'Analyzes Windows Security, System, and Sysmon event logs in Splunk to
Parse Windows LNK shortcut files to extract target paths, timestamps,
Parse Windows Prefetch files using the windowsprefetch Python library
Extract and analyze Windows Registry hives to uncover user activity,
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing
'Systematically audit AWS S3 bucket permissions to identify publicly
'Auditing Microsoft Entra ID (Azure Active Directory) configuration to
'This skill details how to conduct cloud security audits using Center
'Auditing Google Cloud Platform IAM permissions to identify overly permissive
'Auditing Kubernetes cluster RBAC configurations to identify overly permissive
'Auditing Terraform infrastructure-as-code for security misconfigurations
'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate
'Automates the enrichment of raw indicators of compromise with multi-source
Build an automated system to track adversary infrastructure using passive
Extract and catalog attack patterns from cyber threat intelligence reports
'Builds an automated malware submission and analysis pipeline that collects
Build and configure a resilient command-and-control infrastructure using
'This skill covers deploying Microsoft Sentinel as a cloud-native SIEM
Build effective detection rules using Splunk Search Processing Language
'Builds vendor-agnostic detection rules using the Sigma rule format for
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD
Establish SAML 2.0 identity federation between on-premises Active Directory
'Builds comprehensive identity governance and lifecycle management processes
'Builds real-time incident response dashboards in Splunk, Elastic, or
'Designs and documents structured incident response playbooks that define
Build collaborative forensic incident timelines using Timesketch to ingest,
Build an automated pipeline to defang indicators of compromise (URLs,
OpenCTI is an open-source platform for managing cyber threat intelligence