
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repo'Perform security analysis of Siemens S7comm and S7CommPlus protocols
'This skill covers implementing Software Composition Analysis (SCA) using
'Perform security assessments of SCADA Human-Machine Interface (HMI)
Detect and exploit second-order SQL injection vulnerabilities where malicious
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options,
'Performing security reviews of serverless functions across AWS Lambda,
Audit service accounts across enterprise infrastructure to identify orphaned,
Automate credential rotation for service accounts across Active Directory,
Perform security testing of SOAP web services by analyzing WSDL definitions
'Performs tabletop exercises for SOC teams simulating security incidents
'Automates SOC 2 Type II audit preparation including gap assessment against
Perform forensic analysis of SQLite databases to recover deleted records
SSL/TLS certificate lifecycle management encompasses the full process
'Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy
Configure SSL/TLS inspection on network security devices to decrypt,
Assess SSL/TLS server configurations using the sslyze Python library
Test for Server-Side Request Forgery vulnerabilities by probing cloud
'Performs static analysis of Windows PE (Portable Executable) malware
Detect and extract hidden data embedded in images, audio, and other media
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder
Simulate and detect software supply chain attacks including typosquatting
Conduct a thick client application penetration test to identify insecure
'Executes Atomic Red Team tests for MITRE ATT&CK technique validation
'Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL
'Use YARA pattern-matching rules to hunt for malware, suspicious files,
Use PyMISP to create, enrich, and share threat intelligence events on
Conduct a sector-specific threat landscape assessment by analyzing threat
Use OWASP Threat Dragon to create data flow diagrams, identify threats
Build comprehensive forensic super-timelines using Plaso (log2timeline)
'Performs User and Entity Behavior Analytics (UEBA) to detect anomalous
'Simulates VLAN hopping attacks using switch spoofing and double tagging
'Performs authenticated and unauthenticated vulnerability scanning using
Bypass Web Application Firewall protections using encoding techniques,
'Performs systematic security testing of web applications following the
Nikto is an open-source web server and web application scanner that tests
Triage web application vulnerability findings from DAST/SAST scanners
Execute web cache deception attacks by exploiting path normalization
Exploiting web cache mechanisms to serve malicious content to other users
'Captures WPA/WPA2 handshakes and performs offline password cracking
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's
Execute a wireless network penetration test to assess WiFi security by
Conduct wireless network security assessments using Kismet to detect
Develop precise YARA rules for malware detection by identifying unique
The Common Vulnerability Scoring System (CVSS) is the industry standard
'Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1
'Develops comprehensive threat actor profiles for APT groups, criminal
Recover deleted files from disk images and storage media using PhotoRec's
'Executes structured recovery from a ransomware incident following NIST
'This skill provides step-by-step procedures for identifying and remediating
'Reverse engineers malicious Android APK files using JADX decompiler