All authors
HermeticOrmus avatar

Claude Skills by HermeticOrmus

github.com/HermeticOrmus
180 skillsA× 161B× 16C× 2D× 13 installs192 views
Firewall PatternsA

Firewall design reference with iptables and nftables rulesets, cloud security group patterns, stateful versus stateless processing, and common rule mistakes. Use when writing or reviewing host or cloud firewall rules.

securitygobash
0
4
Network SegmentationA

Network segmentation strategies: trust zones, VLAN and DMZ design, micro-segmentation, and lateral movement prevention. Use when designing segmentation or assessing how far a compromise could spread inside a network.

securityrustgo
0
4
Pentest MethodologyB

Reference for PTES phases, the OWASP Testing Guide, and testing patterns by technology and vulnerability class, starting from pre-engagement authorization and rules of engagement. Use when planning or running an authorized penetration test and structuring its report.

securityrustgo
0
4
Data Protection PatternsA

Technical patterns for anonymization, pseudonymization, field-level encryption, data minimization, consent management, and data subject request automation, with the difference between anonymous and pseudonymous data. Use when implementing privacy controls in code or data pipelines.

securitypythongo
0
4
Privacy By DesignA

The seven Privacy by Design principles with software engineering practices for each, such as privacy requirements in specs, privacy-protective defaults, and separating identity from behavioral data. Use when designing features that handle personal data.

securityjavascriptpython
0
4
Adversary EmulationA

Methodology for threat-intelligence-based adversary emulation within written rules of engagement: lifecycle, TIBER-EU and MITRE emulation plans, safety controls, phased scenarios, and atomic testing with benign indicators. Use when designing an authorized emulation or purple team exercise.

securitygoshell
0
4
Mitre Attack FrameworkA

MITRE ATT&CK Enterprise reference: tactics, key techniques with procedures, data sources, detection guidance, and mitigations. Use when mapping behavior to technique IDs, building detections, or planning authorized emulation.

securitygoshell
0
4
Secret DetectionB

Secret detection reference: pattern, entropy, and verification approaches, formats of common credentials, gitleaks and trufflehog configuration, and false positive management. Use when setting up secret scanning or tuning its rules.

securityjavascriptpython
0
4
Vault PatternsA

Secret storage platform reference for HashiCorp Vault, AWS Secrets Manager, and GCP Secret Manager: architecture, platform comparison, the bootstrap problem, and access patterns. Use when choosing or configuring a vault or wiring applications to it.

securitypythongo
0
4
Injection PreventionA

Injection prevention patterns for SQL, XSS, command injection, path traversal, LDAP, and template injection across major languages, including edge cases such as ORDER BY, IN clauses, and second-order injection. Use when writing or fixing code that builds queries, commands, paths, or HTML from input.

developmentjavascriptpython
0
4
Secure Auth PatternsA

Authentication and session implementation patterns: password hashing, session cookie settings, JWT validation and its pitfalls, and access control checks, with language-specific examples. Use when building or reviewing login, sessions, tokens, or authorization code.

securityjavascriptpython
0
4
Automated ResponseA

Automated remediation and containment patterns (endpoint isolation, IOC blocking with allowlists and expiry, alert correlation, threat intelligence feed updates) and a framework for deciding when an action can run automatically and when it needs human approval. Use when designing response playbooks or containment automation.

securitypythonrust
0
4
Soar PatternsA

SOAR playbook design patterns, orchestration architecture components, a platform comparison, and integration strategies, including alert enrichment, phishing response, and automated severity scoring playbooks. Use when designing or reviewing security orchestration workflows.

securitypythonrust
0
4
Security Policy TemplatesA

Reference templates and structure for common security policies (acceptable use, incident reporting, information classification), the policy, standard, procedure, and guideline hierarchy, regulatory mapping, review cycles, progressive enforcement, and exception management. Use when writing, customizing, or auditing security policies.

securitygosecurity
0
4
Social Engineering TaxonomyA

Classification of social engineering attack types, the psychological principles they exploit, recognition cues, and verification habits such as callbacks and multi-channel checks. Use when building awareness training content or teaching staff to recognize manipulation attempts.

securityrustgo
0
4
Cis BenchmarksC

Reference CIS Benchmark controls with audit and remediation commands for Linux (Ubuntu and Debian), Docker, Kubernetes, and AWS Foundations, plus hardening automation and a prioritization framework. Use when hardening a system or checking a configuration against CIS controls.

securitygoshell
0
4
Log Correlation PatternsA

Patterns for correlating events across log sources to detect multi-stage attacks, lateral movement, credential abuse, and data exfiltration, including alert-on-alert, threshold anomaly, and kill chain correlation. Use when designing correlation rules or investigating activity that spans several systems.

securitygoshell
0
4
Siem Query LanguagesA

Reference for Splunk SPL, Elastic KQL/EQL, and Microsoft Sentinel KQL with security query examples, a cross-platform conversion cheat sheet, Sigma for write-once rules, and query performance tips. Use when writing or translating SIEM queries.

securitygoshell
0
4
Defense StrategiesA

Technical and human controls for preventing, detecting, and responding to social engineering across email, phone, SMS, and physical channels, including SPF, DKIM, DMARC, payment verification callbacks, dual authorization, and response procedures. Use when designing layered defenses or responding to a phishing or BEC incident.

securityrustgo
0
4
Social Engineering AttacksA

Taxonomy of social engineering attack types with their psychological mechanisms, technical indicators, case studies, and detection patterns for phishing, BEC, and multi-channel attacks. Use when analyzing a suspected attack or explaining how one works so defenses can be designed.

securitygogit
0
4
Dependency Risk AssessmentA

Methodology for scoring dependency risk across vulnerability history, maintainer health, dependency depth, license compatibility, and provenance, with a triage matrix, a new-dependency evaluation checklist, automated monitoring, and a pinning strategy. Use when deciding whether to adopt, update, or replace a package.

securitytypescriptrust
0
4
Sbom GenerationA

Reference for generating SPDX and CycloneDX SBOMs: NTIA minimum elements, Package URLs, Syft usage, CI generation in GitHub Actions, VEX enrichment, and diffing SBOMs between versions. Use when producing or automating SBOMs for compliance or release artifacts.

securitygoshell
0
4
Attack TreesA

Attack tree methodology: notation, AND/OR decomposition, reusable tree templates, path analysis, advanced techniques, and using trees to make defense decisions. Use when decomposing an attacker goal into analyzable paths.

securitygosql
0
4
Stride MethodologyA

STRIDE-per-element analysis with threat catalogs and mitigation patterns for common components (web applications, APIs, databases, message queues, cloud services) and an incremental threat modeling process. Use when walking a system or data flow diagram through STRIDE in depth.

securityrustgo
0
4
Threat ModelingA

Checklist-level threat modeling reference: STRIDE and DREAD summaries, a trust boundary checklist, common STRIDE threats per component, frequent MITRE ATT&CK techniques, example attack trees for tenant data theft and account takeover, and a catalog of common threat modeling mistakes. Use when you need a compact checklist while building or reviewing a threat model.

securityrustgo
0
4
Cvss ScoringA

Reference for CVSS v3.1 and v4.0 metrics, scoring guidance, and the difference between severity and remediation priority. Use when scoring a vulnerability, checking a vendor score, or explaining a CVSS vector.

securityrustgo
0
4
Owasp Top 10B

Knowledge base for all ten OWASP Top 10 (2021) categories with vulnerable and fixed code examples, detection techniques, universal defense patterns, and framework security checklists. Use when reviewing web code for a specific vulnerability class or explaining an OWASP category and its fix.

securityjavascriptpython
0
4
Microsegmentation PatternsA

Implementation patterns for microsegmentation: default-deny Kubernetes NetworkPolicy, Cilium L7 and DNS-aware policies, Istio mTLS and authorization, tiered AWS security groups in Terraform, and PCI DSS cardholder data isolation. Use when writing segmentation policies for a cluster, service mesh, or cloud network.

securityrustgo
0
4
Zero Trust PrinciplesA

NIST SP 800-207 reference: core tenets, logical components (policy decision and enforcement points), deployment models, the CISA maturity model, and patterns such as BeyondCorp-style access, conditional access, ZTNA replacing VPN, and SPIFFE workload identity. Use when designing or explaining a zero trust architecture.

securityrustgo
0
4
Verify Libre SecopsA

Install the LibreSecOps-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreSecOps-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.

securitypythonbash
0
4