All authors
meltedinhex avatar

Claude Skills by meltedinhex

github.com/meltedinhex
119 skillsA× 117B× 1D× 10 installs40 views
Emulating Shellcode With UnicornA

'Emulates position-independent shellcode in a controlled CPU emulator (Unicorn) to

securitypythonshell
0
22
Enriching Iocs With Threat Intel SourcesA

'Enriches indicators with context from threat-intel sources: planning lookups against

securitypythonbash
0
22
Establishing Telemetry BaselinesA

'Establishes behavioral baselines from historical telemetry (process, network, or

securitypythongo
0
22
Extracting And Classifying StringsA

'Extracts ASCII and Unicode strings from a binary and classifies them into

securitypythongo
0
22
Extracting Cobalt Strike Beacon ConfigA

'Extracts and interprets a Cobalt Strike Beacon configuration: decoding the

securitypythonshell
0
22
Extracting Config From A Running SampleA

'Extracts an embedded malware configuration (C2 hosts, ports, campaign IDs, keys) from

securitypythonbash
0
22
Extracting Encryption Keys From BinariesA

'Locates candidate encryption keys in a binary by finding high-entropy fixed-size

securitypythongo
0
22
Extracting Iocs From Analysis OutputA

'Extracts indicators of compromise from raw analysis artifacts: parsing strings

securitypythonbash
0
22
Generating Capability Reports With CapaA

'Uses capa to identify malware capabilities from a binary: running rule-based

securitypythonrust
0
22
Handling Malware Samples SafelyA

'Establishes safe practices for acquiring, storing, transferring, and disposing

securitypythonrust
0
22
Hashing And Fingerprinting FilesA

'Computes cryptographic and fuzzy fingerprints for malware samples: MD5/SHA-1/SHA-256

securitypythonrust
0
22
Hunting Active Directory AttacksA

'Hunts for Active Directory credential and replication attacks — DCSync, Golden/Silver

securitypythongo
0
22
Hunting Anomalous Authentication PatternsA

'Hunts for anomalous authentication such as password spraying, brute force, and

securitypythongo
0
22
Hunting C2 Beaconing With Frequency AnalysisA

'Detects command-and-control beacons in network logs by analyzing connection

securitypythonbash
0
22
Hunting Cobalt Strike TrafficA

'Hunts for Cobalt Strike beacon traffic by detecting default stager URI checksum8

securitypythongo
0
22
Hunting Credential Dumping ActivityA

'Hunts for credential dumping by detecting LSASS process access with suspicious access

securitypythonrust
0
22
Hunting Data Staging And ArchivingA

'Hunts for pre-exfiltration data staging and archiving by detecting archive-tool

securitypythonbash
0
22
Hunting Dns Tunneling And ExfiltrationA

'Detects DNS-based tunneling and data exfiltration in DNS logs: scoring high query

securitypythonbash
0
22
Hunting Domain Fronting And Cdn AbuseA

'Hunts for domain fronting and CDN abuse by detecting TLS SNI versus HTTP Host header

securitypythonbash
0
22
Hunting Fileless And In Memory ThreatsA

'Hunts for fileless and in-memory threats by correlating PowerShell script-block logs,

securitypythonshell
0
22
Hunting From A Threat Intel ReportA

'Operationalizes a threat intelligence report into hunts: extracting IOCs and TTPs,

securitypythonbash
0
22
Hunting Kerberoasting And Ticket AttacksA

'Hunts for Kerberoasting and related ticket attacks by analyzing Kerberos service

securitypythonbash
0
22
Hunting Lateral Movement Over Smb And WmiA

'Hunts for lateral movement via remote service creation, admin share writes, and

securitypythongo
0
22
Hunting Lolbin Abuse On WindowsA

'Hunts for living-off-the-land binary (LOLBin) abuse in Windows process-creation

securityjavascriptpython
0
22
Hunting Persistence Mechanisms On WindowsA

'Hunts for Windows persistence across autostart locations: Run keys, services,

securitypythongo
0
22
Hunting Persistence On LinuxD

'Hunts for Linux persistence by inspecting cron, systemd units, shell rc files, SSH

securitypythonrust
0
22
Hunting Process Injection With SysmonA

'Hunts for process injection using Sysmon telemetry: correlating CreateRemoteThread

securitypythongo
0
22
Hunting Ransomware Precursor BehaviorA

'Hunts for ransomware precursor behavior that precedes encryption — shadow-copy and

securitypythonshell
0
22
Hunting Scheduled Task AbuseA

'Hunts for malicious scheduled task persistence by analyzing task registration events

securitypythongo
0
22
Hunting Suspicious Powershell ExecutionA

'Hunts malicious PowerShell using script-block (EID 4104) and module logging:

securitypythonshell
0
22
Hunting Unusual Outbound ConnectionsA

'Hunts for unusual outbound network connections by flagging direct-to-IP traffic,

securitypythonbash
0
22
Hunting Wmi Event Subscription PersistenceA

'Hunts for malicious WMI permanent event subscription persistence by correlating

securitypythongo
0
22
Identifying Anti Debugging TechniquesA

'Identifies and bypasses anti-debugging and anti-analysis checks in malware: PEB

securitypythonbash
0
22
Identifying Cryptographic Routines In BinariesA

'Identifies cryptographic algorithms embedded in a binary by scanning for well-known

securitypythongo
0
22
Identifying File Types And FormatsA

'Identifies a sample''s true file type independent of its extension: matching magic

securitypythonrust
0
22
Manually Unpacking A Packed BinaryA

'Manually unpacks a runtime-packed Windows binary by finding the original entry point

securitypythonbash
0
22
Mapping Hunts To Mitre AttackA

'Maps hunts and detections to MITRE ATT&CK for coverage analysis: tagging hypotheses

securitypythonbash
0
22
Measuring Section Entropy To Detect PackingA

'Detects packing and encryption by measuring Shannon entropy across a binary''s

securitypythonbash
0
22
Monitoring Process And File BehaviorA

'Summarizes runtime behavior of a sample from Procmon-style operation logs — process

securitypythongo
0
22
Operationalizing A Hunt Into A DetectionA

'Converts a successful threat hunt into a durable detection by extracting the

securitypythongo
0
22
Performing Dynamic Analysis In A SandboxA

'Runs a sample in an instrumented sandbox to observe behavior: process tree, file

securitypythonrust
0
22
Performing Static Pe AnalysisA

'Extracts structure and indicators from a Windows PE file without executing it:

securitypythonrust
0
22
Pivoting On Iocs Across Data SourcesA

'Pivots on indicators of compromise across multiple data sources by correlating a seed

securitypythonbash
0
22
Profiling A Threat Actor From TtpsA

'Profiles a threat actor by aggregating observed ATT&CK techniques into a TTP profile

securitypythonbash
0
22
Recovering Injected Code And ShellcodeA

'Carves injected PE images and position-independent shellcode from a memory dump or

securitypythonshell
0
22
Resolving Dynamic Api HashingA

'Resolves dynamically hashed Windows API names by brute-forcing observed hash constants

securitypythongo
0
22
Reverse Engineering Arm BinariesA

'Reverse engineers ARM/AArch64 malware by identifying the architecture and instruction

securitypythonbash
0
22
Reverse Engineering Binaries With Binary NinjaA

'Reverse engineers binaries with Binary Ninja using its analysis stack and Python API

securitypythongo
0
22
Reverse Engineering Binaries With GhidraA

'Uses Ghidra to disassemble and decompile a binary, navigate to key routines via

securitypythonrust
0
22
Reverse Engineering Binaries With Radare2 RizinA

'Reverse engineers binaries using radare2/rizin interactively, covering analysis

securitypythonrust
0
22