All authors
mukul975 avatar

Claude Skills by mukul975

github.com/mukul975
1,604 skillsA× 1,483B× 84C× 17D× 12F× 84 installs1,829 views
Detecting Container Escape AttemptsA

Container escape is a critical attack technique where an adversary breaks out of container isolation to access

securitybashdocker
0
31,965
Detecting Container Escape With Falco RulesD

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file

securitygobash
0
31,965
Detecting Credential Dumping TechniquesA

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows

securitypythondatabase
0
31,965
Detecting Cryptomining In CloudA

'This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations

securitypythongo
0
31,965
Detecting Dcsync Attack In Active DirectoryA

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes

securitypythongo
0
31,965
Detecting Deepfake Audio In Vishing AttacksA

'Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features

securitypythongo
0
31,965
Detecting Dll Sideloading AttacksA

Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack

securityrustgo
0
31,965
Detecting Dnp3 Protocol AnomaliesA

'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring

securitypythonsecurity
0
31,965
Detecting Dns Exfiltration With Dns Query AnalysisA

Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT

securitypythonbash
0
31,965
Detecting Email Account CompromiseA

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in

securitypythongo
0
31,965
Detecting Email Forwarding Rules AttackA

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications

securitysecurity
0
31,965
Detecting Evasion Techniques In Endpoint LogsA

'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,

securityjavascriptrust
0
31,965
Detecting Exfiltration Over Dns With ZeekA

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query

securitypythongit
0
31,965
Detecting Fileless Attacks On EndpointsA

'Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files

securityshellexpress
0
31,965
Detecting Fileless Malware TechniquesA

'Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,

securityjavascriptpython
0
31,965
Detecting Golden Ticket Attacks In Kerberos LogsA

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption

securitygosecurity
0
31,965
Detecting Golden Ticket ForgeryA

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),

securitypythongo
0
31,965
Detecting Insider Data Exfiltration Via DlpA

'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,

securitypythontesting
0
31,965
Detecting Insider Threat BehaviorsA

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,

securitysecurity
0
31,965
Detecting Insider Threat With UebaA

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate

securitypythonbackend
0
31,965
Detecting Kerberoasting AttacksA

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with

securitygosecurity
0
31,965
Detecting Lateral Movement In NetworkA

'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,

securitygoshell
0
31,965
Detecting Lateral Movement With SplunkA

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,

securitygoshell
0
31,965
Detecting Lateral Movement With ZeekA

'Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log,

securitypythonbash
0
31,965
Detecting Living Off The Land AttacksA

'Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process

securityjavascriptpython
0
31,965
Detecting Living Off The Land With LolbasA

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32

securitypythongit
0
31,965
Detecting Malicious Scheduled Tasks With SysmonA

'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),

securityswiftshell
0
31,965
Detecting Mimikatz Execution PatternsA

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory

securitygoshell
0
31,965
Detecting Misconfigured Azure StorageB

'Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption

securitygoshell
0
31,965
Detecting Mobile Malware BehaviorA

'Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse

securityjavascriptrust
0
31,965
Detecting Modbus Command Injection AttacksA

'Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized

securitypythongo
0
31,965
Detecting Modbus Protocol AnomaliesA

'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems.

securitypythonreact
0
31,965
Detecting Network Anomalies With ZeekB

'Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate

securitybashnode
0
31,965
Detecting Network Scanning With Ids SignaturesA

Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection

securitypythongit
0
31,965
Detecting Ntlm Relay With Event CorrelationA

'Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for

securitygoshell
0
31,965
Detecting Oauth Token TheftA

'Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra

securityrustgo
0
31,965
Detecting Pass The Hash AttacksA

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where

securitygosecurity
0
31,965
Detecting Pass The Ticket AttacksA

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous

securitypythonsecurity
0
31,965
Detecting Port Scanning With Fail2banA

'Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts,

securityrustphp
0
31,965
Detecting Privilege Escalation AttemptsA

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel

securitysecurity
0
31,965
Detecting Privilege Escalation In Kubernetes PodsB

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and

securitygobash
0
31,965
Detecting Process Hollowing TechniqueA

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child

securityrustgit
0
31,965
Detecting Process Injection TechniquesA

'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,

securitypythonrust
0
31,965
Detecting Qr Code Phishing With Email SecurityA

Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious

securityrustgo
0
31,965
Detecting Ransomware Encryption BehaviorA

'Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and

securitypythonshell
0
31,965
Detecting Ransomware Precursors In NetworkA

'Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access

securitypythongo
0
31,965
Detecting Rdp Brute Force AttacksA

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event

securitypythongo
0
31,965
Detecting Rootkit ActivityA

'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified

securitypythonrust
0
31,965
Detecting S3 Data Exfiltration AttemptsA

'Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs,

securitygobash
0
31,965
Detecting Serverless Function InjectionF

'Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google

securityjavascriptpython
0
31,965