All authors
mukul975 avatar

Claude Skills by mukul975

github.com/mukul975
1,604 skillsA× 1,483B× 84C× 17D× 12F× 84 installs1,829 views
Detecting Service Account AbuseA

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement,

securitygosql
0
31,965
Detecting Shadow Api EndpointsA

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis,

securitypythongo
0
31,965
Detecting Shadow It Cloud UsageA

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow

securitypythongo
0
31,965
Detecting Spearphishing With Email GatewayA

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam

securityrustsecurity
0
31,965
Detecting Sql Injection Via Waf LogsA

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity

securitypythonbash
0
31,965
Detecting Stuxnet Style AttacksA

'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying

securitypythongo
0
31,965
Detecting Supply Chain Attacks In Ci CdA

'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned

securitypythongo
0
31,965
Detecting Suspicious Oauth Application ConsentA

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit

securitypythonazure
0
31,965
Detecting Suspicious Powershell ExecutionA

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts,

securityshellsecurity
0
31,965
Detecting T1003 Credential Dumping With EdrA

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials

securitygogit
0
31,965
Detecting T1055 Process Injection With SysmonA

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection

securitygoshell
0
31,965
Detecting T1548 Abuse Elevation Control MechanismA

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation

securityrustgo
0
31,965
Detecting Typosquatting Packages In Npm PypiA

'Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using

securitypythongo
0
31,965
Detecting Wmi PersistenceA

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter,

securitygoshell
0
31,965
Eradicating Malware From Infected SystemsF

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring

securitygophp
0
31,965
Evaluating Threat Intelligence PlatformsA

'Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including

securitypythongo
0
31,965
Executing Active Directory Attack SimulationA

'Executes authorized attack simulations against Active Directory environments to identify misconfigurations,

securitypythonrust
0
31,965
Executing Phishing Simulation CampaignA

'Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based

securitygotesting
0
31,965
Executing Red Team Engagement PlanningA

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE),

securitypythongo
0
31,965
Executing Red Team ExerciseA

'Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s

securityrustgo
0
31,965
Exploiting Active Directory Certificate Services Esc1A

Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates

securitypythongo
0
31,965
Exploiting Active Directory With BloodhoundA

BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and

securitypythonrust
0
31,965
Exploiting Api Injection VulnerabilitiesB

'Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP

securitypythongo
0
31,965
Exploiting Bgp Hijacking VulnerabilitiesB

'Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation,

securitypythonbash
0
31,965
Exploiting Broken Function Level AuthorizationA

'Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative

securityjavascriptpython
0
31,965
Exploiting Broken Link HijackingA

Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned

securityjavascriptjava
0
31,965
Exploiting Constrained Delegation AbuseA

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users

securitypythonrust
0
31,965
Exploiting Deeplink VulnerabilitiesA

'Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications

securityjavascriptgo
0
31,965
Exploiting Excessive Data Exposure In ApiA

'Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying

securitypythongo
0
31,965
Exploiting Http Request SmugglingA

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding

securitypythongo
0
31,965
Exploiting Idor VulnerabilitiesA

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources

securitygobash
0
31,965
Exploiting Insecure Data Storage In MobileB

'Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including

securitygojava
0
31,965
Exploiting Insecure DeserializationA

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications

securitypythonrust
0
31,965
Exploiting Ipv6 VulnerabilitiesA

'Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding,

securitypythonbash
0
31,965
Exploiting Jwt Algorithm Confusion AttackB

'Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the

securitypythonrust
0
31,965
Exploiting Kerberoasting With ImpacketA

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active

securityshellbash
0
31,965
Exploiting Mass Assignment In Rest ApisA

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields,

securitypythongo
0
31,965
Exploiting Ms17 010 Eternalblue VulnerabilityA

MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code

securitypythongo
0
31,965
Exploiting Nopac Cve 2021 42278 42287A

Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion)

securitypythonshell
0
31,965
Exploiting Nosql Injection VulnerabilitiesB

Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate

securityjavascriptpython
0
31,965
Exploiting Oauth MisconfigurationA

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation,

securityjavascriptpython
0
31,965
Exploiting Prototype Pollution In JavascriptA

Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications

securityjavascriptjava
0
31,965
Exploiting Race Condition VulnerabilitiesA

Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack

securitypythongo
0
31,965
Exploiting Server Side Request ForgeryB

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network

securityrustgo
0
31,965
Exploiting Smb Vulnerabilities With MetasploitA

'Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration

securitypythonshell
0
31,965
Exploiting Sql Injection VulnerabilitiesA

'Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests

securityjavaphp
0
31,965
Exploiting Sql Injection With SqlmapB

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized

securitypythongo
0
31,965
Exploiting Template Injection VulnerabilitiesC

Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,

securitypythongo
0
31,965
Exploiting Type Juggling VulnerabilitiesA

Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent

securitypythonphp
0
31,965
Exploiting Vulnerabilities With Metasploit FrameworkB

The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7.

securityshellbash
0
31,965