All authors
mukul975 avatar

Claude Skills by mukul975

github.com/mukul975
1,604 skillsA× 1,483B× 84C× 17D× 12F× 84 installs1,829 views
Exploiting Websocket VulnerabilitiesC

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure

securitypythonrust
0
31,965
Exploiting Zerologon Vulnerability Cve 2020 1472A

Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller

securitypythongo
0
31,965
Extracting Browser History ArtifactsA

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge

securitypythongo
0
31,965
Extracting Config From Agent Tesla RatA

Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials,

securitypythonrust
0
31,965
Extracting Credentials From Memory DumpA

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using

securitypythongo
0
31,965
Extracting Iocs From Malware SamplesA

'Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs,

securitypythonrust
0
31,965
Extracting Memory Artifacts With RekallA

'Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD

securitypythongo
0
31,965
Extracting Windows Event Logs ArtifactsA

Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral

securitypythongo
0
31,965
Generating Threat Intelligence ReportsA

'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored

securityrustgo
0
31,965
Hardening Docker Containers For ProductionB

Hardening Docker containers for production involves applying security best practices aligned with CIS Docker

securitypythonrust
0
31,965
Hardening Docker Daemon ConfigurationC

Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless

securityrustbash
0
31,965
Hardening Linux Endpoint With Cis BenchmarkB

'Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface,

securitygoshell
0
31,965
Hardening Windows Endpoint With Cis BenchmarkA

'Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack

securitygoshell
0
31,965
Hunting Advanced Persistent ThreatsA

'Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven

securitygoshell
0
31,965
Hunting Credential Stuffing AttacksA

'Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,

securitypythontesting
0
31,965
Hunting For Anomalous Powershell ExecutionA

'Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event

securitypythonshell
0
31,965
Hunting For Beaconing With Frequency AnalysisA

Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,

securityrustgo
0
31,965
Hunting For Cobalt Strike BeaconsA

Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM

securitypythongit
0
31,965
Hunting For Command And Control BeaconingA

Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation

securityrustgo
0
31,965
Hunting For Data Exfiltration IndicatorsA

Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud

securitygodatabase
0
31,965
Hunting For Data Staging Before ExfiltrationA

Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp

securitypythondatabase
0
31,965
Hunting For Dcom Lateral MovementA

'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows

securitypythongo
0
31,965
Hunting For Dcsync AttacksA

Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests

securitypythonazure
0
31,965
Hunting For Defense Evasion Via TimestompingA

'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps

securitypythonshell
0
31,965
Hunting For Dns Based PersistenceA

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,

securitypythonrails
0
31,965
Hunting For Dns Tunneling With ZeekA

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive

securitybashgit
0
31,965
Hunting For Domain Fronting C2 TrafficA

Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate

securitypythonazure
0
31,965
Hunting For Lateral Movement Via WmiA

Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for

securitypythonshell
0
31,965
Hunting For Living Off The Cloud TechniquesA

Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse

securitygoaws
0
31,965
Hunting For Living Off The Land BinariesA

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while

securityrustshell
0
31,965
Hunting For Lolbins Execution In Endpoint LogsA

Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs

securityjavascriptgo
0
31,965
Hunting For Ntlm Relay AttacksA

Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying

securitypythongo
0
31,965
Hunting For Persistence Mechanisms In WindowsA

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,

securitygoshell
0
31,965
Hunting For Persistence Via Wmi SubscriptionsA

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI

securitygoshell
0
31,965
Hunting For Process Injection TechniquesA

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection

securitypythongit
0
31,965
Hunting For Registry Persistence MechanismsA

Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and

securitygoshell
0
31,965
Hunting For Registry Run Key PersistenceA

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry

securitypythongo
0
31,965
Hunting For Scheduled Task PersistenceA

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task

securityshellsecurity
0
31,965
Hunting For Shadow Copy DeletionA

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring

securityshellsecurity
0
31,965
Hunting For Spearphishing IndicatorsA

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect

securityshellsecurity
0
31,965
Hunting For Startup Folder PersistenceA

Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,

securitypythongo
0
31,965
Hunting For Supply Chain CompromiseA

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,

securityrustsecurity
0
31,965
Hunting For Suspicious Scheduled TasksA

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious

securitygoshell
0
31,965
Hunting For T1098 Account ManipulationA

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group

securitypythonsecurity
0
31,965
Hunting For Unusual Network ConnectionsA

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard

securitysecurity
0
31,965
Hunting For Unusual Service InstallationsA

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event

securitypythonshell
0
31,965
Hunting For Webshell ActivityA

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious

securityphpshell
0
31,965
Implementing Aes Encryption For Data At RestA

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect

securitypythongo
0
31,965
Implementing Alert Fatigue ReductionA

'Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts,

securitygoshell
0
31,965
Implementing Anti Phishing Training ProgramA

Security awareness training is the human layer of phishing defense. An effective anti-phishing training program

securitysecurityperformance
0
31,965