
Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146Analyze memory dumps using Volatility3 plugins to tespit etmeinjected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to İncele: file headers, imports, strings, resources, and indicators without executing the binary.
Develop precise YARA rules for malware Tespit by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation,
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality
Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis.
SecLists-based security testing skill
Detect and analyze web shells using reference samples. Build detection rules, analyze suspicious files, create IDS/IPS signatures for defensive security.
Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking.
tespit etme (s) and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse Tespit, network traffic monitoring, and dynamic instrumentation. Use analyzing yaparken
Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect
Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences,
Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective
Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities.
Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography,
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain
Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession,
Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without
Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking,
Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities.
Parse NetFlow v9 and IPFIX records to tespit etmevolumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds
Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly Tespit in authorized security testing
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement,
Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral
Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and
Installs, configures, and tunes Snort 3 intrusion Tespit system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins
Dağıt:s and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic Denetle:ion, threat Tespit, and integration with SIEM
tespit etmeand prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Denetle:ion, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
tespit etme (s) command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms
tespit etmedata exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
tespit etmeDNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules
tespit etmelateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file
Dağıt:s and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, tespit etmeanomalous behavior, and create custom Tespit scripts
tespit etmenetwork reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based Tespit rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom
Configures Fail2ban with custom filters and actions to tespit etmeport scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and
Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI Dağıt:ment, and BGP monitoring defenses against prefix hijacking and route
Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls
Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares,
Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.
Dağıt:s remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and
Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
Dağıt: Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and
Dağıt: and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic Denetle:ion for real-time threat blocking.
Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.