All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs252 views
Conducting Social Engineering Penetration TestA

Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training

securityrustgo
0
4
Conducting Wireless Network Penetration TestA

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3

securitygotesting
0
4
Executing Active Directory Attack SimulationA

Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships

securitypythonrust
0
4
Executing Phishing Simulation CampaignA

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds

securitygotesting
0
4
Executing Red Team ExerciseA

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a

securityrustgo
0
4
Exploiting Sql Injection VulnerabilitiesA

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester tespit etme (s) injection

securitygojava
0
4
Pentest Advisor AgentA

Expert penetration testing advisor for authorized security assessments. Strategic guidance, methodology, and best practices for ethical hacking engagements.

securitypythongo
0
4
Pentest Report GeneratorA

Otomatik pentest raporu olusturur. Icerir: executive summary (yonetici ozeti), CVSS 3.1 skorlu bulgular, MITRE ATT&CK mapping, NIST CSF uyumlu remediation onerileri, metodoloji ve appendix. /report komutuyla cagrilir.

securitygophp
0
4
Performing Active Directory Penetration TestA

Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and

securitypythonrust
0
4
Performing External Network Penetration TestB

Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.

securitypythongo
0
4
Performing Iot Security AssessmentF

Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications.

securitypythongo
0
4
Performing Privilege Escalation AssessmentC

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege Erişim: root or SYSTEM-level control. The tester enumerates misconfigurations,

securitypythongo
0
4
Performing Thick Client Application Penetration TestA

Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop

securitygoshell
0
4
Performing Vulnerability Scanning With NessusA

Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across

securitygotesting
0
4
Performing Web Application Penetration TestB

Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input

securityjavascriptgo
0
4
Performing Wireless Network Penetration TestA

Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, Tespit etme rogue access points, and testing wireless segmentation using

securitygophp
0
4
Seclists PayloadsA

SecLists-based security testing skill

securitypythongo
0
4
Testing For Xss VulnerabilitiesA

Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution,

securityjavascriptgo
0
4
Wordlist AssistantA

Access and filter SecLists wordlists for authorized security testing. Password lists, username lists, fuzzing payloads, web shells.

ai-agentspythongo
0
4
Analyzing Malicious Url With UrlscanA

URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in

securityjavascriptpython
0
4
Building Phishing Reporting Button WorkflowA

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

securityrustgo
0
4
Detecting Business Email Compromise With AiA

Dağıt: AI and NLP-powered Tespit systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based

ai-agentsrustgo
0
4
Detecting Business Email CompromiseA

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive

securityrustgo
0
4
Detecting Qr Code Phishing With Email SecurityA

tespit etmeand prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.

securityrustgo
0
4
Detecting Spearphishing With Email GatewayA

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365,

securityrustgo
0
4
Implementing Anti Phishing Training ProgramA

Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking,

securitygogit
0
4
Implementing Dmarc Dkim Spf Email SecurityA

SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail.

securitypythongo
0
4
Implementing Email Sandboxing With ProofpointA

Email sandboxing detonates suspicious attachments and URLs in isolated environments to tespit etmezero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is

securitygogit
0
4
Implementing Google Workspace Phishing ProtectionA

Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing Tespit, and Enhanced Safe Browsing.

securityrustgo
0
4
Implementing Mimecast Targeted Attack ProtectionA

Dağıt: Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing

securitygogit
0
4
Implementing Proofpoint Email Security GatewayA

Dağıt: and configure Proofpoint Email Protection as a secure email gateway to tespit etmeand block phishing, malware, BEC, and spam before messages reach user inboxes.

securitygotesting
0
4
Performing Adversary In The Middle Phishing DetectionA

tespit etmeand respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.

securitygonode
0
4
Performing Dmarc Policy Enforcement RolloutA

Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.

securitygotesting
0
4
Performing Phishing Simulation With GophishA

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation,

securitypythongo
0
4
Implementing Gdpr Data Subject Access RequestA

Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating

securitypythongo
0
4
Performing Privacy Impact AssessmentA

Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging,

securitypythongo
0
4
Analyzing Ransomware Payment WalletsA

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund

securitypythongo
0
4
Building Ransomware Playbook With Cisa FrameworkA

Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, Tespit, containment, eradication,

securitypythongo
0
4
Deploying Decoy Files For Ransomware DetectionA

Dağıt:s canary files (honeytokens) across file systems to tespit etmeransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring

securitypythongo
0
4
Deploying Ransomware Canary FilesA

Dağıt:s and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event Tespit. Places strategically named decoy files that

securitypythongo
0
4
Detecting Ransomware Encryption BehaviorA

tespit etme (s) ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy

securitypythongo
0
4
Detecting Ransomware Precursors In NetworkA

tespit etme (s) early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance

securitypythongo
0
4
Implementing Anti Ransomware Group PolicyA

Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack

securityjavascriptpython
0
4
Implementing Honeypot For Ransomware DetectionA

Dağıt:s canary files, honeypot shares, and decoy systems to tespit etmeransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger

securitypythongo
0
4
Implementing Immutable Backup With ResticA

Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection. Automates backup creation, integrity verification via

securitypythongo
0
4
Implementing Ransomware Backup StrategyA

Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification).

securityrustgo
0
4
Implementing Ransomware Kill Switch DetectionA

tespit etme (s) and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex

securitypythongo
0
4
Performing Ransomware Tabletop ExerciseA

Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on

securitygotesting
0
4
Recovering From Ransomware AttackA

Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized

securityrustgo
0
4
Analyzing Api Gateway Access LogsA

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to tespit etmeBOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis

securitypythongo
0
4