
Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to tespit etmesuspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
Analyzes DNS query logs to tespit etmedata exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to tespit etmeobfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and
Queries Certificate Transparency logs via crt.sh and pycrtsh to tespit etmephishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting
Parse Apache and Nginx access logs to tespit etmeSQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern
Analyzes Windows Security, System, and Sysmon event logs in Splunk to tespit etmeauthentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped
Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners,
Build effective Tespit rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
Builds vendor-agnostic Tespit rules using the Sigma rule format for threat Tespit across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use creating yaparken portable Tespit
Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems,
Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to tespit etme(MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and Tespit coverage
Builds a structured SOC incident response playbook for ransomware attacks covering Tespit, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures,
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to tespit etmemulti-stage attacks across network, endpoint,
Performs statistical analysis of Zeek conn.log connection intervals to tespit etmeC2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival
tespit etme (s) insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to tespit etmeSQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets
Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit Tespit. Applies plugins like pslist,
tespit etme (s) credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses
Implements strategies to reduce SOC alert fatigue by tuning Tespit rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain
Dağıt:s DNS, HTTP, and AWS API key canary tokens across network infrastructure to tespit etmeunauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers
Dağıt: and configure Wazuh SIEM/XDR for endpoint Tespit including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
Dağıt:s canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and
Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure
Build an append-only log integrity chain using SHA-256 hash chaining for tamper Tespit. Each log entry is hashed with the previous entry's hash to Şunu oluştur: blockchain-like structure where
Implement MITRE ATT&CK coverage mapping to identify Tespit gaps, prioritize rule development, and measure SOC Tespit maturity against adversary techniques.
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains,
Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify Tespit and response capabilities. Tests WAF bypass, firewall rule removal,
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to tespit etmethreats, enforce compliance, and respond to security events across
Write multi-event correlation rules that tespit etmeAPT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk
Tune SIEM Tespit rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring Tespit efficacy metrics in Splunk and Elastic
Implements SIEM Tespit use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when
Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident
Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess Tespit coverage gaps, and prioritize defensive investments. Use when
Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance
Araştır:s insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and
Araştır:s phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and Araştır: security alerts for SOC operations.
Dağıt:s deception technology including honeypots, honeytokens, and decoy systems to tespit etmeattackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false
tespit etme (s) DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, Denetle:ing TXT record payloads, and identifying high subdomain cardinality. Uses
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.