All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs252 views
Analyzing Azure Activity Logs For ThreatsA

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to tespit etmesuspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

securitypythongo
0
4
Analyzing Dns Logs For ExfiltrationA

Analyzes DNS query logs to tespit etmedata exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length

securitypythongo
0
4
Analyzing Memory Forensics With Lime And VolatilityA

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded

securitypythongo
0
4
Analyzing Powershell Script Block LoggingA

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to tespit etmeobfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and

securitypythongo
0
4
Analyzing Tls Certificate Transparency LogsA

Queries Certificate Transparency logs via crt.sh and pycrtsh to tespit etmephishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting

securitypythongo
0
4
Analyzing Web Server Logs For IntrusionC

Parse Apache and Nginx access logs to tespit etmeSQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern

securityjavascriptpython
0
4
Analyzing Windows Event Logs In SplunkA

Analyzes Windows Security, System, and Sysmon event logs in Splunk to tespit etmeauthentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped

securitygoswift
0
4
Building Automated Malware Submission PipelineA

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners,

securitypythonrust
0
4
Building Detection Rule With Splunk SplA

Build effective Tespit rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

securitygoshell
0
4
Building Detection Rules With SigmaA

Builds vendor-agnostic Tespit rules using the Sigma rule format for threat Tespit across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use creating yaparken portable Tespit

securitypythongo
0
4
Building Incident Response DashboardA

Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems,

securitygoazure
0
4
Building Soc Escalation MatrixA

Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.

securitypythongo
0
4
Building Soc Metrics And Kpi TrackingA

Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to tespit etme(MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and Tespit coverage

securitygogit
0
4
Building Soc Playbook For RansomwareA

Builds a structured SOC incident response playbook for ransomware attacks covering Tespit, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures,

securityrustgo
0
4
Building Threat Intelligence Enrichment In SplunkA

Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.

securitypythonrust
0
4
Building Threat Intelligence Feed IntegrationA

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time

securitypythonrust
0
4
Building Vulnerability Scanning WorkflowA

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

securitypythongo
0
4
Correlating Security Events In QradarA

Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to tespit etmemulti-stage attacks across network, endpoint,

ai-agentsgobash
0
4
Detecting Beaconing Patterns With ZeekA

Performs statistical analysis of Zeek conn.log connection intervals to tespit etmeC2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival

securitypythongo
0
4
Detecting Insider Data Exfiltration Via DlpA

tespit etme (s) insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral

securitypythongo
0
4
Detecting Sql Injection Via Waf LogsA

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to tespit etmeSQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR

securitypythongo
0
4
Detecting Supply Chain Attacks In Ci CdA

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets

securitypythongo
0
4
Extracting Memory Artifacts With RekallA

Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit Tespit. Applies plugins like pslist,

securitypythongo
0
4
Hunting Credential Stuffing AttacksA

tespit etme (s) credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses

securitypythongo
0
4
Implementing Alert Fatigue ReductionA

Implements strategies to reduce SOC alert fatigue by tuning Tespit rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain

securitygoshell
0
4
Implementing Canary Tokens For Network IntrusionD

Dağıt:s DNS, HTTP, and AWS API key canary tokens across network infrastructure to tespit etmeunauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic

securitypythongo
0
4
Implementing Ebpf Security MonitoringC

Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers

ai-agentspythongo
0
4
Implementing Endpoint Detection With WazuhA

Dağıt: and configure Wazuh SIEM/XDR for endpoint Tespit including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.

securitypythongo
0
4
Implementing Honeytokens For Breach DetectionB

Dağıt:s canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and

securitypythongo
0
4
Implementing Log Forwarding With FluentdA

Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure

securitypythongo
0
4
Implementing Log Integrity With BlockchainA

Build an append-only log integrity chain using SHA-256 hash chaining for tamper Tespit. Each log entry is hashed with the previous entry's hash to Şunu oluştur: blockchain-like structure where

securitypythongo
0
4
Implementing Mitre Attack Coverage MappingA

Implement MITRE ATT&CK coverage mapping to identify Tespit gaps, prioritize rule development, and measure SOC Tespit maturity against adversary techniques.

securitypythongo
0
4
Implementing Mtls For Zero Trust ServicesA

Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains,

securitypythonrust
0
4
Implementing Security Chaos EngineeringA

Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify Tespit and response capabilities. Tests WAF bypass, firewall rule removal,

securitypythongo
0
4
Implementing Security Monitoring With DatadogB

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to tespit etmethreats, enforce compliance, and respond to security events across

securitypythongo
0
4
Implementing Siem Correlation Rules For AptA

Write multi-event correlation rules that tespit etmeAPT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk

securitypythongo
0
4
Implementing Siem Use Case TuningA

Tune SIEM Tespit rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring Tespit efficacy metrics in Splunk and Elastic

securitypythongo
0
4
Implementing Siem Use Cases For DetectionA

Implements SIEM Tespit use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when

securitypythongo
0
4
Implementing Soar Automation With PhantomA

Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident

securitypythonrust
0
4
Implementing Soar Playbook For PhishingA

Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks

securitypythongo
0
4
Implementing Soar Playbook With Palo Alto XsoarA

Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

securityjavascriptpython
0
4
Implementing Syslog Centralization With RsyslogA

Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate

securitypythongo
0
4
Implementing Threat Modeling With Mitre AttackA

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess Tespit coverage gaps, and prioritize defensive investments. Use when

securitypythongo
0
4
Implementing Ticketing System For IncidentsA

Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance

securitypythongo
0
4
Investigating Insider Threat IndicatorsA

Araştır:s insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and

securitypythongo
0
4
Investigating Phishing Email IncidentA

Araştır:s phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like

securitypythonrust
0
4
Performing Alert Triage With Elastic SiemA

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and Araştır: security alerts for SOC operations.

securitygosql
0
4
Performing Deception Technology DeploymentA

Dağıt:s deception technology including honeypots, honeytokens, and decoy systems to tespit etmeattackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false

securitypythongo
0
4
Performing Dns Tunneling DetectionA

tespit etme (s) DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, Denetle:ing TXT record payloads, and identifying high subdomain cardinality. Uses

securitypythongo
0
4
Performing False Positive Reduction In SiemA

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

securitypythongo
0
4