All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs251 views
Hunting For Data Staging Before ExfiltrationA

tespit etmedata staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via

securitypythongo
0
4
Hunting For Dcom Lateral MovementA

Hunt for DCOM-based lateral movement by Tespit etme abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network

securitypythongo
0
4
Hunting For Dcsync AttacksA

tespit etmeDCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.

securitypythongo
0
4
Hunting For Defense Evasion Via TimestompingA

tespit etmeNTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal

securitypythongo
0
4
Hunting For Dns Based PersistenceA

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails

securitypythongo
0
4
Hunting For Dns Tunneling With ZeekA

tespit etmeDNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating

securitygobash
0
4
Hunting For Domain Fronting C2 TrafficA

tespit etmedomain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate Denetle:ion

securitypythongo
0
4
Hunting For Lateral Movement Via WmiA

tespit etmeWMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event

securitypythongo
0
4
Hunting For Living Off The Cloud TechniquesA

Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse of Azure, AWS, GCP services, and SaaS platforms.

securitygoaws
0
4
Hunting For Living Off The Land BinariesA

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading Tespit.

securityrustgo
0
4
Hunting For Lolbins Execution In Endpoint LogsA

Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for

securityjavascriptgo
0
4
Hunting For Ntlm Relay AttacksA

tespit etmeNTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status,

securitypythongo
0
4
Hunting For Persistence Mechanisms In WindowsA

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

securitygoshell
0
4
Hunting For Persistence Via Wmi SubscriptionsA

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered

securitygoshell
0
4
Hunting For Process Injection TechniquesA

tespit etmeprocess injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

securitypythongo
0
4
Hunting For Registry Persistence MechanismsA

Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.

securitygoshell
0
4
Hunting For Registry Run Key PersistenceA

tespit etmeMITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.

securitypythongo
0
4
Hunting For Scheduled Task PersistenceA

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

securitygoshell
0
4
Hunting For Shadow Copy DeletionA

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.

securitygoshell
0
4
Hunting For Spearphishing IndicatorsA

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to tespit etmetargeted email attacks.

securitygoshell
0
4
Hunting For Startup Folder PersistenceA

tespit etmeT1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem

securitypythongo
0
4
Hunting For Supply Chain CompromiseA

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

securityrustgo
0
4
Hunting For Suspicious Scheduled TasksA

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005

securitygoshell
0
4
Hunting For T1098 Account ManipulationA

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event

securitypythongo
0
4
Hunting For Unusual Network ConnectionsA

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

securitygogit
0
4
Hunting For Unusual Service InstallationsA

tespit etmesuspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence

securitypythongo
0
4
Hunting For Webshell ActivityA

Hunt for web shell Dağıt:ments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

securitygophp
0
4
Performing Threat Hunting With Yara RulesA

Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration

securitypythonrust
0
4
Analyzing Apt Group With Mitre NavigatorA

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for Tespit gap analysis and threat-informed defense.

securitypythongo
0
4
Analyzing Campaign Attribution EvidenceA

Campaign attribution analysis involves systematically evaluating evidence to Belirle: which threat actor or group is responsible for a cyber operation. bu skill covers collecting and weighting

securitypythongo
0
4
Analyzing Certificate Transparency For PhishingA

Monitor Certificate Transparency logs using crt.sh and Certstream to tespit etmephishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

securitypythonrust
0
4
Analyzing Cyber Kill ChainA

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls

securitygoshell
0
4
Analyzing Indicators Of CompromiseA

Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to Belirle: maliciousness confidence, campaign attribution, and blocking priority.

securitypythonrust
0
4
Analyzing Malware Family Relationships With MalpediaA

Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for Tespit across malware lineages.

securitypythongo
0
4
Analyzing Ransomware Leak Site IntelligenceA

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

securitypythongo
0
4
Analyzing Threat Actor Ttps With Mitre AttackA

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. bu skill covers systematically mapping threat

securitypythongo
0
4
Analyzing Threat Actor Ttps With Mitre NavigatorA

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries

securitypythongo
0
4
Analyzing Threat Intelligence FeedsA

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds,

securitypythonrust
0
4
Analyzing Threat Landscape With MispA

Şunu analiz et: threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time.

securitypythongo
0
4
Analyzing Typosquatting Domains With DnstwistA

tespit etmetyposquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

securitypythongo
0
4
Auditing Tls Certificate Transparency LogsA

Monitors Certificate Transparency (CT) logs to tespit etmeunauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses

securitypythonrust
0
4
Automating Ioc EnrichmentA

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time

securitypythonrust
0
4
Building Adversary Infrastructure Tracking SystemA

Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.

securitypythonrust
0
4
Building Attack Pattern Library From Cti ReportsA

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for Tespit engineering and threat-informed defense.

securitypythongo
0
4
Building Ioc Defanging And Sharing PipelineA

Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.

securitypythongo
0
4
Building Ioc Enrichment Pipeline With OpenctiA

OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. bu skill covers building an automated IOC enrichment pipeline

securitypythonrust
0
4
Building Threat Actor Profile From OsintA

Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.

securitypythonrust
0
4
Building Threat Feed Aggregation With MispA

Dağıt: MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM

securitypythongo
0
4
Building Threat Intelligence PlatformA

Building a Threat Intelligence Platform (TIP) involves Dağıt:ing and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence.

securitypythonrust
0
4
Collecting Open Source IntelligenceA

Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools,

securitypythonrust
0
4