All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs251 views
Collecting Threat Intelligence With MispA

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks,

securitypythongo
0
4
Correlating Threat CampaignsA

Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract

securitypythongo
0
4
Evaluating Threat Intelligence PlatformsA

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst

securitypythongo
0
4
Generating Threat Intelligence ReportsA

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical

securityrustgo
0
4
Hunting Advanced Persistent ThreatsA

Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts.

securitygoshell
0
4
Implementing Diamond Model AnalysisA

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This

securitypythongo
0
4
Implementing Security Information Sharing With Stix2A

Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

testingpythongo
0
4
Implementing Stix Taxii Feed IntegrationA

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

securitypythonrust
0
4
Implementing Taxii Server With OpentaxiiA

Dağıt: and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

securitypythonrust
0
4
Implementing Threat Intelligence Lifecycle ManagementA

Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational

securitypythongo
0
4
Managing Intelligence LifecycleA

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products

securitygogit
0
4
Mapping Mitre Attack TechniquesA

Maps observed adversary behaviors, security alerts, and Tespit rules to MITRE ATT&CK techniques and sub-techniques to quantify Tespit coverage and guide control prioritization. Use when

securitypythongo
0
4
Monitoring Darkweb SourcesA

Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications

securitygobash
0
4
Performing Ai Driven Osint CorrelationB

Use AI and LLM-based reasoning to correlate Bul:ings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web

ai-agentspythonrust
0
4
Performing Brand Monitoring For ImpersonationA

Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to tespit etmephishing campaigns, fake sites, and unauthorized brand usage targeting your

securitypythonrust
0
4
Performing Dark Web Monitoring For ThreatsA

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including

securityjavascriptpython
0
4
Performing Indicator Lifecycle ManagementA

Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, Dağıt:ment, monitoring, and eventual retirement. bu skill covers implementing systematic

securitypythonrust
0
4
Performing Ip Reputation Analysis With ShodanA

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.

securitypythongo
0
4
Performing Malware Hash Enrichment With VirustotalA

Enrich malware file hashes using the VirusTotal API to retrieve Tespit rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.

securitypythonrust
0
4
Performing Malware Ioc ExtractionA

Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs),

securitypythonrust
0
4
Performing Osint With SpiderfootA

Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources

securitypythonrust
0
4
Performing Paste Site Monitoring For CredentialsA

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to tespit etmebreaches early.

securitypythongo
0
4
Performing Threat Emulation With Atomic Red TeamA

Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates

securitypythongo
0
4
Performing Threat Intelligence Sharing With MispA

Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.

securitypythongo
0
4
Performing Threat Landscape Assessment For SectorA

Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk

securitypythongo
0
4
Processing Stix Taxii FeedsA

Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when

securitypythongo
0
4
Profiling Threat Actor GroupsA

Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints,

securitypythongo
0
4
Tracking Threat Actor InfrastructureA

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof

securitypythonrust
0
4
Building Patch Tuesday Response ProcessA

Establish a structured operational process to triage, test, and Dağıt: Microsoft Patch Tuesday security updates within risk-based remediation SLAs.

securitypythongo
0
4
Building Vulnerability Aging And Sla TrackingA

Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.

securitypythongo
0
4
Building Vulnerability Dashboard With DefectdojoA

Dağıt: DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.

securitypythongo
0
4
Building Vulnerability Exception Tracking SystemA

Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.

securitypythonrust
0
4
Exploiting Vulnerabilities With Metasploit FrameworkB

The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation

securitygoshell
0
4
Implementing Attack Path Analysis With Xm CyberA

Dağıt: XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.

securitypythonrust
0
4
Implementing Cloud Vulnerability Posture ManagementA

Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability Tespit.

securitypythongo
0
4
Implementing Continuous Security Validation With BasA

Dağıt: Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.

securitypythongo
0
4
Implementing Epss Score For Vulnerability PrioritizationB

Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.

securitypythongo
0
4
Implementing Patch Management WorkflowA

Patch management is the systematic process of identifying, testing, Dağıt:ing, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective

securitypythongo
0
4
Implementing Rapid7 Insightvm For ScanningA

Dağıt: and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.

securitypythongo
0
4
Implementing Vulnerability Management With GreenboneA

Dağıt: and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.

securitypythongo
0
4
Implementing Vulnerability Remediation SlaA

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA

securitypythongo
0
4
Implementing Vulnerability Sla Breach AlertingA

Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

securitypythongo
0
4
Performing Active Directory Vulnerability AssessmentB

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

securitypythonrust
0
4
Performing Agentless Vulnerability ScanningA

Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.

securitypythongo
0
4
Performing Asset Criticality Scoring For VulnsA

Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.

securitypythongo
0
4
Performing Authenticated Scan With OpenvasB

Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.

securitypythongo
0
4
Performing Authenticated Vulnerability ScanB

Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep Denetle:ion of installed software, patches, configurations, and security

securitypythongo
0
4
Performing Cve Prioritization With Kev CatalogA

Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.

securitypythongo
0
4
Performing Web Application Scanning With NiktoA

Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies

securitypythongo
0
4
Performing Web Application Vulnerability TriageA

Triage web application vulnerability Bul:ings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.

securitypythonrust
0
4