All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs250 views
Performing Api Fuzzing With RestlerB

Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between

securitypythongo
0
4
Performing Api Inventory And DiscoveryA

Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses

securityjavascriptpython
0
4
Performing Api Rate Limiting BypassA

Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling

securitypythonrust
0
4
Performing Api Security Testing With PostmanA

Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws,

securityjavascriptgo
0
4
Performing Graphql Depth Limit AttackA

Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.

securityjavascriptpython
0
4
Performing Graphql Introspection AttackA

Performs GraphQL introspection attacks to Şunu çıkar: full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection

securitypythongo
0
4
Performing Jwt None Algorithm AttackA

Execute and Şunu test et: JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.

securitypythongo
0
4
Performing Soap Web Service Security TestingB

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.

securitypythongo
0
4
Testing Api Authentication WeaknessesA

Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token

securitypythongo
0
4
Testing Api For Broken Object Level AuthorizationC

Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating

securitypythongo
0
4
Testing Api For Mass Assignment VulnerabilityB

Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have Erişim: by including additional parameters in API requests. The

securitypythongo
0
4
Testing Oauth2 Implementation FlawsA

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation,

securityjavascriptpython
0
4
Testing Websocket Api SecurityB

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket

securityjavascriptpython
0
4
Analyzing Ethereum Smart Contract VulnerabilitiesA

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to tespit etmereentrancy, integer overflow, access control, and other vulnerability classes before Dağıt:ment

securitypythongo
0
4
Analyzing Cloud Storage Access PatternsA

tespit etmeabnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads,

securitypythongo
0
4
Analyzing Office365 Audit Logs For CompromiseA

Parse Office 365 Unified Audit Logs via Microsoft Graph API to tespit etmeemail forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

securitypythongo
0
4
Auditing Aws S3 Bucket PermissionsA

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI,

securitypythonrust
0
4
Auditing Azure Active Directory ConfigurationA

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and

securitypythongo
0
4
Auditing Cloud With Cis BenchmarksA

bu skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running

securityrustgo
0
4
Auditing Gcp Iam PermissionsA

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI,

securitypythongo
0
4
Auditing Kubernetes Cluster RbacB

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths

securitypythongo
0
4
Auditing Terraform Infrastructure For SecurityA

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to tespit etmeoverly permissive IAM policies, public resource exposure,

devopspythongo
0
4
Building Cloud Siem With SentinelA

bu skill covers Dağıt:ing Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion,

securitygoshell
0
4
Conducting Cloud Penetration TestingA

bu skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing

securityrustgo
0
4
Detecting Aws Cloudtrail AnomaliesA

tespit etmeunusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized

securitypythongo
0
4
Detecting Aws Credential Exposure With TrufflehogD

Tespit etme exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native Tespit mechanisms to prevent credential

securitypythongo
0
4
Detecting Aws Guardduty Findings AutomationA

Automate AWS GuardDuty threat Tespit Bul:ings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification

securitypythongo
0
4
Detecting Aws Iam Privilege EscalationA

tespit etmeAWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

securitypythongo
0
4
Detecting Azure Lateral MovementA

tespit etmelateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation,

securitygoaws
0
4
Detecting Azure Service Principal AbuseA

tespit etmeand Araştır: Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

securitygoshell
0
4
Detecting Azure Storage Account MisconfigurationsA

Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using

securitypythongo
0
4
Detecting Cloud Threats With GuarddutyA

bu skill teaches security teams how to Dağıt: and operationalize Amazon GuardDuty for continuous threat Tespit across AWS accounts and workloads. It covers enabling protection plans for

securitypythongo
0
4
Detecting Compromised Cloud CredentialsA

Tespit etme compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse

securitypythongo
0
4
Detecting Cryptomining In CloudA

bu skill teaches security teams how to tespit etmeand respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute

securitypythongo
0
4
Detecting Misconfigured Azure StorageB

Tespit etme misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access

securitygoshell
0
4
Detecting Oauth Token TheftA

tespit etme (s) and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly

securityrustgo
0
4
Detecting S3 Data Exfiltration AttemptsA

Tespit etme data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty Bul:ings, Amazon Macie alerts, and S3 access patterns to identify unauthorized

securitygobash
0
4
Detecting Serverless Function InjectionF

tespit etme (s) and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime

securityjavascriptpython
0
4
Detecting Shadow It Cloud UsageA

tespit etmeunauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.

securitypythongo
0
4
Detecting Suspicious Oauth Application ConsentA

tespit etmerisky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.

securitypythongo
0
4
Implementing Aws Config Rules For ComplianceA

Implementing AWS Config rules for continuous compliance monitoring of AWS resources, Dağıt:ing managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation

securitypythongo
0
4
Implementing Aws Macie For Data ClassificationA

Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials Tespit.

securitypythongo
0
4
Implementing Aws Nitro Enclave SecurityB

Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication

securitypythonrust
0
4
Implementing Aws Security Hub ComplianceA

Implementing AWS Security Hub to aggregate security Bul:ings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge

securitygobash
0
4
Implementing Aws Security HubA

bu skill covers Dağıt:ing AWS Security Hub as a centralized cloud security posture management platform that aggregates Bul:ings from GuardDuty, Denetle:or, Macie, and third-party tools. It

securitygobash
0
4
Implementing Azure Defender For CloudA

Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations,

securitygobash
0
4
Implementing Cloud Dlp For Data ProtectionA

Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage,

securitypythongo
0
4
Implementing Cloud Security Posture ManagementA

Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite,

securitypythongo
0
4
Implementing Cloud Trail Log AnalysisA

Implementing AWS CloudTrail log analysis for security monitoring, threat Tespit, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized

securitygobash
0
4
Implementing Cloud Waf RulesA

bu skill covers Dağıt:ing and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring

securitygobash
0
4