All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs251 views
Implementing Cloud Workload ProtectionA

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly Tespit, and file integrity checking on EC2/GCE instances. Scans for

securitypythongo
0
4
Implementing Gcp Binary AuthorizationB

Implement GCP Binary Authorization to enforce Dağıt:-time security controls that ensure only trusted, attested container images are Dağıtılmış to Google Kubernetes Engine and Cloud Run.

securityrustgo
0
4
Implementing Gcp Organization Policy ConstraintsA

Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization,

securitygobash
0
4
Implementing Gcp Vpc Firewall RulesA

Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor

securityrustgo
0
4
Implementing Secrets Management With VaultB

bu skill covers Dağıt:ing HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption,

securityrustgo
0
4
Implementing Zero Trust In CloudA

bu skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access

securityrustgo
0
4
Implementing Zero Trust Network AccessA

Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and

securityrustgo
0
4
Managing Cloud Identity With OktaA

bu skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, Dağıt:ing phishing- resistant MFA with Okta

securityrustgo
0
4
Performing Aws Account Enumeration With Scout SuiteA

Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and Şunu üret:ctionable security reports.

securitypythongo
0
4
Performing Aws Privilege Escalation AssessmentA

Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal

securitypythonrust
0
4
Performing Cloud Asset Inventory With CartographyA

Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS,

securitypythonrust
0
4
Performing Cloud Forensics With Aws CloudtrailA

Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.

securitypythongo
0
4
Performing Cloud Log Forensics With AthenaB

Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for Tespit etme

securitypythongo
0
4
Performing Cloud Native Forensics With FalcoB

Uses Falco YAML rules for runtime threat Tespit in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco

securitypythongo
0
4
Performing Cloud Native Threat Hunting With Aws DetectiveA

Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty Bul:ing correlation, and automated entity profiling across IAM users, EC2 instances,

securitypythongo
0
4
Performing Cloud Penetration Testing With PacuA

Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting,

securityrustgo
0
4
Performing Gcp Penetration Testing With GcpbucketbruteA

Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing

securitypythongo
0
4
Performing Gcp Security Assessment With ForsetiA

Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage

securitypythongo
0
4
Performing Serverless Function Security ReviewA

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables,

securitypythonrust
0
4
Remediating S3 Bucket MisconfigurationA

bu skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block

securitygobash
0
4
Securing Api Gateway With Aws WafB

Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation

securitygobash
0
4
Securing Aws Iam PermissionsA

bu skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission

securitygobash
0
4
Securing Aws Lambda Execution RolesA

Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate

securityrustgo
0
4
Securing Azure With Microsoft DefenderA

bu skill instructs security practitioners on Dağıt:ing Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers

securitygoshell
0
4
Securing Container Registry ImagesF

Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building

securitygobash
0
4
Securing Kubernetes On CloudA

bu skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls,

securityrustgo
0
4
Securing Serverless FunctionsA

bu skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability

securitypythongo
0
4
Implementing Gdpr Data Protection ControlsA

The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This

securitygorails
0
4
Implementing Iso 27001 Information Security ManagementA

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). bu skill covers the

securityrustgo
0
4
Implementing Pci Dss Compliance ControlsA

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

securitygotesting
0
4
Performing Nist Csf Maturity AssessmentA

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect,

securitygoreact
0
4
Performing Soc2 Type2 Audit PreparationA

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing

securitypythonrust
0
4
Analyzing Kubernetes Audit LogsA

Parses Kubernetes API server audit logs (JSON lines) to tespit etmeexec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat Tespit rules

securitypythongo
0
4
Detecting Container Drift At RuntimeA

tespit etmeunauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.

securitygoshell
0
4
Detecting Container Escape AttemptsA

Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Tespit involves monitoring for escape

securitygobash
0
4
Detecting Container Escape With Falco RulesD

tespit etmecontainer escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

securitygobash
0
4
Detecting Privilege Escalation In Kubernetes PodsB

tespit etmeand prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

securitygobash
0
4
Hardening Docker Containers For ProductionB

Hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce

securitypythonrust
0
4
Hardening Docker Daemon ConfigurationC

Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.

securityrustgo
0
4
Implementing Container Image Minimal Base With DistrolessA

Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.

securitypythonrust
0
4
Implementing Container Network Policies With CalicoA

Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.

securitypythonrust
0
4
Implementing Image Provenance Verification With CosignB

Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.

securitygobash
0
4
Implementing Kubernetes Network Policy With CalicoA

Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.

securityrustgo
0
4
Implementing Kubernetes Pod Security StandardsA

Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes

securitygobash
0
4
Implementing Network Policies For KubernetesA

Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with

securityrustgo
0
4
Implementing Opa Gatekeeper For Policy EnforcementA

Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.

securitygobash
0
4
Implementing Pod Security Admission ControllerA

Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

securitygobash
0
4
Implementing Rbac Hardening For KubernetesA

Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.

securitygobash
0
4
Implementing Runtime Security With TetragonB

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat Tespit and policy enforcement.

securitygobash
0
4
Implementing Supply Chain Security With In TotoA

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.

securitypythongo
0
4