All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs251 views
Analyzing Docker Container ForensicsD

Araştır: compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

securitypythongo
0
4
Analyzing Email Headers For Phishing InvestigationB

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

securityjavascriptpython
0
4
Analyzing Linux Kernel RootkitsA

tespit etmekernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to

securitypythongo
0
4
Analyzing Linux System ArtifactsD

İncele: Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.

securitypythongo
0
4
Analyzing Lnk File And Jump List ArtifactsA

Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell

securitypythongo
0
4
Analyzing Mft For Deleted File RecoveryA

Şunu analiz et: NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT,

securitypythongo
0
4
Analyzing Outlook Pst For Email ForensicsA

Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email

securitypythongo
0
4
Analyzing Prefetch Files For Execution HistoryA

Parse Windows Prefetch files to Belirle: program execution history including run counts, timestamps, and referenced files for forensic investigation.

securitypythongo
0
4
Analyzing Slack Space And File System ArtifactsA

İncele: file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

securitypythongo
0
4
Analyzing Usb Device Connection HistoryA

Araştır: USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

securitypythongo
0
4
Analyzing Windows Amcache ArtifactsA

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric

securityrustgo
0
4
Analyzing Windows Lnk Files For ArtifactsA

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

securitypythongo
0
4
Analyzing Windows Prefetch With PythonA

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, tespit etmerenamed or masquerading binaries, and identify suspicious program

securitypythongo
0
4
Analyzing Windows Registry For ArtifactsA

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

securitypythongo
0
4
Analyzing Windows Shellbag ArtifactsA

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, tespit etmeErişim: removable media and network shares, and establish user interaction with directories even

securitypythongo
0
4
Extracting Browser History ArtifactsA

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

securitypythongo
0
4
Extracting Credentials From Memory DumpA

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

securitypythongo
0
4
Extracting Windows Event Logs ArtifactsA

Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to tespit etmelateral movement, persistence, and privilege escalation.

securitypythongo
0
4
Investigating Ransomware Attack ArtifactsA

Identify, collect, and analyze ransomware attack artifacts to Belirle: the variant, initial access vector, encryption scope, and recovery options.

securitypythonrust
0
4
Performing Cloud Forensics InvestigationA

Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services.

securitypythongo
0
4
Performing Cloud Storage Forensic AcquisitionB

Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts

securitypythongo
0
4
Performing File Carving With ForemostA

Recover files from disk images and unalBul:d space using Foremost's header-footer signature carving to extract evidence regardless of file system state.

securitypythongo
0
4
Performing Linux Log Forensics InvestigationB

Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, tespit etmeunauthorized access, and

securitypythongo
0
4
Performing Log Analysis For Forensic InvestigationB

Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.

securitypythongo
0
4
Performing Malware Persistence InvestigationB

Systematically Araştır: all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.

securitypythongo
0
4
Performing Memory Forensics With Volatility3B

Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

securitypythongo
0
4
Performing Mobile Device Forensics With CellebriteA

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

securitypythongo
0
4
Performing Network Forensics With WiresharkB

Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.

securitypythonrust
0
4
Performing Network Packet Capture AnalysisA

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious

securitypythongo
0
4
Performing Sqlite Database ForensicsA

Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps,

ai-agentspythonrust
0
4
Performing Steganography DetectionA

tespit etmeand extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.

securitypythongo
0
4
Performing Timeline Reconstruction With PlasoA

Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.

securitypythongo
0
4
Performing Windows Artifact Analysis With Eric Zimmerman ToolsA

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry

securitypythongo
0
4
Recovering Deleted Files With PhotorecA

Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.

ai-agentsgobash
0
4
Configuring Host Based Intrusion DetectionC

Configures host-based intrusion Tespit systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use Dağıt:ing yaparken OSSEC, Wazuh,

securitygoshell
0
4
Configuring Windows Defender Advanced SettingsA

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

securitygoshell
0
4
Configuring Windows Event Logging For DetectionA

Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat Tespit and forensic investigation. Use enabling yaparken audit policies for

securitygoshell
0
4
Deploying Edr Agent With CrowdstrikeB

Dağıt:s and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat Tespit, behavioral analysis, and automated response. Use onboarding yaparken endpoints

securitygoshell
0
4
Deploying Osquery For Endpoint MonitoringA

Dağıt:s and configures osquery for real-time endpoint monitoring using SQL-based queries to Denetle: running processes, open ports, installed software, and system configuration. Use building yaparken

securityrustgo
0
4
Detecting Evasion Techniques In Endpoint LogsA

tespit etme (s) defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use investigating yaparken suspicious

securityjavascriptrust
0
4
Detecting Fileless Attacks On EndpointsA

tespit etme (s) fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use building yaparken Tespits for PowerShell-based

securitygoshell
0
4
Hardening Linux Endpoint With Cis BenchmarkB

Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use Dağıt:ing yaparken

securitygoshell
0
4
Hardening Windows Endpoint With Cis BenchmarkA

Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when

securitygoshell
0
4
Implementing Application Whitelisting With ApplockerA

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT.

securityjavascriptrust
0
4
Implementing Disk Encryption With BitlockerA

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use Dağıt:ing yaparken encryption

securityrustgo
0
4
Implementing Endpoint Dlp ControlsA

Implements endpoint Data Loss Prevention (DLP) controls to tespit etmeand prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use Dağıt:ing yaparken DLP agents, creating

securitygogit
0
4
Implementing File Integrity Monitoring With AideA

Configure AIDE (Advanced Intrusion Tespit Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change Tespit, and alerting

securitypythongo
0
4
Implementing Memory Protection With Dep AslrA

Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent

securitygoshell
0
4
Implementing Usb Device Control PolicyA

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use Dağıt:ing yaparken

securitygoshell
0
4
Performing Endpoint Forensics InvestigationA

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use investigating yaparken security

securitygoshell
0
4