All authors
nexuslinkproductions avatar

Claude Skills by nexuslinkproductions

github.com/nexuslinkproductions
1,122 skillsA× 1,055B× 48C× 9D× 5F× 50 installs360 views
Cyber Detecting Attacks On Scada SystemsA

This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly

ai-agentsgonode
0
2
Cyber Detecting Aws Cloudtrail AnomaliesA

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

datagonode
0
2
Cyber Detecting Aws Credential Exposure With TrufflehogA

Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.

securitygonode
0
2
Cyber Detecting Aws Guardduty Findings AutomationA

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

toolsgonode
0
2
Cyber Detecting Aws Iam Privilege EscalationA

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

ai-agentsgonode
0
2
Cyber Detecting Azure Lateral MovementA

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

ai-agentsgonode
0
2
Cyber Detecting Azure Service Principal AbuseA

Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

researchgonode
0
2
Cyber Detecting Azure Storage Account MisconfigurationsA

Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.

developmentpythongo
0
2
Cyber Detecting Beaconing Patterns With ZeekA

Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data.

datagonode
0
2
Cyber Detecting Bluetooth Low Energy AttacksA

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wi

securitypythongo
0
2
Cyber Detecting Broken Object Property Level AuthorizationA

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

securitygonode
0
2
Cyber Detecting Business Email Compromise With AiA

Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.

ai-agentsgonode
0
2
Cyber Detecting Business Email CompromiseA

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,

ai-agentsrustgo
0
2
Cyber Emulating Cloud Attacks With Stratus Red TeamA

Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.

devopsgonode
0
2
Cyber Enumerating Cloud With CloudfoxA

Map AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.

ai-agentsgonode
0
2
Cyber Eradicating Malware From Infected SystemsA

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.

ai-agentsgonode
0
2
Cyber Escaping Containers To HostA

Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.

devopsgonode
0
2
Cyber Evaluating Threat Intelligence PlatformsA

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests

toolsgonode
0
2
Cyber Executing Active Directory Attack SimulationA

Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, an

securityrustgo
0
2
Cyber Executing Nist Rmf Authorization To OperateA

>- Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously. Use when a system needs an ATO or a renewal, when working a FISMA/FedRAMP authorization package, when building or revi

securitygonode
0
2
Cyber Executing Phishing Simulation CampaignA

Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests i

devopsgonode
0
2
Cyber Executing Red Team Engagement PlanningA

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

ai-agentsgonode
0
2
Cyber Executing Red Team ExerciseA

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization''s detection and response capabilities. This differs from penetrati

businessgonode
0
2
Cyber Exploiting Active Directory Certificate Services Esc1A

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.

securitygonode
0
2
Cyber Exploiting Active Directory With BloodhoundA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac

securitygonode
0
2
Cyber Exploiting Adcs With CertipyA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.

securitygonode
0
2
Cyber Exploiting Api Injection VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:202

securitygosql
0
2
Cyber Exploiting Aws With PacuA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Use Pacu modules for AWS privilege escalation, persistence, and backdooring.

securitygonode
0
2
Cyber Exploiting Bgp Hijacking VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.

devopsgonode
0
2
Cyber Exploiting Broken Function Level AuthorizationA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken

securitygonode
0
2
Cyber Exploiting Broken Link HijackingA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.

securitygonode
0
2
Cyber Exploiting Constrained Delegation AbuseA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

securitygonode
0
2
Cyber Exploiting Deeplink VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based navigation. Activates for requests involving deep link security tes

securitygonode
0
2
Cyber Exploiting Excessive Data Exposure In ApiA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property

securitygonode
0
2
Cyber Exploiting Http Request SmugglingA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

securitygonode
0
2
Cyber Exploiting Idor VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

securitygonode
0
2
Cyber Exploiting Insecure Data Storage In MobileA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirem

securitygonode
0
2
Cyber Exploiting Insecure DeserializationA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

securitypythongo
0
2
Cyber Exploiting Ipv6 VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.

securitygonode
0
2
Cyber Exploiting Jwt Algorithm Confusion AttackA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to sup

securitygonode
0
2
Cyber Exploiting Kerberoasting With ImpacketA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.

securitygonode
0
2
Cyber Exploiting Mass Assignment In Rest ApisA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.

securitygonode
0
2
Cyber Exploiting Ms17 010 Eternalblue VulnerabilityA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it

securitygonode
0
2
Cyber Exploiting Nopac Cve 2021 42278 42287A

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.

securitygonode
0
2
Cyber Exploiting Nosql Injection VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.

securitygosql
0
2
Cyber Exploiting Oauth MisconfigurationA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

securitygonode
0
2
Cyber Exploiting Prototype Pollution In JavascriptA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

securityjavascriptgo
0
2
Cyber Exploiting Race Condition VulnerabilitiesA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.

securitygonode
0
2
Cyber Exploiting Server Side Request ForgeryA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.

securitygonode
0
2
Cyber Exploiting Smb Vulnerabilities With MetasploitA

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.

securitygonode
0
2