
Claude Skills by nuroctane
github.com/nuroctaneRuns a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server processes, and anomalous HTTP request patterns. Use when hunting for web shells after a public-facing app compromise, when EDR/SIEM alerts fire on webserver process anomalies, or during incident response on internet-facing infrastructure.
Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session events to spot impossible travel, refresh-token reuse, and token use from anomalous ASNs. Use when hunting MFA-bypass via stolen cookies/tokens, investigating impossible-travel alerts, or scoping SaaS lateral movement after phishing.
Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Use when deploying or configuring encryption for data at rest, establishing controls to meet compliance requirements, or reviewing an implementation during a security assessment.
'Implements strategies to reduce SOC alert fatigue by tuning detection
Guides designing, deploying, and measuring an anti-phishing security awareness program - baseline phishing simulations, interactive training modules, just-in-time learning, and metric tracking - using platforms like KnowBe4, Proofpoint Security Awareness, or Cofense. Use when building or maturing a phishing awareness program, establishing training controls for compliance, or measuring phishing susceptibility and reporting rates over time.
'Configures Windows Group Policy Objects to block ransomware execution
Implements API abuse detection using token bucket, sliding window, and
'Configures API gateways such as Kong, AWS API Gateway, Azure APIM,
'Implements secure API key generation with sufficient entropy, server-side
'Implements API rate limiting and throttling with token bucket, sliding
Implements API schema validation using OpenAPI Specification and JSON
Implements API Security Posture Management (API-SPM) to continuously
Implements API security testing on the 42Crunch platform, combining
Implements API threat protection using Google Apigee reverse-proxy
'Implements application whitelisting using Windows AppLocker to restrict
Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations,
Deploys XM Cyber's continuous exposure management platform to build
'Implements external attack surface management (EASM) using Shodan, Censys,
'Implements AWS Config managed and custom rules for continuous compliance
Configures AWS IAM permission boundaries that cap the maximum permissions
Enable and configure Amazon Macie via AWS CLI/Terraform to discover, classify, and protect sensitive data (PII, financial data, credentials) in S3 using ML and pattern matching, including discovery jobs, custom data identifiers, allow lists, and EventBridge-based remediation. Use when setting up S3 data classification, cloud DLP, or auditing S3 for unprotected sensitive data.
'Build AWS Nitro Enclave confidential computing environments using nitro-cli
'Deploy AWS Security Hub, backed by AWS Config, to aggregate findings
'Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS
Configure Microsoft Entra Privileged Identity Management (PIM) to convert
'Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers,
'Implement Google''s BeyondCorp zero trust access model using Cloud
Implement RPKI-based BGP route origin validation by creating Route Origin
'Deploys remote browser isolation (RBI) as a core component of a Zero
'Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure
Assess, gap-analyze, and progressively implement the CISA Zero Trust
'Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft
'Continuously monitor multi-cloud environments (AWS, Azure, GCP) for
'Implementing AWS CloudTrail log analysis for security monitoring, threat
Implement multi-cloud CSPM to detect cloud-native misconfigurations
'Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF,
'Implements cloud workload protection using boto3 and google-cloud APIs
'Implements code signing for build artifacts (binaries, packages, containers)
Configures Microsoft Entra ID (Azure AD) Conditional Access policies for
'Implements secure conduit architecture for OT remote access under the
Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using multi-stage build patterns plus debugging and scanning techniques adapted to distroless. Use when hardening container images, cutting attack surface in a container architecture, or answering an assessment finding about bloated base images. Keywords: distroless, multi-stage build, no shell, nonroot tag, debu...
Uses Calico's own policy CRDs beyond the upstream Kubernetes API - GlobalNetworkPolicy, HostEndpoint, NetworkSet, policy tiers, and DNS-based egress rules - applied and audited with calicoctl. Use when a policy must span namespaces or protect the host itself, when egress has to be expressed by domain name, or when ordering policies into tiers. Keywords: calicoctl, GlobalNetworkPolicy, HostEndpoint, NetworkSet, tier, DNS egress, order. Do not use for portable upstream NetworkPolicy - use imple...
Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach,
'Implements DLP policies using Microsoft Purview PowerShell cmdlets and
Configure Cloudflare DDoS protection with managed rulesets, rate limiting,
Deploys and monitors Canary Tokens via the Thinkst Canary REST API for
'Implements Delinea Secret Server for privileged access management,
'Implements device posture assessment as a zero trust access control
'Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for
The Diamond Model of Intrusion Analysis provides a structured framework