All authors
nuroctane avatar

Claude Skills by nuroctane

github.com/nuroctane
1,166 skillsA× 1,024B× 97C× 20D× 16F× 90 installs218 views
Hunting For Webshell ActivityA

Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server processes, and anomalous HTTP request patterns. Use when hunting for web shells after a public-facing app compromise, when EDR/SIEM alerts fire on webserver process anomalies, or during incident response on internet-facing infrastructure.

ai-agentsphpshell
0
3
Hunting Saas Sso Token AbuseA

Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session events to spot impossible travel, refresh-token reuse, and token use from anomalous ASNs. Use when hunting MFA-bypass via stolen cookies/tokens, investigating impossible-travel alerts, or scoping SaaS lateral movement after phishing.

ai-agentspythongo
0
3
Implementing Aes Encryption For Data At RestA

Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Use when deploying or configuring encryption for data at rest, establishing controls to meet compliance requirements, or reviewing an implementation during a security assessment.

ai-agentspythongo
0
3
Implementing Alert Fatigue ReductionA

'Implements strategies to reduce SOC alert fatigue by tuning detection

ai-agentsgoshell
0
3
Implementing Anti Phishing Training ProgramA

Guides designing, deploying, and measuring an anti-phishing security awareness program - baseline phishing simulations, interactive training modules, just-in-time learning, and metric tracking - using platforms like KnowBe4, Proofpoint Security Awareness, or Cofense. Use when building or maturing a phishing awareness program, establishing training controls for compliance, or measuring phishing susceptibility and reporting rates over time.

ai-agentssecurityperformance
0
3
Implementing Anti Ransomware Group PolicyA

'Configures Windows Group Policy Objects to block ransomware execution

ai-agentsjavascriptpython
0
3
Implementing Api Abuse Detection With Rate LimitingA

Implements API abuse detection using token bucket, sliding window, and

ai-agentspythongo
0
3
Implementing Api Gateway Security ControlsA

'Configures API gateways such as Kong, AWS API Gateway, Azure APIM,

ai-agentspythongo
0
3
Implementing Api Key Security ControlsA

'Implements secure API key generation with sufficient entropy, server-side

ai-agentspythonbash
0
3
Implementing Api Rate Limiting And ThrottlingA

'Implements API rate limiting and throttling with token bucket, sliding

ai-agentspythonrust
0
3
Implementing Api Schema Validation SecurityA

Implements API schema validation using OpenAPI Specification and JSON

ai-agentsjavascriptpython
0
3
Implementing Api Security Posture ManagementA

Implements API Security Posture Management (API-SPM) to continuously

ai-agentspythongo
0
3
Implementing Api Security Testing With 42crunchA

Implements API security testing on the 42Crunch platform, combining

ai-agentspythongo
0
3
Implementing Api Threat Protection With ApigeeA

Implements API threat protection using Google Apigee reverse-proxy

ai-agentsgobash
0
3
Implementing Application Whitelisting With ApplockerA

'Implements application whitelisting using Windows AppLocker to restrict

ai-agentsjavascriptrust
0
3
Implementing Aqua Security For Container ScanningA

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations,

ai-agentspythongo
0
3
Implementing Attack Path Analysis With Xm CyberA

Deploys XM Cyber's continuous exposure management platform to build

ai-agentspythonrust
0
3
Implementing Attack Surface ManagementA

'Implements external attack surface management (EASM) using Shodan, Censys,

ai-agentspythongo
0
3
Implementing Aws Config Rules For ComplianceA

'Implements AWS Config managed and custom rules for continuous compliance

ai-agentspythonbash
0
3
Implementing Aws Iam Permission BoundariesA

Configures AWS IAM permission boundaries that cap the maximum permissions

ai-agentsrustbash
0
3
Implementing Aws Macie For Data ClassificationA

Enable and configure Amazon Macie via AWS CLI/Terraform to discover, classify, and protect sensitive data (PII, financial data, credentials) in S3 using ML and pattern matching, including discovery jobs, custom data identifiers, allow lists, and EventBridge-based remediation. Use when setting up S3 data classification, cloud DLP, or auditing S3 for unprotected sensitive data.

ai-agentspythongo
0
3
Implementing Aws Nitro Enclave SecurityB

'Build AWS Nitro Enclave confidential computing environments using nitro-cli

ai-agentspythonrust
0
3
Implementing Aws Security Hub ComplianceA

'Deploy AWS Security Hub, backed by AWS Config, to aggregate findings

ai-agentspythonbash
0
3
Implementing Aws Security HubA

'Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS

ai-agentsbashaws
0
3
Implementing Azure Ad Privileged Identity ManagementA

Configure Microsoft Entra Privileged Identity Management (PIM) to convert

ai-agentspythonrust
0
3
Implementing Azure Defender For CloudA

'Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers,

ai-agentsgobash
0
3
Implementing Beyondcorp Zero Trust Access ModelA

'Implement Google''s BeyondCorp zero trust access model using Cloud

ai-agentsrustgo
0
3
Implementing Bgp Security With RpkiD

Implement RPKI-based BGP route origin validation by creating Route Origin

ai-agentspythonrust
0
3
Implementing Browser Isolation For Zero TrustA

'Deploys remote browser isolation (RBI) as a core component of a Zero

ai-agentsjavascriptpython
0
3
Implementing Canary Tokens For Network IntrusionF

'Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure

ai-agentspythonsql
0
3
Implementing Cisa Zero Trust Maturity ModelA

Assess, gap-analyze, and progressively implement the CISA Zero Trust

ai-agentspythonrust
0
3
Implementing Cloud Dlp For Data ProtectionA

'Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft

ai-agentspythongo
0
3
Implementing Cloud Security Posture ManagementA

'Continuously monitor multi-cloud environments (AWS, Azure, GCP) for

ai-agentspythongo
0
3
Implementing Cloud Trail Log AnalysisA

'Implementing AWS CloudTrail log analysis for security monitoring, threat

ai-agentsgobash
0
3
Implementing Cloud Vulnerability Posture ManagementA

Implement multi-cloud CSPM to detect cloud-native misconfigurations

ai-agentspythongo
0
3
Implementing Cloud Waf RulesA

'Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF,

ai-agentsbashsql
0
3
Implementing Cloud Workload ProtectionA

'Implements cloud workload protection using boto3 and google-cloud APIs

ai-agentspythongo
0
3
Implementing Code Signing For ArtifactsA

'Implements code signing for build artifacts (binaries, packages, containers)

ai-agentsrustbash
0
3
Implementing Conditional Access Policies Azure AdA

Configures Microsoft Entra ID (Azure AD) Conditional Access policies for

ai-agentspythonrust
0
3
Implementing Conduit Security For Ot Remote AccessA

'Implements secure conduit architecture for OT remote access under the

ai-agentspythonrust
0
3
Implementing Container Image Minimal Base With DistrolessA

Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using multi-stage build patterns plus debugging and scanning techniques adapted to distroless. Use when hardening container images, cutting attack surface in a container architecture, or answering an assessment finding about bloated base images. Keywords: distroless, multi-stage build, no shell, nonroot tag, debu...

ai-agentspythonrust
0
3
Implementing Container Network Policies With CalicoA

Uses Calico's own policy CRDs beyond the upstream Kubernetes API - GlobalNetworkPolicy, HostEndpoint, NetworkSet, policy tiers, and DNS-based egress rules - applied and audited with calicoctl. Use when a policy must span namespaces or protect the host itself, when egress has to be expressed by domain name, or when ordering policies into tiers. Keywords: calicoctl, GlobalNetworkPolicy, HostEndpoint, NetworkSet, tier, DNS egress, order. Do not use for portable upstream NetworkPolicy - use imple...

ai-agentspythonrust
0
3
Implementing Continuous Security Validation With BasA

Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach,

ai-agentspythongo
0
3
Implementing Data Loss Prevention With Microsoft PurviewA

'Implements DLP policies using Microsoft Purview PowerShell cmdlets and

ai-agentspythonrust
0
3
Implementing Ddos Mitigation With CloudflareA

Configure Cloudflare DDoS protection with managed rulesets, rate limiting,

ai-agentspythongo
0
3
Implementing Deception Based Detection With CanarytokenA

Deploys and monitors Canary Tokens via the Thinkst Canary REST API for

ai-agentspythonaws
0
3
Implementing Delinea Secret Server For PamB

'Implements Delinea Secret Server for privileged access management,

ai-agentsgoshell
0
3
Implementing Device Posture Assessment In Zero TrustA

'Implements device posture assessment as a zero trust access control

ai-agentspythonrust
0
3
Implementing Devsecops Security ScanningA

'Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for

ai-agentspythonbash
0
3
Implementing Diamond Model AnalysisA

The Diamond Model of Intrusion Analysis provides a structured framework

ai-agentspythonnode
0
3