All authors
nuroctane avatar

Claude Skills by nuroctane

github.com/nuroctane
1,173 skillsA× 1,031B× 97C× 20D× 16F× 90 installs219 views
Implementing Network Intrusion Prevention With SuricataB

Deploys and configures Suricata as an inline network intrusion prevention system,

ai-agentsrustgo
0
3
Implementing Network Policies For KubernetesA

Writes portable upstream Kubernetes NetworkPolicy YAML - default-deny-all, DNS egress, namespace and pod selector rules - that works on any conformant CNI such as Calico or Cilium. Use when segmentation must stay CNI-portable, introducing a default-deny posture, or restricting east-west traffic between pods and namespaces without depending on a vendor CRD. Keywords: NetworkPolicy, default deny, podSelector, namespaceSelector, ingress, egress, CNI portable. Do not use for Calico-specific resou...

ai-agentsrustbash
0
3
Implementing Network Segmentation For OtA

'Implements OT network segmentation using VLANs, OT-aware firewalls, data diodes,

ai-agentspythonrust
0
3
Implementing Network Segmentation With Firewall ZonesA

Designs and implements network segmentation using firewall security zones, VLANs,

ai-agentspythonrust
0
3
Implementing Network Traffic Analysis With ArkimeA

Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,

ai-agentspythonbash
0
3
Implementing Network Traffic BaseliningA

Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python

ai-agentspythonsecurity
0
3
Implementing Next Generation Firewall With Palo AltoA

Configures and deploys Palo Alto Networks next-generation firewalls end-to-end,

ai-agentsrustgo
0
3
Implementing Opa Gatekeeper For Policy EnforcementA

Deploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego plus instantiated Constraints to validate, mutate, or deny resource requests at admission time. Use when enforcing custom policy-as-code at admission on Kubernetes v1.24+, blocking non-compliant workloads before scheduling, or expressing a rule that built-in controls cannot. Keywords: Gatekeeper, ConstraintTemplate, Constraint, Rego, admission webhook, audit, mutation. Do not use for ...

ai-agentsgobash
0
3
Implementing Ot Incident Response PlaybookB

'Develops OT-specific incident response playbooks using a SANS PICERL-based Python

ai-agentspythonrust
0
3
Implementing Ot Network Traffic Analysis With NozomiA

'Deploy Nozomi Networks Guardian sensors for passive OT network traffic

ai-agentspythongo
0
3
Implementing Pam For Database AccessA

Deploy privileged access management for database systems including Oracle,

ai-agentspythonsql
0
3
Implementing Passwordless Auth With Microsoft EntraB

'Implements passwordless authentication using Microsoft Entra ID with

ai-agentsrustgo
0
3
Implementing Passwordless Authentication With Fido2A

Deploy FIDO2/WebAuthn passwordless authentication using security keys

ai-agentspythongo
0
3
Implementing Patch Management For Ot SystemsA

'Implements a structured patch management program for OT/ICS environments

ai-agentspythontesting
0
3
Implementing Pci Dss Compliance ControlsA

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives

ai-agentsgotesting
0
3
Implementing Pod Security Admission ControllerA

Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via AdmissionConfiguration, exemptions for usernames, runtime classes and namespaces, version pinning, and troubleshooting pods the controller rejected. Use when wiring PSA up on a cluster, setting cluster-wide default enforcement, exempting system namespaces, debugging why a pod was rejected or why enforcement is not f...

ai-agentsbashnode
0
3
Implementing Policy As Code With Open Policy AgentA

'Implements policy-as-code enforcement with Open Policy Agent (OPA)

ai-agentsgobash
0
3
Implementing Privileged Access Management With CyberarkA

Deploy CyberArk Privileged Access Management to discover, vault, rotate,

ai-agentspythonsql
0
3
Implementing Privileged Access WorkstationA

Design and implement Privileged Access Workstations (PAWs) using the

ai-agentspythonrust
0
3
Implementing Privileged Session MonitoringD

'Implements privileged session monitoring and recording using PAM

ai-agentspythonshell
0
3
Implementing Proofpoint Email Security GatewayA

Deploy and configure Proofpoint Email Protection as a secure email gateway

ai-agentsgotesting
0
3
Implementing Purdue Model Network SegmentationA

'Implement network segmentation based on the Purdue Enterprise Reference

ai-agentspythonrust
0
3
Implementing Ransomware Backup StrategyA

'Designs a ransomware-resilient backup strategy using the 3-2-1-1-0

ai-agentsrustgo
0
3
Implementing Ransomware Kill Switch DetectionA

'Analyzes ransomware kill switch mechanisms, including mutex-based execution

ai-agentspythongo
0
3
Implementing Rapid7 Insightvm For ScanningA

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines,

ai-agentspythonshell
0
3
Implementing Rbac Hardening For KubernetesA

Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC identity provider. Use when tightening cluster access control, removing excessive ClusterRoleBindings, or hardening service-account permissions against escalation and lateral movement. Keywords: RBAC, Role, ClusterRole, RoleBinding, least privilege, service account, OIDC, cluster-admin. Do not use fo...

ai-agentsgobash
0
3
Implementing Rsa Key Pair ManagementA

Generates, stores, rotates, and manages RSA key pairs following NIST

ai-agentspythongo
0
3
Implementing Runtime Security With TetragonB

Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage...

ai-agentsgobash
0
3
Implementing Saml Sso With OktaA

Implement SAML 2.0 Single Sign-On using Okta as the Identity Provider,

ai-agentspythongo
0
3
Implementing Scim Provisioning With OktaA

Implement automated user lifecycle provisioning and deprovisioning using

ai-agentspythonreact
0
3
Implementing Secrets Management With VaultB

'Deploy HashiCorp Vault for centralized secrets management, covering dynamic

ai-agentsrustbash
0
3
Implementing Security Information Sharing With Stix2A

'Create, validate, and share STIX 2.1 threat intelligence objects (indicators,

ai-agentspythongo
0
3
Implementing Siem Correlation Rules For AptA

Write multi-event correlation rules in Splunk SPL and Sigma format that

ai-agentspythongo
0
3
Implementing Siem Use Case TuningA

Tune SIEM detection rules in Splunk and Elastic to reduce false positives

ai-agentspythongo
0
3
Implementing Sigstore For Software SigningA

'Implements Sigstore-based software signing and verification using Cosign

ai-agentspythonrust
0
3
Implementing Soar Playbook For PhishingA

Automates phishing incident response by calling the Splunk SOAR (Phantom)

ai-agentspythonapi
0
3
Implementing Soar Playbook With Palo Alto XsoarA

Build automated incident response playbooks in Cortex XSOAR (Demisto)

ai-agentsjavascriptpython
0
3
Implementing Stix Taxii Feed IntegrationA

Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and

ai-agentspythonrust
0
3
Implementing Supply Chain Security With In TotoA

Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadata, verifying before deployment, enforcing at Kubernetes admission, and integrating with SLSA. Use when attesting CI/CD pipeline steps, proving an image followed the approved build process, or enforcing provenance at admission. Keywords: in-toto, layout, link metadata, step, inspection, SLSA, prov...

ai-agentspythongo
0
3
Implementing Syslog Centralization With RsyslogA

Configure rsyslog for centralized log collection with TLS encryption,

ai-agentspythonbash
0
3
Implementing Taxii Server With OpentaxiiA

Deploy and configure a TAXII 2.1 server (Medallion) with Docker, publish

ai-agentspythonrust
0
3
Implementing Threat Intelligence Lifecycle ManagementA

Build out a full CTI program around the six-phase threat intelligence

ai-agentspythongo
0
3
Implementing Vulnerability Management With GreenboneA

Deploy and operate Greenbone/OpenVAS vulnerability management using the

ai-agentspythonapi
0
3
Implementing Vulnerability Remediation SlaA

Design a vulnerability remediation SLA program covering asset tiering,

ai-agentspythongo
0
3
Implementing Vulnerability Sla Breach AlertingA

Build an automated SLA breach alerting system for vulnerability remediation,

ai-agentspythongo
0
3
Implementing Web Application Logging With ModsecurityA

Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web

ai-agentssqlsecurity
0
3
Implementing Zero Knowledge Proof For AuthenticationA

Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.

ai-agentspythontesting
0
3
Implementing Zero Standing Privilege With CyberarkA

Deploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.

ai-agentsrustgo
0
3
Implementing Zero Trust Dns With NextdnsB

Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME cloaking, and enforces organizational DNS policy across endpoints. Use when deploying DNS-layer threat blocking and acceptable-use enforcement, or when extending zero trust controls (including Windows 11 Zero Trust DNS) to the DNS resolution path.

ai-agentsrustgo
0
3
Implementing Zero Trust For Saas ApplicationsA

Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity verification and device compliance. Use when adding MFA/device-compliance conditional access, discovering shadow IT, governing OAuth consent grants, or applying session controls to sensitive SaaS data.

ai-agentsrustgo
0
3