
Claude Skills by nuroctane
github.com/nuroctaneDeploys and configures Suricata as an inline network intrusion prevention system,
Writes portable upstream Kubernetes NetworkPolicy YAML - default-deny-all, DNS egress, namespace and pod selector rules - that works on any conformant CNI such as Calico or Cilium. Use when segmentation must stay CNI-portable, introducing a default-deny posture, or restricting east-west traffic between pods and namespaces without depending on a vendor CRD. Keywords: NetworkPolicy, default deny, podSelector, namespaceSelector, ingress, egress, CNI portable. Do not use for Calico-specific resou...
'Implements OT network segmentation using VLANs, OT-aware firewalls, data diodes,
Designs and implements network segmentation using firewall security zones, VLANs,
Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,
Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python
Configures and deploys Palo Alto Networks next-generation firewalls end-to-end,
Deploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego plus instantiated Constraints to validate, mutate, or deny resource requests at admission time. Use when enforcing custom policy-as-code at admission on Kubernetes v1.24+, blocking non-compliant workloads before scheduling, or expressing a rule that built-in controls cannot. Keywords: Gatekeeper, ConstraintTemplate, Constraint, Rego, admission webhook, audit, mutation. Do not use for ...
'Develops OT-specific incident response playbooks using a SANS PICERL-based Python
'Deploy Nozomi Networks Guardian sensors for passive OT network traffic
Deploy privileged access management for database systems including Oracle,
'Implements passwordless authentication using Microsoft Entra ID with
Deploy FIDO2/WebAuthn passwordless authentication using security keys
'Implements a structured patch management program for OT/ICS environments
Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives
Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via AdmissionConfiguration, exemptions for usernames, runtime classes and namespaces, version pinning, and troubleshooting pods the controller rejected. Use when wiring PSA up on a cluster, setting cluster-wide default enforcement, exempting system namespaces, debugging why a pod was rejected or why enforcement is not f...
'Implements policy-as-code enforcement with Open Policy Agent (OPA)
Deploy CyberArk Privileged Access Management to discover, vault, rotate,
Design and implement Privileged Access Workstations (PAWs) using the
'Implements privileged session monitoring and recording using PAM
Deploy and configure Proofpoint Email Protection as a secure email gateway
'Implement network segmentation based on the Purdue Enterprise Reference
'Designs a ransomware-resilient backup strategy using the 3-2-1-1-0
'Analyzes ransomware kill switch mechanisms, including mutex-based execution
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines,
Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC identity provider. Use when tightening cluster access control, removing excessive ClusterRoleBindings, or hardening service-account permissions against escalation and lateral movement. Keywords: RBAC, Role, ClusterRole, RoleBinding, least privilege, service account, OIDC, cluster-admin. Do not use fo...
Generates, stores, rotates, and manages RSA key pairs following NIST
Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage...
Implement SAML 2.0 Single Sign-On using Okta as the Identity Provider,
Implement automated user lifecycle provisioning and deprovisioning using
'Deploy HashiCorp Vault for centralized secrets management, covering dynamic
'Create, validate, and share STIX 2.1 threat intelligence objects (indicators,
Write multi-event correlation rules in Splunk SPL and Sigma format that
Tune SIEM detection rules in Splunk and Elastic to reduce false positives
'Implements Sigstore-based software signing and verification using Cosign
Automates phishing incident response by calling the Splunk SOAR (Phantom)
Build automated incident response playbooks in Cortex XSOAR (Demisto)
Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and
Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadata, verifying before deployment, enforcing at Kubernetes admission, and integrating with SLSA. Use when attesting CI/CD pipeline steps, proving an image followed the approved build process, or enforcing provenance at admission. Keywords: in-toto, layout, link metadata, step, inspection, SLSA, prov...
Configure rsyslog for centralized log collection with TLS encryption,
Deploy and configure a TAXII 2.1 server (Medallion) with Docker, publish
Build out a full CTI program around the six-phase threat intelligence
Deploy and operate Greenbone/OpenVAS vulnerability management using the
Design a vulnerability remediation SLA program covering asset tiering,
Build an automated SLA breach alerting system for vulnerability remediation,
Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web
Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.
Deploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.
Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME cloaking, and enforces organizational DNS policy across endpoints. Use when deploying DNS-layer threat blocking and acceptable-use enforcement, or when extending zero trust controls (including Windows 11 Zero Trust DNS) to the DNS resolution path.
Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity verification and device compliance. Use when adding MFA/device-compliance conditional access, discovering shadow IT, governing OAuth consent grants, or applying session controls to sensitive SaaS data.