
Claude Skills by nuroctane
github.com/nuroctaneRuns Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secrets, and licences, generating CycloneDX or SPDX SBOMs. Use when integrating Trivy into CI/CD, deploying the Trivy Kubernetes operator, scanning non-image targets, or triaging results at scale. Keywords: Trivy, trivy k8s, operator, SBOM, CycloneDX, SPDX, misconfig, secret scanning. Do not use for a ...
Analyze Content-Security-Policy headers and bypass them to achieve cross-site
Extract stored credentials from compromised endpoints using the LaZagne
A cryptographic audit systematically reviews an application's use of
Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog,
Test web applications for path traversal and Local/Remote File Inclusion
'Conduct disk forensics investigations using forensic imaging, file system
Execute a phased DMARC rollout by inventorying sending sources, configuring
Runs Docker Bench for Security, the open-source CIS Docker Benchmark audit script, across host configuration, daemon settings, images, and runtime configuration, then interprets pass/fail/warn output and remediates the common failures. Use when auditing Docker hosts for CIS compliance, scheduling recurring container assessments, or validating runtime hardening controls after a change. Keywords: docker-bench-security, CIS Docker Benchmark, audit script, pass fail warn, host configuration, reme...
'Perform interactive dynamic malware analysis using the ANY.RUN cloud sandbox
'Runs entitlement review and access certification campaigns in SailPoint
Reduces SIEM false positives through systematic rule tuning, threshold
Recovers files from disk images and unallocated space using Foremost's
'Performs firmware image extraction and analysis using binwalk to identify
'Analyzes firmware images for embedded malware, backdoors, and unauthorized
'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting
Performs authorized GCP security testing using GCPBucketBrute to enumerate
'Performs GraphQL introspection attacks that extract the full API schema
Integrates Hardware Security Modules (HSMs) via the PKCS#11 interface
Cracks password hashes with Hashcat, covering hash-type identification,
Executes HTTP Parameter Pollution attacks that inject duplicate request
'Performs ICS/OT asset discovery with Claroty xDome, combining passive
Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan,
Perform authorized initial access using EvilGinx3 adversary-in-the-middle
'Investigates insider threat incidents involving employees, contractors,
Execute and test the JWT none algorithm attack, crafting tokens with
Perform Kerberoasting, a post-exploitation technique that enumerates
Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and packaging evidence for SOC 2 or PCI DSS. Use when conducting a scheduled compliance audit, triaging kube-bench results, deciding which controls are not applicable on EKS, GKE, or AKS, or producing hardening evidence for an auditor. Keywords: CIS Kubernetes Benchmark, control plane, remediation, compli...
Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. Use when auditing or hardening a control plane, reviewing whether Secrets are encrypted at rest, or protecting etcd backups, since etcd stores Secrets, RBAC policy, and ConfigMaps in plaintext by default. Keywords: etcd, EncryptionConfiguration, encryption at rest, peer TLS, snapshot, backup, control plane. Do not us...
Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates, and manual kubectl exploitation to find paths to cluster compromise. Use for an authorized penetration test or hands-on validation that controls actually stop an attacker. Keywords: kube-hunter, Kubescape, peirates, kubelet 10250, anonymous auth, token theft, lateral movement, cluster takeover. ...
'Detects lateral movement techniques including Pass-the-Hash, PsExec,
Perform forensic investigation of Linux system logs including syslog,
Collect, parse, and correlate system, application, and security logs
Perform structured log source onboarding into SIEM platforms (Splunk,
Enrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal
Systematically investigate all persistence mechanisms on Windows and
'Performs rapid malware triage and classification using YARA rules that
Analyze volatile memory (RAM) dumps using the Volatility 3 framework
Acquire and analyze mobile device data using Cellebrite UFED Touch/4PC, UFED Physical Analyzer, and open-source alternatives (ALEAPP, iLEAPP, MEAT, libimobiledevice) to extract communications, call logs, location data, and application artifacts. Use when extracting or recovering deleted evidence from smartphones or tablets during criminal, corporate, or employee-misuse investigations.
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control communications. Use when analyzing captured traffic from a security incident, reconstructing data exfiltration, or finding network indicators of compromise during malware analysis.
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity. Use when a PCAP file from an incident needs to be examined to prove lateral movement, malware delivery, or unauthorized access.
Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs, domains, URLs), and identify DNS tunneling patterns from PCAP files. Use when scripted or repeatable analysis of packet captures is needed rather than interactive inspection.
Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and integrate outputs with SIEM platforms. Use when standing up continuous, high-fidelity network traffic monitoring for threat detection, anomaly identification, or forensic investigation beyond what raw PCAP analysis provides.
Conduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the six core Functions (Govern, Identify, Protect, Detect, Respond, Recover), scoring organizational posture against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) and producing an improvement roadmap. Use when benchmarking an organization's cybersecurity program maturity or preparing a CSF-based gap analysis and remediation plan.
'Performs OAuth 2.0 scope minimization review to identify over-permissioned
Conduct cybersecurity assessments of upstream, midstream, and downstream oil and gas operations, covering pipeline SCADA, refinery DCS, safety instrumented systems, and remote wellhead RTUs, and evaluate compliance with API 1164, TSA Pipeline Security Directives, and IEC 62443. Use when assessing a refinery, pipeline, or production facility or preparing for TSA/API compliance audits; not for IT-only or purely physical-security assessments.
Automate OSINT collection with the SpiderFoot REST API and CLI (sf.py/spiderfoot-cli) across 200+ modules, selecting scan modes (footprint, investigate, passive) and parsing results for domains, IPs, emails, leaked credentials, and DNS records into a target intelligence profile. Use when mapping an organization's attack surface or profiling a target for threat intelligence.
Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe device querying with CVE/ICS-CERT advisory correlation for remediation prioritization. Use for scheduled IEC 62443 or NERC CIP OT vulnerability assessments, initial xDome deployment, or generating CIP-010-4 compliance evidence; not for active PLC scanning or penetration testing.
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials,
Deploy and run authorized phishing awareness campaigns with GoPhish, covering admin panel setup, SMTP sending profiles, email template and landing page creation, target user groups, and campaign reporting to measure click and credential-submission rates. Use when planning or executing a phishing simulation for employee security-awareness testing or measuring susceptibility to social engineering.