All authors
nuroctane avatar

Claude Skills by nuroctane

github.com/nuroctane
1,173 skillsA× 1,031B× 97C× 20D× 16F× 90 installs217 views
Performing Physical Intrusion AssessmentA

Conduct authorized physical penetration testing against facilities, server rooms, and restricted areas using tailgating, RFID badge cloning, lock bypassing, rogue network device deployment, and security-guard procedure testing. Use as part of a full-scope red team engagement to evaluate physical security controls and their path to network access, always under signed client authorization.

ai-agentsrustshell
0
3
Performing Power Grid Cybersecurity AssessmentA

Conduct cybersecurity assessments of power grid infrastructure spanning generation, transmission substations, distribution, and EMS control centers, covering NERC CIP compliance verification, IEC 61850 (GOOSE/MMS) substation protocol analysis, and synchrophasor (PMU) network security against threats like Industroyer/CrashOverride. Use for periodic NERC CIP assessments, substation automation or EMS/SCADA security reviews, or regional entity compliance audits; not for non-BES systems or generic...

ai-agentspythongo
0
3
Performing Privilege Escalation On LinuxA

Guides manual enumeration and automated tooling to escalate from a low-privilege

ai-agentspythonaws
0
3
Performing Privileged Account Access ReviewA

Conducts systematic reviews of privileged accounts to validate access

ai-agentsrustgo
0
3
Performing Privileged Account DiscoveryA

Discovers and inventories privileged accounts across enterprise infrastructure,

ai-agentspythontesting
0
3
Performing Purple Team Atomic TestingA

'Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam

ai-agentspythongo
0
3
Performing Ransomware ResponseA

'Executes a structured ransomware incident response from detection through

ai-agentsgotesting
0
3
Performing Ransomware Tabletop ExerciseA

'Plans and facilitates tabletop exercises simulating ransomware incidents,

ai-agentsgotesting
0
3
Performing Red Team Phishing With GophishA

Automates GoPhish phishing simulation campaigns using the Python gophish

ai-agentspythongo
0
3
Performing Red Team With CovenantA

Conducts red team operations using the Covenant C2 framework for authorized

ai-agentspythonshell
0
3
Performing Service Account Credential RotationA

Automates credential rotation for service accounts across Active Directory,

ai-agentspythongo
0
3
Performing Soap Web Service Security TestingB

Performs security testing of SOAP web services by analyzing WSDL definitions

ai-agentspythongo
0
3
Performing Sqlite Database ForensicsA

Performs forensic analysis of SQLite databases by examining B-tree page

ai-agentspythonrust
0
3
Performing Ssl Certificate Lifecycle ManagementA

Automates the full SSL/TLS certificate lifecycle, including generating

ai-agentspythonrust
0
3
Performing Ssl Stripping AttackB

Simulates SSL stripping / HTTPS downgrade attacks using sslstrip, Bettercap, and mitmproxy in authorized lab environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms. Use when performing an authorized penetration test to validate HSTS preloading and TLS certificate handling, demonstrate downgrade-attack risk to stakeholders, or train SOC teams to detect SSL stripping indicators in network traffic.

ai-agentspythongo
0
3
Performing Ssl Tls Inspection ConfigurationA

Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying trusted CA certificates, managing exemptions for certificate-pinned apps, and privacy compliance. Use when setting up or auditing TLS inspection on network security devices to close the encrypted-traffic blind spot.

ai-agentsrustgo
0
3
Performing Ssl Tls Security AssessmentA

Assess SSL/TLS server configurations using the sslyze Python scanning library to evaluate supported protocol versions, cipher suite strength, certificate chain validation, HSTS enforcement, OCSP stapling, and known vulnerabilities such as Heartbleed and ROBOT. Use when conducting a security assessment of a server's TLS configuration or verifying remediation of cipher/certificate weaknesses.

ai-agentspythongo
0
3
Performing Ssrf Vulnerability ExploitationC

Tests web application URL parameters for Server-Side Request Forgery by probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254), internal network services, and protocol handlers (file://, gopher://, dict://) using a Python script, including IP-encoding bypass and DNS rebinding checks. Use during authorized penetration testing to confirm SSRF in a URL-fetching parameter and generate a vulnerability report.

ai-agentspythongo
0
3
Performing Static Malware Analysis With Pe StudioA

Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis tricks, and malicious imports. Use for pre-execution triage of a suspicious Windows executable before sandbox detonation.

ai-agentspythonrust
0
3
Performing Steganography DetectionA

Detects and extracts hidden data embedded in images, audio, and other media files using steganalysis tools such as StegDetect, zsteg, stegsolve, binwalk, steghide, and OpenStego to uncover covert communication channels. Use when investigating suspected data hiding or exfiltration via media files, espionage/insider-threat cases, or anomalies in media file properties found during standard file analysis.

ai-agentspythongo
0
3
Performing Supply Chain Attack SimulationA

Simulates and detects software supply chain attacks: typosquatting detection via Levenshtein distance against popular PyPI package names, dependency confusion testing against private registries, SHA-256 package hash verification, and known-CVE scanning with pip-audit. Use when auditing a project's dependencies for malicious or confused packages, or when assessing package-registry supply-chain risk.

ai-agentspythonrust
0
3
Performing Threat Intelligence Sharing With MispA

Uses PyMISP (the official MISP REST API library) to create events with structured IOCs (IPs, domains, hashes, URLs), enrich them with MITRE ATT&CK tags and galaxy clusters, manage sharing groups and distribution levels, search existing intelligence, and export in STIX 2.1 format. Use when creating, enriching, or sharing threat intelligence events on a MISP instance, or integrating IOC feeds with other platforms.

ai-agentspythontesting
0
3
Performing Threat Landscape Assessment For SectorA

Conducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the attackcti/pandas Python stack, and analyzing exploited CVEs and incident trends from ISAC and vendor reports. Use when producing CTI for risk management or board-level reporting on an industry's threat exposure.

ai-agentspythongo
0
3
Performing Threat Modeling With Owasp Threat DragonA

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF threat model reports. Use during secure design review of an application architecture to build a formal threat model and document mitigations for GRC compliance.

ai-agentsrustgo
0
3
Performing Timeline Reconstruction With PlasoA

Builds comprehensive forensic super-timelines using Plaso (log2timeline and psort) to correlate events across file system metadata, event logs, browser history, and registry artifacts into a unified chronological view. Use during complex forensic investigations that need cross-source event correlation, or when standard log analysis is insufficient to establish the sequence of activities for reporting findings.

ai-agentspythongo
0
3
Performing Vlan Hopping AttackA

Simulates VLAN hopping attacks using switch spoofing and 802.1Q double tagging techniques in authorized lab environments to test VLAN segmentation effectiveness and switch port security. Use during an authorized penetration test to validate trunk port hardening, confirm DTP is disabled on access ports, and demonstrate Layer 2 segmentation bypass risk to network teams.

ai-agentspythongo
0
3
Performing Web Application Firewall BypassA

Bypasses Web Application Firewall protections using encoding tricks,

ai-agentsjavascriptjava
0
3
Performing Web Application Scanning With NiktoA

Runs Nikto, an open-source web server and web application scanner,

ai-agentspythonshell
0
3
Performing Web Application Vulnerability TriageA

Triages web application vulnerability findings from DAST/SAST scanners

ai-agentspythonrust
0
3
Performing Web Cache Deception AttackA

Executes web cache deception attacks by exploiting path normalization

ai-agentsbashaws
0
3
Performing Windows Artifact Analysis With Eric Zimmerman ToolsA

Performs comprehensive Windows forensic artifact analysis using Eric

ai-agentspythongo
0
3
Performing Yara Rule Development For DetectionA

Develops precise YARA and YARA-X rules for malware detection by identifying

ai-agentspythonrust
0
3
Post Exploiting Microsoft Graph With GraphrunnerA

Runs GraphRunner, a PowerShell post-exploitation toolset built on

ai-agentsshellazure
0
3
Recovering Deleted Files With PhotorecA

Recovers deleted files from disk images and storage media using PhotoRec's

ai-agentsgobash
0
3
Recovering From Ransomware AttackA

'Executes structured ransomware incident recovery following NIST/CISA

ai-agentsrustgo
0
3
Red Teaming Llms With GarakA

Runs NVIDIA garak probe suites (jailbreak, prompt injection, data

ai-agentspythongo
0
3
Relaying Ntlm For Adcs Esc8A

Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer,

ai-agentspythongo
0
3
Remediating S3 Bucket MisconfigurationA

'Provides step-by-step procedures for remediating Amazon S3 bucket

ai-agentsgobash
0
3
Reverse Engineering Android Malware With JadxA

'Reverse engineers malicious Android APK files using the JADX decompiler

ai-agentspythongo
0
3
Reverse Engineering Dotnet Malware With DnspyA

'Reverse engineers .NET malware samples using the dnSpy decompiler and

ai-agentspythongo
0
3
Reverse Engineering Malware With GhidraA

'Reverse engineers malware binaries using NSA''s Ghidra disassembler and

ai-agentspythongo
0
3
Reverse Engineering Ransomware Encryption RoutineA

Reverse engineer ransomware encryption routines to identify cryptographic

ai-agentspythongo
0
3
Reverse Engineering Rust MalwareA

Reverse engineers Rust-compiled malware using IDA Pro and Ghidra, covering

ai-agentspythonrust
0
3
Scanning Container Images With GrypeD

Scans container images, filesystems, and SBOMs for known CVEs with Anchore Grype, matching Syft-generated SBOM packages against NVD, GitHub Advisories, and OS-specific feeds with configurable severity thresholds and failure gates. Use when Grype or Syft is the chosen toolchain, when scanning an existing SBOM rather than an image, or when gating a build on severity. Keywords: Grype, Syft, SBOM, NVD, GitHub Advisory, --fail-on, severity threshold. Do not use when the toolchain is Trivy - use sc...

ai-agentsjavascriptpython
0
3
Scanning Containers With Trivy In CicdA

'Integrates Aqua Security''s Trivy scanner into CI/CD pipelines to detect

ai-agentspythongo
0
3
Scanning Docker Images With TrivyB

Scans a Docker image with Trivy for vulnerabilities in OS packages and language dependencies, misconfiguration, exposed secrets, and licence violations, emitting SARIF, CycloneDX, or SPDX output. Use when scanning or gating a specific image, wiring an image scan into CI/CD, or checking an image during an incident investigation. Keywords: Trivy, image scan, --severity, --exit-code, SARIF, ignore file, .trivyignore. Do not use for cluster-wide scanning or non-image targets - use performing-cont...

ai-agentspythonbash
0
3
Scanning Iac And Images With TrivyB

Scans container images, Infrastructure-as-Code (Terraform, CloudFormation,

ai-agentspythongo
0
3
Scanning Kubernetes Manifests With KubesecA

Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it. Use when gating manifests in CI, reviewing YAML or a rendered chart before it reaches a cluster, or explaining why a manifest scored negatively. Keywords: Kubesec, manifest score, securityContext, readOnlyRootFilesystem, runAsNonRoot, CI gate. Do not use for scanning built images for CVEs - use scanni...

ai-agentsgobash
0
3
Scanning Network With Nmap AdvancedA

'Performs advanced network recon using Nmap''s Scripting Engine (NSE),

ai-agentsbashsql
0
3
Securing Agentic Ai Tool InvocationA

Implements defense-in-depth controls at an AI agent's tool-invocation

ai-agentspythonrust
0
3