
Claude Skills by oyi77
github.com/oyi77Use when hunt for adversary abuse of Living Off the Land Binaries (LOLBins)
Use when systematically hunt for adversary persistence mechanisms across
Use when hunt for adversary persistence through Windows Management Instrumentation
Use when hunt for registry-based persistence mechanisms including Run
Use when hunt for adversary persistence via Windows Scheduled Tasks by
Use when hunt for Volume Shadow Copy deletion activity that indicates
Use when hunt for spearphishing campaign indicators across email logs,
Use when detect T1547.001 startup folder persistence by monitoring Windows
Use when hunt for supply chain compromise indicators including trojanized
Use when hunt for adversary persistence and execution via Windows scheduled
Use when hunt for MITRE ATT&CK T1098 account manipulation including shadow
Use when hunt for unusual network connections by analyzing outbound traffic
Use when detect suspicious Windows service installations (MITRE ATT&CK
Use when hunt for web shell deployments on internet-facing servers by
Use when AES (Advanced Encryption Standard) is a symmetric block cipher
'Use when implements strategies to reduce SOC alert fatigue by tuning
Use when security awareness training is the human layer of phishing defense.
Use when configures Windows Group Policy Objects (GPO) to prevent ransomware
Use when implement API abuse detection using token bucket, sliding window,
Use when implements security controls at the API gateway layer including
Use when implements secure API key generation, storage, rotation, and
Use when implements API rate limiting and throttling controls using token
Use when implement API schema validation using OpenAPI specifications
Use when implement API Security Posture Management to continuously discover,
Use when implement comprehensive API security testing using the 42Crunch
Use when implement API threat protection using Google Apigee policies
'Use when implements application whitelisting using Windows AppLocker
Use when deploy Aqua Security's Trivy scanner to detect vulnerabilities,
Use when deploy XM Cyber's continuous exposure management platform to
'Use when implements external attack surface management (EASM) using
Use when implementing AWS Config rules for continuous compliance monitoring
Use when configure IAM permission boundaries in AWS to delegate role
Use when implement Amazon Macie to automatically discover, classify,
Use when implements AWS Nitro Enclave-based confidential computing environments
Use when implementing AWS Security Hub to aggregate security findings
Use when this skill covers deploying AWS Security Hub as a centralized
Use when configure Microsoft Entra Privileged Identity Management to
Use when implementing Microsoft Defender for Cloud to enable cloud security
Use when implementing Google's BeyondCorp zero trust access model to
Use when implement BGP route origin validation using RPKI with Route
Use when deploys remote browser isolation (RBI) as a core component of
'Use when deploys DNS, HTTP, and AWS API key canary tokens across network
Use when implement the CISA Zero Trust Maturity Model v2.0 across the
Use when implementing Cloud Data Loss Prevention (DLP) using Amazon Macie,
Use when implementing Cloud Security Posture Management (CSPM) to continuously
Use when implementing AWS CloudTrail log analysis for security monitoring,
Use when implement Cloud Security Posture Management using AWS Security
Use when this skill covers deploying and tuning Web Application Firewall
'Use when implements cloud workload protection using boto3 and google-cloud
Use when this skill covers implementing code signing for build artifacts