
Claude Skills by oyi77
github.com/oyi77Use when implementing security monitoring using Datadog Cloud SIEM, Cloud
Use when write custom Semgrep SAST rules in YAML to detect application-specific
Use when write multi-event correlation rules that detect APT lateral
Use when tune SIEM detection rules to reduce false positives by analyzing
'Use when implements SIEM detection use cases by designing correlation
Use when implements Sigstore-based software signing and verification
'Use when implements Security Orchestration, Automation, and Response
Use when automating phishing incident response using Splunk SOAR REST
Use when implementing automated incident response playbooks in Cortex
Use when STIX (Structured Threat Information eXpression) and TAXII (Trusted
Use when implement software supply chain integrity verification for container
Use when configuring rsyslog for centralized log collection with TLS
Use when deploying and configuring an OpenTAXII server to share and consume
Use when implement a structured threat intelligence lifecycle encompassing
'Use when implements threat modeling using the MITRE ATT&CK framework
'Use when implements an integrated incident ticketing system connecting
'Use when implements USB device control policies to restrict unauthorized
Use when deploy and configure Velociraptor for scalable endpoint forensic
Use when deploy and operate Greenbone/OpenVAS vulnerability management
Use when vulnerability remediation SLAs define mandatory timeframes for
Use when building automated alerting for vulnerability remediation SLA
Use when configuring ModSecurity WAF with OWASP Core Rule Set (CRS) for
Use when zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge
Use when deploy CyberArk Secure Cloud Access to eliminate standing privileges
Use when implement NextDNS as a zero trust DNS filtering layer with encrypted
Use when implementing zero trust access controls for SaaS applications
Use when this skill guides organizations through implementing zero trust
Use when implementing Zero Trust Network Access (ZTNA) in cloud environments
Use when implement HashiCorp Boundary for identity-aware zero trust infrastructure
Use when this skill covers integrating OWASP ZAP (Zed Attack Proxy) for
Use when this skill covers integrating Static Application Security Testing
'Use when intercepts and analyzes HTTP/HTTPS traffic from mobile applications
'Use when investigates insider threat indicators including data exfiltration
'Use when investigates phishing email incidents from initial user report
Use when identify, collect, and analyze ransomware attack artifacts to
Use when ioT and embedded device security testing — firmware analysis,
'Use when front-end JavaScript reverse engineering for web apps and anti-bot
Use when linux and Windows kernel exploitation for privilege escalation.
Use when this skill covers implementing Okta as a centralized identity
Use when manages the end-to-end cyber threat intelligence lifecycle from
'Use when maps observed adversary behaviors, security alerts, and detection
Use when android and mobile application security testing — emulators,
Use when monitors dark web forums, marketplaces, paste sites, and ransomware
Use when monitors Modbus TCP traffic on SCADA and ICS networks to detect
Use when trace and analyze blockchain transactions to investigate illicit
Use when orchestrate 35 specialized Claude Code subagents for offensive
Use when aI-powered pentesting terminal UI with 4 modes (Assist, Agent,
Use when configure and execute access recertification campaigns in Saviynt
Use when conduct systematic access reviews and certifications to ensure
Use when use BloodHound and SharpHound to enumerate Active Directory