
Claude Skills by oyi77
github.com/oyi77Use when investigate Active Directory compromise by analyzing authentication
Use when enumerate and audit Active Directory forest trust relationships
Use when conduct a focused Active Directory penetration test to enumerate
Use when assess Active Directory security posture using PingCastle, BloodHound,
Use when detect and respond to Adversary-in-the-Middle (AiTM) phishing
Use when configure and execute agentless vulnerability scanning using
Use when use AI and LLM-based reasoning to correlate findings across
Use when perform systematic alert triage in Elastic Security SIEM to
Use when performs automated static analysis of Android applications using
Use when uses Microsoft RESTler to perform stateful REST API fuzzing
Use when performs API inventory and discovery to identify all API endpoints
Use when tests API rate limiting implementations for bypass vulnerabilities
Use when using Postman to perform structured API security testing by
Use when simulates ARP spoofing attacks in authorized lab or pentest
Use when develop and apply a multi-factor asset criticality scoring model
Use when configure and execute authenticated vulnerability scans using
Use when authenticated (credentialed) vulnerability scanning uses valid
Use when deploying and operating CAPEv2 sandbox for automated malware
Use when performing comprehensive security posture assessment of AWS
Use when performing authorized privilege escalation assessments in AWS
Use when simulates bandwidth throttling and network degradation attacks
Use when analyzing binary exploitation techniques including buffer overflows
Use when detect and exploit blind Server-Side Request Forgery vulnerabilities
Use when assess Bluetooth Low Energy device security by scanning, enumerating
Use when monitor for brand impersonation attacks across domains, social
Use when testing web applications for clickjacking vulnerabilities by
Use when perform comprehensive cloud asset inventory and relationship
Use when conduct forensic investigations in cloud environments by collecting
Use when perform forensic investigation of AWS environments using CloudTrail
Use when execute cloud-native incident containment across AWS, Azure,
'Use when uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access
'Use when uses Falco YAML rules for runtime threat detection in containers
Use when hunting for threats in AWS environments using Detective behavior
Use when performing authorized AWS penetration testing using Pacu, the
Use when perform forensic acquisition and analysis of cloud storage services
'Use when detects container escape attempts by analyzing namespace configurations,
Use when this skill covers hardening container images by minimizing attack
Use when scan container images, filesystems, and Kubernetes manifests
Use when analyze and bypass Content Security Policy implementations to
Use when extract stored credentials from compromised endpoints using
Use when a cryptographic audit systematically reviews an application's
Use when testing web applications for Cross-Site Request Forgery vulnerabilities
Use when leverage the CISA Known Exploited Vulnerabilities catalog alongside
Use when dark web monitoring involves systematically scanning Tor hidden
'Use when deploys deception technology including honeypots, honeytokens,
Use when testing web applications for path traversal vulnerabilities
'Use when conducts disk forensics investigations using forensic imaging,
Use when execute a phased DMARC rollout from p=none monitoring through
Use when enumerates DNS records, attempts zone transfers, brute-forces
'Use when detects DNS tunneling by computing Shannon entropy of DNS query