
Claude Skills by oyi77
github.com/oyi77Use when detect DNS-based data exfiltration by analyzing Zeek dns.log
'Use when detects fileless malware and in-memory attacks that execute
Use when detect Kerberos Golden Ticket forgery by analyzing Windows Event
Use when detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including
Use when detect Cobalt Strike beacon network activity using default TLS
Use when proactively hunt for adversary abuse of legitimate system binaries
Use when detect NTLM relay attacks by analyzing Windows Event 4624 logon
Use when detect process injection techniques (T1055) including CreateRemoteThread,
Use when detect MITRE ATT&CK T1547.001 registry Run key persistence by
Use when implement Zero Trust Network Access using Zscaler Private Access
Use when deploy Google BeyondCorp Enterprise zero trust access controls
Use when analyze volatile memory dumps using Volatility 3 to extract
Use when create forensically sound bit-for-bit disk images using dd and
Use when active Directory and Windows domain exploitation for enterprise
Use when aI and LLM security testing — prompt injection, model manipulation,
Use when detect dangerous ACL misconfigurations in Active Directory using
Use when perform static analysis of Android APK malware samples using
'Use when parses API Gateway access logs (AWS API Gateway, Kong, Nginx)
Use when analyze advanced persistent threat (APT) group techniques using
'Use when queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
Use when analyzing bootkit and advanced rootkit malware that infects
Use when analyze Chromium-based browser artifacts using Hindsight to
Use when campaign attribution analysis involves systematically evaluating
Use when monitor Certificate Transparency logs using crt.sh and Certstream
Use when detect abnormal access patterns in AWS S3, GCS, and Azure Blob
Use when extract and analyze Cobalt Strike beacon configuration from
Use when analyzing malware command-and-control (C2) communication protocols
Use when analyzes intrusion activity against the Lockheed Martin Cyber
Use when perform comprehensive forensic analysis of disk images using
'Use when analyzes DNS query logs to detect data exfiltration via DNS
Use when investigate compromised Docker containers by analyzing images,
Use when parse and analyze email headers to trace the origin of phishing
Use when perform static and symbolic analysis of Solidity smart contracts
Use when reverse engineer Go-compiled malware using Ghidra with specialized
Use when detect and analyze heap spray attacks in memory dumps using
'Use when analyzes indicators of compromise (IOCs) including IP addresses,
Use when performs runtime mobile security exploration of iOS applications
'Use when parses Kubernetes API server audit logs (JSON lines) to detect
Use when using the Linux Audit framework (auditd) with ausearch and aureport
Use when analyzing malicious Linux ELF (Executable and Linkable Format)
Use when detect kernel-level rootkits in Linux memory dumps using Volatility3
Use when examine Linux system artifacts including auth logs, cron jobs,
Use when analyze Windows LNK shortcut files and Jump List artifacts to
Use when analyzes malicious VBA macros embedded in Microsoft Office documents
Use when perform static analysis of malicious PDF documents using peepdf,
Use when uRLScan.io is a free service for scanning and analyzing suspicious
Use when executing malware samples in Cuckoo Sandbox to observe runtime
Use when use the Malpedia platform and API to research malware family
Use when use Sysinternals Autoruns to systematically identify and analyze
Use when detect sandbox evasion techniques in malware samples by analyzing