
Claude Skills by oyi77
github.com/oyi77Use when analyzes RAM memory dumps from compromised systems using the
'Use when performs Linux memory acquisition using LiME (Linux Memory
Use when analyze the NTFS Master File Table ($MFT) to recover metadata
Use when detect and analyze covert communication channels used by malware
Use when parse NetFlow v9 and IPFIX records to detect volumetric anomalies,
Use when craft, send, sniff, and dissect network packets using Scapy
'Use when analyzes network traffic captures and flow data to identify
Use when analyzes network traffic generated by malware during sandbox
Use when captures and analyzes network packet data using Wireshark and
Use when parse Office 365 Unified Audit Logs via Microsoft Graph API
Use when analyze Microsoft Outlook PST and OST files for email forensic
Use when identifying and unpacking UPX-packed and other packed malware
Use when analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf
Use when detect and analyze Linux persistence mechanisms including crontab
Use when detect PowerShell Empire framework artifacts in Windows event
Use when parse Windows PowerShell Script Block Logs (Event ID 4104) from
Use when parse Windows Prefetch files to determine program execution
Use when analyzing encryption algorithms, key management, and file encryption
Use when monitor and analyze ransomware group data leak sites (DLS) to
Use when identify ransomware network indicators including C2 beaconing
Use when traces ransomware cryptocurrency payment flows using blockchain
Use when parsing Software Bill of Materials (SBOM) in CycloneDX and SPDX
Use when leverages Splunk Enterprise Security and SPL (Search Processing
Use when examine file system slack space, MFT entries, USN journal, and
Use when investigate supply chain attack artifacts including trojanized
Use when MITRE ATT&CK is a globally-accessible knowledge base of adversary
'Use when analyzes structured and unstructured threat intelligence feeds
Use when analyzing the threat landscape using MISP (Malware Information
Use when querying Certificate Transparency logs via crt.sh and pycrtsh
Use when detecting typosquatting, homograph phishing, and brand impersonation
Use when analyzing UEFI bootkit persistence mechanisms including firmware
Use when investigate USB device connection history from Windows registry,
Use when parse Apache and Nginx access logs to detect SQL injection attempts,
Use when parses and analyzes the Windows Amcache.hve registry hive to
'Use when analyzes Windows Security, System, and Sysmon event logs in
Use when extract and analyze Windows Registry hives to uncover user activity,
Use when analyze Windows Shellbag registry artifacts to reconstruct folder
Use when aggressive API security testing for REST, GraphQL, gRPC, and
Use when systematically audit AWS S3 bucket permissions to identify publicly
Use when auditing Microsoft Entra ID (Azure Active Directory) configuration
Use when this skill details how to conduct cloud security audits using
Use when auditing Google Cloud Platform IAM permissions to identify overly
Use when auditing Kubernetes cluster RBAC configurations to identify
Use when auditing Terraform infrastructure-as-code for security misconfigurations
Use when monitors Certificate Transparency (CT) logs to detect unauthorized
Use when authentication and authorization bypass specialist — OAuth,
Use when automates the enrichment of raw indicators of compromise with
Automated reconnaissance using BBOT (Black Lantern Security's recursive
Use when binary exploitation and reverse engineering for finding zero-days
Use when find and prioritize high-paying bug bounty programs. Use when