
Claude Skills by oyi77
github.com/oyi77Use when responding to malware infections across enterprise endpoints
Use when simulates man-in-the-middle attacks using Ettercap, mitmproxy,
Use when conducts penetration testing of iOS and Android mobile applications
Use when conducts comprehensive network penetration tests against authorized
Use when pass-the-Ticket (PtT) is a lateral movement technique that uses
Use when responding to phishing incidents by analyzing reported emails,
Use when facilitate structured post-incident reviews to identify root
Use when design and execute a social engineering penetration test including
Use when plan and execute authorized vishing (voice phishing) pretext
Use when spearphishing simulation is a targeted social engineering attack
Use when conducts authorized wireless network penetration tests to assess
Use when implementing Microsoft's Enhanced Security Admin Environment
Use when configure AWS Verified Access to provide VPN-less zero trust
Use when a Certificate Authority (CA) is the trust anchor in a PKI hierarchy,
'Use when configures host-based intrusion detection systems (HIDS) to
Use when hardware Security Modules (HSMs) are tamper-resistant physical
Use when configuring Google Cloud Identity-Aware Proxy (IAP) to enforce
Use when hardening LDAP directory services against common attacks including
Use when configure microsegmentation policies to enforce least-privilege
Use when deploying Cisco Duo multi-factor authentication across enterprise
Use when designs and implements VLAN-based network segmentation on managed
Use when configuring secure OAuth 2.0 authorization flows including Authorization
Use when configures pfSense firewall rules, NAT policies, VPN tunnels,
Use when installs, configures, and tunes Snort 3 intrusion detection
Use when deploys and configures Suricata IDS/IPS with Emerging Threats
Use when tLS 1.3 (RFC 8446) is the latest version of the Transport Layer
Use when configures Microsoft Defender for Endpoint (MDE) advanced protection
'Use when configures Windows Event Logging with advanced audit policies
Use when configuring Zscaler Private Access (ZPA) to replace traditional
'Use when executes containment strategies to stop active adversary operations
Automated continuous bug hunting pipeline that runs 24/7 across multiple
'Use when correlates security events in IBM QRadar SIEM using AQL (Ariel
Use when correlates disparate security incidents, IOCs, and adversary
Use when cryptographic attack techniques for breaking implementations,
Use when starting any cybersecurity task — master router that determines the testing phase (Recon/Validation/Exploitation/Post-Exploitation) and routes to the correct specialized skill (Recon, Web/API/Infra/AD/Cloud/Mobile/Binary/Crypto/Forensics/Threat Intel).
Use when autonomous red team agent executing full attack chains with
Use when analyze DeFi security incidents including flash loan attacks,
Use when deobfuscates malicious JavaScript code used in web-based attacks,
Use when systematically deobfuscate multi-layer PowerShell malware using
'Use when deploys deception-based honeytokens in Active Directory including
Use when deploying Cloudflare Access with Cloudflare Tunnel to provide
'Use when deploys canary files (honeytokens) across file systems to detect
'Use when deploys and configures CrowdStrike Falcon EDR agents across
'Use when deploys and configures osquery for real-time endpoint monitoring
Use when deploying Palo Alto Networks Prisma Access for SASE-based zero
Use when deploys and monitors ransomware canary files across critical
Use when deploy a Software-Defined Perimeter using the CSA v2.0 specification
Use when deploy and configure Tailscale as a WireGuard-based zero trust
Use when detects prompt injection attacks targeting LLM-based applications
Use when this skill covers deploying anomaly detection systems for industrial