
Claude Skills by oyi77
github.com/oyi77Use when detects anomalous authentication patterns using UEBA analytics,
Use when detect and prevent API enumeration attacks including BOLA and
Use when detect and prevent ARP spoofing attacks using ARPWatch, Dynamic
Use when detect cyber attacks targeting OT historian servers (OSIsoft
Use when this skill covers detecting cyber attacks targeting Supervisory
Use when detect unusual API call patterns in AWS CloudTrail logs using
Use when detecting exposed AWS credentials in source code repositories,
Use when automating AWS GuardDuty threat detection findings processing
Use when detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining
Use when detect lateral movement in Azure AD/Entra ID environments using
Use when detect and investigate Azure service principal abuse including
Use when audit Azure Blob and ADLS storage accounts for public access
'Use when performs statistical analysis of Zeek conn.log connection intervals
Use when detects and analyzes Bluetooth Low Energy (BLE) security attacks
Use when detect and test for OWASP API3:2023 Broken Object Property Level
Use when business Email Compromise (BEC) is a sophisticated fraud scheme
Use when this skill teaches security teams how to deploy and operationalize
Use when detecting command-and-control (C2) communications tunneled through
Use when detecting compromised cloud credentials across AWS, Azure, and
Use when detect unauthorized modifications to running containers by monitoring
Use when container escape is a critical attack technique where an adversary
Use when detect container escape attempts in real-time using Falco runtime
Use when detect LSASS credential dumping, SAM database extraction, and
Use when this skill teaches security teams how to detect and respond
Use when detect DCSync attacks where adversaries abuse Active Directory
Use when detecting AI-generated deepfake audio used in voice phishing
Use when detect DLL side-loading attacks where adversaries place malicious
Use when detect anomalies in DNP3 (Distributed Network Protocol 3) communications
Use when detect data exfiltration through DNS tunneling by analyzing
Use when detect compromised O365 and Google Workspace email accounts
Use when detect malicious email forwarding rules created by adversaries
'Use when detects defense evasion techniques used by adversaries in endpoint
Use when detects and analyzes fileless malware that operates entirely
Use when detect Golden Ticket attacks in Active Directory by analyzing
'Use when detects insider data exfiltration by analyzing DLP policy violations,
Use when detect insider threat behavioral indicators including unusual
Use when implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch
Use when detect Kerberoasting attacks by monitoring for anomalous Kerberos
Use when identifies lateral movement techniques in enterprise networks
Use when detect adversary lateral movement across networks using Splunk
Use when detect lateral movement in network traffic using Zeek (formerly
Use when detect abuse of legitimate Windows binaries (LOLBins) used for
Use when detecting malicious scheduled task creation and modification
Use when detect Mimikatz execution through command-line patterns, LSASS
Use when detecting misconfigured Azure Storage accounts including publicly
'Use when detects and analyzes malicious behavior in mobile applications
Use when detect command injection attacks against Modbus TCP/RTU protocol
Use when this skill covers detecting anomalies in Modbus/TCP and Modbus
Use when deploying and configuring Zeek (formerly Bro) network security
Use when detect network reconnaissance and port scanning using Suricata