
Claude Skills by oyi77
github.com/oyi77Use when detect NTLM relay attacks through Windows Security Event correlation
Use when detecting and responding to OAuth token theft and replay attacks
Use when detect Pass-the-Hash attacks by analyzing NTLM authentication
Use when detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows
Use when configures Fail2ban with custom filters and actions to detect
Use when detect privilege escalation attempts including token manipulation,
Use when detect and prevent privilege escalation in Kubernetes pods by
Use when detect process hollowing (T1055.012) by analyzing memory-mapped
Use when detects and analyzes process injection techniques used by malware
Use when detect and prevent QR code phishing (quishing) attacks that
'Use when detects ransomware encryption activity in real time using entropy
Use when detects early-stage ransomware indicators in network traffic
Use when detect RDP brute force attacks by analyzing Windows Security
Use when detects rootkit presence on compromised systems by identifying
Use when detecting data exfiltration attempts from AWS S3 buckets by
Use when detects and prevents code injection attacks targeting serverless
Use when detect abuse of service accounts through anomalous interactive
Use when discover and inventory shadow API endpoints that operate outside
Use when detect unauthorized SaaS and cloud service usage (shadow IT)
Use when spearphishing targets specific individuals using personalized,
Use when analyzing WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect
Use when this skill covers detecting sophisticated cyber-physical attacks
'Use when scans GitHub Actions workflows and CI/CD pipeline configurations
Use when detect risky OAuth application consent grants in Azure AD /
Use when detect suspicious PowerShell execution patterns including encoded
Use when detect OS credential dumping techniques targeting LSASS memory,
Use when detect process injection techniques (T1055) including classic
Use when detect abuse of elevation control mechanisms including UAC bypass,
Use when detects typosquatting attacks in npm and PyPI package registries
Use when detect WMI event subscription persistence by analyzing Sysmon
Use when reverse JavaScript-based custom DSL/VM interpreters, non-standard
Use when systematically remove malware, backdoors, and attacker persistence
Use when evaluates and selects Threat Intelligence Platform (TIP) products
Use when executes authorized attack simulations against Active Directory
Use when executes authorized phishing simulation campaigns to assess
Use when red team engagement planning is the foundational phase that
Use when executes comprehensive red team exercises that simulate real-world
Use when exploit misconfigured Active Directory Certificate Services
Use when bloodHound is a graph-based Active Directory reconnaissance
Use when tests APIs for injection vulnerabilities including SQL injection,
Use when analyzes and simulates BGP hijacking scenarios in authorized
Use when tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities
Use when discover and exploit broken link hijacking vulnerabilities by
Use when exploit Kerberos Constrained Delegation misconfigurations in
'Use when tests and exploits deep link (URL scheme and App Link) vulnerabilities
Use when tests APIs for excessive data exposure where endpoints return
Use when detecting and exploiting HTTP request smuggling vulnerabilities
Use when identifying and exploiting Insecure Direct Object Reference
Use when identifies and exploits insecure local data storage vulnerabilities
Use when identifying and exploiting insecure deserialization vulnerabilities