All authors

Claude Skills by plurigrid
github.com/plurigrid2,535 skills6 installs3,507 views
- Hunting For Persistence Via Wmi SubscriptionsHunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.Votes: 0GitHub stars: 61
- Hunting For Process Injection TechniquesDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetryVotes: 0GitHub stars: 61
- Hunting For Registry Persistence MechanismsHunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.Votes: 0GitHub stars: 61
- Hunting For Registry Run Key PersistenceDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.Votes: 0GitHub stars: 61
- Hunting For Scheduled Task PersistenceHunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.Votes: 0GitHub stars: 61
- Hunting For Shadow Copy DeletionHunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.Votes: 0GitHub stars: 61
- Hunting For Spearphishing IndicatorsHunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.Votes: 0GitHub stars: 61
- Hunting For Startup Folder PersistenceDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.Votes: 0GitHub stars: 61
- Hunting For Supply Chain CompromiseHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.Votes: 0GitHub stars: 61
- Hunting For Suspicious Scheduled TasksHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.Votes: 0GitHub stars: 61
- Hunting For T1098 Account ManipulationHunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.Votes: 0GitHub stars: 61
- Hunting For Unusual Network ConnectionsHunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.Votes: 0GitHub stars: 61
- Hunting For Unusual Service InstallationsDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.Votes: 0GitHub stars: 61
- Hunting For Webshell ActivityHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.Votes: 0GitHub stars: 61
- Hy EmacsHylang Emacs integration with hy-mode, Hyuga LSP, and DisCoPy sexp coloringVotes: 0GitHub stars: 61
- HythermalHyThermal SkillVotes: 0GitHub stars: 61
- Iecsat StorageIECsat Storage SkillVotes: 0GitHub stars: 61
- Ies TriadicIES Triadic SkillVotes: 0GitHub stars: 61
- IesiesVotes: 0GitHub stars: 61
- Ikea Varmblixt Smart LampIKEA VARMBLIXT smart donut lamp (Matter over Thread). Use when pairing, factory resetting, troubleshooting, configuring, or integrating the VARMBLIXT with Apple Home, Google Home, Amazon Alexa, SmartThings, Home Assistant, or other Matter ecosystems. Covers BILRESA remote, wall mounting, color quirks.Votes: 0GitHub stars: 61
- Image EnhancerImproves the quality of images, especially screenshots, by enhancingVotes: 0GitHub stars: 61
- Implementing Aes Encryption For Data At RestAES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM mVotes: 0GitHub stars: 61
- Implementing Alert Fatigue ReductionImplements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.Votes: 0GitHub stars: 61
- Implementing Anti Phishing Training ProgramSecurity awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positivVotes: 0GitHub stars: 61
- Implementing Anti Ransomware Group PolicyConfigures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy.Votes: 0GitHub stars: 61
- Implementing Api Abuse Detection With Rate LimitingImplement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.Votes: 0GitHub stars: 61
- Implementing Api Gateway Security ControlsImplements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) to act as a centralized security enforcement point that validates, throttles, and monitors all API traffic before it reaches backend services. Activates for requests involving API gateway security, API management security, gateway a...Votes: 0GitHub stars: 61
- Implementing Api Key Security ControlsImplements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Activates for requests involving API key management, API key security, key rotation policy, or API credenti...Votes: 0GitHub stars: 61
- Implementing Api Rate Limiting And ThrottlingImplements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers. Activates for requests involving rate limiting implementation, API t...Votes: 0GitHub stars: 61
- Implementing Api Schema Validation SecurityImplement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.Votes: 0GitHub stars: 61
- Implementing Api Security Posture ManagementImplement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.Votes: 0GitHub stars: 61
- Implementing Api Security Testing With 42crunchImplement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.Votes: 0GitHub stars: 61
- Implementing Api Threat Protection With ApigeeImplement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.Votes: 0GitHub stars: 61
- Implementing Application Whitelisting With ApplockerImplements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.Votes: 0GitHub stars: 61
- Implementing Aqua Security For Container ScanningDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.Votes: 0GitHub stars: 61
- Implementing Attack Path Analysis With Xm CyberDeploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.Votes: 0GitHub stars: 61
- Implementing Attack Surface ManagementImplements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.Votes: 0GitHub stars: 61
- Implementing Aws Config Rules For ComplianceImplementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts.Votes: 0GitHub stars: 61
- Implementing Aws Iam Permission BoundariesConfigure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.Votes: 0GitHub stars: 61
- Implementing Aws Macie For Data ClassificationImplement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.Votes: 0GitHub stars: 61
- Implementing Aws Nitro Enclave SecurityImplements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activate...Votes: 0GitHub stars: 61
- Implementing Aws Security Hub ComplianceImplementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.Votes: 0GitHub stars: 61
- Implementing Aws Security HubThis skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations Benchmark, configuring automated remediation, and building executive dashboards for compliance tracking across multi-account AWS organizations.Votes: 0GitHub stars: 61
- Implementing Azure Ad Privileged Identity ManagementConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.Votes: 0GitHub stars: 61
- Implementing Azure Defender For CloudImplementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.Votes: 0GitHub stars: 61
- Implementing Beyondcorp Zero Trust Access ModelImplementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.Votes: 0GitHub stars: 61
- Implementing Bgp Security With RpkiImplement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.Votes: 0GitHub stars: 61
- Implementing Browser Isolation For Zero TrustDeploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention controls within isolated sessions, and integration with Secure Web Gateway and ZTNA platforms. Based on Cloudflare Browser Isolation, Menlo Security, and Zscaler RBI approaches. Use when hardening web access against zero-day exploits, phishing...Votes: 0GitHub stars: 61
- Implementing Canary Tokens For Network IntrusionDeploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.Votes: 0GitHub stars: 61
- Implementing Cisa Zero Trust Maturity ModelImplement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.Votes: 0GitHub stars: 61