All authors

Claude Skills by plurigrid
github.com/plurigrid2,535 skills6 installs3,507 views
- Implementing Saml Sso With OktaImplement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, aVotes: 0GitHub stars: 61
- Implementing Scim Provisioning With OktaImplement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.Votes: 0GitHub stars: 61
- Implementing Secret Scanning With GitleaksThis skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.Votes: 0GitHub stars: 61
- Implementing Secrets Management With VaultThis skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It addresses eliminating hardcoded credentials from application code and CI/CD pipelines by implementing short-lived, automatically rotated secrets.Votes: 0GitHub stars: 61
- Implementing Secrets Scanning In Ci CdIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deploymentVotes: 0GitHub stars: 61
- Implementing Security Chaos EngineeringImplements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.Votes: 0GitHub stars: 61
- Implementing Security Information Sharing With Stix2Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.Votes: 0GitHub stars: 61
- Implementing Security Monitoring With DatadogImplements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.Votes: 0GitHub stars: 61
- Implementing Semgrep For Custom Sast RulesWrite custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.Votes: 0GitHub stars: 61
- Implementing Siem Correlation Rules For AptWrite multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.Votes: 0GitHub stars: 61
- Implementing Siem Use Case TuningTune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and ElasticVotes: 0GitHub stars: 61
- Implementing Siem Use Cases For DetectionImplements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.Votes: 0GitHub stars: 61
- Implementing Sigstore For Software SigningImplements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain sign...Votes: 0GitHub stars: 61
- Implementing Soar Automation With PhantomImplements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.Votes: 0GitHub stars: 61
- Implementing Soar Playbook For PhishingAutomate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooksVotes: 0GitHub stars: 61
- Implementing Soar Playbook With Palo Alto XsoarImplement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.Votes: 0GitHub stars: 61
- Implementing Stix Taxii Feed IntegrationSTIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.Votes: 0GitHub stars: 61
- Implementing Supply Chain Security With In TotoImplement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.Votes: 0GitHub stars: 61
- Implementing Syslog Centralization With RsyslogConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.Votes: 0GitHub stars: 61
- Implementing Taxii Server With OpentaxiiDeploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.Votes: 0GitHub stars: 61
- Implementing Threat Intelligence Lifecycle ManagementImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.Votes: 0GitHub stars: 61
- Implementing Threat Modeling With Mitre AttackImplements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.Votes: 0GitHub stars: 61
- Implementing Ticketing System For IncidentsImplements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.Votes: 0GitHub stars: 61
- Implementing Usb Device Control PolicyImplements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.Votes: 0GitHub stars: 61
- Implementing Velociraptor For Ir CollectionDeploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.Votes: 0GitHub stars: 61
- Implementing Vulnerability Management With GreenboneDeploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.Votes: 0GitHub stars: 61
- Implementing Vulnerability Remediation SlaVulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programsVotes: 0GitHub stars: 61
- Implementing Vulnerability Sla Breach AlertingBuild automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.Votes: 0GitHub stars: 61
- Implementing Web Application Logging With ModsecurityConfigure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.Votes: 0GitHub stars: 61
- Implementing Zero Knowledge Proof For AuthenticationZero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificatiVotes: 0GitHub stars: 61
- Implementing Zero Standing Privilege With CyberarkDeploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.Votes: 0GitHub stars: 61
- Implementing Zero Trust Dns With NextdnsImplement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.Votes: 0GitHub stars: 61
- Implementing Zero Trust For Saas ApplicationsImplementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.Votes: 0GitHub stars: 61
- Implementing Zero Trust In CloudThis skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.Votes: 0GitHub stars: 61
- Implementing Zero Trust Network Access With ZscalerImplement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.Votes: 0GitHub stars: 61
- Implementing Zero Trust Network AccessImplementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP.Votes: 0GitHub stars: 61
- Implementing Zero Trust With BeyondcorpDeploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.Votes: 0GitHub stars: 61
- Implementing Zero Trust With Hashicorp BoundaryImplement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.Votes: 0GitHub stars: 61
- Implicit CoordinationStigmergic agent coordination through environment modification, not messages. Vehicle semantics where carrier encodes meaning.Votes: 0GitHub stars: 61
- Infinity Operads∞-Operads for pairwise/tritwise Cat# interactions with lazy ACSet materialization unifying effective, realizability, and Grothendieck topoi via dendroidal Segal spaces.Votes: 0GitHub stars: 61
- Influence PropagationLayer 7: Interperspectival Network Analysis and Influence FlowVotes: 0GitHub stars: 61
- Initial Value ProblemExistence and uniqueness of solutions to ODEs with initial conditionsVotes: 0GitHub stars: 61
- Integrating Dast With Owasp Zap In PipelineThis skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and establishing DAST quality gates in GitHub Actions and GitLab CI.Votes: 0GitHub stars: 61
- Integrating Sast Into Github Actions PipelineThis skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.Votes: 0GitHub stars: 61
- Intent SinkIntent Sink SkillVotes: 0GitHub stars: 61
- Intercepting Mobile Traffic With BurpsuiteIntercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.Votes: 0GitHub stars: 61
- Internal CommsWrite internal communications using company formats. Use when writingVotes: 0GitHub stars: 61
- Interpreting Culture IndexUse when interpreting Culture Index surveys, CI profiles, behavioral assessments, or personality data. Supports individual interpretation, team composition (gas/brake/glue), burnout detection, profile comparison, hiring profiles, manager coaching, interview transcript analysis for trait prediction, candidate debrief, onboarding planning, and conflict mediation. Handles PDF vision or JSON input.Votes: 0GitHub stars: 61
- Invariant SetSets preserved by the flowVotes: 0GitHub stars: 61
- Investigating Insider Threat IndicatorsInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.Votes: 0GitHub stars: 61