All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs404 views
Api Key Sec ControlsA

'Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication

securitypythonbash
0
9
Api Mass Assgnm VulnB

'Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they

testingpythongo
0
9
Api Rate Limiting BypassA

'Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses,

securitypythonrust
0
9
Api Rate Limiting ThrttlA

'Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms

businesspythonrust
0
9
Api Schema Vldtn SecA

Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts

developmentjavascriptpython
0
9
Api Sec Owasp Top 10A

Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated

securityrustbash
0
9
Api Sec Posture MgmtA

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while

devopspythongo
0
9
Api Sec Test 42crunchA

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic

securitypythongo
0
9
Api Sec Test PostmanA

'Uses Postman to perform structured API security testing by building collections that test for OWASP API Security

securityjavascriptjava
0
9
Api Sec TestA

'Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,

securitygosql
0
9
Api Threat Prtctn ApigeeA

Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0,

securitygobash
0
9
App Whtlst ApplckA

'Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints,

devopsjavascriptrust
0
9
Apt Group Mitre NvgtrA

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps

devopspythongo
0
9
Aqua Sec Cntnr ScanA

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues

devopspythongo
0
9
Arp Psnng Net TrafficB

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom

devopspythonrust
0
9
Arp Spoo Atta SmltA

'Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy

securitypythonrust
0
9
Asse Crtc Scor VulnA

Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based

businesspythontesting
0
9
Athntc Scan OpenvasB

Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with

securitypythonbash
0
9
Athntc Vuln ScanB

Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and

securitypythongo
0
9
Atmt Malw Sbms PipeA

'Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and

toolspythonrust
0
9
Atmtd Malware Ana CapeA

Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,

devopspythontesting
0
9
Atmtng Ioc EnrchmA

'Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using

devopspythonrust
0
9
Atta Patt Libr Cti RepoA

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library

securitypythongo
0
9
Attack Path Ana Xm CyberA

Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize

devopspythonrust
0
9
Attack Surface MgmtA

'Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder,

securitypythongo
0
9
Attacks Hstrn ServersA

'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT

securitypythongo
0
9
Attacks Scada SystemsA

'This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems

securitypythongo
0
9
Audi Aws S3 Buck PrmsA

'Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,

securitypythonrust
0
9
Audi Azur Act Dir CfgA

'Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,

securitypythongo
0
9
Audi Clou Cis BnchA

'This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS,

devopsrustgo
0
9
Audi K8s Clus RbacB

'Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous

devopspythonbash
0
9
Audi Tls Cert Trns LogsA

'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains

devopspythonrust
0
9
Audi Trrf Infr SecA

'Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and

devopspythongo
0
9
Auditing Gcp Iam PrmssnA

'Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,

securitypythongo
0
9
Aws Acco Enmr Scou SuitA

Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify

securitypythongo
0
9
Aws Cldtrl AnmlsA

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis

devopspythonaws
0
9
Aws Config Rules CmplncA

'Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom

devopspythonbash
0
9
Aws Crdn Expo TrffD

'Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using

devopspythongo
0
9
Aws Grdd Find AtmtA

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time

devopspythongo
0
9
Aws Iam Prmssn BndrsA

Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege

devopsrustbash
0
9
Aws Iam PrmssnA

'This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce

devopsgobash
0
9
Aws Iam Prvlg EscltnA

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive

securitypythonaws
0
9
Aws Lambda Exctn RolesA

'Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries,

devopsrustbash
0
9
Aws Macie Data ClssfcA

Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine

devopspythongo
0
9
Aws Nitro Enclave SecB

'Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy

devopspythonrust
0
9
Aws Prvlg Escltn AssssmA

'Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations

securitypythonrust
0
9
Aws Sec Hub CmplncA

'Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards

devopspythonbash
0
9
Aws Sec HubA

'This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that

securitybashaws
0
9
Aws Verified Access ZtnaA

Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity

devopsrustgo
0
9
Azur Acti Logs ThreA

'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative

securitypythonreact
0
9