
Claude Skills by Undermybelt
github.com/Undermybelt'Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication
'Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they
'Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses,
'Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms
Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts
Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated
Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while
Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic
'Uses Postman to perform structured API security testing by building collections that test for OWASP API Security
'Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0,
'Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
'Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy
Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
'Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and
Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,
'Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using
Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library
Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize
'Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder,
'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
'This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems
'Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,
'Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,
'This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS,
'Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous
'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains
'Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and
'Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,
Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify
Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis
'Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom
'Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using
Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time
Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege
'This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce
Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive
'Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries,
Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine
'Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy
'Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations
'Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards
'This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that
Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity
'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative