
Claude Skills by Undermybelt
github.com/UndermybeltConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows,
Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin
Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing
'Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across
Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel
'This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application
Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,
'Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the
'Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation,
Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and
'Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library.
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions,
'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
'Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments
'Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached
'Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation
Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect
'Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive
Systematically testing web applications for broken access control vulnerabilities including privilege escalation,
Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege
'Implementing Google''s BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter,
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing
Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or
'Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates,
Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications,
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting
'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications,
Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security
'Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud
Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify
Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata
Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking
'Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
'Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation.
'Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
'Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate
'This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP