
Claude Skills by Undermybelt
github.com/Undermybelt'Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations,
'This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security
'This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection
'Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation
Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source
'This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare
'Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process
'Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible
Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based
Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users
Reduce container attack surface by building application images on Google distroless base images that contain
Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control
'Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed
Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system
Container escape is a critical attack technique where an adversary breaks out of container isolation to access
'Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file
'This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing
Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable
Harbor is an open-source container registry that provides security features including vulnerability scanning
'Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed
'This skill covers integrating Aqua Security''s Trivy scanner into CI/CD pipelines for comprehensive container
Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,
Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM
'This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout
Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation
'Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures,
'Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools
'Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations,
Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows
'Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,
'Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks,
'Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and
'This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases
Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and
'Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational
'This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud
'Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange
Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp
Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like