All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs404 views
Dbfsct Js MalwareA

'Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing

developmentjavascriptpython
0
9
Dcom Lateral MovementA

'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows

securitypythongo
0
9
Dcptn Based Dtctn CnrytkA

Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug

devopspythonaws
0
9
Dcptn Tchnlg DplymnA

'Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have

devopspythongo
0
9
Dcsync Attack Act DirA

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes

securitypythongo
0
9
Dcsync AttacksA

Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests

securitypythonazure
0
9
Ddos Mtgtn CldflrA

Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin

securitypythongo
0
9
Decoy Files Rnsmwr DtctnA

'Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.

businesspythongo
0
9
Deep Audi Vish AttaA

'Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features

businesspythongo
0
9
Deeplink VulnsA

'Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications

securityjavascriptgo
0
9
Defense Evasion TmstmpA

'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps

devopspythonshell
0
9
Deleted Files PhotorecA

Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine

toolsgobash
0
9
Deli Secr Serv PamB

'Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,

devopsgoshell
0
9
Devi Post Asss Zero TrusA

'Implementing device posture assessment as a zero trust access control by integrating endpoint health signals

securitypythonrust
0
9
Diamond Model AnaA

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining

securitypythonnode
0
9
Digital Sgntrs Ed25519A

Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit

testingpythongo
0
9
Dir Trvrsl TestC

Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on

securitygophp
0
9
Disk Encryp BtlckrA

'Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from

securityrustgo
0
9
Disk Frnscs InvA

'Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and

toolsgoshell
0
9
Disk Image AutopsyA

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and

securitygojava
0
9
Dkr Bench Sec AssssmA

Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying

devopsrustbash
0
9
Dkr Cntnr FrnscsD

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to

devopspythongo
0
9
Dkr Images TrivyB

Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS

devopspythonbash
0
9
Dll Sdldng AttacksA

Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack

securityrustgo
0
9
Dmarc Dkim Spf Email SecA

SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate

devopspythongo
0
9
Dmarc Policy Enfrcm RollA

Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring

devopsgotesting
0
9
Dnp3 Protocol AnmlsA

'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring

devopspythonsecurity
0
9
Dns Based PrsstnA

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,

devopspythonrails
0
9
Dns Enmrtn Zone TransferA

'Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during

securitygobash
0
9
Dns Exfltr Dns Query AnaA

Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT

datapythonbash
0
9
Dns Logs ExfltrA

'Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert

devopspythongo
0
9
Dns Tnnlng DtctnA

'Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions,

securitypythongo
0
9
Dns Tnnlng ZeekA

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive

devopsbashgit
0
9
Doma Fron C2 TrafA

Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate

devopspythonazure
0
9
Domain Prsstn DcsyncA

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting

securitypythongo
0
9
Dragos Platform Ot MonA

'Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol

securitypythongo
0
9
Dtctn Rule Splunk SplA

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify

securitygoshell
0
9
Dtctn Rules SigmaA

'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms

toolspythongo
0
9
Dvsc Pipe Gitl CiA

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,

securitygojava
0
9
Dvscps Sec ScanA

'Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software

devopspythonbash
0
9
Dynamic Ana Android AppA

'Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to

securityjavascriptpython
0
9
Dynamic Ana Any RunA

'Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution

securityrustgo
0
9
Ebpf Sec MonC

'Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network

devopspythongo
0
9
Edr Agent CrwdstB

'Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat

devopsgoshell
0
9
Emai Frwr Rule AttaA

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications

researchsecurity
0
9
Emai Head Phis InvB

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify

developmentjavascriptpython
0
9
Email Account CmprmsA

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in

securitypythongo
0
9
Email Header InjctnB

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject

securityrustgo
0
9
Email Sndbxn PrfpntA

Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware

securityapisecurity
0
9
End End Encryp MssgngA

End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary

securitypythongo
0
9