
Claude Skills by Undermybelt
github.com/Undermybelt'Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing
'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows
Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug
'Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests
Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin
'Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
'Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features
'Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications
'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps
Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine
'Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,
'Implementing device posture assessment as a zero trust access control by integrating endpoint health signals
The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining
Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit
Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on
'Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from
'Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying
Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to
Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate
Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring
'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring
Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,
'Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during
Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT
'Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert
'Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions,
Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive
Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate
Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting
'Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify
'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,
'Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
'Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to
'Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution
'Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network
'Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify
Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in
Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject
Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware
End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary