
Claude Skills by Undermybelt
github.com/Undermybelt'Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through
Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule
'Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging,
'Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
'Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager
Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself
Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based
Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,
'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
'Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including
'Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query
Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure
'Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s
Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials,
Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using
'Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs,
'Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD
Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral
Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement,
Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation,
'Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files
'Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,
'Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives,
'Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers,
Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using
Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling,
'Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover
Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested
Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy,
Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation
'Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security,
'Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing
'Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across
Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection
'This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction,
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning,
'Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant
Configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized
Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service
'Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions,
Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service
'Implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication