
Claude Skills by Undermybelt
github.com/UndermybeltIntegrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength.
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns,
Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing
'Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records)
'Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible
'Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and
Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web
'Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface,
'Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack
Hardening Docker containers for production involves applying security best practices aligned with CIS Docker
Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless
'Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates
Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and
'This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting
Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding
'Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty
'Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using
'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute
Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID)
Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based
'Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation,
Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle
Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources
'This skill covers designing and implementing security zones and conduits for industrial automation and control
Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations,
'Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant
'Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership
'Designs and documents structured incident response playbooks that define step-by-step procedures for specific
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source
'Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts
'Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security
Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment,
'This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using
Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network
Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session
'Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including
Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications
'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
'Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
'Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure
'Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy
'Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation,
Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption
Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing