All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs404 views
Ioc Enrc Pipe OpenA

OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its

developmentpythonrust
0
9
Ioc Enrchm AtmtnA

'Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan,

devopspythonrust
0
9
Ios App Sec AssssmA

'Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection

securityjavascriptpython
0
9
Ios App Sec ObjctnA

'Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that

developmentjavascriptpython
0
9
Iot Sec AssssmF

'Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces,

securitypythongo
0
9
Ip Rpttn Ana ShodanA

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities,

securitypythontesting
0
9
Ipv6 VulnsA

'Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding,

securitypythonbash
0
9
Iso 2700 Infr Sec MgmtA

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete

devopsrustgo
0
9
Json Web Token VulnsA

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid

securitypythongo
0
9
Just Time Access PrvsnnA

Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound

securitypythonrust
0
9
Jwt Algrth Cnfsn AttackB

'Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the

securitypythonrust
0
9
Jwt None Algrth AttackA

Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header

securitypythongo
0
9
Jwt Signing VrfctnA

JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization

securitypythongo
0
9
Jwt Token SecA

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization

securitypythongo
0
9
K8s Audit LogsA

'Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications,

devopspythonshell
0
9
K8s Cis Bnchmr Kube BencA

Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control

securitygobash
0
9
K8s CloudA

'This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards,

devopsrustgo
0
9
K8s Etcd Sec AssssmA

Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration,

securityrustgo
0
9
K8s Mnfsts KubesecA

Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations,

devopsgobash
0
9
K8s Net Policy CalicoA

Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod

devopsrustbash
0
9
K8s Pntrtn TestC

Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against

securitybashnode
0
9
K8s Pod Sec StndrdA

Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted

devopsbashkubernetes
0
9
Krbrst AttackA

Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting

securitypythonshell
0
9
Krbrst AttacksA

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with

researchgosecurity
0
9
Krbrst ImpacketA

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active

securityshellbash
0
9
Lateral Movement DtctnA

'Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based

securitygoshell
0
9
Lateral Movement NetA

'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,

securitygoshell
0
9
Lateral Movement SplunkA

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,

securitygoshell
0
9
Lateral Movement WmiA

Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for

devopspythonshell
0
9
Lateral Movement WmiexecA

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket

securitypythongo
0
9
Lateral Movement ZeekA

'Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log,

devopspythonbash
0
9
Ldap Sec HrdnngA

Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous

securitypythontesting
0
9
Lin Audit Logs IntrsnD

'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized

securityshellbash
0
9
Lin Elf MalwareC

'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware,

devopspythongo
0
9
Lin Kernel RootkitsA

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules),

devopspythongo
0
9
Lin Log Frnscs InvB

Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and

securitypythongo
0
9
Lin System ArtfctD

Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover

securitypythongo
0
9
Living Off Cloud TchnqsA

Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse

devopsgoaws
0
9
Living Off Land AttacksA

'Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process

devopsjavascriptpython
0
9
Living Off Land BinariesA

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while

researchrustshell
0
9
Living Off Land LolbasA

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32

devopspythongit
0
9
Llm Grdrls SecA

'Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection,

securitypythongo
0
9
Lnk File Jump List ArtfA

Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution,

devopspythonshell
0
9
Log Ana Forensic InvB

Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines

securitypythongo
0
9
Log Frwrdn FluentdA

Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed

devopspythonruby
0
9
Log Intgrt BlckchA

Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is

testingpythonbash
0
9
Log Source Onbrdn SiemA

Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization,

devopsgoshell
0
9
Lolb Exct Endp LogsA

Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs

devopsjavascriptgo
0
9
Macr Malw Offi DcmnA

'Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download

toolspythongo
0
9
Malw Beha Cuck SandA

'Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system

developmentpythonphp
0
9