
Claude Skills by Undermybelt
github.com/UndermybeltUse the Malpedia platform and API to research malware family relationships, track variant evolution, link families
Build structured communication templates for malware incidents including stakeholder notifications, executive
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction
Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches,
'Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise
Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives
'Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences,
'Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
'This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO
'Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing,
Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields,
'Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create
Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like
'Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules,
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware
'Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
'Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout
Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record
Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect,
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory
Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure
'Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,
'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),
URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content,
'Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception
'Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication,
'Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged
'Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications,
'Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse
'Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems.
MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code
'Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption
'Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate
Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points.
'This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection
Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass,
'Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch
'Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate
Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,
Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts,
Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets,