
Claude Skills by Undermybelt
github.com/Undermybelt'Performs advanced network reconnaissance using Nmap''s scripting engine, timing controls, evasion techniques,
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct
Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and
'Conducts comprehensive network penetration tests against authorized target environments by performing host discovery,
Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection
Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies
'This skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial
'Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce
Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API
Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection,
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection,
Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
'Analyzes network traffic generated by malware during sandbox execution or live incident response to identify
'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,
Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies,
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion)
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate
Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying
'Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for
Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation,
'Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations,
'Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra
Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and
'Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception,
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation,
'This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream
Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper
Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters,
Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators
'Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and
Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance,
'Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running
'Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443,
'This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including
'Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset
'This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for
'Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries,
Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments,
'Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for
'Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments
'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents,
Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL.
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
Patch management is the systematic process of identifying, testing, deploying, and verifying software updates