
Claude Skills by Undermybelt
github.com/Undermybelt'This skill covers implementing a structured patch management program for OT/ICS environments where traditional
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,
'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation,
Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported
'Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
'Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device
'This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including
Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace
'This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes
'Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts,
Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce
'Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards.
'This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced
Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware,
'Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices,
Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child
'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,
Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum
Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD
Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,
Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across
'Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and
Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised
Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration
Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions,
Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local
'Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing
Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn
'Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for
'Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate
'Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the
'Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,
Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious
Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings,
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for