All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs402 views
Red Team CovenantA

Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener

securitypythonshell
0
9
Red Team Enggmn PlanningA

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE),

securitypythongo
0
9
Red Team ExerciseA

'Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s

securityrustgo
0
9
Red Team Phishing GophisA

Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with

securitypythongo
0
9
Registry Prsstn MchnsmA

Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and

researchgoshell
0
9
Registry Run Key PrsstnA

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry

developmentpythongo
0
9
Remote Access Ot EnvrnmA

'This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors

devopspythonrust
0
9
Reveng Android Malware JA

'Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify

businesspythongo
0
9
Reveng Dotnet Malware DnA

'Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify

developmentpythongo
0
9
Reveng Ios App FridaA

'Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract

developmentjavascriptpython
0
9
Reveng Malware GhidraA

'Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,

businesspythongo
0
9
Reveng Rnsmwr Encryp RouA

Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and

securitypythongo
0
9
Reveng Rust MalwareA

Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated

securitypythonrust
0
9
Rnsm Play Cisa FrmwA

'Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST

securitypythongo
0
9
Rnsmwr AttackA

'Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment

devopsrustgo
0
9
Rnsmwr Backup StrategyA

'Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies,

devopsrustgo
0
9
Rnsmwr Canary FilesA

'Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for

businesspythontesting
0
9
Rnsmwr Encryp BehaviorA

'Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and

devopspythonshell
0
9
Rnsmwr Encryp MchnsmA

'Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to

businesspythongo
0
9
Rnsmwr Kill Switch DtctnA

'Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based

devopspythongo
0
9
Rnsmwr Leak Site IntelA

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence

securitypythongit
0
9
Rnsmwr Net IndctrA

Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration

securitypythonnode
0
9
Rnsmwr Payment WalletsA

'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,

blockchainpythonreact
0
9
Rnsmwr Prcrsr NetA

'Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access

securitypythongo
0
9
Rnsmwr Recv PrcdrsA

Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,

securitygobash
0
9
Rnsmwr RespA

'Executes a structured ransomware incident response from initial detection through containment, forensic analysis,

securitygotesting
0
9
Rnsmwr Tabletop ExerciseA

'Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,

businessgotesting
0
9
Role Mining Rbac OptmztA

Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission

datapythongo
0
9
Rootkit ActivityA

'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified

developmentpythonrust
0
9
Rsa Key Pair MgmtA

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital

testingpythongo
0
9
Runtime App Self PrtctnA

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application

securitypythongo
0
9
Runtime Sec TetragonB

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon

devopsgobash
0
9
S3 Bucket MscnfgA

'This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations

devopsgobash
0
9
S3 Data Exfltr AttemptsA

'Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs,

devopsgobash
0
9
S7comm Protocol Sec AnaA

'Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities

securitypythonrust
0
9
Saml Sso OktaA

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end

securitypythongo
0
9
Sast Gith Acti PipeA

'This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub

developmentjavascripttypescript
0
9
Sbdmn Enmrtn SbfndrA

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map

devopsrustgo
0
9
Sbom Supply Chain VulnsA

'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities

developmentpythongo
0
9
Sca Dpndnc Scan SnykA

'This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source

securitypythongo
0
9
Scad Modb Traf AnmlA

'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized

devopspythonreact
0
9
Scada Hmi Sec AssssmA

'Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based

securitypythongo
0
9
Schdld Task PrsstnA

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task

researchshellsecurity
0
9
Scim Prvsnn OktaA

Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.

securitypythonfastapi
0
9
Sec Alerts SplunkA

'Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events,

businessgoapi
0
9
Sec Chaos EngA

'Implements security chaos engineering experiments that deliberately disable or degrade security controls to

devopspythontesting
0
9
Sec Headers AuditA

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing

securityjavascriptgo
0
9
Sec Incident Ir PlaybookB

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response

securitypythonrust
0
9
Sec IncidentA

'Performs initial triage of security incidents to determine severity, scope, and required response actions using

securityrustgo
0
9
Sec Infrmt Sharing Stix2A

'Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators,

testingpythongo
0
9