
Claude Skills by Undermybelt
github.com/UndermybeltConduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener
Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE),
'Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with
Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and
Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry
'This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors
'Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify
'Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify
'Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract
'Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated
'Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
'Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment
'Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies,
'Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for
'Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and
'Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to
'Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based
Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence
Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration
'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
'Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,
'Executes a structured ransomware incident response from initial detection through containment, forensic analysis,
'Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,
Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission
'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified
RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital
Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application
Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon
'This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations
'Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs,
'Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities
Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end
'This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities
'This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source
'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized
'Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based
Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task
Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
'Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events,
'Implements security chaos engineering experiments that deliberately disable or degrade security controls to
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response
'Performs initial triage of security incidents to determine severity, scope, and required response actions using
'Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators,