
Claude Skills by Undermybelt
github.com/Undermybelt'Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents
'Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and
'This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.
'This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including
Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases
Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network
Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement,
Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant
Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis,
Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring
Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow
Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events,
Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting
'Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics
'Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency
Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data
'Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration
'Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious
Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage,
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,
'Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom)
Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC
Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger
Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification
'Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to
'Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication,
'Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to
'Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9),
Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical
Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social
Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam
Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect
Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.
Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized
'Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity
Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode
'This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions,
'Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google
'Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions
SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,
'Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test
Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for
Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains,
Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit
Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts,