All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs402 views
Sec Logs SplunkA

'Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents

devopsgoshell
0
9
Sec Mon DatadogB

'Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection

devopspythongo
0
9
Second Order Sql InjctnA

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and

securitypythonrust
0
9
Secret Scan GitleaksA

'This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.

devopspythongo
0
9
Secrets Mgmt VaultB

'This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including

devopsrustbash
0
9
Secrets Scan Ci CdA

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment

devopspythongit
0
9
Semg Cust Sast RuleA

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,

devopsjavascripttypescript
0
9
Serv Acco Crdn RotaA

Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases

devopspythongo
0
9
Server Side Req ForgeryB

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network

securityrustgo
0
9
Service Account AbuseA

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement,

researchgosql
0
9
Service Account AuditA

Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant

securitypythongo
0
9
Shadow Api EndpntA

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis,

developmentpythongo
0
9
Shadow Copy DeletionA

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring

securityshellsecurity
0
9
Shadow It Cloud UsageA

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow

securitypythongo
0
9
Siem Crrltn Rules AptA

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events,

securitypythongo
0
9
Siem Use Case TuningA

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting

businesspythongo
0
9
Siem Use Cases DtctnA

'Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics

devopspythongo
0
9
Sigs Soft SignA

'Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency

devopspythonrust
0
9
Slac Spac File Syst ArtfA

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data

researchpythonbash
0
9
Smb Vulns MtspltA

'Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration

securitypythonshell
0
9
Snort Ids Intrsn DtctnB

'Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious

devopspythongo
0
9
Snstv Data ExposureB

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage,

securityjavascriptgo
0
9
Soap Web Service Sec TesB

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,

securitypythongo
0
9
Soar Atmtn PhantomA

'Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom)

securitypythonrust
0
9
Soar Play Palo Alto XsoaA

Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC

devopsjavascriptpython
0
9
Soar Playbook PhishingA

Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger

toolspythonapi
0
9
Soc Escltn MatrixA

Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification

securitypythontesting
0
9
Soc Metrics Kpi TrackingA

'Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to

datagosecurity
0
9
Soc Playbook RnsmwrA

'Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication,

securityrustgo
0
9
Soc Tabletop ExerciseA

'Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to

businessgoswift
0
9
Soc2 Type2 Audit PrprtnA

'Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9),

devopspythonrust
0
9
Social Eng Pntrtn TestA

Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical

securityrustgo
0
9
Social Eng Pretext CallA

Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social

securityrustgo
0
9
Software Defined PrmtrA

Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual

devopspythonrust
0
9
Sprphs Email GatewayA

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam

securityrustsecurity
0
9
Sprphs IndctrA

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect

researchshellsecurity
0
9
Sprphs Smltn CampaignA

Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.

devopspythongo
0
9
Sql Injctn SqlmapB

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized

securitypythongo
0
9
Sql Injctn VulnsA

'Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests

securityjavaphp
0
9
Sql Injctn Waf LogsA

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity

securitypythonbash
0
9
Sqlite Database FrnscsA

Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode

developmentpythonrust
0
9
Srvrls FnctnsA

'This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions,

securitypythongo
0
9
Srvrls Function InjctnF

'Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google

securityjavascriptpython
0
9
Srvrls Function Sec ReviA

'Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions

securitypythonrust
0
9
Ssl Cert Lfcycl MgmtA

SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,

devopspythonrust
0
9
Ssl Strppn AttackB

'Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test

securitypythongo
0
9
Ssl Tls Inspct CfgA

Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for

securityrustgo
0
9
Ssl Tls Sec AssssmA

Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains,

securitypythongo
0
9
Sspcs Oauth App ConsentA

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit

securitypythonazure
0
9
Sspcs Pwrshl ExctnA

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts,

researchshellsecurity
0
9