All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs397 views
Sspcs Schdld TasksA

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious

securitygoshell
0
9
Ssrf Vuln ExplttC

Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,

securitypythongo
0
9
Startup Folder PrsstnA

Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,

devopspythongo
0
9
Static Malware Ana Pe StA

'Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file

developmentpythonrust
0
9
Stgngr DtctnA

Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover

datapythongo
0
9
Stix Taxii Feed IntgrtA

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)

securitypythonrust
0
9
Stix Taxii FeedsA

'Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native

devopspythongo
0
9
Stuxnet Style AttacksA

'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying

securitypythongo
0
9
Supp Chai Atta Ci CdA

'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned

securitypythongo
0
9
Supp Chai Malw ArtfA

Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,

developmentpythonrust
0
9
Supply Chain Attack SmltA

Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,

securitypythonrust
0
9
Supply Chain CmprmsA

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,

devopsrustsecurity
0
9
Supply Chain Sec TotoA

Implement software supply chain integrity verification for container builds using the in-toto framework to create

devopspythongo
0
9
Suricata Net MonB

'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for

devopsrustgo
0
9
Syslog Cntrlz RsyslogA

Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates

securitypythonbash
0
9
T1003 Crdntl Dumping EdrA

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials

securitygogit
0
9
T1055 Proc Injctn SysmonA

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection

devopsgoshell
0
9
T1098 Account MnpltnA

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group

securitypythonsecurity
0
9
T154 Abus Elvt Cont MchnA

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation

securityrustgo
0
9
Taxii Server OpntxA

Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using

devopspythonrust
0
9
Tcktng System IncdntA

'Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for

securitypythongo
0
9
Template Injctn VulnsC

Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,

securitypythongo
0
9
Thick Client App PntrtnA

Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,

securitygojava
0
9
Thre Acto Ttps Mitr AttaA

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)

devopspythongit
0
9
Thre Acto Ttps Mitr NvgtA

'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework

datapythonshell
0
9
Thre Hunt Hypt FrmwA

Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and

researchsecurity
0
9
Thre Inte Enrc SpluA

Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular

devopspythonrust
0
9
Thre Mode Mitr AttaA

'Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,

businesspythonshell
0
9
Thre Mode Owas Thre DragA

Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,

securityrustgo
0
9
Threat Actor GroupsA

'Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives

securitypythondatabase
0
9
Threat Actor Prof OsintA

Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary

devopspythonrust
0
9
Threat Emltn Atomic RedA

'Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.

testingpythonshell
0
9
Threat Feed Aggrgt MispA

Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence

devopspythongo
0
9
Threat Hunt Elastic SiemA

'Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline

businessgoshell
0
9
Threat Hunt Yara RulesA

'Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems

devopspythonrust
0
9
Threat Intel Feed IntgrtA

'Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat

businesspythonrust
0
9
Threat Intel FeedsA

'Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,

businesspythonrust
0
9
Threat Intel Lfcycl MgmtA

Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis,

securitypythongo
0
9
Threat Intel MispA

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,

securitypythongo
0
9
Threat Intel PlatformA

Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified

devopspythonrust
0
9
Threat Intel ReportsA

'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored

businessrustgo
0
9
Threat Intel Sharing MisA

Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,

securitypythontesting
0
9
Threat Lndscp Assssm SecA

Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack

securitypythongo
0
9
Threat Lndscp MispA

Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,

securitypythonbash
0
9
Timeline Rcnstr PlasoA

Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems,

devopspythongo
0
9
Tls 1 3 Sec CmmnctA

TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements

securitypythontesting
0
9
Tls Cert Trnspr LogsA

'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate

devopspythontesting
0
9
Tlscl Zero Trust VpnD

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,

devopsrustgo
0
9
Tracking Threat ActorA

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control

devopspythonrust
0
9
Type Juggling VulnsA

Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent

securitypythonphp
0
9