
Claude Skills by Undermybelt
github.com/UndermybeltHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious
Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,
Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,
'Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file
Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover
STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)
'Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native
'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying
'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned
Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,
Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,
Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,
Implement software supply chain integrity verification for container builds using the in-toto framework to create
'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates
Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection
Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation
Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using
'Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for
Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)
'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework
Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular
'Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,
Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,
'Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary
'Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence
'Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline
'Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems
'Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat
'Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis,
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified
'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack
Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems,
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,
Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control
Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent