All authors
Undermybelt avatar

Claude Skills by Undermybelt

github.com/Undermybelt
1,299 skillsA× 1,156B× 103C× 18D× 12F× 101 installs397 views
Typsqt Domains DnstwistA

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations

devopspythongo
0
9
Typsqt Packages Npm PypiA

'Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using

securitypythongo
0
9
Uefi Bootkit PrsstnA

'Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition

securitypythonrust
0
9
Unusual Net CnnctnA

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard

researchsecurity
0
9
Unusual Service InstllA

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event

securitypythonshell
0
9
Usb Devi Cnnc HistA

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable

researchpythonbash
0
9
Usb Devi Cont PoliA

'Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing

devopsgoshell
0
9
User Behavior AnlytcA

'Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible

devopsreactazure
0
9
Vlan Hopping AttackA

'Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments

securitypythongo
0
9
Vlcrpt Ir CllctnA

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response

devopspythongo
0
9
Vldtng Backup Intgrt RecA

Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection,

devopspythonrust
0
9
Vola Evid Cmpr HostB

Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory,

securityrustgo
0
9
Vuln Aging Sla TrackingA

Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against

securitypythonsecurity
0
9
Vuln Dshbrd DfctdjA

Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,

securitypythongo
0
9
Vuln Excp Trac SystA

Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls

securitypythonrust
0
9
Vuln Mgmt GrnbnA

Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,

securitypythonapi
0
9
Vuln Rmdtn SlaA

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities

businesspythongo
0
9
Vuln Scan FlowA

'Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,

securitypythongo
0
9
Vuln Scan NessusA

'Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,

securitygotesting
0
9
Vuln Sla Breach AlertingA

Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation

databasespythongo
0
9
Vulns Mtsplt FrmwrkB

The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7.

securityshellbash
0
9
Vulns Ssvc FrmwrkA

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision

securitypythongo
0
9
Wbsckt Api SecB

'Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket

securityjavascriptpython
0
9
Wbsckt VulnsC

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure

securitypythonrust
0
9
Web App Firewall BypassA

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution,

securityjavascriptjava
0
9
Web App Logging MdscrtA

'Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false

devopssqlsecurity
0
9
Web App Pntrtn TestB

'Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG)

securityjavascriptrust
0
9
Web App Scan NiktoA

Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous

securitypythonshell
0
9
Web App Vuln TriA

Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to

securitypythonrust
0
9
Web Cache Dcptn AttackA

Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers

securitybashaws
0
9
Web Cache Psnng AttackA

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through

securityjavascriptgo
0
9
Web Server Logs IntrsnC

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal,

developmentjavascriptpython
0
9
Webshell ActivityA

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious

devopsphpshell
0
9
Wifi Pass Crac AircA

'Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary

securitybashtesting
0
9
Win Amcache ArtfctA

'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application

developmentrustgo
0
9
Win Arti Ana Eric Zmmr TA

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including

toolspythongo
0
9
Win Defe Adva SettA

'Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction

securityjavascriptrust
0
9
Win Event Logging DtctnA

'Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for

securitygoshell
0
9
Win Event Logs SplunkA

'Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege

securitygoswift
0
9
Win Lnk Files ArtfctA

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers

toolspythonshell
0
9
Win Prefetch PyA

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,

devopspythonshell
0
9
Win Registry ArtfctA

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and

toolspythonshell
0
9
Win Shellbag ArtfctA

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable

developmentpythonshell
0
9
Wireless Net Pntrtn 32dbA

'Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing

securitytestinggit
0
9
Wireless Net Pntrtn TestA

Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3

securitygophp
0
9
Wireless Sec Assssm KismA

Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak

securitypythongo
0
9
Wmi PrsstnA

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter,

devopsgoshell
0
9
Xml Injctn VulnsB

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks

securitypythonphp
0
9
Xss Vulns BrpstA

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater

securityjavascriptrust
0
9
Xss VulnsA

'Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into

securityjavascriptgo
0
9