
Claude Skills by Undermybelt
github.com/UndermybeltDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations
'Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using
'Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition
Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard
Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable
'Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing
'Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible
'Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments
Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response
Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection,
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory,
Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against
Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,
Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
'Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,
'Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation
The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7.
Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision
'Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket
Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure
Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution,
'Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false
'Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG)
Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous
Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to
Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through
Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal,
Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious
'Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary
'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including
'Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction
'Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
'Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable
'Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak
Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter,
Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater
'Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into