All authors
yanacuti1121 avatar

Claude Skills by yanacuti1121

github.com/yanacuti1121
3,362 skillsA× 3,037B× 234C× 42D× 31F× 180 installs890 views
Detecting Fileless Malware TechniquesA

'Detects and analyzes fileless malware that operates entirely in memory

ai-agentsjavascriptpython
0
3
Detecting Golden Ticket Attacks In Kerberos LogsA

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos

ai-agentsgogit
0
3
Detecting Golden Ticket ForgeryA

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769

ai-agentspythongo
0
3
Detecting Insider Data Exfiltration Via DlpA

'Detects insider data exfiltration by analyzing DLP policy violations,

ai-agentspythontesting
0
3
Detecting Insider Threat BehaviorsA

Detect insider threat behavioral indicators including unusual data access,

ai-agentsgitsecurity
0
3
Detecting Insider Threat With UebaA

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch

ai-agentspythongit
0
3
Detecting Kerberoasting AttacksA

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS

ai-agentsgogit
0
3
Detecting Lateral Movement In NetworkA

'Identifies lateral movement techniques in enterprise networks by analyzing

ai-agentsgoshell
0
3
Detecting Lateral Movement With SplunkA

Detect adversary lateral movement across networks using Splunk SPL queries

ai-agentsgoshell
0
3
Detecting Lateral Movement With ZeekA

'Detect lateral movement in network traffic using Zeek (formerly Bro)

ai-agentspythonbash
0
3
Detecting Living Off The Land AttacksA

'Detect abuse of legitimate Windows binaries (LOLBins) used for living

ai-agentsjavascriptpython
0
3
Detecting Living Off The Land With LolbasA

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including

ai-agentspythongit
0
3
Detecting Malicious Scheduled Tasks With SysmonA

'Detect malicious scheduled task creation and modification using Sysmon

ai-agentsswiftshell
0
3
Detecting Mimikatz Execution PatternsA

Detect Mimikatz execution through command-line patterns, LSASS access

ai-agentsgoshell
0
3
Detecting Misconfigured Azure StorageB

'Detecting misconfigured Azure Storage accounts including publicly accessible

ai-agentsgoshell
0
3
Detecting Mobile Malware BehaviorA

'Detects and analyzes malicious behavior in mobile applications through

ai-agentsjavascriptrust
0
3
Detecting Modbus Command Injection AttacksA

'Detect command injection attacks against Modbus TCP/RTU protocol in

ai-agentspythongo
0
3
Detecting Modbus Protocol AnomaliesA

'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications

ai-agentspythonreact
0
3
Detecting Network Anomalies With ZeekB

'Deploys and configures Zeek (formerly Bro) network security monitor

ai-agentsbashnode
0
3
Detecting Network Scanning With Ids SignaturesA

Detect network reconnaissance and port scanning using Suricata and Snort

ai-agentspythongit
0
3
Detecting Ntlm Relay With Event CorrelationA

'Detect NTLM relay attacks through Windows Security Event correlation

ai-agentsgoshell
0
3
Detecting Oauth Token TheftA

'Detects and responds to OAuth token theft and replay attacks in cloud

ai-agentsrustgo
0
3
Detecting Pass The Hash AttacksA

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns,

ai-agentsgogit
0
3
Detecting Pass The Ticket AttacksA

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event

ai-agentspythongit
0
3
Detecting Port Scanning With Fail2banA

'Configures Fail2ban with custom filters and actions to detect port scanning

ai-agentsrustphp
0
3
Detecting Privilege Escalation AttemptsA

Detect privilege escalation attempts including token manipulation, UAC

ai-agentsgitsecurity
0
3
Detecting Privilege Escalation In Kubernetes PodsB

Detect and prevent privilege escalation in Kubernetes pods by monitoring

ai-agentsgobash
0
3
Detecting Process Hollowing TechniqueA

Detect process hollowing (T1055.012) by analyzing memory-mapped sections,

ai-agentsrustgit
0
3
Detecting Process Injection TechniquesA

'Detects and analyzes process injection techniques used by malware including

ai-agentspythonrust
0
3
Detecting Qr Code Phishing With Email SecurityA

Detect and prevent QR code phishing (quishing) attacks that bypass traditional

ai-agentsrustgo
0
3
Detecting Ransomware Encryption BehaviorA

'Detects ransomware encryption activity in real time using entropy analysis,

ai-agentspythonshell
0
3
Detecting Ransomware Precursors In NetworkA

'Detects early-stage ransomware indicators in network traffic before

ai-agentspythongo
0
3
Detecting Rdp Brute Force AttacksA

Detect RDP brute force attacks by analyzing Windows Security Event Logs

ai-agentspythongo
0
3
Detecting Rootkit ActivityA

'Detects rootkit presence on compromised systems by identifying hidden

ai-agentspythonrust
0
3
Detecting S3 Data Exfiltration AttemptsA

'Detecting data exfiltration attempts from AWS S3 buckets by analyzing

ai-agentsgobash
0
3
Detecting Serverless Function InjectionF

'Detects and prevents code injection attacks targeting serverless functions

ai-agentsjavascriptpython
0
3
Detecting Service Account AbuseA

Detect abuse of service accounts through anomalous interactive logons,

ai-agentsgosql
0
3
Detecting Shadow Api EndpointsA

Discover and inventory shadow API endpoints that operate outside documented

ai-agentspythongo
0
3
Detecting Shadow It Cloud UsageA

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing

ai-agentspythongo
0
3
Detecting Spearphishing With Email GatewayA

Spearphishing targets specific individuals using personalized, researched

ai-agentsrustgit
0
3
Detecting Sql Injection Via Waf LogsA

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection

ai-agentspythonbash
0
3
Detecting Stuxnet Style AttacksA

'This skill covers detecting sophisticated cyber-physical attacks that

ai-agentspythongo
0
3
Detecting Supply Chain Attacks In Ci CdA

'Scans GitHub Actions workflows and CI/CD pipeline configurations for

ai-agentspythongo
0
3
Detecting Suspicious Oauth Application ConsentA

Detect risky OAuth application consent grants in Azure AD / Microsoft

ai-agentspythonazure
0
3
Detecting Suspicious Powershell ExecutionA

Detect suspicious PowerShell execution patterns including encoded commands,

ai-agentsshellgit
0
3
Detecting T1003 Credential Dumping With EdrA

Detect OS credential dumping techniques targeting LSASS memory, SAM database,

ai-agentsgogit
0
3
Detecting T1055 Process Injection With SysmonA

Detect process injection techniques (T1055) including classic DLL injection,

ai-agentsgoshell
0
3
Detecting T1548 Abuse Elevation Control MechanismA

Detect abuse of elevation control mechanisms including UAC bypass, sudo

ai-agentsrustgo
0
3
Detecting Typosquatting Packages In Npm PypiA

'Detects typosquatting attacks in npm and PyPI package registries by

ai-agentspythongo
0
3
Detecting Wmi PersistenceA

Detect WMI event subscription persistence by analyzing Sysmon Event IDs

ai-agentsgoshell
0
3