
Claude Skills by yanacuti1121
github.com/yanacuti1121Detect and analyze heap spray attacks in memory dumps using Volatility3
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
'Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,
'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
Detect kernel-level rootkits in Linux memory dumps using Volatility3
Examine Linux system artifacts including auth logs, cron jobs, shell
Analyze Windows LNK shortcut files and Jump List artifacts to establish
'Analyzes malicious VBA macros embedded in Microsoft Office documents
Perform static analysis of malicious PDF documents using peepdf, pdfid,
URLScan.io is a free service for scanning and analyzing suspicious URLs.
'Executes malware samples in Cuckoo Sandbox to observe runtime behavior
Use the Malpedia platform and API to research malware family relationships,
Use Sysinternals Autoruns to systematically identify and analyze malware
Detect sandbox evasion techniques in malware samples by analyzing timing
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Analyze the NTFS Master File Table ($MFT) to recover metadata and content
Detect and analyze covert communication channels used by malware including
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Craft, send, sniff, and dissect network packets using Scapy for protocol
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
'Analyzes network traffic generated by malware during sandbox execution
'Captures and analyzes network packet data using Wireshark and tshark
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Analyze Microsoft Outlook PST and OST files for email forensic evidence
'Identifies and unpacks UPX-packed and other packed malware samples to
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
Detect and analyze Linux persistence mechanisms including crontab entries,
Detect PowerShell Empire framework artifacts in Windows event logs by
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
Parse Windows Prefetch files to determine program execution history including
'Analyzes encryption algorithms, key management, and file encryption
Monitor and analyze ransomware group data leak sites (DLS) to track victim
Identify ransomware network indicators including C2 beaconing patterns,
'Traces ransomware cryptocurrency payment flows using blockchain analysis
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
'Leverages Splunk Enterprise Security and SPL (Search Processing Language)
Examine file system slack space, MFT entries, USN journal, and alternate
Investigate supply chain attack artifacts including trojanized software
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,
'Map advanced persistent threat (APT) group tactics, techniques, and
'Analyzes structured and unstructured threat intelligence feeds to extract
Analyze the threat landscape using MISP (Malware Information Sharing
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
Detect typosquatting, homograph phishing, and brand impersonation domains
'Analyzes UEFI bootkit persistence mechanisms including firmware implants
Investigate USB device connection history from Windows registry, event
Parse Apache and Nginx access logs to detect SQL injection attempts,