
Claude Skills by yanacuti1121
github.com/yanacuti1121Detect kernel-level rootkits in Linux memory dumps using Volatility3
Examine Linux system artifacts including auth logs, cron jobs, shell
Analyze Windows LNK shortcut files and Jump List artifacts to establish
'Analyzes malicious VBA macros embedded in Microsoft Office documents
Perform static analysis of malicious PDF documents using peepdf, pdfid,
URLScan.io is a free service for scanning and analyzing suspicious URLs.
'Executes malware samples in Cuckoo Sandbox to observe runtime behavior
Use the Malpedia platform and API to research malware family relationships,
Use Sysinternals Autoruns to systematically identify and analyze malware
Detect sandbox evasion techniques in malware samples by analyzing timing
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Analyze the NTFS Master File Table ($MFT) to recover metadata and content
Detect and analyze covert communication channels used by malware including
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Craft, send, sniff, and dissect network packets using Scapy for protocol
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
'Analyzes network traffic generated by malware during sandbox execution
'Captures and analyzes network packet data using Wireshark and tshark
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Analyze Microsoft Outlook PST and OST files for email forensic evidence
'Identifies and unpacks UPX-packed and other packed malware samples to
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
Detect and analyze Linux persistence mechanisms including crontab entries,
Detect PowerShell Empire framework artifacts in Windows event logs by
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
Parse Windows Prefetch files to determine program execution history including
'Analyzes encryption algorithms, key management, and file encryption
Monitor and analyze ransomware group data leak sites (DLS) to track victim
Identify ransomware network indicators including C2 beaconing patterns,
'Traces ransomware cryptocurrency payment flows using blockchain analysis
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
'Leverages Splunk Enterprise Security and SPL (Search Processing Language)
Examine file system slack space, MFT entries, USN journal, and alternate
Investigate supply chain attack artifacts including trojanized software
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,
'Map advanced persistent threat (APT) group tactics, techniques, and
'Analyzes structured and unstructured threat intelligence feeds to extract
Analyze the threat landscape using MISP (Malware Information Sharing
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
Detect typosquatting, homograph phishing, and brand impersonation domains
'Analyzes UEFI bootkit persistence mechanisms including firmware implants
Investigate USB device connection history from Windows registry, event
Parse Apache and Nginx access logs to detect SQL injection attempts,
'Parses and analyzes the Windows Amcache.hve registry hive to extract
'Analyzes Windows Security, System, and Sysmon event logs in Splunk to
Parse Windows LNK shortcut files to extract target paths, timestamps,
Parse Windows Prefetch files using the windowsprefetch Python library
Extract and analyze Windows Registry hives to uncover user activity,
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing