All authors
yanacuti1121 avatar

Claude Skills by yanacuti1121

github.com/yanacuti1121
3,362 skillsA× 3,037B× 234C× 42D× 31F× 180 installs893 views
Detecting Kerberoasting AttacksA

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS

ai-agentsgogit
0
3
Detecting Lateral Movement In NetworkA

'Identifies lateral movement techniques in enterprise networks by analyzing

ai-agentsgoshell
0
3
Detecting Lateral Movement With SplunkA

Detect adversary lateral movement across networks using Splunk SPL queries

ai-agentsgoshell
0
3
Detecting Lateral Movement With ZeekA

'Detect lateral movement in network traffic using Zeek (formerly Bro)

ai-agentspythonbash
0
3
Detecting Living Off The Land AttacksA

'Detect abuse of legitimate Windows binaries (LOLBins) used for living

ai-agentsjavascriptpython
0
3
Detecting Living Off The Land With LolbasA

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including

ai-agentspythongit
0
3
Detecting Malicious Scheduled Tasks With SysmonA

'Detect malicious scheduled task creation and modification using Sysmon

ai-agentsswiftshell
0
3
Detecting Mimikatz Execution PatternsA

Detect Mimikatz execution through command-line patterns, LSASS access

ai-agentsgoshell
0
3
Detecting Misconfigured Azure StorageB

'Detecting misconfigured Azure Storage accounts including publicly accessible

ai-agentsgoshell
0
3
Detecting Mobile Malware BehaviorA

'Detects and analyzes malicious behavior in mobile applications through

ai-agentsjavascriptrust
0
3
Detecting Modbus Command Injection AttacksA

'Detect command injection attacks against Modbus TCP/RTU protocol in

ai-agentspythongo
0
3
Detecting Modbus Protocol AnomaliesA

'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications

ai-agentspythonreact
0
3
Detecting Network Anomalies With ZeekB

'Deploys and configures Zeek (formerly Bro) network security monitor

ai-agentsbashnode
0
3
Detecting Network Scanning With Ids SignaturesA

Detect network reconnaissance and port scanning using Suricata and Snort

ai-agentspythongit
0
3
Detecting Ntlm Relay With Event CorrelationA

'Detect NTLM relay attacks through Windows Security Event correlation

ai-agentsgoshell
0
3
Detecting Oauth Token TheftA

'Detects and responds to OAuth token theft and replay attacks in cloud

ai-agentsrustgo
0
3
Detecting Pass The Hash AttacksA

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns,

ai-agentsgogit
0
3
Detecting Pass The Ticket AttacksA

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event

ai-agentspythongit
0
3
Detecting Port Scanning With Fail2banA

'Configures Fail2ban with custom filters and actions to detect port scanning

ai-agentsrustphp
0
3
Detecting Privilege Escalation AttemptsA

Detect privilege escalation attempts including token manipulation, UAC

ai-agentsgitsecurity
0
3
Detecting Privilege Escalation In Kubernetes PodsB

Detect and prevent privilege escalation in Kubernetes pods by monitoring

ai-agentsgobash
0
3
Detecting Process Hollowing TechniqueA

Detect process hollowing (T1055.012) by analyzing memory-mapped sections,

ai-agentsrustgit
0
3
Detecting Process Injection TechniquesA

'Detects and analyzes process injection techniques used by malware including

ai-agentspythonrust
0
3
Detecting Qr Code Phishing With Email SecurityA

Detect and prevent QR code phishing (quishing) attacks that bypass traditional

ai-agentsrustgo
0
3
Detecting Ransomware Encryption BehaviorA

'Detects ransomware encryption activity in real time using entropy analysis,

ai-agentspythonshell
0
3
Detecting Ransomware Precursors In NetworkA

'Detects early-stage ransomware indicators in network traffic before

ai-agentspythongo
0
3
Detecting Rdp Brute Force AttacksA

Detect RDP brute force attacks by analyzing Windows Security Event Logs

ai-agentspythongo
0
3
Detecting Rootkit ActivityA

'Detects rootkit presence on compromised systems by identifying hidden

ai-agentspythonrust
0
3
Detecting S3 Data Exfiltration AttemptsA

'Detecting data exfiltration attempts from AWS S3 buckets by analyzing

ai-agentsgobash
0
3
Detecting Serverless Function InjectionF

'Detects and prevents code injection attacks targeting serverless functions

ai-agentsjavascriptpython
0
3
Detecting Service Account AbuseA

Detect abuse of service accounts through anomalous interactive logons,

ai-agentsgosql
0
3
Detecting Shadow Api EndpointsA

Discover and inventory shadow API endpoints that operate outside documented

ai-agentspythongo
0
3
Detecting Shadow It Cloud UsageA

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing

ai-agentspythongo
0
3
Detecting Spearphishing With Email GatewayA

Spearphishing targets specific individuals using personalized, researched

ai-agentsrustgit
0
3
Detecting Sql Injection Via Waf LogsA

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection

ai-agentspythonbash
0
3
Detecting Stuxnet Style AttacksA

'This skill covers detecting sophisticated cyber-physical attacks that

ai-agentspythongo
0
3
Detecting Supply Chain Attacks In Ci CdA

'Scans GitHub Actions workflows and CI/CD pipeline configurations for

ai-agentspythongo
0
3
Detecting Suspicious Oauth Application ConsentA

Detect risky OAuth application consent grants in Azure AD / Microsoft

ai-agentspythonazure
0
3
Detecting Suspicious Powershell ExecutionA

Detect suspicious PowerShell execution patterns including encoded commands,

ai-agentsshellgit
0
3
Detecting T1003 Credential Dumping With EdrA

Detect OS credential dumping techniques targeting LSASS memory, SAM database,

ai-agentsgogit
0
3
Detecting T1055 Process Injection With SysmonA

Detect process injection techniques (T1055) including classic DLL injection,

ai-agentsgoshell
0
3
Detecting T1548 Abuse Elevation Control MechanismA

Detect abuse of elevation control mechanisms including UAC bypass, sudo

ai-agentsrustgo
0
3
Detecting Typosquatting Packages In Npm PypiA

'Detects typosquatting attacks in npm and PyPI package registries by

ai-agentspythongo
0
3
Detecting Wmi PersistenceA

Detect WMI event subscription persistence by analyzing Sysmon Event IDs

ai-agentsgoshell
0
3
Deusdata Codebase Memory McpC

How to install and use codebase-memory-mcp — a single-binary MCP server that indexes a codebase into a persistent tree-sitter + Hybrid-LSP knowledge graph (158 languages), answering structural queries (call graph, dead code, HTTP/gRPC/GraphQL route linking, ADRs, Cypher-like queries) in sub-millisecond time with ~10x fewer tokens than file-by-file grep/read exploration. Triggers on: 'index this codebase', 'codebase memory mcp', 'code knowledge graph', 'find callers of', 'call graph', 'dead co...

ai-agentsrustshell
0
3
Did Credential LifecycleA

Verifiable credential lifecycle management for agent identity. Issue, verify, revoke credentials, DID document key rotation, credential schema validation, and W3C VC data model compliance. Sources: microsoft/did-sdk-js, W3C VC spec.

ai-agentsjavascripttypescript
0
3
Did Resolver PatternsA

W3C Decentralized Identifier (DID) resolution and cross-agent identity verification. DID document resolution, method routing, key extraction from DID documents, and mutual authentication between Swarm Bus agents. Sources: decentralized-identity/did-resolver.

ai-agentsjavascripttypescript
0
3
Disaggregated Prefill DecodeA

Disaggregated prefill/decode — separate GPU pools for compute-bound prefill and memory-bound decode. KV cache transfer via NIXL (RDMA/TCP). NVIDIA Dynamo (stack-above) vs llm-d (K8s-native). 6x DeepSeek-R1 on GB200+Dynamo. 30–40% cost savings on $2M+ inference budgets. Sources: rohitg00/ai-engineering-from-scratch (Apache-2.0).

ai-agentspythonrust
0
3
Distributed TracingA

Instrument and debug distributed systems with tracing — OpenTelemetry setup, span creation, context propagation (W3C traceparent), sampling strategy, exporter configuration (Jaeger/Tempo/Honeycomb/Datadog), and correlating traces with logs. Use when asked to "add tracing", "OpenTelemetry", "OTel", "distributed trace", "trace propagation", "traceparent header", "find slow span", "Jaeger", "Tempo", "Honeycomb", "why is this request slow across services", or "trace ID in logs". Do NOT use for: m...

ai-agentspythongo
0
3
Docker PatternsD

Build production-grade Docker images — multi-stage builds, layer caching, non-root user, minimal base images, .dockerignore, health checks, docker-compose for local dev, BuildKit secrets, and image size audit. Use when asked about "Docker", "Dockerfile", "multi-stage build", "Docker image too large", "non-root Docker", "Docker layer cache", "docker-compose", "Docker health check", "BuildKit", ".dockerignore", "Docker security", "distroless", or "container image best practices". Do NOT use for...

ai-agentspythongo
0
3