Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 10

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 541–600 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative
Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response
Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),
OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its
Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.
RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents,
Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming…
Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing
Monetize bug bounty findings through writeups, tools, and consulting. Use when turning security research into
Use when extracting AI-generated storyboards from viral TikTok Shop videos, including scene breakdowns, visual — from oyi77/1ai-skills
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted
Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC
Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service
Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,
Generate test suites, analyze coverage, and scaffold E2E tests automatically. Use when creating tests for existing code, improving test coverage, scaffolding integration tests, or…
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,
Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network
Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM
Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while
Data extraction hub — content monitoring, price tracking, web scraping, and social listening for competitive intelligence, market research, and automated revenue generation.
Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack
Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible
Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials,
Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified
Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based
Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking
Hardening Docker containers for production involves applying security best practices aligned with CIS Docker
Performs API inventory and discovery to identify all API endpoints in an organization''s environment including
Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record
Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running
Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant
Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header
Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking,
Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,
Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, — from mahipal
Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations,
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics
Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like
Implement software supply chain integrity verification for container builds using the in-toto framework to create
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules,
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity
Security awareness training is the human layer of phishing defense. An effective anti-phishing training program
Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based
Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download
Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations
Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and
Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during
Centralized database for meta-skill operations. Stores performance metrics, feedback, patterns, and skill evolution
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization,
Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra
Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket
Search all 811 skills by mahipal →