Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 12

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 661–720 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
Run AI models on Replicate cloud API. Deploy image generation, video creation, audio processing, and custom models without managing infrastructure.
Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision
Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,
Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
Integrate Google BigQuery for large-scale data analytics. Write SQL queries, manage datasets, export results, and build data pipelines.
Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty
Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,
Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches,
Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden…
PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data.
Harbor is an open-source container registry that provides security features including vulnerability scanning
Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,
Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have
Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts,
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction,
Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace
Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment,
Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate
Non-negotiable engineering protocol for AI agents. Enforces READ→THINK→DECIDE→PLAN→BUILD→VERIFY→DOCS→REVIEW loop.
Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege
Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including
Implementing Google''s BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter,
Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies,
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with
Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated
JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization
Patch management is the systematic process of identifying, testing, deploying, and verifying software updates
Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the
Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session
Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution
Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events,
Performs advanced network reconnaissance using Nmap''s scripting engine, timing controls, evasion techniques,
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned
Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL.
Reduce container attack surface by building application images on Google distroless base images that contain
Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit
Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and
Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing
Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and
Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications,
The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining
Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iam__privesc_scan, and…
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files
Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications
Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel
Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate
Search all 811 skills by mahipal →