Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsAuthors › mahipal › Page 12

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-08-21 · showing 661–720 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached
Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security
Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event
Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments
Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that
Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission
Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization,
Use when extracting AI-generated storyboards from viral TikTok Shop videos, including scene breakdowns, visual — from oyi77/1ai-skills
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions,
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater — from mahipal
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and
Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records)
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction
Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral
Use when activate an AI general manager persona with full context awareness and multi-user adaptation.
Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL.
Apply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP
Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines
Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source
Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using
Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty
Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test
Comprehensive QA→Review→Fix loop protocol for any codebase. Layer-based testing with evidence requirements.
Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or…
Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded
Hardening Docker containers for production involves applying security best practices aligned with CIS Docker
Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS — from Undermybelt/hermes-skills
Use NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, password-spray safely across lockout thresholds, execute commands, and dump SAM/LSA/NTDS credentials…
Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack
Implement software supply chain integrity verification for container builds using the in-toto framework to create
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive
The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining
Extracts LLM system prompts using direct requests, jailbreak/instruction-override
Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard
Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned
Find relevant B-roll and stock footage by analyzing script content with semantic search. Match video meaning to text instead of random selection.
Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify
Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts,
Patch management is the systematic process of identifying, testing, deploying, and verifying software updates
Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity
Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC
Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative
Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution,
Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS
Use when find bottleneck companies — the critical constraint in supply chains that have pricing power, low competition, and high returns.
Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and…
Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations,
Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible
Search all 811 skills by mahipal →