Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 3

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 121–180 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify
Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,
Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations,
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral
Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling,
Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications,
Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution,
Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations,
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength.
Executes a structured ransomware incident response from initial detection through containment, forensic analysis,
Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures,
Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication,
Use NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, password-spray safely across lockout thresholds, execute commands, and dump SAM/LSA/NTDS credentials…
Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify
Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT
Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests
Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service
Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to
Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive
Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings,
Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection,
Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,
Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak
Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with
Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to
Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and…
Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking
Executes authorized attack simulations against Active Directory environments to identify misconfigurations,
Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content,
Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and
Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound,
Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments
Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing
Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE),
Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage…
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials
Search all 811 skills by mahipal →