Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 5

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 241–300 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from mahipal
Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0,
Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators,
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences
Analyzes network traffic generated by malware during sandbox execution or live incident response to identify
Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy,
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Skill: agent-arena-skill. See SKILL.md body for details. Use when this domain is relevant.
Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation
Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary…
Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events,
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns,
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like…
Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record
Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting
Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection,
Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing
Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to
Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation,
Performs initial triage of security incidents to determine severity, scope, and required response actions using
Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding,
Extracts LLM system prompts using direct requests, jailbreak/instruction-override
Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using
Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement,
Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities,
Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover
Uses Postman to perform structured API security testing by building collections that test for OWASP API Security
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,
Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues
Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network
Cryptographic attack techniques for breaking implementations, side-channel attacks, and exploiting crypto weaknesses.
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,
Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence
Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual
Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules),
Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies
Implements security chaos engineering experiments that deliberately disable or degrade security controls to
Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger
Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache,…
Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable
Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families
Search all 811 skills by mahipal →