Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 6

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 301–360 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

MCP server for Slack integration. Send messages, manage channels, and automate Slack workflows via standardized protocol.
Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request
Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal,
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater — from mahipal
Discover and connect to MCP servers automatically. Browse available tools and register new server endpoints. Use when working with mcp discover.
Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,
Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,
Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and
Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443,
Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for
Produce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.
Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege
Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion)
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
Parse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.
Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,
Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.
Apply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations,
Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards
Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus…
Find relevant B-roll and stock footage by analyzing script content with semantic search. Match video meaning to text instead of random selection.
End-to-end competitive analysis automation that combines product research, video analysis, and storyboard extraction — from oyi77/1ai-skills
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection
Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse
Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based
Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification
Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven
Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to
Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and
Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Investigate token and NFT scams including rug pulls, honeypot tokens, pump-and-dump schemes,
Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware
Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD
Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,
Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,
Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on
Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert
Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints,
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy,…
Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce
Use when foundational core infrastructure skill providing system foundation capabilities for the agent ecosystem.
Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize
Search all 811 skills by mahipal →