Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsAuthors › mahipal › Page 8

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-08-21 · showing 421–480 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have
Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,
Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives
Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows,
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s
Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious
Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and
Systematically testing web applications for broken access control vulnerabilities including privilege escalation,
Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, — from Undermybelt/hermes-skills
Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection
Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous
Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions
Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection,
Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints,
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam
Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject
Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements
Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using
Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems,
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory.
Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass,
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory,
Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets,
Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter,
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy
Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using
MCP servers for cloud infrastructure. Connect AI agents to AWS, GCP, and Azure for deployment, management, and
Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,
Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage,
Run MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate
Non-negotiable engineering protocol for AI agents. Enforces READ→THINK→DECIDE→PLAN→BUILD→VERIFY→DOCS→REVIEW loop.
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller
Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives
Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations
Generate test suites, analyze coverage, and scaffold E2E tests automatically. Use when creating tests for existing code, improving test coverage, scaffolding integration tests, or…
Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit
Test web applications using browser DevTools, Playwright, or Puppeteer. Automate E2E testing, visual regression, performance auditing, and accessibility checking.
Master Git workflows including branching strategies, interactive rebase, cherry-pick, bisect, worktrees, and advanced merge conflict resolution.
Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests
Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper
Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for
Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries,
Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies,
Search all 811 skills by mahipal →