Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkills › Authors › mahipal › Page 9

mahipal

811 Claude Code skills authored by mahipal.

updated 2026-10-04 · showing 481–540 of 811 by quality score

Average Pro QualityScore: 79.1/100

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation,
Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard
Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points.
Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp
Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy
Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection
Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and
Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing
Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat
Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy
Probe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection,
Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities
Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract
HashiCorp Consul — service discovery, health checking, KV store, service mesh, intentions. Use when working with consul service mesh.
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,
Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself
Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory
Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject
Use when trade earnings reports for profit — pre-earnings positioning, post-earnings momentum, and management quality scoring.
Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed
Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security
Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to
Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated
Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception
Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection
Flux CD GitOps — source controllers, kustomize/helm controllers, image automation, notifications. Use when working with fluxcd gitops.
Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,
Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached
Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other…
Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug
Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child
Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID)
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through
Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular
Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS
Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s
Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts — from mahipal
Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,
SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,
Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions,
Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions,
Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts,
Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false
Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user
Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious
Search all 811 skills by mahipal →