Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Forensics › Page 4

Forensics (Page 4 of 5)

295 Claude Code skills in the Forensics sub-category of Security.

295 skills · updated 2026-08-26 · showing 181–240 of 295 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art.
Generate a NIST Cybersecurity Framework (CSF) 2.0 compliance report — interactively walks through every function, category, and subcategory, collecting evidence and pulling…
Run an office move or reconfiguration without losing a week of work — the dependency-ordered plan (internet lead times rule everything), the workstream owners, the comms that keep…
Design or audit one offline/local-first synchronization and conflict protocol: local storage, queued mutations, idempotency, causality/order, reconnect, tombstones, optimistic…
Evaluate a document, report, spreadsheet, hypothesis, decision memo, or Agent Skill with independent evidence review, conditional disruption, and evidence-based adjudication.
[omh] Hermes Verification Gate workflow: define and record build, lint, typecheck, test, security, docs, generated-output, and CI evidence before completion or merge.
Research external libraries with evidence-backed responses and GitHub permalinks. Use when investigating library APIs, implementation patterns, or historical context for open…
Operate security tools through an AI agent with explicit authority and evidence boundaries. Use when an agent may invoke local CLIs, GUI apps, browser automation, MCP servers,…
Create or redesign enterprise AI, automation, security, and operations product pages that explain system boundaries, approvals, auditability, exceptions, and rollback.
Simulates the opposing party's litigation and negotiation strategy by mapping their likely factual narrative, categorizing defenses, predicting evidence attacks, and designing…
Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.
OSINT Investigator v2.1 — comprehensive open-source intelligence skill. Triggers on: OSINT, recon, digital footprint, dorking, social media investigation, username lookups, email…
GRIMSEC Agent 11: Evidence-backed forensic investigation of open-source GitHub repositories. Use when investigating supply chain incidents, suspicious commits, compromised…
Digital forensics — evidence acquisition, memory/disk imaging analiz, timeline reconstruction, IOC extraction advisory.
Operator OPSEC + evidence handling — operator identity hygiene, source IP design, burner infrastructure, evidence chain of custody, log retention advisory.
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines
Use when scanning an external macro environment with PESTEL/PESTLE (and its variant family STEEPLE, STEEPLED, PESTLIED, STEEP, DESTEP, LoNGPESTLE): political, economic, social,…
Develop, test, benchmark, and operate PostgreSQL extensions with reusable harnesses and reference protocols.
Use after PNAS reviews arrive to triage the decision, prioritize experiments, and draft a point-by-point response that is respectful, evidence-led, and honest about limits.
Use after PNAS Nexus reviews arrive to triage the decision, prioritize experiments, and draft a point-by-point response that is respectful, evidence-led, and honest about limits.
Preserve and document security evidence before analysis, containment, or remediation changes it. Use for suspicious artifacts, volatile host state, vulnerability validation,…
Route cross-domain production evidence (readiness, migration, recovery, capacity/cost, incident-learning) into a launch or operational decision — go, no-go, defer, exception, or…
Create or refine promptfoo redteam setup configs: purpose, targets, plugins, strategies, frameworks, multi-input target inputs, policy text, grader guidance, contexts, and…
Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code,…
Reusable writing-style contract for agent outputs (reports, ARCH docs, verdicts, threat models). Forces direct prose with concrete evidence, no marketing voice, no hedge words.
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool…
AI red-teaming framework for testing LLMs and generative AI systems for jailbreaks, prompt injection, harmful content, data leakage, and multi-turn attacks.
Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing,…
Use when reviewing, designing, or modifying Java enterprise systems that may support essential or important entities, critical-sector services, managed service providers — from…
Turn Apple-platform security research evidence into a reproducible, exact-build technical report. Use when Codex must document affected hardware and OS builds, expected and…
Write a reproducible security assessment or penetration-test report from validated evidence. Use when technical findings, negative results, scope, methodology, limitations,…
Resolve the material product, behavior, compatibility, data, permission, security, migration, and acceptance decisions that remain open before specification or implementation.
Research one macOS security control on an exact build, separating public contracts, private evidence, and hypotheses.
Design, exercise, and evidence graceful degradation, disaster recovery, and restoration behavior across systems and dependencies.
Use for recurring backup-restore validation and disaster-recovery simulation, including restore runbooks, drill frequency, pass/fail gates, evidence capture, and remediation…
Analyze reproduction evidence to identify the root cause of bugs. Use after reproduction to trace execution and find the exact location and reason for the failure.
Use Bug Hunter to run scan-first adversarial code audits where Hunter, Skeptic, and Referee agents check repository bugs, security issues, and fix evidence before any approved…
RAPTOR turns Claude Code into an evidence-first offensive and defensive security research workflow for mapping attack surfaces, validating scanner findings, analyzing binaries,…
Conduct a bounded, repository-grounded code self-review and repair loop with objective 1-5 scoring, exact scope preservation, targeted fixes, and focused and full verification.
Use when a strategist needs a structured situation synthesis before committing to a strategic direction.
Use to build or instrument a Sail Voyage — Sail's name for one background or long-running agent run, recorded as a trace of named agents, spans, and events.
Discover SameDayDesk's nineteen account-free machine services and produce a verified, non-spending purchase intent from the live OpenAPI contract and unpaid HTTP 402 challenge.
Package and structure audit evidence for SAP controls covering Segregation of Duties, change management, access management, and financial controls.
SAP BTP best practices for enterprise architecture, account management, security, and operations, with verification evidence tracked in the repository ledger.
Enumerate and export SAP BTP and S/4HANA landscape configuration using read-only list, get, describe, and export operations only.
Plan and remediate dependency vulnerabilities with Endor SCA findings, VersionUpgrade/UIA evidence, separate low-risk PR lanes, deterministic risk decisions, local validation, and…
Get your security deposit back — the move-out documentation that wins disputes before they start, the itemized-deduction challenge, the demand-letter ladder, and the small-claims…
Generate the quarterly macOS security-compliance evidence screenshot package for Nathan. Use when asked to create/recreate the evidence zip (e.g.
Workflow for authorized, evidence-preserving security review and remediation-task preparation.
Creates response procedures for security incidents with containment steps, communication templates, and evidence collection.
Use when the user wants a security-maturity scorecard / posture assessment of a module — category ratings with evidence, not a vulnerability hunt.
Generate UI for .NET MAUI (Shiny.Maui.Controls) and Blazor (Shiny.Blazor.Controls) - includes TableView with 14 cell types, TreeView with lazy loading, drag/drop reorder…
Tear a written plan apart to find gaps before implementing it. Use when the user has a plan — a docs/*-plan.md file or a plan just produced in the conversation — and wants it…
Close a meaningful build milestone before the next development phase by protecting accepted state, recording evidence in the Build Ledger or a staged delta, preserving failures…
Evaluate researched options against explicit decision criteria, constraints, strategic fit, technical fit, licensing, cost, security, readiness burden, reversibility, integration…
Govern whether an exact accepted artifact may be promoted or distributed by checking artifact identity, provenance, acceptance evidence, security/recovery gates, versioning,…
Verify whether a specific claim is actually supported by the available evidence without silently upgrading static, compile, automated, runtime, human-observed, security, signing,…
Use when reviewing vulnerability reports, reproduction notes, scanner tickets, submission drafts, audit findings, or claimed technical_confirmed vulnerabilities for evidence…
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Threat Hunting (754) · Identity Access (496) · Network Security (414) · Appsec Tools (381) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Zero Trust (82) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)