Performs a deep code quality, security, and structure audit on modified files prior to publishing a PR.
Notare: amtsenthebung vermögensverfall - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit, Belegplan und…
Ad hoc SQL analytics on local parquet, CSV, Excel, JSON, Avro, or SQLite files — auto-triggers on data analysis requests
Performs tracked, evidence-bounded security posture assessment for a project, sub-directory, module, concept, or feature topic with standards mapping and registered report output.
Ce skill fournit un cadre méthodologique complet pour analyser l'organisation spatiale, les dynamiques démographiques, les besoins en services, la vulnérabilité et les politiques…
Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence
Network protocol analyzer and packet capture tool for traffic analysis, security investigations, and forensic examination using Wireshark's command-line interface.
Analyze industry structure using Porter's Five Forces. Use when asked to assess industry attractiveness, competitive dynamics, profit potential, or structural threats.
Calculate and visualize magnetic fields produced by current distributions using the Biot-Savart law, Ampere's law, and magnetic dipole approximations.
Inspect captured RAM images to enumerate processes, modules, handles, and suspicious in-memory behavior before escalation or evidence handoff.
Enterprise-grade repository analysis with arc42/C4 architecture documentation, technical debt quantification, security assessment, and multi-stakeholder reporting
Evaluates corporate vulnerability to shareholder activism with governance assessment, valuation gaps, and operational improvement opportunities.
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative
Evaluates blockchain use cases in financial services with DLT assessment and implementation feasibility.
Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates,
Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures,
Maps competitive landscapes with market share tracking and Porter's Five Forces analysis. Use when analyzing competition, assessing market structure, or evaluating competitive…
Maps competitive dynamics with market positioning, feature comparison, funding histories, and differentiation assessment.
Expert at analyzing the quality and effectiveness of Claude Code components (agents, skills, commands, hooks). Assumes component is already technically valid.
Identifies weak cryptographic algorithms, hardcoded keys, and insecure key management practices in binary code.
Structures cryptocurrency tax analysis with cost basis tracking, gain classification, and reporting requirements.
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases
Analyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries.
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify
Structures EM economic analysis with growth, inflation, external vulnerability, and political risk assessment.
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction,
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns,
Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware,
Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download
Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system
Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families
Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction
Analyze cryptocurrency market sentiment using Fear & Greed Index, news analysis, and market momentum.
Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Analyzes network traffic generated by malware during sandbox execution or live incident response to identify
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,
Process perform on-chain analysis including whale tracking, token flows, and network activity. Use when performing crypto analysis.
Track crypto options flow to identify institutional positioning and market sentiment. Use when tracking institutional options flow.
Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for
Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,
Analyzes network protocol implementations to identify parsing vulnerabilities, state machine issues, and protocol-level security problems.
Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to
Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence
Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor,
Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities
Structures forward-looking scenario analysis with macroeconomic assumptions and portfolio impact assessment.
Analyze HTTP security headers of web domains to identify vulnerabilities and misconfigurations. Use when you need to audit website security headers, assess header compliance, or…
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents
Detects session management vulnerabilities including session fixation, session hijacking, and insecure cookie handling.