Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 53

Claude Security Skills (Page 53 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 3121–3180 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Detects whether a user task contains multiple independent subtasks and splits it into a JSON array. Internal helper for orchestrate Phase 0.5; uses session credentials (no API…
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
Detects arbitrary read vulnerabilities by identifying unchecked array indexing and out-of-bounds memory access.
Detects arbitrary write vulnerabilities by identifying unchecked array indexing and out-of-bounds memory writes.
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive
Detects stack and heap buffer overflow vulnerabilities in binary code by identifying unsafe memory operations.
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
Detects OS command injection vulnerabilities by identifying unsafe system/popen/exec calls with user-controlled input.
Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible
Container escape is a critical attack technique where an adversary breaks out of container isolation to access
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like…
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
Detects double free vulnerabilities by identifying attempts to free the same memory block twice. Use when analyzing memory management, cleanup paths, or investigating heap…
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files
Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,
Detects format string vulnerabilities by identifying unsafe printf family function calls with user-controlled format strings.
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
Detects information disclosure vulnerabilities including sensitive data in logs, error message exposure, and memory leaks.
Detects various injection vulnerabilities including SQL injection, LDAP injection, XPath injection, and code injection.
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
Detects integer overflow and underflow vulnerabilities in arithmetic operations used for buffer sizing or allocation.
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process
Detects logic bypass vulnerabilities including authentication bypass, authorization bypass, and business logic flaws.
Detects various memory corruption vulnerabilities beyond simple buffer overflows including heap overflow, stack smashing, and double free.
Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse
Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming…
Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection
Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for
Detects null pointer dereference vulnerabilities by identifying unchecked pointer usage and missing validation.
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts,
Detects privilege escalation vulnerabilities including setuid/setgid abuse, permission check bypasses, and unsafe privilege management.
Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,
Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious
Detects race condition vulnerabilities including TOCTOU, double-checked locking issues, and shared state problems.
Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and
Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
Detect hardcoded secrets, API keys, tokens, and credentials in code and git history. Use when auditing for leaked secrets or before publishing code.
Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity
Search all 10,533 Security skills →