Back to authors
autohandai

autohandai

798 Skills published on GitHub.

analyzing-windows-event-logs-in-splunk

>

UncategorizedView skill →

analyzing-windows-lnk-files-for-artifacts

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

UncategorizedView skill →

analyzing-windows-prefetch-with-python

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

UncategorizedView skill →

analyzing-windows-registry-for-artifacts

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

UncategorizedView skill →

analyzing-windows-shellbag-artifacts

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

UncategorizedView skill →

api-design-restful

RESTful API design patterns, error handling, and documentation

UncategorizedView skill →

api-design

Design RESTful and GraphQL APIs following best practices. Use when creating new APIs, refactoring existing endpoints, or documenting API specifications. Handles OpenAPI, REST, GraphQL, versioning.

api-designRESTGraphQLOpenAPIversioningbackend
UncategorizedView skill →

api-documentation

Create comprehensive API documentation for developers. Use when documenting REST APIs, GraphQL schemas, or SDK methods. Handles OpenAPI/Swagger, interactive docs, examples, and API reference guides.

API-documentationOpenAPISwaggerRESTGraphQLdeveloper-docs
UncategorizedView skill →

auditing-aws-s3-bucket-permissions

>

UncategorizedView skill →

auditing-azure-active-directory-configuration

>

UncategorizedView skill →

auditing-cloud-with-cis-benchmarks

>

UncategorizedView skill →

auditing-gcp-iam-permissions

>

UncategorizedView skill →

auditing-kubernetes-cluster-rbac

>

UncategorizedView skill →

auditing-kubernetes-rbac-permissions

Kubernetes Role-Based Access Control (RBAC) auditing systematically reviews roles, cluster roles, bindings, and service account permissions to identify overly permissive access, privilege escalation p

UncategorizedView skill →

auditing-terraform-infrastructure-for-security

>

UncategorizedView skill →

authentication-setup

Design and implement authentication and authorization systems. Use when setting up user login, JWT tokens, OAuth, session management, or role-based access control. Handles password security, token management, SSO integration.

authenticationauthorizationsecurityJWTOAuthRBAC
UncategorizedView skill →

automating-ioc-enrichment

>

UncategorizedView skill →

brand-guidelines

Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.

UncategorizedView skill →

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

UncategorizedView skill →

conducting-cloud-penetration-testing

>

UncategorizedView skill →

browser-use

Automates browser interactions for web testing, form filling, screenshots, and data extraction. Use when the user needs to navigate websites, interact with web pages, fill forms, take screenshots, or extract information from web pages.

UncategorizedView skill →

building-adversary-infrastructure-tracking-system

Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.

UncategorizedView skill →

building-attack-pattern-library-from-cti-reports

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

UncategorizedView skill →

building-automated-malware-submission-pipeline

>

UncategorizedView skill →

building-c2-infrastructure-with-sliver-framework

Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.

UncategorizedView skill →

building-cloud-security-posture-management

>

UncategorizedView skill →

building-cloud-siem-with-sentinel

>

UncategorizedView skill →

building-detection-rule-with-splunk-spl

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

UncategorizedView skill →

building-detection-rules-with-sigma

>

UncategorizedView skill →

building-devsecops-pipeline-with-gitlab-ci

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.

UncategorizedView skill →

building-identity-federation-with-saml-azure-ad

Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.

UncategorizedView skill →

building-identity-governance-lifecycle-process

>

UncategorizedView skill →

building-incident-response-dashboard

>

UncategorizedView skill →

building-incident-response-playbook

>

UncategorizedView skill →

building-incident-timeline-with-timesketch

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.

UncategorizedView skill →

building-ioc-defanging-and-sharing-pipeline

Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.

UncategorizedView skill →

building-ioc-enrichment-pipeline-with-opencti

OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O

UncategorizedView skill →

building-malware-incident-communication-template

Build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.

UncategorizedView skill →

building-patch-tuesday-response-process

Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.

UncategorizedView skill →

building-phishing-reporting-button-workflow

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

UncategorizedView skill →

building-red-team-c2-infrastructure-with-havoc

Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.

UncategorizedView skill →

building-role-mining-for-rbac-optimization

Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.

UncategorizedView skill →

building-soc-escalation-matrix

Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.

UncategorizedView skill →

building-soc-metrics-and-kpi-tracking

>

UncategorizedView skill →

building-soc-playbook-for-ransomware

>

UncategorizedView skill →

building-threat-actor-profile-from-osint

Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.

UncategorizedView skill →

building-threat-feed-aggregation-with-misp

Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.

UncategorizedView skill →

building-threat-hunt-hypothesis-framework

Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.

UncategorizedView skill →

building-threat-intelligence-enrichment-in-splunk

Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.

UncategorizedView skill →

building-threat-intelligence-feed-integration

>

UncategorizedView skill →

Page 3 of 16 · 798 results