← all publishers

undermybelt

@undermybelt source repo

1255 published skills · page 1 of 13

  1. Anysearch · undermybelt bundle
    Real-time search engine supporting web search, vertical domain search, parallel batch search, and URL content extraction.
    2
    installs
  2. Archify · undermybelt bundle
    Create professional architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as standalone HTML files with SVG graphics, a built-in dark/light theme toggle, and one-click export to PNG / JPEG / WebP / SVG. Use when the user asks for system architecture diagrams, infrastructure diagrams, cloud architecture visualizations, security diagrams, network topology diagrams, technical workflows, approval flows, runbooks, CI/CD flows, process diagrams, API call sequences, request lifecycles, interaction diagrams, data pipelines, analytics flows, ETL/ELT maps, PII boundaries, governance/data lineage diagrams, state machines, lifecycle diagrams, status transitions, or terminal/retry paths.
    0
    installs
  3. Deep Discuss · undermybelt
    结构化深度讨论 Skill,用于与用户进行多轮问题分析和方案设计。当用户描述一个问题现象、故障表现、 技术困惑、方案选择困难,或明确说"讨论一下"、"帮我分析"、"我遇到一个问题"、"你觉得怎么样"、 "帮我想想"、"我在纠结"时,必须使用本 skill。当用户提供了一段描述(可能附带截图)并期望深入分析 而非直接给答案时,也应触发本 skill。即使用户只是抛出一个现象描述没有明确提问,也要使用本 skill 来引导结构化思考。不要在简单的事实查询("X是什么")或明确的执行指令("帮我写个脚本")上触发。
    0
    installs
  4. Cn Index · undermybelt
    A股指数数据与申万行业分类。上证/深证指数行情、成分股权重、申万行业分类。 当用户询问"上证指数""深证成指""申万行业""成分股权重""指数行情"时触发。
    0
    installs
  5. Cn Kline · undermybelt
    A股K线数据查询。获取日线、周线、月线行情。 当用户询问"茅台日K""万科周线""A股月线""K线走势"时触发。
    0
    installs
  6. Hk Kline · undermybelt
    港股K线数据查询。获取日线、周线、月线行情。 当用户询问"腾讯日K""港股K线""港交所周线""恒指月线"时触发。
    0
    installs
  7. Us Kline · undermybelt
    美股K线数据查询。获取日线行情。 当用户询问"苹果日K""特斯拉周线""美股K线走势"时触发。
    0
    installs
  8. Cn Market · undermybelt
    A股市场全量数据服务。编排 A股所有细粒度 skill:实时行情、K线、基础数据、市场机制、指数、技术指标。 当用户提及"A股""沪深""创业板""北京交所"且未明确指定数据维度时触发。
    0
    installs
  9. Hk Market · undermybelt
    港股市场全量数据服务。编排港股所有细粒度 skill:实时行情、K线、基础数据、港股通、技术指标。 当用户提及"港股""HKEX""恒生""腾讯"且未明确指定数据维度时触发。
    0
    installs
  10. Us Market · undermybelt
    美股市场全量数据服务。编排美股所有细粒度 skill:实时行情、K线、基础数据、技术指标。 当用户提及"美股""纽交所""纳斯达克""苹果""特斯拉"且未明确指定数据维度时触发。
    0
    installs
  11. Hk Connect · undermybelt
    港股通数据查询。港股通Top10、每日成交、持仓数据。 当用户询问"港股通Top10""北向资金""南向持仓""港股通成交"时触发。
    0
    installs
  12. Generative UI · undermybelt bundle
    Design system and guidelines for Claude's built-in generative UI — the show_widget tool that renders interactive HTML/SVG widgets inline in claude.ai conversations. This skill provides the complete Anthropic "Imagine" design system so Claude produces high-quality widgets without needing to call read_me first. Use this skill whenever the user asks to visualize data, create an interactive chart, build a dashboard, render a diagram, draw a flowchart, show a mockup, create an interactive explainer, or produce any visual content beyond plain text or markdown. Triggers include: "show me", "visualize", "draw", "chart", "dashboard", "diagram", "flowchart", "widget", "interactive", "mockup", "illustrate", "explain how X works" (with visual), or any request for visual/interactive output. Also triggers when the user wants to display financial data visually, create comparison grids, or build tools with sliders, toggles, or live-updating displays.
    0
    installs
  13. Skill Router · undermybelt
    Skill 索引与编排中心 — 根据用户意图自动路由到正确的 skill 组合并编排执行顺序。 当用户提问涉及股票行情、加密货币、技术指标、财经新闻、研报生成等任何需要调用 skill 的场景时触发。 也在用户询问"数据从哪来"、"你能做什么"、"有哪些功能"时触发。
    0
    installs
  14. Executing Analysis · undermybelt
    Use when you have a pre-registered analysis plan to execute inline in this session with review checkpoints, on a platform without subagents
    0
    installs
  15. Options Payoff · undermybelt bundle
    Generate an interactive options payoff curve chart with dynamic parameter controls. Use this skill whenever the user shares an options position screenshot, describes an options strategy, or asks to visualize how an options trade makes or loses money. Triggers include: any mention of butterfly, spread (vertical/calendar/diagonal/ratio), straddle, strangle, condor, covered call, protective put, iron condor, or any multi-leg options structure. Also triggers when a user pastes strike prices, premiums, expiry dates, or says things like "show me the payoff", "draw the P&L curve", "what does this trade look like", or uploads a screenshot from a broker (IBKR, TastyTrade, Robinhood, etc). Always use this skill even if the user only provides partial info — extract what you can and use defaults for the rest.
    0
    installs
  16. Crypto Market · undermybelt
    加密货币市场全量数据服务。覆盖 K线、持仓、爆仓、资金费率、多空比、CVD/买卖、ETF、 市场指标(恐惧贪婪/AHR999等)、新闻、巨鲸追踪、大额订单、排行榜、订单簿、资金流等。 当用户提及"BTC""比特币""以太坊""加密货币""合约""资金费率""爆仓""持仓量""恐惧贪婪指数"时触发。
    0
    installs
  17. Cn Fundamental · undermybelt
    A股基础数据查询。股票列表、公司信息、每日指标(PE/PB/换手率)、更名历史。 当用户询问"茅台公司信息""PE是多少""股票列表""万科更名"时触发。
    0
    installs
  18. Hk Fundamental · undermybelt
    港股基础数据查询。港股列表、交易日历。 当用户询问"港股列表""港股交易日""港股代码查询"时触发。
    0
    installs
  19. Us Fundamental · undermybelt
    美股基础数据查询。美股列表、交易日历。 当用户询问"美股列表""美股交易日""美股代码查询"时触发。
    0
    installs
  20. Surveying Prior Work · undermybelt
    Use after framing a question and before designing an analysis, or when choosing a method, judging whether a result is novel, or needing a prior effect size for a power calculation
    0
    installs
  21. Designing The Analysis · undermybelt
    Use when you have an approved research question and need a concrete analysis plan, before touching outcome data or fitting any model
    0
    installs
  22. Writing Science Skills · undermybelt
    Use when creating new skills, editing existing skills, or verifying skills work before deployment
    0
    installs
  23. Cn Realtime Quote · undermybelt
    A股实时行情查询。批量获取沪深京三市证券实时报价。 当用户询问"茅台实时价格""沪深实时行情""A股报价""股票现价"时触发。
    0
    installs
  24. Crypto Indicators · undermybelt
    加密货币技术指标服务。支持 27 种技术指标,覆盖 MA/EMA/RSI/MACD/KDJ/布林带/ADX/ATR/CCI/VWAP 等。 当用户询问"BTC RSI""以太坊 MACD""加密货币技术指标""BTC 布林带"时触发。
    0
    installs
  25. Hk Realtime Quote · undermybelt
    港股实时行情查询。批量获取 HKEX 证券实时报价。 当用户询问"腾讯实时价格""港股实时行情""HK报价""港交所现价"时触发。
    0
    installs
  26. Us Realtime Quote · undermybelt
    美股实时行情查询。批量获取美股证券实时报价。 当用户询问"苹果实时价格""美股实时行情""AAPL报价""美股现价"时触发。
    0
    installs
  27. Subagent Driven Analysis · undermybelt bundle
    Use when executing a pre-registered analysis plan with mostly independent steps in the current session
    0
    installs
  28. Cn Market Mechanics · undermybelt
    A股市场机制数据。涨跌停价格、停复牌信息、新股IPO、交易日历、复权因子。 当用户询问"涨跌停""停复牌""新股IPO""交易日历""复权因子"时触发。
    0
    installs
  29. Receiving Critical Review · undermybelt
    Use when receiving critical feedback on an analysis or manuscript, before implementing suggestions, especially if feedback seems unclear or methodologically questionable - requires verification, not performative agreement or blind changes
    0
    installs
  30. Requesting Red Team Review · undermybelt bundle
    Use after completing an analysis or before reporting a finding, to have a skeptical reviewer attack the conclusion before you believe it
    0
    installs
  31. Cross Market Indicators · undermybelt
    跨市场股票技术指标服务。支持 A股/港股/美股 27种技术指标,包括 MA/EMA/RSI/MACD/KDJ/布林带/ADX/ATR/CCI/VWAP等。 当用户询问"RSI""MACD""布林带""技术指标""KDJ""OBV"等时触发。 ⚠️ 加密货币技术指标请使用 crypto-indicators skill。
    0
    installs
  32. Investigating Anomalous Results · undermybelt
    Use when a result is surprising, impossible, contradicts a sanity check, a pipeline fails, a model won't converge, or a replication fails - before adjusting anything
    0
    installs
  33. Setting Up Reproducible Analysis · undermybelt
    Use when starting analysis work that needs isolation, or before executing a pre-registered plan - ensures an isolated, reproducible workspace with pinned environment, fixed seeds, and immutable raw data
    0
    installs
  34. Dispatching Parallel Investigations · undermybelt
    Use when facing 2+ independent investigations that can proceed without shared state - parallel literature survey, multi-dataset replication, or pre-specified robustness checks
    0
    installs
  35. Domain Prsstn Dcsync · undermybelt bundle
    Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
    0
    installs
  36. Email Account Cmprms · undermybelt bundle
    Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
    0
    installs
  37. Endpoint Dtctn Wazuh · undermybelt bundle
    Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    0
    installs
  38. Exfltr Over Dns Zeek · undermybelt bundle
    Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
    0
    installs
  39. File Intgrt Mon Aide · undermybelt bundle
    Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
    0
    installs
  40. Firmware Malware Ana · undermybelt bundle
    Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
    0
    installs
  41. Github Actions Flows · undermybelt bundle
    This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
    0
    installs
  42. Immtbl Backup Restic · undermybelt bundle
    Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection. Automates backup creation, integrity verification via restic check --read-data, snapshot retention policy enforcement, and restore testing. Integrates with AWS S3 Object Lock, MinIO, and Backblaze B2 for WORM (Write Once Read Many) storage that prevents backup deletion or encryption by ransomware actors.
    0
    installs
  43. Incident Resp Dshbrd · undermybelt bundle
    Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
    0
    installs
  44. Infrst Code Sec Scan · undermybelt bundle
    This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.
    0
    installs
  45. Insider Threat Bhvrs · undermybelt bundle
    Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
    0
    installs
  46. JSON Web Token Vulns · undermybelt bundle
    Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
    0
    installs
  47. Lateral Movement Net · undermybelt bundle
    Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
    0
    installs
  48. Lateral Movement Wmi · undermybelt bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    0
    installs
  49. Log Ana Forensic Inv · undermybelt bundle
    Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
    0
    installs
  50. Memory Frnscs Vltlty · undermybelt bundle
    Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
    0
    installs
  51. Ms17 010 Etrnlb Vuln · undermybelt bundle
    MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it
    0
    installs
  52. Mscnfg Azure Storage · undermybelt bundle
    Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.
    0
    installs
  53. Net Traffic Ana Zeek · undermybelt bundle
    Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
    0
    installs
  54. Osquery Endpoint Mon · undermybelt bundle
    Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
    0
    installs
  55. Ot Net Traf Ana Nozo · undermybelt bundle
    Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
    0
    installs
  56. Packet Injctn Attack · undermybelt bundle
    Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
    0
    installs
  57. Plc Firmware Sec Ana · undermybelt bundle
    This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampering.
    0
    installs
  58. Prvlgd Access Wrkstt · undermybelt bundle
    Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
    0
    installs
  59. Purple Team Exercise · undermybelt bundle
    Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
    0
    installs
  60. Pwrshl Empire Artfct · undermybelt bundle
    Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
    0
    installs
  61. Reveng IOS App Frida · undermybelt bundle
    Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
    0
    installs
  62. Rnsmwr Encryp Mchnsm · undermybelt bundle
    Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
    0
    installs
  63. Runtime Sec Tetragon · undermybelt bundle
    Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
    0
    installs
  64. Sca Dpndnc Scan Snyk · undermybelt bundle
    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
    0
    installs
  65. Secret Scan Gitleaks · undermybelt bundle
    This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
    0
    installs
  66. Shadow Copy Deletion · undermybelt bundle
    Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
    0
    installs
  67. Siem Use Case Tuning · undermybelt bundle
    Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic
    0
    installs
  68. Siem Use Cases Dtctn · undermybelt bundle
    Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
    0
    installs
  69. Sprphs Email Gateway · undermybelt bundle
    Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
    0
    installs
  70. Ssl Cert Lfcycl Mgmt · undermybelt bundle
    SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading
    0
    installs
  71. Supp Chai Atta CI CD · undermybelt bundle
    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
    0
    installs
  72. T1098 Account Mnpltn · undermybelt bundle
    Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
    0
    installs
  73. Tcktng System Incdnt · undermybelt bundle
    Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.
    0
    installs
  74. Threat Intel Reports · undermybelt bundle
    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.
    0
    installs
  75. Tls Cert Trnspr Logs · undermybelt bundle
    Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for proactive phishing domain detection and certificate monitoring.
    0
    installs
  76. Tlscl Zero Trust Vpn · undermybelt bundle
    Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
    0
    installs
  77. User Behavior Anlytc · undermybelt bundle
    Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.
    0
    installs
  78. Win Lnk Files Artfct · undermybelt bundle
    Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
    0
    installs
  79. Zero Trust Saas Apps · undermybelt bundle
    Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.
    0
    installs
  80. Access Rcrtfc Saviynt · undermybelt bundle
    Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
    0
    installs
  81. Android Intents Vulns · undermybelt bundle
    Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.
    0
    installs
  82. API Sec Test 42crunch · undermybelt bundle
    Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
    0
    installs
  83. Apt Group Mitre Nvgtr · undermybelt bundle
    Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
    0
    installs
  84. Arp Psnng Net Traffic · undermybelt bundle
    Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
    0
    installs
  85. Attacks Hstrn Servers · undermybelt bundle
    Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
    0
    installs
  86. Audi AWS S3 Buck Prms · undermybelt bundle
    Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.
    0
    installs
  87. Audi Azur Act Dir Cfg · undermybelt bundle
    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
    0
    installs
  88. AWS Macie Data Clssfc · undermybelt bundle
    Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
    0
    installs
  89. AWS Nitro Enclave Sec · undermybelt bundle
    Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activates for requests involving Nitro Enclave setup, enclave attestation validation, confidential computing on AWS, or KMS enclave policy configuration.
    0
    installs
  90. Business Email Cmprms · undermybelt bundle
    Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
    0
    installs
  91. Cloud Dlp Data Prtctn · undermybelt bundle
    Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines.
    0
    installs
  92. Cloud Workload Prtctn · undermybelt bundle
    Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.
    0
    installs
  93. Cntnr Escape Attempts · undermybelt bundle
    Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
    0
    installs
  94. Cntnr Registry Harbor · undermybelt bundle
    Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio
    0
    installs
  95. Cntnr Registry Images · undermybelt bundle
    Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned images.
    0
    installs
  96. Cobalt Strike Beacons · undermybelt bundle
    Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
    0
    installs
  97. Command Control Bcnng · undermybelt bundle
    Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
    0
    installs
  98. Cond Sec Ot Remo Acce · undermybelt bundle
    Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly.
    0
    installs
  99. Crdntl Access Lazagne · undermybelt bundle
    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
    0
    installs
  100. Crdntl Dumping Tchnqs · undermybelt bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
    0
    installs