all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 12 of 18

  1. ▌
    Github Actions Security · yanacuti1121
    Harden GitHub Actions workflows against the well-known footguns. Covers SHA-pinned third-party actions, scoped GITHUB_TOKEN permissions, OIDC in place of long-lived cloud credentials, the pull_request_target trap, untrusted-input interpolation, and protected deploy environments. Invoke when adding a new workflow, introducing a third-party action, or migrating from long-lived secrets to OIDC.
    2 repo stars
  2. ▌
    Stripe Webhook Security · yanacuti1121
    Verify and process Stripe webhooks safely against the real-world failure modes. Covers signature verification against the raw body, idempotency keys, replay protection, event-type allowlists, the partial-refund and dual-currency traps, and re-fetching authoritative state from Stripe for real-money actions. Invoke when wiring webhooks for the first time, when adding a new event type, or after a payments incident.
    2 repo stars
  3. ▌
    Hunting For Ntlm Relay Attacks · yanacuti1121 bundle
    Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
    2 repo stars
  4. ▌
    Scaffold Exercises · yanacuti1121
    Create exercise directory structures with sections, problems, solutions, and explainers that pass linting. Use when user wants to scaffold exercises, create exercise stubs, or set up a new course section.
    2 repo stars
  5. ▌
    Mukul975 Cybersecurity Skills · yanacuti1121
    754 cybersecurity skills cho AI agent — 26 domains, map sang 5 frameworks (MITRE ATT&CK v19.1, NIST CSF 2.0, ATLAS v5.4, D3FEND v1.3, AI RMF 1.0). Real practitioner workflows.
    2 repo stars
  6. ▌
    Openai Cloudflare Agents Sdk · yanacuti1121 bundle
    Build AI agents on Cloudflare Workers using the Agents SDK. Load when creating stateful agents, durable workflows, real-time WebSocket apps, scheduled tasks, MCP servers, or chat applications. Covers Agent class, state management, callable RPC, Workflows integration, and React hooks. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
    2 repo stars
  7. ▌
    Openai Cloudflare Cloudflare · yanacuti1121 bundle
    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
    2 repo stars
  8. ▌
    Performing Ransomware Response · yanacuti1121 bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.
    2 repo stars
  9. ▌
    Performing Vlan Hopping Attack · yanacuti1121 bundle
    Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
    2 repo stars
  10. ▌
    Pewdiepie Archdaemon Odysseus · yanacuti1121
    Self-hosted AI workspace — Chat, Agent, Email IMAP AI triage, Deep Research, Calendar, Memory/Skills. Dùng khi cần build hoặc self-host một AI assistant đầy đủ tính năng.
    2 repo stars
  11. ▌
    Shubhamsaboo Awesome LLM Apps · yanacuti1121
    100+ AI Agent & RAG app templates sẵn sàng chạy — 14 categories: starter agents, multi-agent teams, voice AI, MCP agents, RAG, memory, fine-tuning. Apache-2.0.
    2 repo stars
  12. ▌
    Sovereign Interceptor Patterns · yanacuti1121
    Build L3 sovereign security interceptors for agent runtimes. AST scanning of agent-generated code, command allow-lists, honey-vault canary token detection, and SHA256 payload fingerprinting.
    2 repo stars
  13. ▌
    Competitor Monitoring · yanacuti1121
    When the user wants to set up ongoing tracking of competitor activity — pricing changes, feature launches, hiring signals, content, or public mentions. Also use when the user mentions "track competitors", "what are competitors doing", "competitor alerts", or "market watch".
    2 repo stars
  14. ▌
    Earned Media Outreach · yanacuti1121
    When the user wants to get press coverage, appear on podcasts, or build relationships with journalists and content creators. Also use when the user mentions "podcast guesting", "press outreach", "PR", "media exposure", "get on podcasts", or "journalist outreach".
    2 repo stars
  15. ▌
    Testing Websocket API Security · yanacuti1121 bundle
    Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates for requests involving WebSocket security testing, WS penetration testing, CSWSH attack, or real-time API security assessment.
    2 repo stars
  16. ▌
    Code Simplification · yanacuti1121
    Simplifies code for clarity. Use when refactoring code for clarity without changing behavior. Use when code works but is harder to read, maintain, or extend than it should be. Use when reviewing code that has accumulated unnecessary complexity.
    2 repo stars
  17. ▌
    Context Engineering · yanacuti1121
    Optimizes agent context setup. Use when starting a new session, when agent output quality degrades, when switching between tasks, or when you need to configure rules files and context for a project.
    2 repo stars
  18. ▌
    Shipping And Launch · yanacuti1121
    Prepares production launches. Use when preparing to deploy to production. Use when you need a pre-launch checklist, when setting up monitoring, when planning a staged rollout, or when you need a rollback strategy.
    2 repo stars
  19. ▌
    Analyzing Kubernetes Audit Logs · yanacuti1121 bundle
    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.
    2 repo stars
  20. ▌
    Analyzing Linux Kernel Rootkits · yanacuti1121 bundle
    Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.
    2 repo stars
  21. ▌
    Conducting API Security Testing · yanacuti1121 bundle
    Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.
    2 repo stars
  22. ▌
    Configuring Hsm For Key Storage · yanacuti1121 bundle
    Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
    2 repo stars
  23. ▌
    Detecting Cryptomining In Cloud · yanacuti1121 bundle
    This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
    2 repo stars
  24. ▌
    Detecting Golden Ticket Forgery · yanacuti1121 bundle
    Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM
    2 repo stars
  25. ▌
    Detecting Kerberoasting Attacks · yanacuti1121 bundle
    Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
    2 repo stars
  26. ▌
    Detecting Pass The Hash Attacks · yanacuti1121 bundle
    Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.
    2 repo stars
  27. ▌
    Detecting Service Account Abuse · yanacuti1121 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    2 repo stars
  28. ▌
    Detecting Shadow It Cloud Usage · yanacuti1121 bundle
    Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.
    2 repo stars
  29. ▌
    Detecting Stuxnet Style Attacks · yanacuti1121 bundle
    This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation from operators. It addresses PLC logic integrity monitoring, physics-based process anomaly detection, engineering workstation compromise indicators, USB-borne attack vectors, and multi-stage attack chain detection spanning IT-to-OT lateral movement through to process manipulation.
    2 repo stars
  30. ▌
    Exploiting Idor Vulnerabilities · yanacuti1121 bundle
    Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.
    2 repo stars
  31. ▌
    Exploiting Ipv6 Vulnerabilities · yanacuti1121 bundle
    Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
    2 repo stars
  32. ▌
    Backup Disaster Recovery · yanacuti1121
    Design backups that actually work when they are needed. Covers RPO and RTO definition, the 3-2-1 rule, encryption before leaving the host, ransomware-resistant immutable storage, restore drills, and the split between operational and legal retention. Invoke when 'we have backups but nobody has restored them' is true, after a near-miss, or before a major migration.
    2 repo stars
  33. ▌
    Distributed System Audit · yanacuti1121
    Audit distributed systems where the highest-impact findings live between the components, not inside any one of them. Covers architecture mapping, trust boundary enumeration, per-channel protocol review (replay, ordering, forgery), STRIDE-lite threat modeling, failure-mode analysis, and forensic accountability. Invoke when auditing client / server, microservices, IoT backends, or agent-platform architectures.
    2 repo stars
  34. ▌
    LLM Coding Failure Modes · yanacuti1121
    Recognize the recurring security failure modes of LLM coding agents — Claude Code, Copilot, Cursor, Windsurf, and similar. Covers bulk operations without per-item review, safety-guard bypass as friction removal, acting on indirect injection, secrets in logs and commits, slopsquatting, outdated training patterns, sycophancy on insecure proposals, and silent error swallowing. Invoke when reviewing LLM-written code, designing a coding agent's guardrails, or onboarding a team to LLM-assisted workflows.
    2 repo stars
  35. ▌
    Prompt Injection Defense · yanacuti1121
    Contain direct and indirect prompt injection in LLM-integrated applications. Covers source-of-trust tagging, tool-use confirmation after untrusted input, output validation, markdown-image exfiltration prevention, and context-window hygiene. Invoke when building any app where untrusted text reaches an LLM, when the LLM has tools that act on real systems, or after a suspected injection incident.
    2 repo stars
  36. ▌
    Implementing Saml Sso With Okta · yanacuti1121 bundle
    Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
    2 repo stars
  37. ▌
    Managing Intelligence Lifecycle · yanacuti1121 bundle
    Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
    2 repo stars
  38. ▌
    Mapping Mitre Attack Techniques · yanacuti1121 bundle
    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
    2 repo stars
  39. ▌
    Migrate To Shoehorn · yanacuti1121
    Migrate test files from `as` type assertions to @total-typescript/shoehorn. Use when user mentions shoehorn, wants to replace `as` in tests, or needs partial test data.
    2 repo stars
  40. ▌
    Openai Cloudflare Sandbox Sdk · yanacuti1121
    Build sandboxed applications for secure code execution. Load when building AI code execution, code interpreters, CI/CD systems, interactive dev environments, or executing untrusted code. Covers Sandbox SDK lifecycle, commands, files, code interpreter, and preview URLs. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
    2 repo stars
  41. ▌
    Performing Kerberoasting Attack · yanacuti1121 bundle
    Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names
    2 repo stars
  42. ▌
    Performing Purple Team Exercise · yanacuti1121 bundle
    Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
    2 repo stars
  43. ▌
    Performing Ssl Stripping Attack · yanacuti1121 bundle
    Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.
    2 repo stars
  44. ▌
    Securing Helm Chart Deployments · yanacuti1121 bundle
    Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
    2 repo stars
  45. ▌
    Testing For Xss Vulnerabilities · yanacuti1121 bundle
    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies all injection points and output contexts, crafts context-appropriate payloads, and bypasses sanitization and CSP protections. Activates for requests involving XSS testing, cross-site scripting assessment, client-side injection testing, or JavaScript injection vulnerability testing.
    2 repo stars
  46. ▌
    CI CD And Automation · yanacuti1121
    Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
    2 repo stars
  47. ▌
    Codex CLI Bridge · yanacuti1121
    Bridge between Claude Code and OpenAI Codex CLI - generates AGENTS.md from CLAUDE.md, provides Codex CLI execution helpers, and enables seamless interoperability between both tools
    2 repo stars
  48. ▌
    Analyzing Linux System Artifacts · yanacuti1121 bundle
    Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
    2 repo stars
  49. ▌
    Analyzing PDF Malware With Pdfid · yanacuti1121 bundle
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.
    2 repo stars
  50. ▌
    Auditing Kubernetes Cluster Rbac · yanacuti1121 bundle
    Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
    2 repo stars
  51. ▌
    Book Domain Driven Design Full · yanacuti1121
    Domain-Driven Design (Eric Evans) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Domain-Driven Design principles or review code against Domain-Driven Design standards.
    2 repo stars
  52. ▌
    Book Domain Driven Design Mini · yanacuti1121
    Domain-Driven Design (Eric Evans) — Condensed rules — key principles distilled. Use when asked to apply Domain-Driven Design principles or review code against Domain-Driven Design standards.
    2 repo stars
  53. ▌
    Book Domain Driven Design Nano · yanacuti1121
    Domain-Driven Design (Eric Evans) — Minimal rules — essential one-liners only. Use when asked to apply Domain-Driven Design principles or review code against Domain-Driven Design standards.
    2 repo stars
  54. ▌
    Deobfuscating Javascript Malware · yanacuti1121 bundle
    Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic. Activates for requests involving JavaScript malware analysis, script deobfuscation, web skimmer analysis, or obfuscated dropper investigation.
    2 repo stars
  55. ▌
    Detecting Azure Lateral Movement · yanacuti1121 bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    2 repo stars
  56. ▌
    Docker Container Security · yanacuti1121
    Run containers with a defensive baseline that survives production. Covers non-root users, read-only filesystems, dropped Linux capabilities, secret mounts instead of build-time bake-in, image scanning with trivy, distroless and minimal base images, and the Docker-bypasses-UFW firewall pitfall. Invoke when adding Docker to a VPS with UFW, writing a new Dockerfile, or pushing an image to a public registry.
    2 repo stars
  57. ▌
    Hunting For Shadow Copy Deletion · yanacuti1121 bundle
    Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
    2 repo stars
  58. ▌
    Implementing Zero Trust In Cloud · yanacuti1121 bundle
    This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.
    2 repo stars
  59. ▌
    Writing Great Skills · yanacuti1121 bundle
    Reference for writing and editing skills well — the vocabulary and principles that make a skill predictable.
    2 repo stars
  60. ▌
    Opentelemetry Semantic Telemetry · yanacuti1121
    Instrument multi-agent swarms with OpenTelemetry spans, semantic drift monitoring, anomaly detection, distributed trace propagation across 87 agents, and SIEM bridge export for security events.
    2 repo stars
  61. ▌
    Performing Osint With Spiderfoot · yanacuti1121 bundle
    Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources
    2 repo stars
  62. ▌
    Performing Service Account Audit · yanacuti1121 bundle
    Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
    2 repo stars
  63. ▌
    Performing Soc Tabletop Exercise · yanacuti1121 bundle
    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
    2 repo stars
  64. ▌
    Reverse Engineering Rust Malware · yanacuti1121 bundle
    Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis.
    2 repo stars
  65. ▌
    Accelerator Application · yanacuti1121
    When the user wants to apply to startup accelerators, incubators, or fellowship programs. Also use when the user mentions "YC application", "Techstars", "accelerator", or "apply to programs".
    2 repo stars
  66. ▌
    User Research Synthesis · yanacuti1121
    When the user has raw customer interview transcripts, survey responses, support tickets, or other qualitative data and needs to extract actionable insights.
    2 repo stars
  67. ▌
    Vibecode Production QA Validator · yanacuti1121
    End-to-end production QA, build verification, and launch-readiness checklist for fullstack Next.js apps before going live or shipping a major update. Covers TypeScript, linting, tests, build, SEO tags, route regression, and sitemap validation.
    2 repo stars
  68. ▌
    Analyzing API Gateway Access Logs · yanacuti1121 bundle
    Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.
    2 repo stars
  69. ▌
    Analyzing Disk Image With Autopsy · yanacuti1121 bundle
    Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
    2 repo stars
  70. ▌
    Analyzing Heap Spray Exploitation · yanacuti1121 bundle
    Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
    2 repo stars
  71. ▌
    Building Cloud Siem With Sentinel · yanacuti1121 bundle
    This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.
    2 repo stars
  72. ▌
    Chrome Devtools Network Inspector · yanacuti1121
    Inspect, list, and analyze live browser network requests via Chrome DevTools MCP. Identify slow requests, failed fetches, API payloads, CORS errors, and waterfall bottlenecks.
    2 repo stars
  73. ▌
    Chrome Devtools Performance Trace · yanacuti1121
    Record and analyze Chrome performance traces via DevTools MCP. Capture CPU flame graphs, long tasks, layout thrash, and JS execution timelines. Extract actionable insights from trace data.
    2 repo stars
  74. ▌
    Conducting Pass The Ticket Attack · yanacuti1121 bundle
    Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro
    2 repo stars
  75. ▌
    Danielmiessler Personal AI Infra · yanacuti1121
    Personal AI Infrastructure (PAI) — Life OS chạy trên Claude Code: 45 skills, 171 workflows, 37 hooks, ISA pattern, Telos (life direction), Pulse dashboard localhost:31337.
    2 repo stars
  76. ▌
    Deploying Ransomware Canary Files · yanacuti1121 bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.
    2 repo stars
  77. ▌
    Detecting API Enumeration Attacks · yanacuti1121 bundle
    Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
    2 repo stars
  78. ▌
    Detecting Dll Sideloading Attacks · yanacuti1121 bundle
    Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
    2 repo stars
  79. ▌
    Detecting Dnp3 Protocol Anomalies · yanacuti1121 bundle
    Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
    2 repo stars
  80. ▌
    Detecting Mobile Malware Behavior · yanacuti1121 bundle
    Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
    2 repo stars
  81. ▌
    Detecting Pass The Ticket Attacks · yanacuti1121 bundle
    Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM
    2 repo stars
  82. ▌
    Detecting Rdp Brute Force Attacks · yanacuti1121 bundle
    Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
    2 repo stars
  83. ▌
    Exploiting HTTP Request Smuggling · yanacuti1121 bundle
    Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
    2 repo stars
  84. ▌
    Exploiting OAUTH Misconfiguration · yanacuti1121 bundle
    Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.
    2 repo stars
  85. ▌
    Hunting For Cobalt Strike Beacons · yanacuti1121 bundle
    Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
    2 repo stars
  86. ▌
    Hunting For Dcom Lateral Movement · yanacuti1121 bundle
    Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation, WMI event analysis, RPC endpoint mapper traffic on port 135, and DCOM-specific parent-child process relationships.
    2 repo stars
  87. ▌
    Hunting For Dns Based Persistence · yanacuti1121 bundle
    Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
    2 repo stars
  88. ▌
    Implementing Siem Use Case Tuning · yanacuti1121 bundle
    Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic
    2 repo stars
  89. ▌
    Jamwithai Production Agentic RAG · yanacuti1121
    Production-grade RAG system patterns — keyword search foundations + vector hybrid retrieval, FastAPI, OpenSearch, Airflow pipelines. Dùng khi build RAG cho production.
    2 repo stars
  90. ▌
    Managing Cloud Identity With Okta · yanacuti1121 bundle
    This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
    2 repo stars
  91. ▌
    Performing Csrf Attack Simulation · yanacuti1121 bundle
    Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
    2 repo stars
  92. ▌
    Performing Malware Ioc Extraction · yanacuti1121 bundle
    Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist
    2 repo stars
  93. ▌
    Performing Red Team With Covenant · yanacuti1121 bundle
    Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
    2 repo stars
  94. ▌
    Performing Security Headers Audit · yanacuti1121 bundle
    Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
    2 repo stars
  95. ▌
    Recovering From Ransomware Attack · yanacuti1121 bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
    2 repo stars
  96. ▌
    Scanning Docker Images With Trivy · yanacuti1121 bundle
    Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati
    2 repo stars
  97. ▌
    Securing API Gateway With AWS Waf · yanacuti1121 bundle
    Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness.
    2 repo stars
  98. ▌
    Securing Github Actions Workflows · yanacuti1121 bundle
    This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
    2 repo stars
  99. ▌
    Testing For Broken Access Control · yanacuti1121 bundle
    Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
    2 repo stars
  100. ▌
    Testing For Host Header Injection · yanacuti1121 bundle
    Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
    2 repo stars