26zl

63 mods across 1 repository, 46 stars between them.

cybersec-toolkit

01

26zl/cybersec-toolkit

Plugin Claude Code

Cybersecurity skill library — security how-tos, offensive/defensive methodology, and CTF/bounty playbooks for Claude Code.

46 4d ago A tokens not measured original MIT

cybersec-toolkit

02

26zl/cybersec-toolkit

Plugin Claude Code

872 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context. Bundles vendored skills under mixed licenses (MIT, Apache-2.0, CC-BY-SA-4.0) — see per-source…

46 4d ago A tokens not measured original MIT

SessionStart

03

26zl/cybersec-toolkit

Hook Claude Code

Runs when a session starts, executing agent-guard.sh via bash. From 26zl/cybersec-toolkit.

46 4d ago A tokens not measured original MIT

PreToolUse

04

26zl/cybersec-toolkit

Hook Claude Code

Runs before the agent uses a tool for Bash tool calls, executing agent-guard.sh via bash. From 26zl/cybersec-toolkit.

46 4d ago A tokens not measured original MIT

cybersec-toolkit

05

26zl/cybersec-toolkit

Settings file Claude Code

Agent settings declaring 2 hook events (SessionStart, PreToolUse).

46 4d ago A tokens not measured original MIT

add-tool

07

26zl/cybersec-toolkit

Skill Claude CodeCodex

Use when adding a new cybersecurity tool to this installer. Walks through editing the right module file, adding to toolsconfig.json, running validators, and syncing MCP server data if needed. Triggers on phrases like "add tool", "add ", "register a new tool", "include X in the installer".

46 4d ago A 68 tokens original MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Use for AI/LLM security assessments, prompt injection, RAG security, agent/tool permissioning, model supply chain, LLM red teaming, AI governance, eval design, data leakage, jailbreak testing, and secure AI application review.

46 4d ago A 55 tokens original MIT

ai-threat-testing

09

26zl/cybersec-toolkit

Skill Claude CodeCodex

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

46 4d ago A 55 tokens original MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.

46 4d ago A 50 tokens copy · 95% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.

46 4d ago A 72 tokens copy · 100% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.

46 4d ago A 48 tokens copy · 91% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or…

46 4d ago A 68 tokens copy · 100% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit…

46 4d ago A 94 tokens copy · 92% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.

46 4d ago A 53 tokens copy · 88% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr.

46 4d ago A 38 tokens copy · 88% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines…

46 4d ago A 79 tokens copy · 100% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.

46 4d ago A 55 tokens copy · 89% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon…

46 4d ago A 80 tokens copy · 94% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused…

46 4d ago A 99 tokens copy · 100% MIT

26zl/cybersec-toolkit

Skill Claude CodeCodex

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

46 4d ago B 32 tokens copy · 86% MIT