EvilFreelancer

90 mods across 9 repositories, 454 stars between them.

EvilFreelancer/secs

Skill Claude CodeCodex

Investigate a suspected Google Cloud compromise from the control plane — Cloud Audit Logs (Admin Activity, Data Access, System Event, Policy Denied), Cloud Logging, and VPC Flow Logs — to reconstruct IAM and service-account abuse, key creation, data access, and log tampering into a timeline. Use when the evidence is…

10 23d ago A 103 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and session theft, and consent abuse. Use for a suspected…

10 23d ago A 110 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Investigate a live or triaged Windows host for intrusion evidence using disk and registry artifacts — MFT/$UsnJrnl, registry hives, AmCache/ShimCache, Prefetch, LNK/JumpLists, ShellBags, and event logs — parsed with the Eric Zimmerman suite and consolidated into a timeline. Use when a Windows endpoint is suspect and…

10 23d ago A 113 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Keep the durable record that outlives a session — credential provenance, access inventory, artifacts left on target for cleanup, findings with evidence, and a dead-end log — so work spanning days or analysts does not restart or contradict itself. Use when an engagement or investigation runs longer than one sitting…

10 23d ago A 100 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions. Use when…

10 23d ago A 96 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the purple-team loop from technique to detection to validation. Use when a request names an ATT&CK ID like T1003.001, a tactic…

10 23d ago A 96 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh context adversarially refute every candidate against the real artifact (a reproduced crash, a working request, a proven…

10 23d ago A 176 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. Use when gathering intelligence or mapping attack surface.

10 23d ago B 41 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Run authorized social-engineering assessments — pretext development from OSINT, phishing and spearphishing campaigns (Gophish), vishing and smishing, and physical pretexting — to measure the human attack surface and produce awareness-driving metrics. Use when the engagement scope explicitly authorizes testing people…

10 23d ago A 105 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Turn raw observations, extracted IOCs, and open sources into finished threat intelligence — running the intelligence cycle (direction, collection, processing, analysis, dissemination, feedback), enriching and grading indicators, pivoting on TTPs over atomic IOCs, structuring attribution with calibrated confidence, and…

10 23d ago A 118 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and telltale patterns so a planted tripwire does not burn the…

10 23d ago C 119 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. Use when writing up a vulnerability, producing a pentest or audit report, triaging a bug bounty submission, or preparing…

10 23d ago A 66 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a disk or memory image, reconstructing an attacker timeline…

10 23d ago D 74 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT configuration, and password storage. Use when auditing code that encrypts, signs, hashes, or authenticates, or when…

10 23d ago A 70 tokens copy · 100% Apache-2.0

securing-ai-systems

63

EvilFreelancer/secs

Skill Claude CodeCodex

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP Top 10 for LLM and Agentic Applications. Use when reviewing an AI feature, agent, MCP server, or RAG pipeline for…

10 23d ago A 85 tokens copy · 100% Apache-2.0

testing-apis

64

EvilFreelancer/secs

Skill Claude CodeCodex

Test REST and GraphQL APIs for authentication bypasses, authorization flaws, IDOR, mass assignment, injection attacks, and rate limiting issues. Use when pentesting APIs or testing microservices security.

10 23d ago A 43 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Safely assess industrial control system and OT networks and their protocols (Modbus, DNP3, S7comm, EtherNet/IP-CIP, OPC UA, IEC 60870-5-104, BACnet) using a passive-first, safety-gated methodology aligned to the Purdue model and IEC 62443. Use when mapping an OT network, evaluating IT/OT segmentation and zone/conduit…

10 23d ago A 127 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Test Android and iOS applications for security flaws following OWASP MASVS/MASTG — insecure data storage, weak transport security and certificate pinning, broken authentication and session handling, cryptography misuse, exported-component and deep-link abuse, and client-side resilience. Use when assessing an APK/IPA…

10 23d ago A 109 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Test web applications for security vulnerabilities including SQLi, XSS, command injection, JWT attacks, SSRF, file uploads, XXE, and API flaws. Use when pentesting web apps, analyzing authentication, or exploiting OWASP Top 10 vulnerabilities.

10 23d ago C 56 tokens original Apache-2.0

threat-modeling

68

EvilFreelancer/secs

Skill Claude CodeCodex

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to…

10 23d ago A 117 tokens original Apache-2.0

transferring-files

69

EvilFreelancer/secs

Skill Claude CodeCodex

Transfer files between systems using HTTP, SMB, FTP, netcat, base64 encoding, and living-off-the-land techniques for both Linux and Windows. Use when moving tools or exfiltrating data.

10 23d ago E 46 tokens original Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by cheapest discriminator, time-boxing, and documenting negative results so a closed alert is evidence rather than a…

10 23d ago A 92 tokens copy · 100% Apache-2.0

EvilFreelancer/secs

Skill Claude CodeCodex

Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is loaded into a model's context and its config can run on startup. Use when reviewing a skill pack, Claude Code / Cursor / Cline plugin, or MCP server before adoption; when a repo ships a SKILL.md…

10 23d ago C 110 tokens copy · 98% Apache-2.0

writing-sigma-rules

72

EvilFreelancer/secs

Skill Claude CodeCodex

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with Hayabusa or Chainsaw. Use when translating threat intel into vendor-agnostic detection logic, building a detection-as-code…

10 23d ago A 83 tokens copy · 100% Apache-2.0