marysatasselshaped667/skills-collection-1

Organize AI agent skills, scripts, and references in scalable folders for fast reuse across engineering, research, writing, and automation tasks

1Stars on the repository
200Mods indexed here, across every type
yesterdayLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis…

not rated 1 yesterday C 80 tokens copy · 98% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.

not rated 1 yesterday A 71 tokens copy · 83% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and…

not rated 1 yesterday A 76 tokens copy · 91% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic…

not rated 1 yesterday A 91 tokens copy · 97% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding…

not rated 1 yesterday A 81 tokens copy · 94% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

not rated 1 yesterday B 49 tokens copy · 91% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.

not rated 1 yesterday A 56 tokens copy · 86% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer…

not rated 1 yesterday A 79 tokens copy · 91% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious…

not rated 1 yesterday A 84 tokens copy · 92% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.

not rated 1 yesterday A 54 tokens copy · 89% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression…

not rated 1 yesterday A 88 tokens copy · 81% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware…

not rated 1 yesterday A 79 tokens copy · 100% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware…

not rated 1 yesterday A 76 tokens copy · 91% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports.…

not rated 1 yesterday A 110 tokens copy · 95% MIT

marysatasselshaped667/skills-collection-1

Skill Claude CodeCodex

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk…

not rated 1 yesterday A 82 tokens copy · 89% MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: