⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
Reconnaissance & OSINT Automation
Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
🛡️ Antivirus Notice: Some AV engines may flag this repository due to security testing payload templates (string constants for authorized pentesting). These are false positives — no executable malware exists. This is standard for all cybersecurity toolkits (SecLists, PayloadsAllTheThings, Metasploit face the same detections). See SECURITY.md for details.
Claude Code CyberSecurity Skill Collection
22 production-quality Claude Code Skills for cybersecurity professionals — covering offensive security, defensive operations, reverse engineering, threat hunting, threat intelligence, purple team / adversary emulation, CSOC automation, AI/LLM security, mobile, OT/ICS, GRC, software supply chain security, and more. Version 3.1 — expanded coverage, sharper methodology, and stronger automation.
Transform Claude Code into your ultimate cybersecurity co-pilot. Each skill provides Claude with structured methodology, decision frameworks, ready-to-run commands, and output templates that enable precise, expert-level assistance for real-world security operations.
What Are Claude Code Skills?
Claude Code Skills are structured SKILL.md files that you install into your ~/.claude/skills/ directory (global) or .claude/skills/ (project-specific). When Claude reads these files, it gains deep, domain-specific expertise that goes far beyond generic knowledge.
How Skills Work
Skills are instruction documents Claude reads at conversation start. Each SKILL.md contains:
- YAML frontmatter —
name,description,tagsfor skill identification - Activation triggers — Explicit list of prompts that should invoke this skill
- Methodology — Step-by-step procedures Claude follows natively
- Output templates — Exact formats for reports, rules, and artifacts Claude produces
- Script references — When and how to use the included Python automation scripts
- Authorization gates — Built-in prompts for offensive skills to confirm legal scope
Claude Code-Native Design
These skills are built around what Claude does natively in Claude Code:
- Read configuration files, code, and logs directly — no copy-paste needed
- Bash tool to run scripts, network commands, and system queries
- Analysis of disassembly, PCAP data, log events, and code with full context
- Generation of detection rules, hardening scripts, reports, and payloads
- WebSearch for CVE lookups, threat intelligence, and vulnerability research
Update proof of works
Update testing
Skill Collection
| # | Skill | Domain | Key Capabilities |
|---|---|---|---|
| 01 | Recon & OSINT | Reconnaissance | Subdomain enum, DNS analysis, technology fingerprinting, Google dorking, WHOIS |
| 02 | Vulnerability Scanner | Assessment | Dependency auditing, config review, CVSS scoring, structured vulnerability reports |
| 03 | Exploit Development | Offensive | PoC templates, payload generation, buffer overflow, web exploit payloads |
| 04 | Reverse Engineering | Analysis | Binary triage, assembly interpretation, firmware RE, protocol reversing, CTF |
| 05 | Malware Analysis | Threat Analysis | Static analysis, YARA generation, sandbox setup, behavioral analysis, IOC extraction |
| 06 | Threat Hunting | Hunting | IOC extraction, ATT&CK mapping, hunt hypotheses, Sigma + SIEM query library |
| 07 | Incident Response | IR & Forensics | PICERL playbooks, evidence collection, timeline analysis, memory forensics, IR reports |
| 08 | Network Security | Network | PCAP analysis, Suricata/Snort rules, firewall auditing, beaconing detection |
| 09 | Web Security | Web | OWASP Top 10, injection testing, API security, JWT analysis, security headers |
| 10 | Cloud Security | Cloud | AWS/Azure/GCP audit, Dockerfile review, K8s hardening, IaC scanning |
| 11 | CSOC Automation | SOC Operations | Alert triage, playbook YAML, escalation workflows, shift reports, KPI tracking |
| 12 | Log Analysis & SIEM | Log Analysis | SIEM query library (Splunk/KQL/EQL), Sigma rules, anomaly detection, correlation |
| 13 | Cryptographic Analysis | Cryptography | TLS auditing, cipher analysis, hash identification, crypto code review, PQC guidance |
| 14 | Red Team Operations | Red Team | Engagement planning, C2 design, AD attacks, OPSEC, social engineering, reporting |
| 15 | Blue Team Defense | Blue Team | Linux/Windows hardening, detection engineering, baselines, patch management |
| 16 | AI & LLM Security | AI Security | Prompt injection, OWASP LLM Top 10, RAG & agent/tool-use security, model supply chain, AI red teaming |
| 17 | Mobile Security | Mobile | Android/iOS testing, MASVS/MASTG, APK/IPA static analysis, Frida/objection, mobile malware triage |
| 18 | OT / ICS / SCADA Security | Industrial | Purdue model, Modbus/DNP3/S7 analysis, IEC 62443, ATT&CK for ICS, safety-first methodology |
| 19 | GRC & Compliance | Governance | Risk scoring, NIST CSF 2.0/ISO 27001/SOC 2 mapping, gap analysis, audit evidence, policy generation |
| 20 | Supply Chain Security | Supply Chain | SBOM generation/analysis, dependency confusion & typosquatting detection, CI/CD pipeline hardening, SLSA/Sigstore provenance |
| 21 | Threat Intelligence & CTI | Threat Intel | Intelligence cycle, IOC extraction/defang/normalize, STIX/TAXII & MISP, Diamond/Kill Chain, source & confidence scoring, attribution, finished reporting |
| 22 | Purple Team & Adversary Emulation | Purple Team | Threat-informed emulation planning (ATT&CK, Atomic Red Team, CALDERA), detect–tune–validate loop, coverage measurement (Navigator/DeTT&CT), MTTD/coverage reporting |
Quick Start
1. Clone the Repository
git clone https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill.git
cd Claude-Code-CyberSecurity-Skill
2. Install Skills into Claude Code
Claude Code loads skills from two locations:
| Location | Scope | Path |
|---|---|---|
| Global | All projects | ~/.claude/skills/ |
| Project | This project only | ./.claude/skills/ |
# Install globally (recommended — available everywhere)
mkdir -p ~/.claude/sk
// HOW IT'S BUILT
KEY FILES