Blue Team Defense & Hardening

$npx mdskill add Masriyan/Claude-Code-CyberSecurity-Skill/Blue Team Defense & Hardening

Hardens systems, creates detection rules, and improves security posture.

  • Hardening Linux/Windows servers and workstations against attacks.
  • Depends on Sigma, Splunk, KQL, YARA, Snort, Suricata, Sysmon, auditd.
  • Analyzes provided configurations and system state to recommend specific actions.
  • Outputs hardening commands, detection rules, and improvement plans.

SKILL.md

.github/skills/Blue Team Defense & HardeningView on GitHub ↗

No skill content available yet.

More from Masriyan/Claude-Code-CyberSecurity-Skill

SkillDescription
AI & LLM SecurityLLM and AI application security testing — prompt injection, jailbreak resistance, OWASP LLM Top 10 (2025), RAG and agent/tool-use security, model supply chain, and AI red teaming for authorized assessments
Cloud Security & Container HardeningAWS/Azure/GCP security auditing, container and Kubernetes hardening, Infrastructure as Code scanning, and cloud compliance assessment
Cryptographic Analysis & AssessmentSSL/TLS auditing, cipher suite analysis, hash algorithm identification, encryption implementation review, and cryptographic weakness detection in code
CSOC Operations & Playbook AutomationSOC alert triage, incident playbook automation, escalation workflows, shift reporting, and SOC KPI tracking
Exploit Development & Payload EngineeringProof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
GRC & ComplianceGovernance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation
Incident Response & Digital ForensicsIR playbook execution, evidence collection, forensic timeline analysis, memory forensics, and post-incident reporting following NIST SP 800-61 and SANS PICERL methodology
Log Analysis & SIEM IntegrationSecurity log parsing, anomaly detection, SIEM query building, Sigma rule creation, and correlation rule development across Splunk, Elastic, QRadar, and Microsoft Sentinel
Malware Analysis & SandboxingStatic and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Mobile Application SecurityAndroid and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments