acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains
$ npx -y skills add Mikaru0Mystic/sectinel --skill auditing-tls-certificate-transparency-logs --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/auditing-tls-certificate-transparency-logsContext preview
The summary Claude sees to decide when to auto-load this skill.
Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains
name: auditing-tls-certificate-transparency-logs description: 'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting. ' domain: cybersecurity subdomain: threat-intelligence tags: - certificate-transparency - CT-logs - crt-sh - subdomain-discovery - TLS-monitoring - RFC-6962 version: 1.0.0 author: mukul975 license: Apache-2.0 nist_csf: - ID.RA-01 - ID.RA-05 - DE.CM-01 - DE.AE-02
**Do not use** for attacking or disrupting Certificate Authorities, for scraping CT logs in violation of rate limits or terms of service, or as the sole method of subdomain enumeration without corroborating results through DNS verification.
Build the initial certificate inventory for monitored domains:
Set up ongoing monitoring for new certificate issuances:
Extract and validate subdomains found in certificate transparency data:
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative