defensive-jwt
CommunityDetect JWT attacks and bolster identity security.
Authorriparino
Version1.0.0
Installs0
System Documentation
What problem does it solve?
JWTs are a common attack surface; misconfigurations and weak validation enable token forgery, header injection, and token leakage. This skill helps security teams detect and triage JWT abuse in cloud and application environments.
Core Features & Use Cases
- Detection of alg:none tokens, JWK/JKU header injection, and algorithm confusion.
- Sigma rules and KQL queries for Entra ID SigninLogs and AuditLogs to support SOC triage.
- Hardening guidance for strict token validation and JWKS pinning across identity platforms.
Quick Start
Configure detectors to flag unsigned JWTs, JWK/JKU injection, and algorithm confusion, then apply Sigma and KQL patterns to your logs.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: defensive-jwt Download link: https://github.com/riparino/Claude-Cyber/archive/main.zip#defensive-jwt Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.