
How AI went from "interesting toy" to force multiplier for building security tools. A practical guide using a real DLL hijacking pipeline.
There's a gap in security that doesn't get talked about honestly. It's the distance between knowing a technique exists and being able to use it at 2am when you actually need it. Between reading about DLL search order hijacking and shipping a tool that finds every vulnerable binary on a target. Between understanding MITRE ATT&CK conceptually and mapping a real engagement to it without losing your mind.
Closing that gap used to mean time. Lots of it. Grinding through labs, rebuilding the same tooling everyone else has rebuilt, making the same mistakes, losing weekends to YAML.
AI changes the shape of that gap. It doesn't replace the work - anyone who tells you it does is selling something - but it collapses the distance between "I have an idea" and "I have a working thing." This post is about how I've been using Claude and the ecosystem around it (Skills, pipelines, subagents) to actually level up.
That message box is Notepad++ loading a DLL it shouldn't. The tool that found the vulnerability, generated the POC, compiled it, and told me exactly where to drop it was built in evenings, not weeks.
Security content is everywhere. Techniques are documented. ATT&CK is open. Finding out what to do has never been the hard part. It's the translation layer. Turning a whitepaper into a repo. Turning a repo into a pipeline. Turning a pipeline into something your team can actually use on a Tuesday.
That's where junior-to-senior time gets burned. It's also where most side projects die.
This is the layer AI is genuinely good at.
Claude's Skills concept reframes how you work. A Skill is a bundle of instructions, examples, and reference material that gets loaded on demand when it's relevant to the task.
Think of it as the institutional knowledge you wish your team had written down. Instead of re-explaining your report format every engagement, you write it once as a Skill. Instead of reminding the model how your purple team playbooks are structured, it just knows.
For security work this is powerful because so much of what we do is convention-heavy. Report structure. Naming. Payload scaffolding. How you document an attack path. How you format a finding so it doesn't get bounced back by the client. All of that is perfect Skill material.
I've started treating Skills as the place I dump "the way we do things here," so every new task starts from my standards, not the model's defaults.
A chat is linear. A pipeline is not. The moment you stop thinking "I'll ask the AI a question" and start thinking "I'll have the AI run a repeatable sequence of steps over arbitrary inputs," the value curve bends hard.
My DLL/COM hijacking pipeline is a good example. The workflow:
None of those steps is novel. Koppeling, PowerSploit, Process Monitor - we've all done this manually. What changed is I could build the whole pipeline end to end in a fraction of the time it would normally take, because Claude handled the boring 80%: the Node.js plumbing, the PowerShell enumeration scripts, the HTML templating, the CLI argument parsing, the POC scaffolding.
I stayed in the seat for the parts that matter: the detection logic, the classification rules, the security hardening (command injection and path traversal were very real issues in v1). The rest I delegated.
Not "AI wrote my tool." AI wrote the parts of my tool I didn't want to write, so I could focus on the parts only I could write.
A subagent is a scoped worker. You hand it a narrow task, its own context, and let it grind. The parent agent coordinates. You supervise the coordinator rather than babysitting every step.
Concrete example from building the hijack pipeline:
Each one has a tight scope, so each one stays reliable. No single monster prompt trying to do everything at once. This pattern maps almost perfectly onto how red team operations already work (recon, enumeration, exploitation, reporting), which is why it feels natural.
For purple team work it's even better. You can have one subagent acting as the red side (generating the TTP execution), another as blue (writing the detection logic), and a coordinator that runs them against each other. That's a closed-loop training rig you can build in an afternoon.
Let's be honest about limits. AI is not replacing a good bug hunter. It will cheerfully walk past things that would make an experienced reverser flinch, and it will confidently invent APIs that don't exist if you let it.
But as a force multiplier for triage and surface area? It's excellent.
Things it's genuinely good at right now:
Things you still own:
The part I care about most is the learning flywheel. Every time I build something with Claude, I'm also being taught by it. Not passively. I'm asking why it chose that approach, what the alternatives are, where this pattern breaks.
A year ago, if I wanted to understand the nuances of COM hijacking persistence, I'd read three blogs, probably get confused by one of them, and move on. Now I can build the detection tool and interrogate the reasoning as I go. The tool is the study guide. You end up with muscle memory you didn't have before, plus an artifact you can ship.
That's the real leveling-up mechanic. Not "AI did it for me." It's "AI let me build the thing, and I understand the thing because I built it, and now I have both the thing and the understanding."
If you want to try this on your own workbench:
The security field has always rewarded people who can build their own tools. AI doesn't change that. It lowers the activation energy. The people who were already building will build more, faster, and weirder. The people who weren't now have no excuse.
Skills give you reusable expertise. Pipelines give you leverage. Subagents give you delegation. Together they're the closest thing we've had to a genuine productivity multiplier since the jump from manual to scripted ops.
Use it on systems you're authorized to touch. Verify every output. And go build the thing you've been putting off.
The DLL/COM hijacking pipeline referenced in this post is an internal tool built for authorized testing engagements. It is not publicly released. Notepad++ is used throughout as a public, benign test target; the sideload paths shown are well-documented and affect many Windows applications that don't pin their imports.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.