GitHub user
Agent skills by mukul975, page 12
Skills by mukul975, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 529 | Detect unauthorized SaaS and cloud service usage (shadow IT) by parsing proxy access logs, DNS query logs, and firewall/netflow data with Python pandas to aggregate traffic by domain, classify… | mukul975/ | 34k | — | ~637 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 530 | Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. | mukul975/ | 34k | — | ~564 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 531 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 532 | Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 533 | Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 534 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 535 | Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 536 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 537 | Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. | mukul975/ | 34k | — | ~642 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 538 | Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 539 | Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 540 | Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 541 | Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 542 | Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. | mukul975/ | 34k | — | ~638 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 543 | Detect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon process-creation and file-system telemetry (Event ID 4688, Sysmon 1/11) for 7-Zip/RAR/tar archive creation, unusual temp or… | mukul975/ | 34k | — | ~801 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 544 | Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARDINFORMATION vs $FILENAME timestamps in the MFT. | mukul975/ | 34k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 545 | Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using… | mukul975/ | 34k | — | ~790 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 546 | Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. | mukul975/ | 34k | — | ~695 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 547 | Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~659 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 548 | Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures… | mukul975/ | 34k | — | ~718 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 549 | Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10… | mukul975/ | 34k | — | ~712 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 550 | Detects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for… | mukul975/ | 34k | — | ~676 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 551 | Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs… | mukul975/ | 34k | — | ~730 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 552 | Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms… | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 553 | Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 554 | Configures Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance requirements, risk-based authentication… | mukul975/ | 34k | — | ~689 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 555 | Uses Calico's own policy CRDs beyond the upstream Kubernetes API - GlobalNetworkPolicy, HostEndpoint, NetworkSet, policy tiers, and DNS-based egress rules - applied and audited with calicoctl. | mukul975/ | 34k | — | ~680 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 556 | Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks. | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 557 | Deploys and monitors Canary Tokens via the Thinkst Canary REST API for deception-based breach detection, programmatically creating web bug, DNS, MS Word document, and AWS API key tokens and… | mukul975/ | 34k | — | ~591 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 558 | Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and… | mukul975/ | 34k | — | ~642 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 559 | Deploys SailPoint IdentityNow or IdentityIQ for identity governance and administration, covering identity lifecycle management, access request workflows, certification campaigns, role mining… | mukul975/ | 34k | — | ~805 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 560 | Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for… | mukul975/ | 34k | — | ~697 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 561 | Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance. | mukul975/ | 34k | — | ~762 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 562 | Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python pandas, computing hourly/daily volume distributions, per-host and protocol/port statistics, and top-talker… | mukul975/ | 34k | — | ~652 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 563 | Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic… | mukul975/ | 34k | — | ~793 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 564 | Design and implement Privileged Access Workstations (PAWs) using the tiered administration model, with device hardening, device compliance enforcement via Microsoft Intune or Group Policy… | mukul975/ | 34k | — | ~650 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 565 | Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment | mukul975/ | 34k | — | ~956 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 566 | Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 567 | Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 568 | Tune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines… | mukul975/ | 34k | — | ~657 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 569 | Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library over the Greenbone Management Protocol (GMP) to connect via Unix socket or TLS, create scan targets and… | mukul975/ | 34k | — | ~778 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 570 | Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of… | mukul975/ | 34k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 571 | Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network… | mukul975/ | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 572 | Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to… | mukul975/ | 34k | — | ~4.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 573 | Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet… | mukul975/ | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 574 | Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 575 | Enumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos… | mukul975/ | 34k | — | ~675 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 576 | Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |