Search
Security · PowerShell
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. | waybarrios/ | 534 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 2 | Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles. | MichaelGrafnetter/ | 2k | — | ~4k | Automated safety check: Pass | MIT | 29 days ago |
| 3 | Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | 27 days ago |
| 4 | Update copyright year references across the project at the beginning of each calendar year. | MichaelGrafnetter/ | 2k | — | ~404 | Automated safety check: Pass | MIT | 29 days ago |
| 5 | Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 6 | Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 7 | Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft… | mukul975/ | 34k | — | ~923 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 8 | Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. | mukul975/ | 34k | — | ~891 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing… | mukul975/ | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 11 | Systematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection… | mukul975/ | 34k | — | ~9.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string… | mukul975/ | 34k | — | ~719 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. | mukul975/ | 34k | — | ~666 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. | mukul975/ | 34k | — | ~638 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~659 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. | briiirussell/ | 413 | — | ~2.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 21 | Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1k | Automated safety check: Notes | No licence | 18 days ago |
| 22 | Windows net diag: ping, traceroute, DNS, port scan (PowerShell) | taracodlabs/ | 852 | — | ~878 | Automated safety check: Pass | Apache-2.0 | 27 days ago |
| 23 | AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.9k | Automated safety check: Pass | MIT | 27 days ago |
| 24 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 157 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | Expert knowledge for Azure Firmware Analysis development including best practices, security, integrations & coding patterns, and deployment. | MicrosoftDocs/ | 776 | — | ~1.2k | Automated safety check: Pass | CC-BY-4.0 | 4 days ago |