Search
Security · Incident response
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 190 | — | ~2.5k | Automated safety check: Notes | Unknown | 14 days ago |
| 2 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 3 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 4 | Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. | avelikiy/ | 103 | — | ~884 | Automated safety check: Notes | MIT | today |
| 5 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 6 | A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"… | RTFM-IT-Services-LLC/ | 115 | — | ~3.3k | Automated safety check: Pass | Unknown | 8 days ago |
| 7 | A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining… | hypnguyen1209/ | 388 | — | ~2.5k | Automated safety check: Pass | MIT | 13 days ago |
| 8 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 9 | Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale. | AgentSecOps/ | 220 | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 10 | 10.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | 2 days ago |
| 11 | Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. | mukul975/ | 34k | — | ~922 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. | mukul975/ | 34k | — | ~907 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation. | sickn33/ | 47k | 1 repo | ~495 | Automated safety check: Pass | MIT | 2 days ago |
| 20 | Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. | mukul975/ | 34k | — | ~631 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. | mukul975/ | 34k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing containment, analysis, eradication, and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Deploy and operationalize Amazon GuardDuty, covering protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity, and building automated response with EventBridge… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 29 | Detect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation… | mukul975/ | 34k | — | ~914 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Detect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All requests issued by… | mukul975/ | 34k | — | ~897 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Automates phishing incident response by calling the Splunk SOAR (Phantom) REST API to create containers, attach artifacts (emails, URLs, attachments), and trigger response playbooks. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under… | mukul975/ | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. | alirezarezvani/ | 28k | — | ~3.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | A skill your agent uses when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the… | alirezarezvani/ | 28k | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Systematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 40 | Automates the full SSL/TLS certificate lifecycle, including generating Certificate Signing Requests, issuing, deploying, monitoring, renewing, and revoking X.509 certificates, using Python and ACME… | mukul975/ | 34k | — | ~867 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and… | mukul975/ | 34k | — | ~796 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 43 | Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 44 | Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. | mukul975/ | 34k | — | ~642 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs… | mukul975/ | 34k | — | ~730 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms… | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Enrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal API v3 to retrieve multi-engine detection rates, sandbox behavioral analysis, YARA rule matches, related indicators, and… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |