Search

Security · Security operations

225 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…

TracecatHQ/tracecat3.8k—~16kAutomated safety check: PassMITtoday
2

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

OTRF/ThreatHunter-Playbook4.7k—~1.2kAutomated safety check: PassMIT9 mo ago
3

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

elastic/agent-skills5921 repo~3.5kAutomated safety check: NotesApache-2.02 days ago
4

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0today
5

Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

OTRF/ThreatHunter-Playbook4.7k—~813Automated safety check: PassMIT9 mo ago
6

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

OTRF/ThreatHunter-Playbook4.7k—~600Automated safety check: PassMIT9 mo ago
7

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

elastic/agent-skills5921 repo~3.9kAutomated safety check: NotesApache-2.02 days ago
8

Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
9

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

timescale/rsigma165—~1.2kAutomated safety check: PassMITyesterday
10

A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

chaitin/chaitin-cli115—~15kAutomated safety check: NotesGPL-3.011 days ago
11

GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

Nebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMITyesterday
12

Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist.

jdforsythe/forge151—~4.5kAutomated safety check: PassMIT3 mo ago
13

Enable, configure, and query Elasticsearch security audit logs.

aspectrr/deer405—~1.7kAutomated safety check: PassMIT5 mo ago
14

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
15

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
16

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT9 mo ago
17

Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
18
18.Dfir

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

transilienceai/communitytools563—~1.5kAutomated safety check: PassMIT2 mo ago
19

Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

AgentSecOps/SecOpsAgentKit2201 repo~4.8kAutomated safety check: NotesUnknown5 mo ago
20

Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
21

Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

zhaoxuya520/reverse-skill41k1 repo~1kAutomated safety check: PassMIT18 days ago
22

Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

briiirussell/cybersecurity-skills413—~3.5kAutomated safety check: NotesMIT4 mo ago
23

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
24

Check for existing SIEM alerts and case management entries related to IOCs.

dandye/ai-runbooks127—~624Automated safety check: PassApache-2.01 mo ago
25

A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing…

gaasher/Agent-Loop-Skills174—~3.6kAutomated safety check: PassMIT3 mo ago
26

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
27

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

FlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.03 days ago
28

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
29

A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

zhaoxuya520/reverse-skill41k2 repos~344Automated safety check: WarnMIT18 days ago
30

Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

aws/tools-for-devops-agent103—~4.8kAutomated safety check: PassApache-2.0today
31

Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

warpdotdev/common-skills6101 repo~1.8kAutomated safety check: PassMITyesterday
32

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

dandye/ai-runbooks127—~702Automated safety check: PassApache-2.01 mo ago
33

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

trailofbits/skills7.5k—~5.9kAutomated safety check: PassCC-BY-SA-4.0today
34

Search for existing cases related to specific indicators or entities.

dandye/ai-runbooks127—~562Automated safety check: PassApache-2.01 mo ago
35

Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.8kAutomated safety check: PassApache-2.01 mo ago
36

A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"…

RTFM-IT-Services-LLC/msp-claude-skills115—~3.3kAutomated safety check: PassUnknown7 days ago
37

Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~3.5kAutomated safety check: PassMITyesterday
38

Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~1kAutomated safety check: PassMITyesterday
39

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads277—~895Automated safety check: PassMIT11 days ago
40

Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

digoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.0yesterday
41

Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
42

Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.

google/skills21k1 repo~4.8kAutomated safety check: PassApache-2.0today
43
43.Secops HuntOfficial

Expert guidance for proactive threat hunting in Google SecOps.

google/skills21k1 repo~2.6kAutomated safety check: PassApache-2.0today
44

Expert guidance for deep security incident and entity investigations in Google SecOps.

google/skills21k1 repo~4.2kAutomated safety check: PassApache-2.0today
45
45.Secops TriageOfficial

Expert guidance for security alert triage in Google SecOps. An agent skill from google/skills.

google/skills21k1 repo~3.3kAutomated safety check: PassApache-2.0today
46

Generic detection rule creation and management using Sigma, the universal SIEM rule format.

AgentSecOps/SecOpsAgentKit2201 repo~4kAutomated safety check: PassUnknown5 mo ago
47

SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

AgentSecOps/SecOpsAgentKit2201 repo~4.9kAutomated safety check: NotesUnknown5 mo ago
48

Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

AgentSecOps/SecOpsAgentKit2201 repo~3.1kAutomated safety check: PassUnknown5 mo ago