Search

Security operations

247 skills found, page 4.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
145

Design and plan end-to-end Azure IoT and Smart City solutions: requirements, architecture, security, operations, cost, and a phased delivery plan with concrete implementation artifacts.

github/awesome-copilot40k1 repo~1.4kAutomated safety check: PassMIT2 days ago
146

Blue-team threat hunting: detection engineering with Sigma/YARA, SIEM query design, and validation of incident detections against known technique patterns.

sickn33/agentic-awesome-skills47k1 repo~474Automated safety check: PassMIT2 days ago
147

Detect command-and-control (C2) traffic tunneled over DNS from tools like Iodine, dnscat2, dns2tcp, and Cobalt Strike DNS beacon, using Shannon entropy analysis of query subdomains, ML-based DGA…

mukul975/Anthropic-Cybersecurity-Skills34k—~13kAutomated safety check: PassApache-2.01 mo ago
148

Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDAP signing, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~8.7kAutomated safety check: PassApache-2.01 mo ago
149

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
150

Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
151

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
152

Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…

mukul975/Anthropic-Cybersecurity-Skills34k—~9.8kAutomated safety check: PassApache-2.01 mo ago
153

Hunt for specific IOCs across your environment. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~958Automated safety check: PassApache-2.01 mo ago
154

Kubernetes alert triage — dedup via YT search, deep control plane investigation, auto-escalation for recurring/flapping/control-plane alerts.

papadopouloskyriakos/agentic-chatops107—~801Automated safety check: NotesNo licence5 days ago
155

Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

telagod/code-abyss244—~777Automated safety check: PassMIT2 mo ago
156

Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.01 mo ago
157

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
158

Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and…

mukul975/Anthropic-Cybersecurity-Skills34k—~796Automated safety check: PassApache-2.01 mo ago
159

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
160

Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
161

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~849Automated safety check: PassApache-2.01 mo ago
162

Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.

mukul975/Anthropic-Cybersecurity-Skills34k—~677Automated safety check: PassApache-2.01 mo ago
163

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: NotesApache-2.01 mo ago
164

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM.

mukul975/Anthropic-Cybersecurity-Skills34k—~717Automated safety check: PassApache-2.01 mo ago
165

Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
166

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
167

Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
168

Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events.

mukul975/Anthropic-Cybersecurity-Skills34k—~638Automated safety check: PassApache-2.01 mo ago
169

Detect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon process-creation and file-system telemetry (Event ID 4688, Sysmon 1/11) for 7-Zip/RAR/tar archive creation, unusual temp or…

mukul975/Anthropic-Cybersecurity-Skills34k—~801Automated safety check: PassApache-2.01 mo ago
170

Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using…

mukul975/Anthropic-Cybersecurity-Skills34k—~790Automated safety check: PassApache-2.01 mo ago
171

Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10…

mukul975/Anthropic-Cybersecurity-Skills34k—~712Automated safety check: PassApache-2.01 mo ago
172

Detects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for…

mukul975/Anthropic-Cybersecurity-Skills34k—~676Automated safety check: PassApache-2.01 mo ago
173

Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms…

mukul975/Anthropic-Cybersecurity-Skills34k—~677Automated safety check: PassApache-2.01 mo ago
174

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
175

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: NotesApache-2.01 mo ago
176

Tune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines…

mukul975/Anthropic-Cybersecurity-Skills34k—~657Automated safety check: PassApache-2.01 mo ago
177

Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: NotesApache-2.01 mo ago
178

Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response.

aiskillstore/marketplace4336 repos~1.7kAutomated safety check: PassNo licenceyesterday
179

Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology.

briiirussell/cybersecurity-skills413—~1.5kAutomated safety check: NotesMIT4 mo ago
180

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

briiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT4 mo ago
181

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

briiirussell/cybersecurity-skills413—~2.9kAutomated safety check: PassMIT4 mo ago
182

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

briiirussell/cybersecurity-skills413—~2.9kAutomated safety check: NotesMIT4 mo ago
183

Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing…

mukul975/Anthropic-Cybersecurity-Skills34k—~582Automated safety check: PassApache-2.01 mo ago
184

蓝队与紫队工程:检测规则编写、SIEM/EDR 调优、事件响应、数字取证、威胁狩猎、ATT&CK 映射、紫队演练闭环。Use when writing Sigma/YARA detection rules, tuning SIEM noise, responding to security incidents, conducting forensic analysis, hunting…

telagod/code-abyss244—~697Automated safety check: PassMIT2 mo ago
185

Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill.

ptn1411/skill219—~1kAutomated safety check: NotesNo licence19 days ago
186

Scan Linux systems for persistence mechanisms including crontab/systemd entries, LDPRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorizedkeys backdoors, then…

mukul975/Anthropic-Cybersecurity-Skills34k—~801Automated safety check: NotesApache-2.01 mo ago
187

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy…

mukul975/Anthropic-Cybersecurity-Skills34k—~754Automated safety check: PassApache-2.01 mo ago
188

Blue-team release-gate analysis for smart contract deployment and upgrade readiness.

quillai-network/quillshield_skills130—~1.7kAutomated safety check: NotesMIT6 mo ago
189

Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev.

mrmps/classifier-dev424—~1.5kAutomated safety check: PassMIT4 days ago
190
190.Domain

Domain-specific: SAP Commerce, OpenSearch detection, WordPress validation, enterprise search.

notque/vexjoy-agent441—~3.7kAutomated safety check: NotesMITyesterday
191

Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools.

google/skills21k—~3.3kAutomated safety check: PassApache-2.0yesterday
192

Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.4kAutomated safety check: PassApache-2.01 mo ago