Search

PowerShell · Security operations

8 skills found.
Category:
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft…

mukul975/Anthropic-Cybersecurity-Skills34k—~923Automated safety check: PassApache-2.01 mo ago
2

Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.

mukul975/Anthropic-Cybersecurity-Skills34k—~891Automated safety check: PassApache-2.01 mo ago
3

Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…

mukul975/Anthropic-Cybersecurity-Skills34k—~9.8kAutomated safety check: PassApache-2.01 mo ago
4

Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
5

Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
6

Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events.

mukul975/Anthropic-Cybersecurity-Skills34k—~638Automated safety check: PassApache-2.01 mo ago
7

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

briiirussell/cybersecurity-skills413—~2.9kAutomated safety check: NotesMIT4 mo ago
8

Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill.

ptn1411/skill219—~1kAutomated safety check: NotesNo licence19 days ago