Search
Security operations
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics. | OTRF/ | 4.7k | — | ~1.2k | Automated safety check: Pass | MIT | 8 mo ago |
| 2 | Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. | elastic/ | 592 | 1 repo | ~3.5k | Automated safety check: Notes | Apache-2.0 | today |
| 3 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | today |
| 4 | Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written. | OTRF/ | 4.7k | — | ~813 | Automated safety check: Pass | MIT | 8 mo ago |
| 5 | Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern. | OTRF/ | 4.7k | — | ~600 | Automated safety check: Pass | MIT | 8 mo ago |
| 6 | Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). | elastic/ | 592 | 1 repo | ~3.9k | Automated safety check: Notes | Apache-2.0 | today |
| 7 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 8 | 8.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 159 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 9 | A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability… | chaitin/ | 114 | — | ~15k | Automated safety check: Notes | GPL-3.0 | 9 days ago |
| 10 | 10.Gates GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework. | Nebulock-Inc/ | 385 | — | ~12k | Automated safety check: Pass | MIT | 5 days ago |
| 11 | Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist. | jdforsythe/ | 151 | — | ~4.5k | Automated safety check: Pass | MIT | 3 mo ago |
| 12 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 13 | 13.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 14 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 15 | Independently implement and validate an alternative solution for an Astro pull request. | withastro/ | 63k | — | ~782 | Automated safety check: Pass | Unknown | today |
| 16 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 8 mo ago |
| 17 | Determines whether a security incident involves personal data, triggers regulatory breach-notification obligations (e.g. | ahmadvh/ | 375 | — | ~861 | Automated safety check: Pass | Unknown | 1 mo ago |
| 18 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills. | BagelHole/ | 1.1k | — | ~4.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | 20.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 562 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 21 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 220 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 22 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 40k | 1 repo | ~1k | Automated safety check: Pass | MIT | 16 days ago |
| 24 | Learn from public breach disclosures — extract the audit question each one implies and check your own stack. | briiirussell/ | 413 | — | ~3.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 25 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Check for existing SIEM alerts and case management entries related to IOCs. | dandye/ | 127 | — | ~624 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 29 | 29.Audit Report Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. | harness/ | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 30 | Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation. | zhaoxuya520/ | 40k | 2 repos | ~344 | Automated safety check: Warn | MIT | 16 days ago |
| 32 | 32.Cis Controls Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection… | Sushegaad/ | 942 | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 3 days ago |
| 33 | 33.Council Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation. | warpdotdev/ | 608 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | today |
| 34 | 34.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 36 | Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs… | aws/ | 100 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | today |
| 37 | Search for existing cases related to specific indicators or entities. | dandye/ | 127 | — | ~562 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | 39.Msp Helpdesk A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"… | RTFM-IT-Services-LLC/ | 113 | — | ~3.3k | Automated safety check: Pass | Unknown | 5 days ago |
| 40 | 40.Blue Team A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 41 | A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call… | RTFM-IT-Services-LLC/ | 113 | — | ~2.6k | Automated safety check: Pass | Unknown | 5 days ago |
| 42 | Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | today |
| 43 | Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1k | Automated safety check: Pass | MIT | today |
| 44 | Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 9 days ago |
| 45 | Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved… | digoal/ | 8.6k | — | ~2.2k | Automated safety check: Pass | GPL-2.0 | 10 days ago |
| 46 | 46.Hunt Apt Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | 47.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | today |
| 48 | Generic detection rule creation and management using Sigma, the universal SIEM rule format. | AgentSecOps/ | 220 | 1 repo | ~4k | Automated safety check: Pass | Unknown | 5 mo ago |