Search

Security operations

246 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

OTRF/ThreatHunter-Playbook4.7k—~1.2kAutomated safety check: PassMIT8 mo ago
2

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

elastic/agent-skills5921 repo~3.5kAutomated safety check: NotesApache-2.0today
3

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0today
4

Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

OTRF/ThreatHunter-Playbook4.7k—~813Automated safety check: PassMIT8 mo ago
5

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

OTRF/ThreatHunter-Playbook4.7k—~600Automated safety check: PassMIT8 mo ago
6

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

elastic/agent-skills5921 repo~3.9kAutomated safety check: NotesApache-2.0today
7

Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
8

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

timescale/rsigma159—~1.2kAutomated safety check: PassMIT2 days ago
9

A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

chaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.09 days ago
10

GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

Nebulock-Inc/agentic-threat-hunting-framework385—~12kAutomated safety check: PassMIT5 days ago
11

Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist.

jdforsythe/forge151—~4.5kAutomated safety check: PassMIT3 mo ago
12

Enable, configure, and query Elasticsearch security audit logs.

aspectrr/deer405—~1.7kAutomated safety check: PassMIT5 mo ago
13

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
14

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
15

Independently implement and validate an alternative solution for an Astro pull request.

withastro/astro63k—~782Automated safety check: PassUnknowntoday
16

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT8 mo ago
17

Determines whether a security incident involves personal data, triggers regulatory breach-notification obligations (e.g.

ahmadvh/octochains375—~861Automated safety check: PassUnknown1 mo ago
18

Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
19

Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

BagelHole/DevOps-Security-Agent-Skills1.1k—~4.5kAutomated safety check: PassMIT4 mo ago
20
20.Dfir

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

transilienceai/communitytools562—~1.5kAutomated safety check: PassMIT2 mo ago
21

Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

AgentSecOps/SecOpsAgentKit2201 repo~4.8kAutomated safety check: NotesUnknown5 mo ago
22

Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
23

Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

zhaoxuya520/reverse-skill40k1 repo~1kAutomated safety check: PassMIT16 days ago
24

Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

briiirussell/cybersecurity-skills413—~3.5kAutomated safety check: NotesMIT4 mo ago
25

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
26

Check for existing SIEM alerts and case management entries related to IOCs.

dandye/ai-runbooks127—~624Automated safety check: PassApache-2.01 mo ago
27

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
28

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

FlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0today
29

Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

harness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0yesterday
30

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
31

A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

zhaoxuya520/reverse-skill40k2 repos~344Automated safety check: WarnMIT16 days ago
32

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4.2kAutomated safety check: PassMIT3 days ago
33

Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

warpdotdev/common-skills6081 repo~1.8kAutomated safety check: PassMITtoday
34

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

dandye/ai-runbooks127—~702Automated safety check: PassApache-2.01 mo ago
35

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

trailofbits/skills7.4k—~5.9kAutomated safety check: PassCC-BY-SA-4.0today
36

Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

aws/tools-for-devops-agent100—~4.8kAutomated safety check: PassApache-2.0today
37

Search for existing cases related to specific indicators or entities.

dandye/ai-runbooks127—~562Automated safety check: PassApache-2.01 mo ago
38

Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.8kAutomated safety check: PassApache-2.01 mo ago
39

A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"…

RTFM-IT-Services-LLC/msp-claude-skills113—~3.3kAutomated safety check: PassUnknown5 days ago
40

A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing…

gaasher/Agent-Loop-Skills174—~3.6kAutomated safety check: PassMIT3 mo ago
41

A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call…

RTFM-IT-Services-LLC/msp-claude-skills113—~2.6kAutomated safety check: PassUnknown5 days ago
42

Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~3.5kAutomated safety check: PassMITtoday
43

Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~1kAutomated safety check: PassMITtoday
44

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads276—~895Automated safety check: PassMIT9 days ago
45

Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

digoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.010 days ago
46

Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
47
47.007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMITtoday
48

Generic detection rule creation and management using Sigma, the universal SIEM rule format.

AgentSecOps/SecOpsAgentKit2201 repo~4kAutomated safety check: PassUnknown5 mo ago