Agent skill

Soc Operations

by briiirussell in briiirussell/cybersecurity-skills

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

MITAuto-check passedDevOps & Cloud

Install Soc Operations

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill soc-operations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills soc-operations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/soc-operations .claude/skills/soc-operations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc-operations
GitHub stars
413
Token cost
~2.9k tokens
SKILL.md length
1,331 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

  • Works in 5 steps: Critical — confirmed compromise… → High — credential-access patterns (LSASS… → Medium — persistence indicators (new… → …
  • The user mentions SOC
  • SKILL.md covers Mode 1 — Build a SOC, Mode 2 — Run the SOC, Mode 3 — Improve the SOC and Output Format, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Soc Operations is an agent skill from briiirussell/cybersecurity-skills. Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs. Use when the user mentions 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage workflow,' 'runbook,' 'escalation,' 'on-call,' 'SOC tiering,' 'tier 1 / tier 2,' 'MTTD,' 'MTTR,' 'alert fatigue,' 'alert tuning,' 'shift handoff,' 'SOAR,' or wants to design or improve a security operations…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Security operations, Runbooks and postmortems and Incident response. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions SOC
  • Security operations
  • Alert triage workflow
  • Tier 1 / tier 2

Example prompts

  • “security operations,”
  • “SOC analyst,”
  • “alert triage workflow,”
  • “/soc-operations”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Grep, Glob, WebSearch

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Critical — confirmed compromise indicator (known-bad hash, C2 callback, ransomware behavior, data egress to known-bad infrastructure)
  2. High — credential-access patterns (LSASS dump, ticket forging), privileged-account unusual behavior, security-control disablement (EDR…
  3. Medium — persistence indicators (new scheduled task, registry run key), discovery commands by service accounts, MFA failures spike
  4. Low — single-event anomalies, behavioral outliers without context
  5. Informational — context-rich events for correlation later, not actionable alone

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc Operations loads about 2.9k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 1,331 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,331 words, ~2,894 tokens.

Download SKILL.mdSave it as .claude/skills/soc-operations/SKILL.md (or your agent's skills folder).
name
soc-operations
description
Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs. Use when the user mentions 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage workflow,' 'runbook,' 'escalation,' 'on-call,' 'SOC tiering,' 'tier 1 / tier 2,' 'MTTD,' 'MTTR,' 'alert fatigue,' 'alert tuning,' 'shift handoff,' 'SOAR,' or wants to design or improve a security operations team.
allowed-tools
Read, Write, Grep, Glob, WebSearch

SOC Operations — Building and Running a Security Operations Center

The operations layer above siem-detection (engineering rules) and incident-triage (response). This skill is about the people and process of running 24/7 alert triage — alert prioritization, runbook authoring, escalation, on-call hygiene, MTTD / MTTR, and the slow drift toward alert fatigue that kills SOCs.

Three modes:

  • Build — designing a SOC from scratch (small org standing up its first IR capability, or MSSP onboarding)
  • Run — daily operations for an existing SOC
  • Improve — analyzing an existing SOC's metrics and fixing the broken parts

Cross-references: siem-detection (the rules that feed alerts to the SOC), incident-triage (the playbook for confirmed incidents), threat-hunting (proactive work between alert triage), breach-patterns (what attacks the SOC should be ready for).

Mode 1 — Build a SOC

Decision: in-house, MSSP, or hybrid?
ModelWhen it fitsPitfalls
Fully in-houseMature security org, ≥ 5 dedicated analysts, regulated industryHard to staff 24/7 with under 8 people; on-call burnout
Fully outsourced (MSSP)Smaller orgs, regulated requirements without internal staffingMSSP context drift — they don't know your business; alert tuning slow
Hybrid (MSSP Tier 1, in-house Tier 2+)Most common for growth-stage companiesHandoff complexity, "MSSP filtered it but didn't tell us" gaps
Staffing model

For 24/7 in-house coverage, the math:

  • 24 × 7 = 168 hours per week of coverage needed
  • One analyst at 40 hours/week (= 160 hr/yr × 50 weeks ≈ 8000 hr/yr - PTO - training ≈ 1700 productive hours)
  • Minimum 5 analysts for true 24/7 if no overlap; realistic minimum 6–7 to handle PTO and burnout
  • Below 6 — consider MSSP for off-hours coverage; the burnout cost of "always on" is real
Analyst tiering

Standard tier model (adjust to taste):

  • Tier 1 — Triage: initial alert review. Closes false positives with notes. Escalates real findings to Tier 2. Typically follows runbooks; deviates with documentation.
  • Tier 2 — Investigation: deeper analysis on escalations. Pivots across data sources, correlates events, decides "incident" vs "noise." Authors new runbooks for patterns Tier 1 should handle next time.
  • Tier 3 — Engineering & response: detection engineering (see siem-detection), threat hunting (see threat-hunting), incident response leadership (see incident-triage). Senior, expensive, the ones building the SOC's capability.

For small SOCs (≤ 4 analysts), the tiers collapse — every analyst does T1+T2 work, T3 is part-time or contracted. Don't pretend you have tiers if you don't.

Tools you actually need
  • SIEM for log aggregation and alerting (see siem-detection)
  • Case management — ServiceNow / Jira Security / TheHive / Tines workflow. Tickets, not Slack threads. Slack is for chatter; the audit trail is in the ticket
  • SOAR for playbook automation — Tines, Torq, Cortex XSOAR, Splunk SOAR. Only worth it after you have stable runbooks worth automating
  • EDR / NDR consoles the analyst can pivot into during triage
  • Asset inventory the analyst can look up — Snipe-IT, ServiceNow CMDB, Axonius
  • Documentation — a wiki where runbooks live (Notion / Confluence / GitBook). Not Slack DMs

Mode 2 — Run the SOC

Alert prioritization

When ten alerts land in five minutes, what's the order?

The default ranking (tweak per environment):

  1. Critical — confirmed compromise indicator (known-bad hash, C2 callback, ransomware behavior, data egress to known-bad infrastructure)
  2. High — credential-access patterns (LSASS dump, ticket forging), privileged-account unusual behavior, security-control disablement (EDR removed, audit log stopped)
  3. Medium — persistence indicators (new scheduled task, registry run key), discovery commands by service accounts, MFA failures spike
  4. Low — single-event anomalies, behavioral outliers without context
  5. Informational — context-rich events for correlation later, not actionable alone

Critical and High should never wait. Medium triages within shift (≤ 8 hours). Low and Info batched.

Runbook authoring

Every alert that fires more than 2-3 times needs a runbook. Without one, every analyst re-derives the response and quality varies.

Runbook structure:

markdown
# Runbook: [Alert name]
## Trigger: [exact SIEM rule / detection name]
## Owner: [team / person]
## Last reviewed: [date]

## Quick reference
- **What the alert means in plain English:** [one sentence]
- **Common false positives:** [list, with how to recognize]
- **Common true positives:** [list, with what to look for next]

## Triage steps
1. [Step 1 — specific query / action]
2. [Step 2]
3. [Decision point — true positive / false positive / escalate]

## False positive handling
- [How to close + what to document]
- [Whether to add to suppression list]

## True positive handling
- [Immediate containment if any]
- [Escalation to whom, with what info]
- [Link to incident-triage skill for full IR]

## Common pivots
- [Other data sources to check]
- [Other systems likely affected]

Runbooks live in version control or a versioned wiki — not in Slack DMs, not in individual analyst notes.

Escalation criteria

Escalation rules should be explicit, not "use your judgment." Judgment lives at Tier 3+; lower tiers need rules.

ConditionEscalate toHow quickly
Active data egress observedTier 2 / on-callImmediately
Privileged account behavior anomalyTier 2This shift
Multiple correlated alerts on one hostTier 2This shift
Detection rule firing > 50× / hour with high TP rateTier 3 (engineering)Next business day
Detection rule firing > 50× / hour with 100% FPTier 3 (engineering)Next business day
Anything Tier 1 doesn't know how to handleTier 2After 30 minutes of triage
Shift handoffs

The single most preventable cause of breaches detected days late is "the night shift had something interesting and the morning shift never heard about it."

Handoff checklist (5–10 minutes per shift):

  • Open cases — what's in progress, what's blocked, what's the next step
  • Watch items — anything not yet a case but worth keeping eyes on
  • Active tuning — rules under tuning, FP patterns being investigated
  • Pages received during shift — even if resolved, the next shift should know
  • Anything you decided to ignore — and why — so next shift doesn't quietly disagree without context

Write it down. Slack handoff channel, daily summary doc, ticketing system shift report — any format works as long as it's persistent and searchable.

Show full SKILL.md (509 more words)Show less

Mode 3 — Improve the SOC

KPIs that actually matter
MetricDefinitionTarget
MTTDMean Time To Detect — from event to alert firing< 5 min for high-confidence rules; < 1 hr for behavioral
MTTRMean Time To Respond — from alert to triage decisionTier 1: < 15 min for Critical; < 4 hr for Medium
MTTCMean Time To Contain — from confirmed incident to spread halted< 1 hr for confirmed compromise (industry P50 is ~6 days; aspire higher)
TP rate per ruleTrue positives / total alerts> 30% for any rule; tune or kill rules below
Alert volume per analyst per shiftAlerts per Tier 1 analyst per 8-hour shift< 25 — above that, fatigue dominates
Coverage by ATT&CK tacticTactics with at least one detection ruleAim for 100% Initial Access, Execution, Persistence, Defense Evasion, Credential Access
Runbook coverage% of alerts that have runbooks> 80% of alert volume
Time to runbookNew alert-type to runbook delivered< 5 alerts of the new type

Don't measure things you can't act on. "Number of alerts processed" is a vanity metric — it goes up with noisier rules.

The tuning loop

The dominant SOC failure mode is alert fatigue from un-tuned rules. The loop that prevents it:

  1. Weekly: review top-N rules by alert volume
  2. For each high-volume rule: what's the TP rate? If < 30%, the rule is broken — tune or retire
  3. Retire vs tune: if the rule's underlying concept is sound, tune (add filter, increase threshold, add allow-list); if the concept is unsound (anomaly that's normal in your environment), retire
  4. Document every retirement — future engineers will want to know why the rule went away
  5. Track tuning cycles — "rule X tuned 3 times in 6 months" means the rule concept is wrong, not the parameters

See siem-detection's tuning section for the engineering side; this is the operations side.

Alert fatigue diagnostic

Symptoms your SOC is suffering:

  • Tier 1 analysts closing alerts in < 30 seconds (not investigating, just clicking through)
  • Same alert types ignored repeatedly without documented suppression
  • Analyst turnover > 25% / year
  • "We didn't catch X" post-mortems pointing to an alert that fired but wasn't actioned

When you see these: full-stop the new-rule pipeline and spend a cycle on tuning. Adding more rules to an over-firing SOC makes things worse.

Output Format

markdown
# SOC Assessment / Build Plan
## Organization: [name]
## Mode: Build / Run / Improve
## Date: [date]

### Current state (or proposed)
- Coverage hours, staffing model
- Tier structure
- Tools in use
- Alert volume / day
- Key metrics — MTTD, MTTR, TP rate distribution

### Findings (Improve mode) / Gaps (Build mode)
| Category | Issue / Gap | Severity |
|----------|-------------|----------|

### Recommendations
| Priority | Item | Owner | Timeline |
|----------|------|-------|----------|

### KPI dashboard proposal
[What to measure, how to source it, target thresholds]

### Runbook backlog
[Alert types that lack runbooks, ranked by volume]

Boundaries

  • This skill produces operations plans, not exploitation
  • Refuse to design SOC capabilities for unauthorized surveillance of employees or third parties
  • Alert tuning that intentionally hides legitimate security events is a finding, not a deliverable
  • Don't help build "compliance-theater" SOCs — if the org's intent is "check the box without actually detecting," push back
  • Where the assessment surfaces an active incident, hand off to incident-triage — don't continue planning work mid-fire

References

  • NIST SP 800-61 Rev. 3 (Computer Security Incident Handling Guide)
  • "Crafting the InfoSec Playbook" — Bollinger / Enright / Valites
  • "The Practice of Network Security Monitoring" — Richard Bejtlich
  • "Intelligence-Driven Incident Response" — Brown / Roberts
  • SANS SOC Survey (annual)
  • Gartner Magic Quadrant for SIEM (rotating — use the current edition)
  • ATT&CK for SOC analysts — attack.mitre.org/resources/training
  • MITRE D3FEND — defensive countermeasures catalog
  • "SOC Maturity Model" — various — pick one and measure against it

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/soc-operations of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Soc Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc Operations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc Operations this skillbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: PassMIT
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Conducting Cloud Incident Responsemukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing Soc Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Incident Responsealirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Analyzing Persistence Mechanisms In Linuxmukul975/Anthropic-Cybersecurity-Skills34k—~801Automated safety check: NotesApache-2.0

Similar skills

  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Cloud Incident Response

    mukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Soc Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    alirezarezvani/claude-skills

    A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

    28k GitHub stars~3.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Analyzing Persistence Mechanisms In Linux

    mukul975/Anthropic-Cybersecurity-Skills

    Scan Linux systems for persistence mechanisms including crontab/systemd entries, LDPRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorizedkeys backdoors, then…

    34k GitHub stars~801 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Triaging Security Alerts

    trilwu/secskills

    Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

    157 GitHub stars~2.5k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Questions about Soc Operations

What does Soc Operations do?

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…. Soc Operations is an agent skill from briiirussell/cybersecurity-skills. Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs.

When should I use Soc Operations?

Soc Operations fits situations like: the user mentions SOC; security operations; alert triage workflow; tier 1 / tier 2.

How do I install Soc Operations in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill soc-operations -a claude-code`. Or copy the skill folder (skills/soc-operations in briiirussell/cybersecurity-skills) into .claude/skills/soc-operations in your project. Claude Code loads it when a task matches its description.

How do I install Soc Operations in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill soc-operations -a codex`. Or copy the skill folder (skills/soc-operations in briiirussell/cybersecurity-skills) into .agents/skills/soc-operations in your project. Codex loads it when a task matches its description.

Can I use Soc Operations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill soc-operations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc-operations, .gemini/skills/soc-operations, .github/skills/soc-operations and .opencode/skills/soc-operations in your project.

What does Soc Operations need to run?

SKILL.md names no scripts, command-line tools or credentials: Soc Operations is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob, WebSearch.

Does Soc Operations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc Operations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Soc Operations use?

Soc Operations is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc Operations use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Soc Operations?

Skills that share tags, products or a category with Soc Operations: Implementing Soar Playbook With Palo Alto Xsoar (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Conducting Cloud Incident Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Soc Tabletop Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Incident Response (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc Operations?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.