Incident Response
alirezarezvani/claude-skills
A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exercise --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .claude/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .claude/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exerciseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exercise --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .agents/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .agents/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exercise --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .cursor/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .cursor/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/performing-soc-tabletop-exercise--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exercise --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .gemini/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .gemini/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exerciseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .github/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .github/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-soc-tabletop-exercise --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-soc-tabletop-exercise .opencode/skills/performing-soc-tabletop-exercise && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-soc-tabletop-exercise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-soc-tabletop-exercise into .opencode/skills/performing-soc-tabletop-exercise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-soc-tabletop-exercise", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-soc-tabletop-exercisePerforms tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…
Performing Soc Tabletop Exercise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in DevOps & Cloud, covering Security operations and Incident response. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Soc Tabletop Exercise loads about 4.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 404 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 404 words, ~4,200 tokens.
.claude/skills/performing-soc-tabletop-exercise/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use this skill when:
Do not use as a replacement for technical purple team exercises — tabletop exercises test processes and decision-making, not technical detection capabilities.
Create a realistic multi-phase scenario with escalating complexity:
tabletop_exercise:
title: "Operation Dark Harvest — Ransomware Attack Scenario"
exercise_id: TTX-2024-Q1
date: 2024-03-22
duration: 3 hours (09:00-12:00)
classification: TLP:AMBER (internal use only)
objectives:
1: "Test SOC team's ability to detect and triage ransomware indicators"
2: "Validate escalation procedures from Tier 1 to incident commander"
3: "Assess cross-functional communication with Legal, PR, and Executive leadership"
4: "Evaluate containment decision-making under time pressure"
5: "Test backup recovery procedures and business continuity activation"
participants:
- role: SOC Tier 1 Analyst (2 participants)
- role: SOC Tier 2 Analyst (2 participants)
- role: SOC Manager / Incident Commander
- role: IT Operations Lead
- role: CISO (or delegate)
- role: Legal Counsel
- role: Communications / PR
- role: Business Unit Leader (Finance)
scenario_background: >
Your organization is a mid-size financial services company with 2,500 employees.
The SOC operates 24/7 with 6 analysts per shift using Splunk ES and CrowdStrike Falcon.
It is Friday afternoon at 3:45 PM. The weekend IT skeleton crew starts at 5 PM.Design scenario injects released at scheduled intervals:
injects:
inject_1:
time: "T+0 (3:45 PM)"
title: "Initial Alert"
content: >
Splunk ES generates a notable event: "Shadow Copy Deletion Detected"
on FILESERVER-03 (10.0.10.50, Finance Department file server).
The alert shows: vssadmin.exe delete shadows /all /quiet
Source user: svc_backup (service account)
This is the first alert from this host today.
questions:
- "What is your initial assessment of this alert?"
- "What additional data would you query in Splunk?"
- "Is this a Tier 1 triage item or immediate escalation?"
inject_2:
time: "T+10 minutes"
title: "Escalating Indicators"
content: >
While investigating the first alert, two more alerts fire:
1. "Mass File Modification Detected" — 2,847 files renamed with .locked extension
on FILESERVER-03 within 5 minutes
2. "Suspicious PowerShell Encoded Command" on WORKSTATION-118 (10.0.5.118)
— same svc_backup account used
CrowdStrike shows process tree: explorer.exe > cmd.exe > powershell.exe -enc [base64]
questions:
- "What is your updated assessment? What incident severity would you assign?"
- "What immediate containment actions would you take?"
- "Who needs to be notified at this point?"
- "How do you determine if this is confined to these two hosts?"
inject_3:
time: "T+25 minutes"
title: "Scope Expansion"
content: >
Enterprise-wide Splunk search reveals:
- 7 additional hosts showing .locked file extensions
- All affected hosts are in the Finance VLAN (10.0.10.0/24)
- svc_backup account was used to RDP to all affected hosts starting at 3:30 PM
- A ransom note "README_UNLOCK.txt" found on all affected hosts
- Ransom note demands 50 BTC, includes Tor payment portal link
- IT reports the svc_backup password was changed 2 days ago (not by IT team)
questions:
- "This is now a confirmed ransomware incident. What is your incident classification?"
- "Walk through your containment strategy — what do you isolate and in what order?"
- "Should you shut down the Finance VLAN entirely? What are the trade-offs?"
- "When and how do you notify executive leadership?"
inject_4:
time: "T+45 minutes"
title: "Business Impact and External Pressure"
content: >
The CFO calls the SOC Manager directly:
"We are closing the quarter-end books this weekend. Finance absolutely needs
access to FILESERVER-03 by Monday morning or we miss SEC filing deadlines."
Additionally:
- Legal asks if customer PII was on any affected servers
- PR reports a journalist called asking about "cybersecurity issues at [company]"
- The ransom note deadline is 48 hours
- IT reports last verified backup of FILESERVER-03 is from Wednesday (3 days old)
questions:
- "How do you balance containment security with business pressure from the CFO?"
- "What is your recommendation on ransom payment? Who makes this decision?"
- "What information does Legal need to assess breach notification obligations?"
- "How do you handle the media inquiry?"
- "Can you recover from the 3-day-old backup? What data is lost?"
inject_5:
time: "T+70 minutes"
title: "Forensic Discovery"
content: >
Tier 3 forensic analysis reveals:
- Initial access was via compromised VPN credentials (svc_backup)
- Credentials were found in a dark web dump from a third-party vendor breach
- Attacker had access for 5 days before deploying ransomware
- Evidence of data exfiltration: 15GB uploaded to Mega.nz over 3 days
- Exfiltrated data includes customer PII (SSN, account numbers) for 12,000 clients
- The ransomware variant is identified as LockBit 3.0
questions:
- "How does confirmed data exfiltration change your response?"
- "What are the regulatory notification requirements? (SEC, state breach laws)"
- "What is the timeline for customer notification?"
- "Should you engage external IR firm? Law enforcement?"
- "How do you handle the vendor who was the source of the credential compromise?"
inject_6:
time: "T+90 minutes"
title: "Recovery Decision Point"
content: >
You are now 6 hours into the incident. Status:
- All 9 affected hosts isolated
- Finance VLAN segmented from corporate network
- LockBit C2 domain blocked at firewall and DNS
- No decryptor available for LockBit 3.0
- Wednesday backup verified clean but 3 days of data missing
- CEO asks for a full situation briefing in 30 minutes
questions:
- "Prepare a 5-minute executive briefing. What do you include?"
- "What is your recovery plan and estimated timeline?"
- "What monitoring will you put in place during and after recovery?"
- "What immediate security improvements would you recommend?"Facilitator Guide:
EXERCISE FACILITATION PROTOCOL
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. OPENING (10 min)
- State exercise objectives and ground rules
- Emphasize: "No wrong answers — this is about testing process, not individuals"
- Remind participants this is a simulation — no actual systems are affected
- Identify the exercise observer/scribe
2. INJECT DELIVERY (110 min)
- Present each inject on screen, allow 2 min reading time
- Ask guided questions to each role group
- Allow discussion but keep on timeline
- Inject additional pressure/complications as needed
- Record decisions, rationale, and gaps identified
3. DISCUSSION RULES
- Participants respond in-character (their actual role)
- Reference actual playbooks and procedures when available
- If participants are unsure, that IS the finding
- Facilitator may add "hot injects" if discussion stalls
4. CLOSING (40 min)
- Hot wash: Each participant shares one thing that went well, one gap
- Facilitator summarizes key findings
- Identify top 5 action items with owners and due datesScore responses against expected outcomes:
evaluation_criteria:
detection_and_triage:
expected: "Immediately recognize shadow copy deletion as ransomware precursor"
scoring:
excellent: "Correctly identified within 2 minutes, initiated proper escalation"
adequate: "Identified after discussion, correct escalation path"
needs_improvement: "Did not recognize significance, delayed escalation"
containment_decision:
expected: "Isolate affected hosts via EDR, segment Finance VLAN, preserve evidence"
scoring:
excellent: "Immediate isolation, correct priority order, evidence preservation"
adequate: "Isolation performed but delayed or incomplete prioritization"
needs_improvement: "Considered powering off hosts (destroys evidence) or delayed isolation"
communication:
expected: "Timely notification chain: SOC Manager -> CISO -> Legal -> Executive"
scoring:
excellent: "Proper notification within defined SLAs, clear and concise briefings"
adequate: "Notifications made but slightly delayed or incomplete"
needs_improvement: "Key stakeholders not notified, unclear communication"
business_continuity:
expected: "Balance security containment with business recovery needs"
scoring:
excellent: "Realistic recovery timeline communicated, alternative workarounds proposed"
adequate: "Recovery discussed but timeline unclear"
needs_improvement: "Overcommitted on timeline or ignored business impact"after_action_report:
exercise: TTX-2024-Q1 "Operation Dark Harvest"
date: 2024-03-22
participants: 10
duration: 3 hours
executive_summary: >
The tabletop exercise tested the organization's ransomware response capabilities
across detection, containment, communication, and recovery phases. The SOC team
demonstrated strong technical triage skills but gaps were identified in cross-
functional communication and backup recovery procedures.
strengths:
- SOC analysts correctly identified ransomware indicators within first inject
- Containment decision-making was swift and technically sound
- Legal team was well-prepared on breach notification requirements
- IT operations had clear understanding of backup recovery procedures
gaps_identified:
- gap_1:
finding: "No documented procedure for notifying CISO after-hours"
risk: High
action: "Update escalation contacts with personal phone numbers and backup contacts"
owner: SOC Manager
due_date: 2024-04-05
- gap_2:
finding: "Backup recovery testing has not been performed in 6 months"
risk: Critical
action: "Schedule quarterly backup restoration drill"
owner: IT Operations Lead
due_date: 2024-04-15
- gap_3:
finding: "No pre-approved media holding statement for cyber incidents"
risk: Medium
action: "Draft and approve 3 holding statement templates with Legal"
owner: Communications Lead
due_date: 2024-04-10
- gap_4:
finding: "Service account (svc_backup) had Domain Admin privileges unnecessarily"
risk: Critical
action: "Audit all service accounts, implement least privilege"
owner: IT Security
due_date: 2024-04-01
- gap_5:
finding: "Unclear decision authority for ransom payment"
risk: High
action: "Document ransom payment decision tree with CEO/Board approval requirement"
owner: CISO
due_date: 2024-04-15
metrics:
overall_score: "72/100 (Adequate)"
detection: "85/100 (Excellent)"
containment: "80/100 (Good)"
communication: "60/100 (Needs Improvement)"
recovery: "65/100 (Needs Improvement)"
next_exercise: "TTX-2024-Q2 — Data Breach / Insider Threat Scenario (June 2024)"--- Track action items from tabletop exercise
| inputlookup ttx_action_items.csv
| eval days_remaining = round((strptime(due_date, "%Y-%m-%d") - now()) / 86400)
| eval status_flag = case(
status="Completed", "GREEN",
days_remaining < 0, "RED — OVERDUE",
days_remaining < 7, "YELLOW — DUE SOON",
1=1, "GREEN"
)
| sort - status_flag, days_remaining
| table gap_id, finding, owner, due_date, days_remaining, status, status_flag| Term | Definition |
|---|---|
| Tabletop Exercise | Discussion-based simulation where participants walk through incident scenarios without executing technical actions |
| Inject | Scenario update introducing new information, complications, or decisions for participants to address |
| Hot Wash | Immediate post-exercise debrief where participants share observations and initial lessons learned |
| After-Action Report (AAR) | Formal document capturing exercise findings, gaps, strengths, and remediation action items |
| Facilitator | Exercise leader who presents injects, guides discussion, and ensures objectives are met |
| Decision Point | Moment in the scenario requiring participants to choose between options with trade-offs |
TABLETOP EXERCISE SUMMARY — TTX-2024-Q1
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Scenario: Operation Dark Harvest (Ransomware)
Date: 2024-03-22 (09:00-12:00 UTC)
Participants: 10 (SOC: 5, IT: 1, Legal: 1, Comms: 1, Exec: 2)
Duration: 3 hours (6 injects delivered)
SCORES:
Detection & Triage: 85/100 Excellent
Containment: 80/100 Good
Communication: 60/100 Needs Improvement
Recovery Planning: 65/100 Needs Improvement
Overall: 72/100 Adequate
KEY FINDINGS:
[+] Strong: Ransomware indicators correctly identified immediately
[+] Strong: EDR isolation procedure well understood
[-] Gap: No after-hours CISO notification procedure
[-] Gap: Backup recovery untested for 6 months
[-] Gap: No pre-approved media statement templates
[-] Gap: Service account over-privileged (Domain Admin)
[-] Gap: Ransom payment decision authority undefined
ACTION ITEMS: 5 (Critical: 2, High: 2, Medium: 1)
NEXT EXERCISE: TTX-2024-Q2 (June 2024) — Insider Threat Scenario© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/performing-soc-tabletop-exercise of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Performing Soc Tabletop Exercise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Soc Tabletop Exercise this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Incident Responsealirezarezvani/claude-skills | 28k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Soc Operationsbriiirussell/cybersecurity-skills | 413 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Triaging Security Alertstrilwu/secskills | 157 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Ise Incident Responseautomateyournetwork/netclaw | 676 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Incident ResponseBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~4.5k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
briiirussell/cybersecurity-skills
Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…
trilwu/secskills
Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…
automateyournetwork/netclaw
Rapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident.
BagelHole/DevOps-Security-Agent-Skills
Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
RTFM-IT-Services-LLC/msp-claude-skills
A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call…
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…. Performing Soc Tabletop Exercise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems.
Performing Soc Tabletop Exercise fits situations like: organizations need to validate IR playbooks; meet compliance requirements for incident response testing.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a claude-code`. Or copy the skill folder (skills/performing-soc-tabletop-exercise in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-soc-tabletop-exercise in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a codex`. Or copy the skill folder (skills/performing-soc-tabletop-exercise in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-soc-tabletop-exercise in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-soc-tabletop-exercise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-soc-tabletop-exercise, .gemini/skills/performing-soc-tabletop-exercise, .github/skills/performing-soc-tabletop-exercise and .opencode/skills/performing-soc-tabletop-exercise in your project.
Going by SKILL.md and its folder, Performing Soc Tabletop Exercise needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Soc Tabletop Exercise is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 653 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Soc Tabletop Exercise: Incident Response (alirezarezvani/claude-skills, 28k stars), Soc Operations (briiirussell/cybersecurity-skills, 413 stars), Triaging Security Alerts (trilwu/secskills, 157 stars) and Ise Incident Response (automateyournetwork/netclaw, 676 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.