Topic · Security
Best red teaming and adversary simulation skills, page 3
Red teaming and adversary simulation skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding, and LDAP signing. | mukul975/ | 34k | — | ~756 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 98 | Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 99 | Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. | mukul975/ | 34k | — | ~849 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 100 | Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 101 | Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 102 | Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 103 | Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. | mukul975/ | 34k | — | ~695 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 104 | Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~659 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 105 | Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures… | mukul975/ | 34k | — | ~718 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 106 | Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs… | mukul975/ | 34k | — | ~730 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 107 | Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 108 | Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance. | mukul975/ | 34k | — | ~762 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 109 | Enumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos… | mukul975/ | 34k | — | ~675 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 110 | Expert guidance for deep security incident and entity investigations in Google SecOps. | google/ | 21k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | today |
| 111 | Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's… | mukul975/ | 34k | — | ~963 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 112 | Perform Kerberoasting, a post-exploitation technique that enumerates Active Directory service accounts with Service Principal Names (SPNs), requests their Kerberos TGS tickets, and cracks the… | mukul975/ | 34k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 113 | Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. | mukul975/ | 34k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 114 | 114.Offensive Wifi Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. | SnailSploit/ | 7.3k | — | ~2.8k | Automated safety check: Notes | MIT | 18 days ago |
| 115 | Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized… | mukul975/ | 34k | — | ~751 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 116 | Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 117 | Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation… | mukul975/ | 34k | — | ~808 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 118 | Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation. | aws/ | 2.8k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | today |
| 119 | 119.Purple Team A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just… | gaasher/ | 174 | — | ~2.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 120 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 121 | Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 122 | Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 123 | 123.Opsec Discipline A skill your agent uses when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or feeding captured traffic to the model) — to decide detection… | hypnguyen1209/ | 386 | — | ~561 | Automated safety check: Pass | MIT | 10 days ago |
| 124 | AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.9k | Automated safety check: Pass | MIT | 25 days ago |
| 125 | Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red. | SnailSploit/ | 7.3k | — | ~3.7k | Automated safety check: Pass | MIT | 18 days ago |
| 126 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 127 | 127.Framing Attacks Catalogue of prompt framings that determine whether an agent refuses or performs specification search, and the harness for probing them. | brycewang-stanford/ | 4.5k | — | ~1.4k | Automated safety check: Pass | Unknown | 3 days ago |
| 128 | 128.Cloud Defense Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. | transilienceai/ | 562 | — | ~476 | Automated safety check: Pass | MIT | 2 mo ago |
| 129 | Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 130 | 130.Red Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). | glebis/ | 389 | — | ~881 | Automated safety check: Pass | MIT | 12 days ago |
| 131 | Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 132 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 156 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 133 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 156 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 134 | Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 135 | Provisions, connects, migrates, and operates Amazon RDS for Db2. | aws/ | 2.8k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | today |
| 136 | 136.Trust Attacks Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. | blacklanternsecurity/ | 287 | — | ~4.5k | Automated safety check: Notes | GPL-3.0 | 10 days ago |
| 137 | Read-only SLA-readiness, availability, and cost review of Amazon FSx for Windows File Server. | aws/ | 100 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | today |
| 138 | Generates Records of Processing Activities automatically from IT system inventories including Active Directory, cloud service catalogs, API gateway logs, and database schemas. | mukul975/ | 295 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 139 | Analyze blast radius, attack paths, and threat landscape across your AI infrastructure. | LeoYeAI/ | 2.2k | — | ~1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 140 | Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 141 | 141.Openart Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework. | AI45Lab/ | 231 | — | ~918 | Automated safety check: Notes | AGPL-3.0 | 5 days ago |
| 142 | A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed… | jeremylongshore/ | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | today |
| 143 | Rapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident. | automateyournetwork/ | 675 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 144 | Network forensics evidence collection and analysis during security incidents. | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38