Topic · Security

Best red teaming and adversary simulation skills, page 3

Skills #97–144 of 148, ranked by score.

Red teaming and adversary simulation skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Red teaming and adversary simulation skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
97

Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding, and LDAP signing.

mukul975/Anthropic-Cybersecurity-Skills34k—~756Automated safety check: PassApache-2.01 mo ago
98

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
99

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~849Automated safety check: PassApache-2.01 mo ago
100

Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.

mukul975/Anthropic-Cybersecurity-Skills34k—~677Automated safety check: PassApache-2.01 mo ago
101

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: NotesApache-2.01 mo ago
102

Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
103

Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL.

mukul975/Anthropic-Cybersecurity-Skills34k—~695Automated safety check: PassApache-2.01 mo ago
104

Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.

mukul975/Anthropic-Cybersecurity-Skills34k—~659Automated safety check: PassApache-2.01 mo ago
105

Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures…

mukul975/Anthropic-Cybersecurity-Skills34k—~718Automated safety check: PassApache-2.01 mo ago
106

Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs…

mukul975/Anthropic-Cybersecurity-Skills34k—~730Automated safety check: PassApache-2.01 mo ago
107

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
108

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

mukul975/Anthropic-Cybersecurity-Skills34k—~762Automated safety check: PassApache-2.01 mo ago
109

Enumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos…

mukul975/Anthropic-Cybersecurity-Skills34k—~675Automated safety check: PassApache-2.01 mo ago
110
110.Secops InvestigateOfficial

Expert guidance for deep security incident and entity investigations in Google SecOps.

google/skills21k—~4.2kAutomated safety check: PassApache-2.0today
111

Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's…

mukul975/Anthropic-Cybersecurity-Skills34k—~963Automated safety check: PassApache-2.01 mo ago
112

Perform Kerberoasting, a post-exploitation technique that enumerates Active Directory service accounts with Service Principal Names (SPNs), requests their Kerberos TGS tickets, and cracks the…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.1kAutomated safety check: PassApache-2.01 mo ago
113

Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.01 mo ago
114

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

SnailSploit/Claude-Red7.3k—~2.8kAutomated safety check: NotesMIT18 days ago
115

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized…

mukul975/Anthropic-Cybersecurity-Skills34k—~751Automated safety check: PassApache-2.01 mo ago
116

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

mukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.01 mo ago
117

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…

mukul975/Anthropic-Cybersecurity-Skills34k—~808Automated safety check: PassApache-2.01 mo ago
118

Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation.

aws/agent-toolkit-for-aws2.8k—~2.7kAutomated safety check: PassApache-2.0today
119

A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just…

gaasher/Agent-Loop-Skills174—~2.6kAutomated safety check: PassMIT3 mo ago
120

Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: WarnApache-2.01 mo ago
121

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: WarnApache-2.01 mo ago
122

Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.01 mo ago
123

A skill your agent uses when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or feeding captured traffic to the model) — to decide detection…

hypnguyen1209/offensive-claude386—~561Automated safety check: PassMIT10 days ago
124

AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.9kAutomated safety check: PassMIT25 days ago
125

Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red.

SnailSploit/Claude-Red7.3k—~3.7kAutomated safety check: PassMIT18 days ago
126
126.Azure Kusto IrqlOfficial

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

microsoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMITtoday
127

Catalogue of prompt framings that determine whether an agent refuses or performs specification search, and the harness for probing them.

brycewang-stanford/Auto-Empirical-Research-Skills4.5k—~1.4kAutomated safety check: PassUnknown3 days ago
128

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.

transilienceai/communitytools562—~476Automated safety check: PassMIT2 mo ago
129

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
130
130.Red

Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use).

glebis/claude-skills389—~881Automated safety check: PassMIT12 days ago
131

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.01 mo ago
132

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills156—~4.8kAutomated safety check: PassMIT1 mo ago
133

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills156—~4.7kAutomated safety check: PassMIT1 mo ago
134

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
135
135.Rds Db2Official

Provisions, connects, migrates, and operates Amazon RDS for Db2.

aws/agent-toolkit-for-aws2.8k—~6.9kAutomated safety check: PassApache-2.0today
136

Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

blacklanternsecurity/red-run287—~4.5kAutomated safety check: NotesGPL-3.010 days ago
137

Read-only SLA-readiness, availability, and cost review of Amazon FSx for Windows File Server.

aws/tools-for-devops-agent100—~3.4kAutomated safety check: PassApache-2.0today
138

Generates Records of Processing Activities automatically from IT system inventories including Active Directory, cloud service catalogs, API gateway logs, and database schemas.

mukul975/Privacy-Data-Protection-Skills295—~3.7kAutomated safety check: PassApache-2.06 mo ago
139

Analyze blast radius, attack paths, and threat landscape across your AI infrastructure.

LeoYeAI/openclaw-master-skills2.2k—~1kAutomated safety check: PassApache-2.02 mo ago
140

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…

trilwu/secskills156—~5.3kAutomated safety check: PassMIT1 mo ago
141

Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.

AI45Lab/OpenART231—~918Automated safety check: NotesAGPL-3.05 days ago
142

A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

jeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMITtoday
143

Rapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident.

automateyournetwork/netclaw675—~3.4kAutomated safety check: PassApache-2.03 days ago
144

Network forensics evidence collection and analysis during security incidents.

LeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.02 mo ago