Topic · Security
Best security operations skills, page 2
Security operations skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 50 | Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale. | AgentSecOps/ | 220 | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 51 | A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU… | davila7/ | 32k | 1 repo | ~4.7k | Automated safety check: Pass | CC-BY-4.0 | today |
| 52 | Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. | mukul975/ | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 55 | Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 56 | Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 57 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 58 | Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 59 | Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 60 | Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft. | mukul975/ | 34k | — | ~897 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 61 | Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 62 | Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. | mukul975/ | 34k | — | ~922 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 63 | Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 64 | Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft… | mukul975/ | 34k | — | ~923 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 65 | Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 66 | Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. | mukul975/ | 34k | — | ~925 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 67 | Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting… | mukul975/ | 34k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 68 | Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 69 | Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. | mukul975/ | 34k | — | ~907 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 70 | Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. | mukul975/ | 34k | — | ~891 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 71 | Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and… | mukul975/ | 34k | — | ~899 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 72 | Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and… | mukul975/ | 34k | — | ~914 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 73 | Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 74 | Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 75 | Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 76 | Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 77 | Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 78 | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. | mukul975/ | 34k | — | ~2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 79 | Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 80 | Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and… | mukul975/ | 34k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 81 | Perform structured log source onboarding into SIEM platforms (Splunk, Elastic, Sentinel, QRadar, or similar) by prioritizing sources with a tiered value framework, configuring collectors, building… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 82 | Develops precise YARA and YARA-X rules for malware detection by identifying unique strings, byte sequences, PE header traits, and behavioral indicators in unpacked malware artifacts while minimizing… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 83 | Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 84 | What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result | deonmenezes/ | 505 | — | ~376 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 85 | Handle security incidents with IR playbooks and procedures. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~3.7k | Automated safety check: Pass | MIT | today |
| 86 | 86.Infra Triage Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes. | papadopouloskyriakos/ | 107 | — | ~714 | Automated safety check: Notes | No licence | yesterday |
| 87 | Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 88 | Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 89 | Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 90 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 91 | Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 92 | Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 93 | Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and… | mukul975/ | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 94 | Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxypass) and Apache (modrewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 95 | Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 96 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38