Topic · Security

Best security operations skills, page 2

Skills #49–96 of 246, ranked by score.

Security operations skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security operations skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

AgentSecOps/SecOpsAgentKit2201 repo~4.9kAutomated safety check: NotesUnknown5 mo ago
50

Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

AgentSecOps/SecOpsAgentKit2201 repo~3.1kAutomated safety check: PassUnknown5 mo ago
51

A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…

davila7/claude-code-templates32k1 repo~4.7kAutomated safety check: PassCC-BY-4.0today
52

Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
53

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender…

mukul975/Anthropic-Cybersecurity-Skills34k—~893Automated safety check: PassApache-2.01 mo ago
54

Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.01 mo ago
55

Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: NotesApache-2.01 mo ago
56

Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
57

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
58

Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
59

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
60

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.

mukul975/Anthropic-Cybersecurity-Skills34k—~897Automated safety check: PassApache-2.01 mo ago
61

Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping…

mukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.01 mo ago
62

Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse.

mukul975/Anthropic-Cybersecurity-Skills34k—~922Automated safety check: PassApache-2.01 mo ago
63

Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk…

mukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.01 mo ago
64

Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft…

mukul975/Anthropic-Cybersecurity-Skills34k—~923Automated safety check: PassApache-2.01 mo ago
65

Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
66

Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e.

mukul975/Anthropic-Cybersecurity-Skills34k—~925Automated safety check: PassApache-2.01 mo ago
67

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.01 mo ago
68

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
69

Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~907Automated safety check: PassApache-2.01 mo ago
70

Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.

mukul975/Anthropic-Cybersecurity-Skills34k—~891Automated safety check: PassApache-2.01 mo ago
71

Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~899Automated safety check: PassApache-2.01 mo ago
72

Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~914Automated safety check: PassApache-2.01 mo ago
73

Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…

mukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.01 mo ago
74

Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
75

Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
76

Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
77

Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
78

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: NotesApache-2.01 mo ago
79

Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
80

Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: PassApache-2.01 mo ago
81

Perform structured log source onboarding into SIEM platforms (Splunk, Elastic, Sentinel, QRadar, or similar) by prioritizing sources with a tiered value framework, configuring collectors, building…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
82

Develops precise YARA and YARA-X rules for malware detection by identifying unique strings, byte sequences, PE header traits, and behavioral indicators in unpacked malware artifacts while minimizing…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
83

Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
84

What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

deonmenezes/mantishack505—~376Automated safety check: PassApache-2.04 days ago
85

Handle security incidents with IR playbooks and procedures. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k1 repo~3.7kAutomated safety check: PassMITtoday
86

Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes.

papadopouloskyriakos/agentic-chatops107—~714Automated safety check: NotesNo licenceyesterday
87

Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
88

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

mukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.01 mo ago
89

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
90

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules…

mukul975/Anthropic-Cybersecurity-Skills34k—~654Automated safety check: PassApache-2.01 mo ago
91

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
92

Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
93

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.7kAutomated safety check: PassApache-2.01 mo ago
94

Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxypass) and Apache (modrewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.01 mo ago
95

Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
96

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago