Topic · Security
Best security operations skills, page 4
Security operations skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 146 | Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 147 | Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection… | mukul975/ | 34k | — | ~9.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 148 | 148.Hunt Ioc Hunt for specific IOCs across your environment. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~958 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 149 | 149.K8s Triage Kubernetes alert triage — dedup via YT search, deep control plane investigation, auto-escalation for recurring/flapping/control-plane alerts. | papadopouloskyriakos/ | 107 | — | ~801 | Automated safety check: Notes | No licence | 2 days ago |
| 150 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 243 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 151 | Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 152 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 153 | Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and… | mukul975/ | 34k | — | ~796 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 154 | Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 155 | Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 156 | Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. | mukul975/ | 34k | — | ~849 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 157 | Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 158 | Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 159 | Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM. | mukul975/ | 34k | — | ~717 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 160 | Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 161 | Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 162 | Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 163 | Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. | mukul975/ | 34k | — | ~638 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 164 | Detect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon process-creation and file-system telemetry (Event ID 4688, Sysmon 1/11) for 7-Zip/RAR/tar archive creation, unusual temp or… | mukul975/ | 34k | — | ~801 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 165 | Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using… | mukul975/ | 34k | — | ~790 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 166 | Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10… | mukul975/ | 34k | — | ~712 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 167 | Detects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for… | mukul975/ | 34k | — | ~676 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 168 | Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms… | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 169 | Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 170 | Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 171 | Tune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines… | mukul975/ | 34k | — | ~657 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 172 | Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 173 | 173.Malware Analyst Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. | aiskillstore/ | 430 | 6 repos | ~1.7k | Automated safety check: Pass | No licence | yesterday |
| 174 | Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. | google/ | 21k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | today |
| 175 | Expert guidance for proactive threat hunting in Google SecOps. | google/ | 21k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 176 | Expert guidance for deep security incident and entity investigations in Google SecOps. | google/ | 21k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | today |
| 177 | Expert guidance for security alert triage in Google SecOps. An agent skill from google/skills. | google/ | 21k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | today |
| 178 | 178.Incident Triage Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. | briiirussell/ | 413 | — | ~1.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 179 | 179.Siem Detection Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 180 | 180.Soc Operations Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst… | briiirussell/ | 413 | — | ~2.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 181 | 181.Threat Hunting Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. | briiirussell/ | 413 | — | ~2.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 182 | Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing… | mukul975/ | 34k | — | ~582 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 183 | 蓝队与紫队工程:检测规则编写、SIEM/EDR 调优、事件响应、数字取证、威胁狩猎、ATT&CK 映射、紫队演练闭环。Use when writing Sigma/YARA detection rules, tuning SIEM noise, responding to security incidents, conducting forensic analysis, hunting… | telagod/ | 243 | — | ~697 | Automated safety check: Pass | MIT | 2 mo ago |
| 184 | Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1k | Automated safety check: Notes | No licence | 16 days ago |
| 185 | Scan Linux systems for persistence mechanisms including crontab/systemd entries, LDPRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorizedkeys backdoors, then… | mukul975/ | 34k | — | ~801 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 186 | Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy… | mukul975/ | 34k | — | ~754 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 187 | 187.Defender Blue-team release-gate analysis for smart contract deployment and upgrade readiness. | quillai-network/ | 129 | — | ~1.7k | Automated safety check: Notes | MIT | 6 mo ago |
| 188 | 188.Soc Alert Triage Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev. | mrmps/ | 424 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 189 | 189.Domain Domain-specific: SAP Commerce, OpenSearch detection, WordPress validation, enterprise search. | notque/ | 438 | — | ~3.7k | Automated safety check: Notes | MIT | 5 days ago |
| 190 | Automates the end-to-end detection engineering workflow in Google SecOps using MCP tools. | google/ | 21k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | today |
| 191 | 191.Hunt Threat Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 192 | Analyze and guide security incident response, investigation, and remediation processes. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38