Topic · Security

Best security operations skills, page 5

Skills #193–240 of 246, ranked by score.

Security operations skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security operations skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
193

Hunt for credential access techniques like LSASS dumping or browser credential theft.

dandye/ai-runbooks127—~1.1kAutomated safety check: WarnApache-2.01 mo ago
194

A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just…

gaasher/Agent-Loop-Skills174—~2.6kAutomated safety check: PassMIT3 mo ago
195

Deploys and operates Falco with the modern eBPF driver in Kubernetes and Docker, covering driver selection, Helm installation, output channels, and the built-in ruleset that detects container…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: WarnApache-2.01 mo ago
196

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: WarnApache-2.01 mo ago
197

Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.

borghei/Claude-Skills881—~4kAutomated safety check: PassMITtoday
198

Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research.

telagod/code-abyss243—~581Automated safety check: PassMIT2 mo ago
199

A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

SCStelz/security-investigator249—~13kAutomated safety check: PassMITyesterday
200

Turn a published threat-intelligence article into a tested threat-hunting campaign.

SCStelz/security-investigator249—~6.9kAutomated safety check: PassMITyesterday
201

Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red.

SnailSploit/Claude-Red7.3k—~3.7kAutomated safety check: PassMIT18 days ago
202
202.Azure Kusto IrqlOfficial

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

microsoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMITtoday
203

Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables.

aws/agent-toolkit-for-aws2.8k—~3.5kAutomated safety check: PassApache-2.0today
204

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.

transilienceai/communitytools562—~476Automated safety check: PassMIT2 mo ago
205

Convene an AI executive board of directors (CEO, CFO, COO, CLO, CISO sub-agent personas) to vet a business idea, product concept, new service offering, M&A target, or operational initiative — and…

davepoon/buildwithclaude3.6k—~1.5kAutomated safety check: PassMITyesterday
206

Respond to a ransomware incident following PICERL methodology.

dandye/ai-runbooks127—~1.7kAutomated safety check: PassApache-2.01 mo ago
207

Triage a security alert or case. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.2kAutomated safety check: PassApache-2.01 mo ago
208

Triage suspicious login alerts like impossible travel, untrusted location, or multiple failures.

dandye/ai-runbooks127—~1kAutomated safety check: PassApache-2.01 mo ago
209
209.Doca ArgusOfficial

A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…

NVIDIA/skills3.5k—~4.8kAutomated safety check: PassApache-2.0today
210

Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations.

ArabelaTso/Skills-4-SE253—~1.8kAutomated safety check: PassApache-2.01 mo ago
211

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices.

trilwu/secskills156—~3.3kAutomated safety check: PassMIT1 mo ago
212

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
213

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills156—~4.8kAutomated safety check: PassMIT1 mo ago
214

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
215

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

trilwu/secskills156—~4.1kAutomated safety check: PassMIT1 mo ago
216

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

trilwu/secskills156—~2.5kAutomated safety check: PassMIT1 mo ago
217

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…

trilwu/secskills156—~4.1kAutomated safety check: PassMIT1 mo ago
218

Issue an evidence-backed Cohere production go or no-go decision covering capacity, quality, security, operations, and rollback.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITtoday
219

Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review afterward.

cbrock84/headcount2k—~1kAutomated safety check: PassMIT20 days ago
220
220.Hack

Entry P0 primary router and operating doctrine for HackSkills.

yaklang/hack-skills2.4k—~4.7kAutomated safety check: NotesMIT24 days ago
221
221.Secops CasesOfficial

Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle.

google/skills21k—~3.2kAutomated safety check: WarnApache-2.0today
222

日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用

wgpsec/AboutSecurity1.8k—~1.2kAutomated safety check: PassNo licence4 days ago
223

威胁猎杀原理与规避方法论。理解蓝队如何主动猎杀(Hypothesis-driven / IOC-driven / Analytics-driven),红队如何设计行为使自己不被猎杀到。当需要评估自身操作是否可被威胁猎杀发现时使用

wgpsec/AboutSecurity1.8k—~1kAutomated safety check: PassNo licence4 days ago
224

Save investigation findings to a markdown report file. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~587Automated safety check: PassApache-2.01 mo ago
225

Implements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring.

mukul975/Privacy-Data-Protection-Skills295—~3kAutomated safety check: PassApache-2.06 mo ago
226

Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation…

mukul975/Privacy-Data-Protection-Skills295—~3.1kAutomated safety check: PassApache-2.06 mo ago
227

Vendor breach notification cascade management per GDPR Article 33(2).

mukul975/Privacy-Data-Protection-Skills295—~2.8kAutomated safety check: PassApache-2.06 mo ago
228

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…

trilwu/secskills156—~5.3kAutomated safety check: PassMIT1 mo ago
229

Execute log analysis security operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~575Automated safety check: PassMITtoday
230

Generate siem rule generator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~570Automated safety check: PassMITtoday
231

Rapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident.

automateyournetwork/netclaw675—~3.4kAutomated safety check: PassApache-2.02 days ago
232

Security incident detection, analysis, containment, eradication, recovery, and lessons learned per NIST SP 800-61r2 and ISO 27035

Hack23/cia239—~7.8kAutomated safety check: PassApache-2.0today
233

Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name.

mohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMITtoday
234

Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis.

mohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: PassMITtoday
235

Run or document a security incident response — contain, eradicate, recover, and learn.

mohitagw15856/pm-claude-skills1.4k—~1kAutomated safety check: PassMITtoday
236

Network forensics evidence collection and analysis during security incidents.

LeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.02 mo ago
237

安全事件响应助手 - 专业的安全事件处置与应急响应专家。适用场景: (1) 安全事件识别与分类 (2) 应急响应计划制定 (3) 事件调查与取证分析 (4) 遏制与根除方案设计 (5) 系统恢复与业务连续性 (6) 事件复盘与改进建议 (7) 安全事件报告撰写 触发关键词:安全事件、应急响应、事件处置、入侵检测、安全告警、取证分析、恢复计划、事件复盘、安全报告、勒索软件、数据泄露

chendongqi/OPB-Skills125—~999Automated safety check: PassNo licence7 mo ago
238

Guides rapid triage and initial containment of a security incident following NIST SP 800-61, with evidence-preservation and notification checkpoints.

criptogus/agent-evolve-network288—~1kAutomated safety check: PassCC-BY-SA-4.028 days ago
239
239.Soe

This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…

infometa/workbuddyskills344—~2.3kAutomated safety check: NotesNo licencetoday
240

Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.

vinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT3 mo ago