Topic · Security
Best security operations skills, page 5
Security operations skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | Hunt for credential access techniques like LSASS dumping or browser credential theft. | dandye/ | 127 | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 194 | 194.Purple Team A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just… | gaasher/ | 174 | — | ~2.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 195 | Deploys and operates Falco with the modern eBPF driver in Kubernetes and Docker, covering driver selection, Helm installation, output channels, and the built-in ruleset that detects container… | mukul975/ | 34k | — | ~3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 196 | Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 197 | Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. | borghei/ | 881 | — | ~4k | Automated safety check: Pass | MIT | today |
| 198 | 198.Securing Systems Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. | telagod/ | 243 | — | ~581 | Automated safety check: Pass | MIT | 2 mo ago |
| 199 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | yesterday |
| 200 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | yesterday |
| 201 | Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red. | SnailSploit/ | 7.3k | — | ~3.7k | Automated safety check: Pass | MIT | 18 days ago |
| 202 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 203 | Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables. | aws/ | 2.8k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | today |
| 204 | 204.Cloud Defense Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. | transilienceai/ | 562 | — | ~476 | Automated safety check: Pass | MIT | 2 mo ago |
| 205 | 205.Theboardroom Convene an AI executive board of directors (CEO, CFO, COO, CLO, CISO sub-agent personas) to vet a business idea, product concept, new service offering, M&A target, or operational initiative — and… | davepoon/ | 3.6k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 206 | Respond to a ransomware incident following PICERL methodology. | dandye/ | 127 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 207 | 207.Triage Alert Triage a security alert or case. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 208 | Triage suspicious login alerts like impossible travel, untrusted location, or multiple failures. | dandye/ | 127 | — | ~1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 209 | A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for… | NVIDIA/ | 3.5k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | today |
| 210 | Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. | ArabelaTso/ | 253 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 211 | Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. | trilwu/ | 156 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 212 | 212.Hunting Threats Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 213 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 156 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 214 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 215 | Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule… | trilwu/ | 156 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 216 | Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment… | trilwu/ | 156 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 217 | Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with… | trilwu/ | 156 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 218 | Issue an evidence-backed Cohere production go or no-go decision covering capacity, quality, security, operations, and rollback. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 219 | Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review afterward. | cbrock84/ | 2k | — | ~1k | Automated safety check: Pass | MIT | 20 days ago |
| 220 | 220.Hack Entry P0 primary router and operating doctrine for HackSkills. | yaklang/ | 2.4k | — | ~4.7k | Automated safety check: Notes | MIT | 24 days ago |
| 221 | Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. | google/ | 21k | — | ~3.2k | Automated safety check: Warn | Apache-2.0 | today |
| 222 | 222.Log Evasion 日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用 | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | 4 days ago |
| 223 | 威胁猎杀原理与规避方法论。理解蓝队如何主动猎杀(Hypothesis-driven / IOC-driven / Analytics-driven),红队如何设计行为使自己不被猎杀到。当需要评估自身操作是否可被威胁猎杀发现时使用 | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Pass | No licence | 4 days ago |
| 224 | 224.Generate Report Save investigation findings to a markdown report file. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~587 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 225 | Implements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring. | mukul975/ | 295 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 226 | Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation… | mukul975/ | 295 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 227 | Vendor breach notification cascade management per GDPR Article 33(2). | mukul975/ | 295 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 228 | Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 229 | Execute log analysis security operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~575 | Automated safety check: Pass | MIT | today |
| 230 | Generate siem rule generator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~570 | Automated safety check: Pass | MIT | today |
| 231 | Rapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident. | automateyournetwork/ | 675 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 232 | Security incident detection, analysis, containment, eradication, recovery, and lessons learned per NIST SP 800-61r2 and ISO 27035 | Hack23/ | 239 | — | ~7.8k | Automated safety check: Pass | Apache-2.0 | today |
| 233 | Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name. | mohitagw15856/ | 1.4k | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 234 | Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis. | mohitagw15856/ | 1.4k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 235 | Run or document a security incident response — contain, eradicate, recover, and learn. | mohitagw15856/ | 1.4k | — | ~1k | Automated safety check: Pass | MIT | today |
| 236 | Network forensics evidence collection and analysis during security incidents. | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 237 | 安全事件响应助手 - 专业的安全事件处置与应急响应专家。适用场景: (1) 安全事件识别与分类 (2) 应急响应计划制定 (3) 事件调查与取证分析 (4) 遏制与根除方案设计 (5) 系统恢复与业务连续性 (6) 事件复盘与改进建议 (7) 安全事件报告撰写 触发关键词:安全事件、应急响应、事件处置、入侵检测、安全告警、取证分析、恢复计划、事件复盘、安全报告、勒索软件、数据泄露 | chendongqi/ | 125 | — | ~999 | Automated safety check: Pass | No licence | 7 mo ago |
| 238 | Guides rapid triage and initial containment of a security incident following NIST SP 800-61, with evidence-preservation and notification checkpoints. | criptogus/ | 288 | — | ~1k | Automated safety check: Pass | CC-BY-SA-4.0 | 28 days ago |
| 239 | 239.Soe This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"… | infometa/ | 344 | — | ~2.3k | Automated safety check: Notes | No licence | today |
| 240 | Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38