~ / skills / security

security/

946 total · showing first 300
productivity 3,805software-engineering 2,099writing 1,172ai-agents 1,111security 946healthcare 712finance 467data-science 435marketing 344hr 334devops 289research 253product-design 193media 181legal 143education 89sales 76project-management 64ecommerce 48support 40manufacturing 38gaming 17

springboot-verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

Unverified229,684

songwriting-and-ai-music

Songwriting craft and Suno AI music prompts.

Unverified214,858

web-pentest

A phased pentesting workflow for running web applications. Adapted from

Unverified214,858

Command Development

This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter"…

Unverified137,847

cso

Chief Security Officer mode. (gstack)

Unverified121,828

security-and-hardening

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted…

Unverified78,200

security-research

security-research

Unverified65,773

security-audit

Security scanning and vulnerability detection.

Unverified64,394

agent-test-long-runner

Agent skill for test-long-runner - invoke with $agent-test-long-runner

Unverified64,394

harness-genome

7-section repo readiness report from `metaharness genome <path>`. Returns repo_type / agent_topology / risk_score / mcp_surface / test_confidence / publish_readiness. Pure-read…

Unverified64,394

harness-threat-model

Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings.…

Unverified64,394

V3 Security Overhaul

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3…

Unverified64,394

security-audit

Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

Unverified43,234

multi-agent-task-orchestrator

Route tasks to specialized AI agents with anti-duplication, quality gates, and 30-minute heartbeat monitoring

Unverified43,234

parallel-agents

Multi-agent orchestration patterns. Use when multiple independent tasks can run with different domain expertise or when comprehensive analysis requires multiple perspectives.

Unverified43,234

sast-configuration

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

Unverified43,234

supply-chain-risk-auditor

Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security…

Unverified43,234

variant-analysis

Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security…

Unverified43,234

laravel-security-audit

Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.

Unverified43,228

payment-integration

Integrate Stripe, PayPal, and payment processors. Handles checkout flows, subscriptions, webhooks, and PCI compliance. Use PROACTIVELY when implementing payments, billing, or…

Unverified43,228

red-team-tactics

Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.

Unverified43,228

vibers-code-review

Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.

Unverified43,228

web-security-testing

Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.

Unverified43,228

auth-implementation-patterns

Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.

Unverified43,191

anti-reversing-techniques

AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.

Unverified43,191

api-patterns

API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.

Unverified43,191

bdistill-behavioral-xray

X-ray any AI model's behavioral patterns — refusal boundaries, hallucination tendencies, reasoning style, formatting defaults. No API key needed.

Unverified43,191

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known…

Unverified43,191

dependency-management-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known…

Unverified43,191

find-bugs

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current…

Unverified43,191

security-scanning-security-dependencies

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to…

Unverified43,191

solidity-security

Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.

Unverified43,191

anti-reversing-techniques

Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when…

Unverified37,902

sast-configuration

Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing…

Unverified37,902

solidity-security

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing…

Unverified37,902

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

Unverified37,902

pci-compliance

Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or…

Unverified37,902

agent-owasp-compliance

Evaluate AI agent systems against the OWASP Agentic Security Initiative (ASI) Top 10 — the industry standard for agent security posture.

Unverified36,563

audit-integrity

Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards…

Unverified36,563

dependabot

Dependabot is GitHub's built-in dependency management tool with three core capabilities:

Unverified36,563

git-flow-branch-creator

Intelligent Git Flow branch creator that analyzes git status/diff and creates appropriate branches following the nvie Git Flow branching model.

Unverified36,563

github-actions-hardening

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters…

Unverified36,563

mcp-implementation-security-review

Check MCP protocol version 2025-03-26 or later (current: 2025-11-25). Flag older versions as a finding but continue the review.

Unverified36,563

security-review

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities…

Unverified36,563

sql-code-review

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server…

Unverified36,563

threat-model-analyst

Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. Supports two modes: (1) Single analysis — full STRIDE-A threat model of a…

Unverified36,563

command-development

This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter"…

Unverified32,122

security-review

Security-focused code review checklist for identifying vulnerabilities

Unverified26,169

building-automated-malware-submission-pipeline

'Builds an automated malware submission and analysis pipeline that collects

Unverified25,570

detecting-anomalous-authentication-patterns

'Detects anomalous authentication patterns using UEBA analytics, statistical

Unverified25,570

detecting-attacks-on-scada-systems

'This skill covers detecting cyber attacks targeting Supervisory Control

Unverified25,570

detecting-command-and-control-over-dns

'Detects command-and-control (C2) communications tunneled through DNS

Unverified25,570

detecting-living-off-the-land-attacks

'Detect abuse of legitimate Windows binaries (LOLBins) used for living

Unverified25,570

detecting-modbus-command-injection-attacks

'Detect command injection attacks against Modbus TCP/RTU protocol in

Unverified25,570

detecting-ntlm-relay-with-event-correlation

'Detect NTLM relay attacks through Windows Security Event correlation

Unverified25,570

detecting-serverless-function-injection

'Detects and prevents code injection attacks targeting serverless functions

Unverified25,570

detecting-stuxnet-style-attacks

'This skill covers detecting sophisticated cyber-physical attacks that

Unverified25,570

exploiting-api-injection-vulnerabilities

'Tests APIs for injection vulnerabilities including SQL injection, NoSQL

Unverified25,570

exploiting-jwt-algorithm-confusion-attack

'Exploits JWT algorithm confusion vulnerabilities where the server''s

Unverified25,570

hunting-for-dcom-lateral-movement

'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application,

Unverified25,570

implementing-api-rate-limiting-and-throttling

'Implements API rate limiting and throttling controls using token bucket,

Unverified25,570

implementing-hardware-security-key-authentication

'Implements FIDO2/WebAuthn hardware security key authentication including

Unverified25,570

implementing-hashicorp-vault-dynamic-secrets

'Implements HashiCorp Vault dynamic secrets engines for database credentials,

Unverified25,570

implementing-iec-62443-security-zones

'This skill covers designing and implementing security zones and conduits

Unverified25,570

implementing-network-segmentation-for-ot

'This skill covers implementing network segmentation in Operational Technology

Unverified25,570

monitoring-scada-modbus-traffic-anomalies

'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous

Unverified25,570

performing-api-rate-limiting-bypass

'Tests API rate limiting implementations for bypass vulnerabilities by

Unverified25,570

performing-graphql-introspection-attack

'Performs GraphQL introspection attacks to extract the full API schema

Unverified25,570

performing-malware-persistence-investigation

Systematically investigate all persistence mechanisms on Windows and

Unverified25,570

performing-ot-network-security-assessment

'This skill covers conducting comprehensive security assessments of Operational

Unverified25,570

performing-plc-firmware-security-analysis

'This skill covers analyzing Programmable Logic Controller (PLC) firmware

Unverified25,570

performing-purple-team-atomic-testing

'Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs

Unverified25,570

testing-websocket-api-security

'Tests WebSocket API implementations for security vulnerabilities including

Unverified25,570

abusing-dpapi-for-credential-access

Extract DPAPI-protected secrets such as credentials and browser data offline and online.

Unverified25,556

abusing-shadow-credentials-for-privesc

Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy…

Unverified25,556

achieving-cmmc-level-2-compliance

When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.

Unverified25,556

acquiring-disk-image-with-dd-and-dcfldd

Create forensically sound bit-for-bit disk images using dd and dcfldd

Unverified25,556

analyzing-active-directory-acl-abuse

Detect dangerous ACL misconfigurations in Active Directory using ldap3

Unverified25,556

analyzing-android-malware-with-apktool

Perform static analysis of Android APK malware samples using apktool

Unverified25,556

analyzing-api-gateway-access-logs

'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect

Unverified25,556

analyzing-apt-group-with-mitre-navigator

Analyze advanced persistent threat (APT) group techniques using MITRE

Unverified25,556

analyzing-azure-activity-logs-for-threats

'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query

Unverified25,556

analyzing-bootkit-and-rootkit-samples

'Analyzes bootkit and advanced rootkit malware that infects the Master

Unverified25,556

analyzing-browser-forensics-with-hindsight

Analyze Chromium-based browser artifacts using Hindsight to extract browsing

Unverified25,556

analyzing-campaign-attribution-evidence

Campaign attribution analysis involves systematically evaluating evidence

Unverified25,556

analyzing-certificate-transparency-for-phishing

Monitor Certificate Transparency logs using crt.sh and Certstream to

Unverified25,556

analyzing-cloud-storage-access-patterns

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage

Unverified25,556

analyzing-cobalt-strike-beacon-configuration

Extract and analyze Cobalt Strike beacon configuration from PE files

Unverified25,556

analyzing-cobaltstrike-malleable-c2-profiles

Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike

Unverified25,556

analyzing-command-and-control-communication

'Analyzes malware command-and-control (C2) communication protocols to

Unverified25,556

analyzing-cyber-kill-chain

'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain

Unverified25,556

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of disk images using Autopsy

Unverified25,556

analyzing-dns-logs-for-exfiltration

'Analyzes DNS query logs to detect data exfiltration via DNS tunneling,

Unverified25,556

analyzing-docker-container-forensics

Investigate compromised Docker containers by analyzing images, layers,

Unverified25,556

analyzing-email-headers-for-phishing-investigation

Parse and analyze email headers to trace the origin of phishing emails,

Unverified25,556

analyzing-golang-malware-with-ghidra

Reverse engineer Go-compiled malware using Ghidra with specialized scripts

Unverified25,556

analyzing-heap-spray-exploitation

Detect and analyze heap spray attacks in memory dumps using Volatility3

Unverified25,556

analyzing-indicators-of-compromise

'Analyzes indicators of compromise (IOCs) including IP addresses, domains,

Unverified25,556

analyzing-ios-app-security-with-objection

Use this skill when:

Unverified25,556

analyzing-kubernetes-audit-logs

'Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,

Unverified25,556

analyzing-linux-audit-logs-for-intrusion

'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities

Unverified25,556

analyzing-linux-elf-malware

'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries

Unverified25,556

analyzing-linux-kernel-rootkits

Detect kernel-level rootkits in Linux memory dumps using Volatility3

Unverified25,556

analyzing-linux-system-artifacts

Examine Linux system artifacts including auth logs, cron jobs, shell

Unverified25,556

analyzing-lnk-file-and-jump-list-artifacts

Analyze Windows LNK shortcut files and Jump List artifacts to establish

Unverified25,556

analyzing-macro-malware-in-office-documents

'Analyzes malicious VBA macros embedded in Microsoft Office documents

Unverified25,556

analyzing-malicious-pdf-with-peepdf

Perform static analysis of malicious PDF documents using peepdf, pdfid,

Unverified25,556

analyzing-malicious-url-with-urlscan

URLScan.io is a free service for scanning and analyzing suspicious URLs.

Unverified25,556

analyzing-malware-behavior-with-cuckoo-sandbox

'Executes malware samples in Cuckoo Sandbox to observe runtime behavior

Unverified25,556

analyzing-malware-family-relationships-with-malpedia

Use the Malpedia platform and API to research malware family relationships,

Unverified25,556

analyzing-malware-persistence-with-autoruns

Use Sysinternals Autoruns to systematically identify and analyze malware

Unverified25,556

analyzing-malware-sandbox-evasion-techniques

Detect sandbox evasion techniques in malware samples by analyzing timing

Unverified25,556

analyzing-memory-dumps-with-volatility

'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,

Unverified25,556

analyzing-memory-forensics-with-lime-and-volatility

'Performs Linux memory acquisition using LiME (Linux Memory Extractor)

Unverified25,556

analyzing-mft-for-deleted-file-recovery

Analyze the NTFS Master File Table ($MFT) to recover metadata and content

Unverified25,556

analyzing-network-covert-channels-in-malware

Detect and analyze covert communication channels used by malware including

Unverified25,556

analyzing-network-flow-data-with-netflow

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port

Unverified25,556

analyzing-network-packets-with-scapy

Craft, send, sniff, and dissect network packets using Scapy for protocol

Unverified25,556

analyzing-network-traffic-for-incidents

'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including

Unverified25,556

analyzing-network-traffic-of-malware

'Analyzes network traffic generated by malware during sandbox execution

Unverified25,556

analyzing-network-traffic-with-wireshark

'Captures and analyzes network packet data using Wireshark and tshark

Unverified25,556

analyzing-office365-audit-logs-for-compromise

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect

Unverified25,556

analyzing-outlook-pst-for-email-forensics

Analyze Microsoft Outlook PST and OST files for email forensic evidence

Unverified25,556

analyzing-packed-malware-with-upx-unpacker

'Identifies and unpacks UPX-packed and other packed malware samples to

Unverified25,556

analyzing-pdf-malware-with-pdfid

'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to

Unverified25,556

analyzing-persistence-mechanisms-in-linux

Detect and analyze Linux persistence mechanisms including crontab entries,

Unverified25,556

analyzing-powershell-empire-artifacts

Detect PowerShell Empire framework artifacts in Windows event logs by

Unverified25,556

analyzing-powershell-script-block-logging

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX

Unverified25,556

analyzing-prefetch-files-for-execution-history

Parse Windows Prefetch files to determine program execution history including

Unverified25,556

analyzing-ransomware-encryption-mechanisms

'Analyzes encryption algorithms, key management, and file encryption

Unverified25,556

analyzing-ransomware-leak-site-intelligence

Monitor and analyze ransomware group data leak sites (DLS) to track victim

Unverified25,556

analyzing-ransomware-network-indicators

Identify ransomware network indicators including C2 beaconing patterns,

Unverified25,556

analyzing-ransomware-payment-wallets

'Traces ransomware cryptocurrency payment flows using blockchain analysis

Unverified25,556

analyzing-sbom-for-supply-chain-vulnerabilities

'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON

Unverified25,556

analyzing-security-logs-with-splunk

'Leverages Splunk Enterprise Security and SPL (Search Processing Language)

Unverified25,556

analyzing-slack-space-and-file-system-artifacts

Examine file system slack space, MFT entries, USN journal, and alternate

Unverified25,556

analyzing-supply-chain-malware-artifacts

Investigate supply chain attack artifacts including trojanized software

Unverified25,556

analyzing-threat-actor-ttps-with-mitre-attack

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,

Unverified25,556

analyzing-threat-actor-ttps-with-mitre-navigator

'Map advanced persistent threat (APT) group tactics, techniques, and

Unverified25,556

analyzing-threat-intelligence-feeds

'Analyzes structured and unstructured threat intelligence feeds to extract

Unverified25,556

analyzing-threat-landscape-with-misp

Analyze the threat landscape using MISP (Malware Information Sharing

Unverified25,556

analyzing-tls-certificate-transparency-logs

'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect

Unverified25,556

analyzing-typosquatting-domains-with-dnstwist

Detect typosquatting, homograph phishing, and brand impersonation domains

Unverified25,556

analyzing-uefi-bootkit-persistence

'Analyzes UEFI bootkit persistence mechanisms including firmware implants

Unverified25,556

analyzing-usb-device-connection-history

Investigate USB device connection history from Windows registry, event

Unverified25,556

analyzing-web-server-logs-for-intrusion

Parse Apache and Nginx access logs to detect SQL injection attempts,

Unverified25,556

analyzing-windows-amcache-artifacts

'Parses and analyzes the Windows Amcache.hve registry hive to extract

Unverified25,556

analyzing-windows-event-logs-in-splunk

'Analyzes Windows Security, System, and Sysmon event logs in Splunk to

Unverified25,556

analyzing-windows-lnk-files-for-artifacts

Parse Windows LNK shortcut files to extract target paths, timestamps,

Unverified25,556

analyzing-windows-prefetch-with-python

Parse Windows Prefetch files using the windowsprefetch Python library

Unverified25,556

analyzing-windows-registry-for-artifacts

Extract and analyze Windows Registry hives to uncover user activity,

Unverified25,556

analyzing-windows-shellbag-artifacts

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing

Unverified25,556

assessing-vector-and-embedding-weaknesses

Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.

Unverified25,556

attacking-entra-id-with-roadtools

Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.

Unverified25,556

attacking-oauth-with-device-code-phishing

Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.

Unverified25,556

auditing-cloud-with-cis-benchmarks

'This skill details how to conduct cloud security audits using Center

Unverified25,556

auditing-entra-id-with-aadinternals

Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate…

Unverified25,556

auditing-foundry-smart-contract-security

Deployed smart contracts are immutable and custody real funds, so a bug

Unverified25,556

auditing-gcp-iam-permissions

'Auditing Google Cloud Platform IAM permissions to identify overly permissive

Unverified25,556

auditing-kubernetes-rbac-privilege-escalation

Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster…

Unverified25,556

auditing-mcp-servers-for-tool-poisoning

Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.

Unverified25,556

auditing-terraform-infrastructure-for-security

'Auditing Terraform infrastructure-as-code for security misconfigurations

Unverified25,556

auditing-uefi-firmware-with-chipsec

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI…

Unverified25,556

automating-ioc-enrichment

'Automates the enrichment of raw indicators of compromise with multi-source

Unverified25,556

benchmarking-kubernetes-with-kube-bench

Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.

Unverified25,556

building-adversary-infrastructure-tracking-system

Build an automated system to track adversary infrastructure using passive

Unverified25,556

building-attack-pattern-library-from-cti-reports

Extract and catalog attack patterns from cyber threat intelligence reports

Unverified25,556

building-c2-infrastructure-with-sliver-framework

Build and configure a resilient command-and-control infrastructure using

Unverified25,556

building-c2-redirector-infrastructure

Architect redirectors with nginx and Apache, malleable profiles, and OPSEC

Unverified25,556

building-detection-rule-with-splunk-spl

Build effective detection rules using Splunk Search Processing Language

Unverified25,556

building-detection-rules-with-sigma

'Builds vendor-agnostic detection rules using the Sigma rule format for

Unverified25,556

building-devsecops-pipeline-with-gitlab-ci

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD

Unverified25,556

building-identity-federation-with-saml-azure-ad

Establish SAML 2.0 identity federation between on-premises Active Directory

Unverified25,556

building-incident-timeline-with-timesketch

Build collaborative forensic incident timelines using Timesketch to ingest,

Unverified25,556

building-ioc-defanging-and-sharing-pipeline

Build an automated pipeline to defang indicators of compromise (URLs,

Unverified25,556

building-ioc-enrichment-pipeline-with-opencti

OpenCTI is an open-source platform for managing cyber threat intelligence

Unverified25,556

building-patch-tuesday-response-process

Establish a structured operational process to triage, test, and deploy

Unverified25,556

building-phishing-reporting-button-workflow

Implement a phishing report button in email clients with automated triage

Unverified25,556

building-red-team-c2-infrastructure-with-havoc

Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,

Unverified25,556

building-role-mining-for-rbac-optimization

Apply bottom-up and top-down role mining techniques to discover optimal

Unverified25,556

building-soc-escalation-matrix

Build a structured SOC escalation matrix defining severity tiers, response

Unverified25,556

building-soc-playbook-for-ransomware

'Builds a structured SOC incident response playbook for ransomware attacks

Unverified25,556

building-super-timelines-with-plaso

Generate log2timeline and Plaso super-timelines and triage them in Timesketch.

Unverified25,556

building-threat-feed-aggregation-with-misp

Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate,

Unverified25,556

building-threat-hunt-hypothesis-framework

Build a systematic threat hunt hypothesis framework that transforms threat

Unverified25,556

building-threat-intelligence-enrichment-in-splunk

Build automated threat intelligence enrichment pipelines in Splunk Enterprise

Unverified25,556

building-threat-intelligence-feed-integration

'Builds automated threat intelligence feed integration pipelines connecting

Unverified25,556

building-threat-intelligence-platform

Building a Threat Intelligence Platform (TIP) involves deploying and

Unverified25,556

building-vulnerability-aging-and-sla-tracking

Implement a vulnerability aging dashboard and SLA tracking system to

Unverified25,556

building-vulnerability-exception-tracking-system

Build a vulnerability exception and risk acceptance tracking system with

Unverified25,556

building-vulnerability-scanning-workflow

'Builds a structured vulnerability scanning workflow using tools like

Unverified25,556

bypassing-authentication-with-forced-browsing

Discovering and accessing unprotected pages, APIs, and administrative

Unverified25,556

coercing-authentication-with-coercer-petitpotam

Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other…

Unverified25,556

collecting-indicators-of-compromise

'Systematically collects, categorizes, and distributes indicators of

Unverified25,556

collecting-open-source-intelligence

'Collects and synthesizes open-source intelligence (OSINT) about threat

Unverified25,556

conducting-cloud-incident-response

'Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,

Unverified25,556

conducting-cloud-penetration-testing

'This skill outlines methodologies for performing authorized penetration

Unverified25,556

conducting-domain-persistence-with-dcsync

Perform DCSync attacks to replicate Active Directory credentials and

Unverified25,556

conducting-full-scope-red-team-engagement

Plan and execute a comprehensive red team engagement covering reconnaissance

Unverified25,556

conducting-internal-network-penetration-test

Execute an internal network penetration test simulating an insider threat

Unverified25,556

conducting-internal-reconnaissance-with-bloodhound-ce

Conduct internal Active Directory reconnaissance using BloodHound Community

Unverified25,556

conducting-man-in-the-middle-attack-simulation

'Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap

Unverified25,556

conducting-memory-forensics-with-volatility

'Performs memory forensics analysis using Volatility 3 to extract evidence

Unverified25,556

conducting-pass-the-ticket-attack

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen

Unverified25,556

conducting-phishing-incident-response

'Responds to phishing incidents by analyzing reported emails, extracting

Unverified25,556

conducting-post-incident-lessons-learned

Facilitate structured post-incident reviews to identify root causes,

Unverified25,556

conducting-social-engineering-pretext-call

Plan and execute authorized vishing (voice phishing) pretext calls to

Unverified25,556

conducting-spearphishing-simulation-campaign

Spearphishing simulation is a targeted social engineering attack vector

Unverified25,556

conducting-wireless-network-penetration-test

'Conducts authorized wireless network penetration tests to assess the

Unverified25,556

configuring-active-directory-tiered-model

Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered

Unverified25,556

configuring-aws-verified-access-for-ztna

Configure AWS Verified Access to provide VPN-less zero trust network

Unverified25,556

configuring-certificate-authority-with-openssl

A Certificate Authority (CA) is the trust anchor in a PKI hierarchy,

Unverified25,556

configuring-host-based-intrusion-detection

'Configures host-based intrusion detection systems (HIDS) to monitor

Unverified25,556

configuring-identity-aware-proxy-with-google-iap

'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request

Unverified25,556

configuring-ldap-security-hardening

Harden LDAP directory services against common attacks including credential

Unverified25,556

configuring-microsegmentation-for-zero-trust

Configure microsegmentation policies to enforce least-privilege workload-to-workload

Unverified25,556

configuring-multi-factor-authentication-with-duo

Deploy Cisco Duo multi-factor authentication across enterprise applications,

Unverified25,556

configuring-oauth2-authorization-flow

Configure secure OAuth 2.0 authorization flows including Authorization

Unverified25,556

configuring-pfsense-firewall-rules

'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic

Unverified25,556

configuring-snort-ids-for-intrusion-detection

'Installs, configures, and tunes Snort 3 intrusion detection system to

Unverified25,556

configuring-suricata-for-network-monitoring

'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets,

Unverified25,556

configuring-tls-1-3-for-secure-communications

TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security

Unverified25,556

configuring-windows-defender-advanced-settings

'Configures Microsoft Defender for Endpoint (MDE) advanced protection

Unverified25,556

configuring-windows-event-logging-for-detection

'Configures Windows Event Logging with advanced audit policies to generate

Unverified25,556

configuring-zscaler-private-access-for-ztna

'Configuring Zscaler Private Access (ZPA) to replace traditional VPN

Unverified25,556

correlating-threat-campaigns

'Correlates disparate security incidents, IOCs, and adversary behaviors

Unverified25,556

defending-llms-with-guardrails

Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.

Unverified25,556

deobfuscating-javascript-malware

'Deobfuscates malicious JavaScript code used in web-based attacks, phishing

Unverified25,556

deobfuscating-powershell-obfuscated-malware

Systematically deobfuscate multi-layer PowerShell malware using AST analysis,

Unverified25,556

deploying-active-directory-honeytokens

'Deploys deception-based honeytokens in Active Directory including fake

Unverified25,556

deploying-cloud-deception-with-decoy-resources

When cloud accounts (AWS/Azure/GCP) hold crown-jewel data or infrastructure and you need a tripwire that fires the moment an attacker who has gained access starts to operate.

Unverified25,556

deploying-cloudflare-access-for-zero-trust

'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust

Unverified25,556

deploying-honeytokens-and-canarytokens

Plant canarytokens and honey credentials and alert on breach.

Unverified25,556

deploying-osquery-for-endpoint-monitoring

'Deploys and configures osquery for real-time endpoint monitoring using

Unverified25,556

deploying-palo-alto-prisma-access-zero-trust

'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust

Unverified25,556

deploying-software-defined-perimeter

Deploy a Software-Defined Perimeter using the CSA v2.0 specification

Unverified25,556

deploying-tailscale-for-zero-trust-vpn

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN

Unverified25,556

designing-adversary-engagement-with-mitre-engage

When an organization owns deception tooling (honeypots, honeytokens, canary tokens, decoy files) but deploys it tactically with no unifying strategy or measurable outcome.

Unverified25,556

detecting-ai-model-prompt-injection-attacks

'Detects prompt injection attacks targeting LLM-based applications using

Unverified25,556

detecting-anomalies-in-industrial-control-systems

'This skill covers deploying anomaly detection systems for industrial

Unverified25,556

detecting-api-enumeration-attacks

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation

Unverified25,556

detecting-arp-poisoning-in-network-traffic

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection,

Unverified25,556

detecting-attacks-on-historian-servers

'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,

Unverified25,556

detecting-aws-cloudtrail-anomalies

Detect unusual API call patterns in AWS CloudTrail logs using boto3,

Unverified25,556

detecting-aws-guardduty-findings-automation

Automate AWS GuardDuty threat detection findings processing using EventBridge

Unverified25,556

detecting-aws-iam-privilege-escalation

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining

Unverified25,556

detecting-azure-lateral-movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft

Unverified25,556

detecting-azure-service-principal-abuse

Detect and investigate Azure service principal abuse including privilege

Unverified25,556

detecting-azure-storage-account-misconfigurations

Audit Azure Blob and ADLS storage accounts for public access exposure,

Unverified25,556

detecting-beaconing-patterns-with-zeek

'Performs statistical analysis of Zeek conn.log connection intervals

Unverified25,556

detecting-broken-object-property-level-authorization

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization

Unverified25,556

detecting-business-email-compromise-with-ai

Deploy AI and NLP-powered detection systems to identify business email

Unverified25,556

detecting-cloud-threats-with-guardduty

'This skill teaches security teams how to deploy and operationalize Amazon

Unverified25,556

detecting-compromised-cloud-credentials

'Detecting compromised cloud credentials across AWS, Azure, and GCP by

Unverified25,556

detecting-container-drift-at-runtime

Detect unauthorized modifications to running containers by monitoring

Unverified25,556

detecting-container-escape-attempts

Container escape is a critical attack technique where an adversary breaks

Unverified25,556

detecting-container-escape-with-falco-rules

Detect container escape attempts in real-time using Falco runtime security

Unverified25,556

detecting-container-runtime-threats-with-falco

Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.

Unverified25,556

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit

Unverified25,556

detecting-cryptomining-in-cloud

'This skill teaches security teams how to detect and respond to unauthorized

Unverified25,556

detecting-data-and-model-poisoning

Identify poisoned training data and backdoored models across the ML pipeline.

Unverified25,556

detecting-dcsync-attack-in-active-directory

Detect DCSync attacks where adversaries abuse Active Directory replication

Unverified25,556

detecting-deepfake-audio-in-vishing-attacks

'Detects AI-generated deepfake audio used in voice phishing (vishing)

Unverified25,556

detecting-dll-sideloading-attacks

Detect DLL side-loading attacks where adversaries place malicious DLLs

Unverified25,556

detecting-dnp3-protocol-anomalies

'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications

Unverified25,556

detecting-dns-exfiltration-with-dns-query-analysis

Detect data exfiltration through DNS tunneling by analyzing query entropy,

Unverified25,556

detecting-email-forwarding-rules-attack

Detect malicious email forwarding rules created by adversaries to maintain

Unverified25,556

detecting-entra-offensive-tools-in-graph-logs

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and…

Unverified25,556

detecting-evasion-techniques-in-endpoint-logs

'Detects defense evasion techniques used by adversaries in endpoint logs

Unverified25,556

detecting-exfiltration-over-dns-with-zeek

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy

Unverified25,556

detecting-fileless-attacks-on-endpoints

'Detects fileless malware and in-memory attacks that execute entirely

Unverified25,556

detecting-fileless-malware-techniques

'Detects and analyzes fileless malware that operates entirely in memory

Unverified25,556

detecting-golden-ticket-attacks-in-kerberos-logs

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos

Unverified25,556

detecting-golden-ticket-forgery

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769

Unverified25,556

detecting-indirect-prompt-injection

Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.

Unverified25,556

detecting-insider-data-exfiltration-via-dlp

'Detects insider data exfiltration by analyzing DLP policy violations,

Unverified25,556

detecting-insider-threat-with-ueba

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch

Unverified25,556

detecting-kerberoasting-attacks

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS

Unverified25,556

detecting-lateral-movement-in-network

'Identifies lateral movement techniques in enterprise networks by analyzing

Unverified25,556

detecting-lateral-movement-with-splunk

Detect adversary lateral movement across networks using Splunk SPL queries

Unverified25,556

detecting-lateral-movement-with-zeek

'Detect lateral movement in network traffic using Zeek (formerly Bro)

Unverified25,556

detecting-living-off-the-land-with-lolbas

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including

Unverified25,556

detecting-malicious-scheduled-tasks-with-sysmon

'Detect malicious scheduled task creation and modification using Sysmon

Unverified25,556

detecting-mimikatz-execution-patterns

Detect Mimikatz execution through command-line patterns, LSASS access

Unverified25,556

detecting-mobile-malware-behavior

'Detects and analyzes malicious behavior in mobile applications through

Unverified25,556

detecting-modbus-protocol-anomalies

'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications

Unverified25,556

detecting-network-anomalies-with-zeek

'Deploys and configures Zeek (formerly Bro) network security monitor

Unverified25,556

detecting-network-scanning-with-ids-signatures

Detect network reconnaissance and port scanning using Suricata and Snort

Unverified25,556

detecting-oauth-token-theft

'Detects and responds to OAuth token theft and replay attacks in cloud

Unverified25,556

detecting-pass-the-hash-attacks

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns,

Unverified25,556

detecting-pass-the-ticket-attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event

Unverified25,556

detecting-port-scanning-with-fail2ban

'Configures Fail2ban with custom filters and actions to detect port scanning

Unverified25,556

detecting-privilege-escalation-attempts

Detect privilege escalation attempts including token manipulation, UAC

Unverified25,556

detecting-privilege-escalation-in-kubernetes-pods

Detect and prevent privilege escalation in Kubernetes pods by monitoring

Unverified25,556

detecting-process-hollowing-technique

Detect process hollowing (T1055.012) by analyzing memory-mapped sections,

Unverified25,556

detecting-process-injection-techniques

'Detects and analyzes process injection techniques used by malware including

Unverified25,556

detecting-qr-code-phishing-with-email-security

Detect and prevent QR code phishing (quishing) attacks that bypass traditional

Unverified25,556

detecting-ransomware-encryption-behavior

'Detects ransomware encryption activity in real time using entropy analysis,

Unverified25,556

detecting-ransomware-precursors-in-network

'Detects early-stage ransomware indicators in network traffic before

Unverified25,556

detecting-rdp-brute-force-attacks

Detect RDP brute force attacks by analyzing Windows Security Event Logs

Unverified25,556