Cybersecurity

Cybersecurity taxonomy generated by the site skill importer.

46 skills
C
virustotal-automation

by ComposioHQ

virustotal-automation helps Claude run VirusTotal workflows through Composio Rube MCP by discovering current tools, checking the connection, and using live schemas for IOC enrichment.

Threat Intelligence
Favorites 0GitHub 67.5k
A
information-security-manager-iso27001

by alirezarezvani

The information-security-manager-iso27001 skill helps AI agents perform ISO 27001:2022 ISMS work for HealthTech, MedTech, and regulated software teams. Use it for risk assessment, Annex A control mapping, compliance review, evidence checklists, incident response planning, and audit gap analysis with included references and scripts.

Compliance Review
Favorites 0GitHub 22.2k
A
senior-security

by alirezarezvani

senior-security helps AI agents run STRIDE/DREAD threat modeling, analyze DFDs, prioritize mitigations, and perform quick secret scans with included scripts and references. Best for architecture reviews where broad security requests need routing to the right specialist skill.

Threat Modeling
Favorites 0GitHub 22.1k
A
iso27001-audit-prep

by alirezarezvani

iso27001-audit-prep is a focused ISO 27001 ISMS audit readiness skill. It uses six forcing questions to pressure-test scope, risk register freshness, Annex A linkage, management review, corrective actions, and sample-ready evidence before internal, certification, or surveillance audits.

Compliance Review
Favorites 0GitHub 22.1k
A
ciso-advisor

by alirezarezvani

ciso-advisor helps AI agents and security leaders turn risk, compliance, incidents, and board reporting into CISO-level decisions. Includes guidance for Security Strategy, SOC 2/ISO 27001/HIPAA/GDPR roadmaps, executive incident response, plus Python tools for risk quantification and compliance tracking.

Security Strategy
Favorites 0GitHub 22.1k
A
ciso-review

by alirezarezvani

ciso-review is a CISO-style Security Audit prompt for plans involving customer data, compliance, vendors, trust boundaries, or production access. It uses six forcing questions—threat model, blast radius, detection, response, regulatory exposure, and ship/no-ship risk—to turn a plan into blockers, mitigations, and launch guidance.

Security Audit
Favorites 0GitHub 22.1k
M
detecting-shadow-it-cloud-usage

by mukul975

detecting-shadow-it-cloud-usage helps identify unauthorized SaaS and cloud usage from proxy logs, DNS queries, and netflow. It classifies domains, compares them with approved lists, and supports security audit workflows with structured evidence from the detecting-shadow-it-cloud-usage skill guide.

Security Audit
Favorites 0GitHub 6.2k
M
detecting-network-anomalies-with-zeek

by mukul975

The detecting-network-anomalies-with-zeek skill helps deploy Zeek for passive network monitoring, review structured logs, and build custom detections for beaconing, DNS tunneling, and unusual protocol activity. It is suited for threat hunting, incident response, SIEM-ready network metadata, and Security Audit workflows—not inline prevention.

Security Audit
Favorites 0GitHub 6.1k
M
detecting-beaconing-patterns-with-zeek

by mukul975

detecting-beaconing-patterns-with-zeek helps analyze Zeek conn.log intervals to detect C2-style beaconing. It uses ZAT, groups flows by source, destination, and port, and scores low-jitter patterns with statistical checks. Ideal for SOC, threat hunting, incident response, and detecting-beaconing-patterns-with-zeek for Security Audit workflows.

Security Audit
Favorites 0GitHub 6.1k
M
building-patch-tuesday-response-process

by mukul975

building-patch-tuesday-response-process helps teams build a repeatable Microsoft Patch Tuesday process to triage advisories, rank risk, test patches, approve rollout, and track compliance. Useful for security operations, vulnerability management, and building-patch-tuesday-response-process for Project Management.

Project Management
Favorites 0GitHub 6.1k
M
analyzing-supply-chain-malware-artifacts

by mukul975

analyzing-supply-chain-malware-artifacts is a malware-analysis skill for tracing trojanized updates, poisoned dependencies, and build-pipeline tampering. Use it to compare trusted and untrusted artifacts, extract indicators, assess compromise scope, and report findings with less guesswork.

Malware Analysis
Favorites 0GitHub 6.1k
M
generating-threat-intelligence-reports

by mukul975

The generating-threat-intelligence-reports skill turns analyzed cyber data into strategic, operational, tactical, or flash threat intelligence reports for executives, SOC teams, IR leads, and analysts. It supports finished intelligence, confidence language, TLP handling, and clear recommendations for Report Writing.

Report Writing
Favorites 0GitHub 0
M
evaluating-threat-intelligence-platforms

by mukul975

evaluating-threat-intelligence-platforms helps you compare TIP products by feed ingestion, STIX/TAXII support, automation, analyst workflow, integrations, and total cost of ownership. Use this evaluating-threat-intelligence-platforms guide for procurement, migration, or maturity planning, including evaluating-threat-intelligence-platforms for Threat Modeling when platform choice affects traceability and evidence sharing.

Threat Modeling
Favorites 0GitHub 0
M
detecting-living-off-the-land-with-lolbas

by mukul975

detecting-living-off-the-land-with-lolbas helps detect LOLBAS abuse with Sysmon and Windows Event Logs, using process telemetry, parent-child context, Sigma rules, and a practical guide for triage, hunting, and rule drafting. It supports detecting-living-off-the-land-with-lolbas for Threat Modeling and analyst workflows with certutil, regsvr32, mshta, and rundll32.

Threat Modeling
Favorites 0GitHub 0
M
detecting-living-off-the-land-attacks

by mukul975

detecting-living-off-the-land-attacks skill for Security Audit, threat hunting, and incident response. Detect abuse of legitimate Windows binaries like certutil, mshta, rundll32, and regsvr32 using process creation, command-line, and parent-child telemetry. The guide focuses on actionable LOLBin detection patterns, not broad Windows hardening.

Security Audit
Favorites 0GitHub 0
M
detecting-lateral-movement-in-network

by mukul975

detecting-lateral-movement-in-network helps detect post-compromise lateral movement in enterprise networks using Windows event logs, Zeek telemetry, SMB, RDP, and SIEM correlation. It is useful for threat hunting, incident response, and detecting-lateral-movement-in-network for Security Audit reviews with practical detection workflows.

Security Audit
Favorites 0GitHub 0
M
detecting-golden-ticket-forgery

by mukul975

detecting-golden-ticket-forgery detects Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769, RC4 downgrade use (0x17), abnormal ticket lifetimes, and krbtgt anomalies in Splunk and Elastic. Built for Security Audit, incident investigation, and threat hunting with practical detection guidance.

Security Audit
Favorites 0GitHub 0
M
detecting-dll-sideloading-attacks

by mukul975

detecting-dll-sideloading-attacks helps Security Audit, threat hunting, and incident response teams detect DLL side-loading with Sysmon, EDR, MDE, and Splunk. This detecting-dll-sideloading-attacks guide includes workflow notes, hunt templates, standards mapping, and scripts to turn suspicious DLL loads into repeatable detections.

Security Audit
Favorites 0GitHub 0
M
detecting-deepfake-audio-in-vishing-attacks

by mukul975

detecting-deepfake-audio-in-vishing-attacks helps security teams analyze audio for AI-generated speech in vishing, fraud, and impersonation cases. It extracts spectral and MFCC-based features, scores suspicious samples, and produces a forensic-style report for review. Ideal for Security Audit and incident response workflows.

Security Audit
Favorites 0GitHub 0
M
detecting-credential-dumping-techniques

by mukul975

The detecting-credential-dumping-techniques skill helps you detect LSASS access, SAM export, NTDS.dit theft, and comsvcs.dll MiniDump abuse using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules. It is built for threat hunting, detection engineering, and Security Audit workflows.

Security Audit
Favorites 0GitHub 0
M
detecting-attacks-on-historian-servers

by mukul975

detecting-attacks-on-historian-servers helps detect suspicious activity on OT historian servers like OSIsoft PI, Ignition, and Wonderware at the IT/OT boundary. Use this detecting-attacks-on-historian-servers guide for Incident Response, unauthorized queries, data manipulation, API abuse, and lateral-movement triage.

Incident Response
Favorites 0GitHub 0
M
detecting-api-enumeration-attacks

by mukul975

detecting-api-enumeration-attacks helps Security Audit teams detect API probing, BOLA, and IDOR by analyzing sequential IDs, 404 bursts, authorization failures, and docs discovery paths. It is built for log-driven detection guidance, rule drafting, and practical review of API abuse patterns.

Security Audit
Favorites 0GitHub 0
M
correlating-threat-campaigns

by mukul975

correlating-threat-campaigns helps Threat Intelligence analysts correlate incidents, IOCs, and TTPs into campaign-level evidence. Use it to compare historical events, separate strong links from weak matches, and build defensible clustering for MISP, SIEM, and CTI reporting.

Threat Intelligence
Favorites 0GitHub 0
M
configuring-pfsense-firewall-rules

by mukul975

The configuring-pfsense-firewall-rules skill helps you design pfSense rules for segmentation, NAT, VPN access, and traffic shaping. Use it to create or audit firewall policy for LAN, DMZ, guest, and IoT zones, with practical guidance for install, usage, and Security Audit workflows.

Security Audit
Favorites 0GitHub 0