Browse Skills
11972 skills across 8 categories
🛡️
4w ago
Add New Skill
Add New Skill provides a structured template for creating cybersecurity-focused Claude Code skills aligned with MITRE ATT&CK and NIST CSF. Use it when documenting a new security capability for the agent.
AI Engineering
27.8K3.4K
🛡️
4w ago
Analyzing Active Directory ACL Abuse
Analyzing Active Directory ACL Abuse connects to a domain controller via ldap3 to parse security descriptors and detect dangerous ACL misconfigurations that enable attacks like privilege escalation.
DevOps
27.8K3.4K
🔍
4w ago
Analyzing Android Malware with Apktool
Analyzing Android Malware with Apktool performs static analysis of Android APK files using apktool, jadx, and androguard to extract permissions, detect dangerous permission combinations, and identify suspicious API calls without executing the sample. Use it to triage a suspicious APK or build mobile malware detection rules.
Quality
27.8K3.4K
🛡️
4w ago
Analyzing APT Group with MITRE Navigator
Analyzing APT Group with MITRE Navigator queries ATT&CK data with attackcti, mitreattack-python, and stix2, then builds Navigator layers and heatmap overlays to compare APT group TTPs, identify detection gaps, and report threat intelligence.
Data
27.8K3.4K
🔐
4w ago
Analyzing Cloud Storage Access Patterns
Analyzing Cloud Storage Access Patterns detects abnormal access in AWS S3, GCS, and Azure Blob Storage via audit logs for after-hours bulk downloads, new-IP access, and API-call spikes. Use when investigating suspected cloud data exfiltration or building detection rules
Data
27.8K3.4K
🛡️
4w ago
Analyzing Cobalt Strike Malleable C2 Profiles
Analyzing Cobalt Strike Malleable C2 Profiles extracts HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior from profile files and beacon payloads, then generates network detection signatures. Use when reverse-engineering profiles or building Beacon detections.
Data
27.8K3.4K
🔍
4w ago
Analyzing Cyber Kill Chain
Analyzing Cyber Kill Chain maps observed adversary actions to the seven Lockheed Martin Cyber Kill Chain phases, identifies detection gaps, and recommends courses of action. Use it for post-incident analysis, layered defensive control design, and threat intelligence reporting.
Data
27.8K3.4K
🔍
4w ago
Analyzing Disk Image with Autopsy
Analyzing Disk Image with Autopsy performs comprehensive forensic analysis of raw, E01, or AFF disk images using Autopsy and The Sleuth Kit to recover deleted files, examine metadata and embedded artifacts, search keywords, and build timelines. Use it when you need structured analysis or visual reports from forensic evidence.
Data
27.8K3.4K
🔍
4w ago
Analyzing DNS Logs for Exfiltration
Analyzing DNS Logs for Exfiltration detects data exfiltration via DNS tunneling by analyzing query logs for long subdomains, high entropy, anomalous query volumes, and known tunneling tools.
Data
27.8K3.4K
🛡️
4w ago
API Gateway Log Analysis
API Gateway Log Analysis parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect attack patterns such as BOLA, excessive data exposure, and injection attempts. Use it when investigating security incidents or building detection rules.
Data
27.8K3.4K
🛡️
4w ago
Azure Activity Log Threat Analysis
Azure Activity Log Threat Analysis queries Azure Monitor activity logs and sign-in logs via the azure-monitor-query Python library to detect suspicious admin operations and sign-in anomalies. Use it when investigating security incidents or building threat hunting queries for Azure environments.
DevOps
27.8K3.4K
🔍
4w ago
Bootkit and Rootkit Analysis
Bootkit and Rootkit Analysis analyzes bootkits and advanced rootkits infecting MBR, VBR, and UEFI firmware. Use it when investigating persistent firmware-level threats that survive OS reinstallation, performing boot sector acquisition, firmware analysis, memory forensics, and boot chain integrity verification.
Quality
27.8K3.4K