Loading...
Loading...
Found 5212 skills
dandye
Automates end-to-end security alert triage including duplicate checks, IOC enrichment, and classification for false positives, benign true positives, true positives, and suspicious alerts.
dandye
Automates security alert triage by assessing ALERT_ID/CASE_ID, enriching IOCs, and determining if an alert is a false positive or requires escalation.
dandye
Conducts comprehensive threat investigation on critical IOCs with GTI pivoting, deep SIEM analysis, and threat attribution for Tier 2+ security incidents.
dandye
Correlates indicators of compromise (IOCs) with existing SIEM alerts and SOAR cases to provide context on past incidents and ongoing investigations.
dandye
Orchestrates ransomware incident response via PICERL methodology, covering identification, containment, eradication, and recovery phases.
dandye
Adds security investigation findings, actions, and recommendations to SOAR cases to maintain audit trails during incident response.
dandye
Investigates and contains account compromise incidents, removes malicious persistence, and restores legitimate access.
dandye
Automates phishing incident response via PICERL methodology, analyzing artifacts, identifying compromised users, containing IOCs, and removing malicious emails.
dandye
Analyzes suspicious login alerts including impossible travel and untrusted locations by evaluating user history, IP reputation, and login patterns to determine escalation needs.
dandye
Explores Global Threat Intelligence (GTI) relationships for an Indicator of Compromise (IOC) to discover connected entities like domains, IPs, and threat actors, expanding security investigations.
dandye
Searches SIEM for behavioral indicators of credential harvesting using MITRE ATT&CK techniques.
dandye
Proactively detects lateral movement threats using PsExec, WMI, and remote process execution indicators in network environments.
dandye
Automates malware incident response using PICERL methodology, orchestrating triage, containment, eradication, and recovery for endpoint security incidents.
dandye
Systematically searches SIEM for IOCs (IPs, domains, hashes, URLs) from threat intel, providing enrichment and documentation.
dandye
Conducts hypothesis-driven threat hunting using threat intelligence, TTPs, and anomaly detection for Tier 3 security analysts, supporting iterative search and documentation.
dandye
Generates timestamped markdown reports for security investigation findings, saving them to the ./reports/ directory for permanent record-keeping.
ryuichi1208
Reviews API security against OWASP Top 10 and Rust best practices, detecting vulnerabilities in authentication, authorization, and code audits.
HacktronAI
Exploits parser discrepancies between Coraza WAF (Go) and Next.js 16 backend (Node.js) to bypass web application firewall protections.
HacktronAI
Analyzes compiled binaries (JARs, DLLs) to compare versions, identify security fixes, and evaluate patch content for vulnerability assessment.
HacktronAI
Automates solving cybersecurity Capture The Flag challenges by analyzing code and environments to extract flags.
TheBeardedBearSAS
Assists in security code reviews, authentication implementation, and code hardening to enhance application security.
Afaneor
Scans code for exposed secrets like API keys and passwords to prevent accidental commits to version control.
danthegoodman1
Performs data and system integrity verification to detect unauthorized modifications and ensure security compliance.
DmitrL-dev
Audits AI agent security against the OWASP Agentic Top 10 2026 framework to identify and mitigate vulnerabilities.