Incident Response skills
Free incident response skills for AI coding agents, part of our security & compliance collection.
230 skills
Honeypot for Ransomware Detection
mukul975
Detect ransomware early with canary files and honeypots.
Deobfuscating PowerShell Malware
mukul975
Reveal hidden payloads in obfuscated PowerShell scripts.
Deploying Honeytokens and Canarytokens
mukul975
Enhance intrusion detection with decoy artifacts.
Analyzing Cobalt Strike Beacon Configuration
mukul975
Extract and analyze Cobalt Strike beacon configurations efficiently.
Hunting Bootkits in EFI
mukul975
Detect and analyze UEFI bootkits on your systems.
Implementing Ransomware Backup Strategy
mukul975
Create a resilient backup strategy against ransomware attacks.
Hunting SaaS SSO Token Abuse
mukul975
Detect and mitigate token replay attacks in SaaS environments.
Analyzing LNK Files
mukul975
Extract and analyze Windows LNK and Jump List artifacts.
Detecting Entra Offensive Tools
mukul975
Identify malicious activity in Microsoft Graph logs.
Detecting Container Escape Attempts
mukul975
Monitor and detect container escape attempts effectively.
Analyzing Browser Forensics
mukul975
Extract and correlate browser data for investigations.
Threat Intelligence Enrichment
mukul975
Automate IOC enrichment in Splunk for enhanced security.
Operationalizing MISP Threat Feeds
mukul975
Enhance threat detection with curated MISP feeds.
Detecting Container Escape with Falco Rules
mukul975
Monitor Linux syscalls to detect container escape attempts in real time.
Building Threat Intelligence Platform
mukul975
Integrate open-source CTI tools for threat intelligence.
Malware Incident Communication Template
mukul975
Streamline your malware incident communications with structured templates.
Analyzing Threat Actor TTPs
mukul975
Map threat actor behavior to the MITRE ATT&CK framework.
Collecting Volatile Evidence
mukul975
Capture critical data from compromised hosts before it's lost.
Detecting Evasion Techniques
mukul975
Identify adversary evasion tactics in endpoint logs.
Building Incident Timeline with Timesketch
mukul975
Collaboratively analyze forensic timelines for incident investigations.
Analyzing Campaign Attribution Evidence
mukul975
Systematically evaluate cyber-campaign evidence for attribution.
Analyzing Windows Shellbag Artifacts
mukul975
Reconstruct folder access history from Windows registry.
Implementing Velociraptor for IR Collection
mukul975
Streamline endpoint forensic artifact collection for incident response.
Detecting Privilege Escalation in Kubernetes Pods
mukul975
Enhance Kubernetes security by detecting privilege escalation risks.
