New to Claude Skills? Learn how to install them →

Incident Response skills

Free incident response skills for AI coding agents, part of our security & compliance collection.

Asset Criticality Scoring for Vulns

mukul975

Prioritize vulnerabilities based on asset criticality.

Security & ComplianceintermediatePython27.6k repo

Performing Alert Triage with Elastic SIEM

mukul975

Streamline alert triage processes in Elastic Security.

Security & ComplianceintermediatePython27.6k repo

Active Directory Vulnerability Assessment

mukul975

Secure your Active Directory with comprehensive assessments.

Security & ComplianceintermediatePython · Shell27.6k repo

Active Directory Investigation

mukul975

Streamline your Active Directory compromise investigations.

Security & ComplianceintermediatePython27.6k repo

Parsing Artifacts with Eric Zimmerman Tools

mukul975

Efficiently parse Windows forensic artifacts for analysis.

Security & ComplianceintermediatePython27.6k repo

Operationalizing MISP Threat Feeds

mukul975

Enhance threat detection with curated MISP feeds.

Security & ComplianceintermediatePython · Shell27.6k repo

Implementing Velociraptor for IR Collection

mukul975

Streamline endpoint forensic artifact collection for incident response.

Security & ComplianceintermediatePython · Shell27.6k repo
I

Implementing SOAR Playbook with Palo Alto XSOAR

mukul975

Automate incident response with Cortex XSOAR playbooks.

Security & ComplianceintermediatePython27.6k repo

Implementing Ransomware Backup Strategy

mukul975

Create a resilient backup strategy against ransomware attacks.

Security & ComplianceintermediatePython · Shell27.6k repo

Honeypot for Ransomware Detection

mukul975

Detect ransomware early with canary files and honeypots.

Security & ComplianceintermediatePython · Shell27.6k repo

Implementing EPSS Score

mukul975

Prioritize vulnerabilities using real-world exploitation data.

Security & ComplianceintermediatePython · Shell27.6k repo

Diamond Model Analysis

mukul975

Analyze cyber intrusions using the Diamond Model framework.

Security & ComplianceintermediatePython27.6k repo

Hunting SaaS SSO Token Abuse

mukul975

Detect and mitigate token replay attacks in SaaS environments.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting for Suspicious Scheduled Tasks

mukul975

Identify and analyze potential persistence threats in Windows.

Security & ComplianceintermediatePython27.6k repo

Hunting for LOLBins Execution

mukul975

Detect and analyze LOLBins in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Hunting for Living-off-the-Land Binaries

mukul975

Proactively detect malicious use of trusted system binaries.

Security & ComplianceintermediatePython27.6k repo

DNS Tunneling Detection with Zeek

mukul975

Identify covert data exfiltration via DNS queries.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting for Beaconing

mukul975

Detect command-and-control beaconing in network traffic.

Security & ComplianceintermediatePython27.6k repo

Hunting EVTX with Chainsaw

mukul975

Rapidly analyze Windows event logs for threats.

Security & ComplianceintermediatePython · Shell27.6k repo

Generating Forensic Timelines

mukul975

Transform Windows event logs into actionable forensic timelines.

Security & ComplianceintermediatePython · Shell27.6k repo

Fleet Hunting with Velociraptor

mukul975

Conduct fleet-wide threat hunts with deep endpoint visibility.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting T1548 Abuse

mukul975

Identify UAC bypass and privilege escalation attempts.

Security & ComplianceintermediatePython27.6k repo

Detecting T1055 Process Injection

mukul975

Identify and analyze process injection techniques using Sysmon.

Security & ComplianceintermediatePython27.6k repo

Detecting Credential Dumping

mukul975

Identify and respond to credential theft in your environment.

Security & ComplianceintermediatePython27.6k repo