Incident Response skills
Free incident response skills for AI coding agents, part of our security & compliance collection.
270 skills
Asset Criticality Scoring for Vulns
mukul975
Prioritize vulnerabilities based on asset criticality.
Performing Alert Triage with Elastic SIEM
mukul975
Streamline alert triage processes in Elastic Security.
Active Directory Vulnerability Assessment
mukul975
Secure your Active Directory with comprehensive assessments.
Active Directory Investigation
mukul975
Streamline your Active Directory compromise investigations.
Parsing Artifacts with Eric Zimmerman Tools
mukul975
Efficiently parse Windows forensic artifacts for analysis.
Operationalizing MISP Threat Feeds
mukul975
Enhance threat detection with curated MISP feeds.
Implementing Velociraptor for IR Collection
mukul975
Streamline endpoint forensic artifact collection for incident response.
Implementing SOAR Playbook with Palo Alto XSOAR
mukul975
Automate incident response with Cortex XSOAR playbooks.
Implementing Ransomware Backup Strategy
mukul975
Create a resilient backup strategy against ransomware attacks.
Honeypot for Ransomware Detection
mukul975
Detect ransomware early with canary files and honeypots.
Implementing EPSS Score
mukul975
Prioritize vulnerabilities using real-world exploitation data.
Diamond Model Analysis
mukul975
Analyze cyber intrusions using the Diamond Model framework.
Hunting SaaS SSO Token Abuse
mukul975
Detect and mitigate token replay attacks in SaaS environments.
Hunting for Suspicious Scheduled Tasks
mukul975
Identify and analyze potential persistence threats in Windows.
Hunting for LOLBins Execution
mukul975
Detect and analyze LOLBins in endpoint logs.
Hunting for Living-off-the-Land Binaries
mukul975
Proactively detect malicious use of trusted system binaries.
DNS Tunneling Detection with Zeek
mukul975
Identify covert data exfiltration via DNS queries.
Hunting for Beaconing
mukul975
Detect command-and-control beaconing in network traffic.
Hunting EVTX with Chainsaw
mukul975
Rapidly analyze Windows event logs for threats.
Generating Forensic Timelines
mukul975
Transform Windows event logs into actionable forensic timelines.
Fleet Hunting with Velociraptor
mukul975
Conduct fleet-wide threat hunts with deep endpoint visibility.
Detecting T1548 Abuse
mukul975
Identify UAC bypass and privilege escalation attempts.
Detecting T1055 Process Injection
mukul975
Identify and analyze process injection techniques using Sysmon.
Detecting Credential Dumping
mukul975
Identify and respond to credential theft in your environment.
