Incident Response skills
Free incident response skills for AI coding agents, part of our security & compliance collection.
295 skills
Detecting T1548 Abuse
mukul975
Identify UAC bypass and privilege escalation attempts.
Detecting T1055 Process Injection
mukul975
Identify and analyze process injection techniques using Sysmon.
Detecting Credential Dumping
mukul975
Identify and respond to credential theft in your environment.
Detecting Spearphishing
mukul975
Enhance email security against targeted phishing attacks.
Detecting Ransomware Precursors
mukul975
Identify early-stage ransomware indicators in network traffic.
Detecting Privilege Escalation in Kubernetes Pods
mukul975
Enhance Kubernetes security by detecting privilege escalation risks.
Detecting Lateral Movement with Zeek
mukul975
Identify lateral movement techniques in network traffic.
Detecting Fileless Attacks
mukul975
Identify fileless malware and in-memory threats effectively.
Detecting Evasion Techniques
mukul975
Identify adversary evasion tactics in endpoint logs.
Detecting Entra Offensive Tools
mukul975
Identify malicious activity in Microsoft Graph logs.
Detecting DCSync Attack
mukul975
Identify and respond to DCSync attacks in Active Directory.
Detecting Container Threats with Falco
mukul975
Real-time detection of container runtime threats in Kubernetes and Docker.
Detecting Container Escape with Falco Rules
mukul975
Monitor Linux syscalls to detect container escape attempts in real time.
Detecting Container Escape Attempts
mukul975
Monitor and detect container escape attempts effectively.
Detecting Container Drift
mukul975
Monitor and secure your containers against unauthorized changes.
Detecting Azure Service Principal Abuse
mukul975
Identify and mitigate Azure service principal security risks.
AWS GuardDuty Findings Automation
mukul975
Automate incident responses for AWS GuardDuty findings.
Deploying Osquery for Endpoint Monitoring
mukul975
Real-time endpoint monitoring with SQL-based queries.
Deploying Honeytokens and Canarytokens
mukul975
Enhance intrusion detection with decoy artifacts.
Deploying EDR Agent with CrowdStrike
mukul975
Streamline deployment of CrowdStrike Falcon EDR agents.
Cloud Deception Deployment
mukul975
Implement decoy resources for cloud security alerts.
Deploying Active Directory Honeytokens
mukul975
Enhance Active Directory security with deception techniques.
Deobfuscating PowerShell Malware
mukul975
Reveal hidden payloads in obfuscated PowerShell scripts.
Configuring Windows Event Logging
mukul975
Enhance Windows security event logging for better detection.
