New to Claude Skills? Learn how to install them →

Incident Response skills

Free incident response skills for AI coding agents, part of our security & compliance collection.

Honeypot for Ransomware Detection

mukul975

Detect ransomware early with canary files and honeypots.

Security & ComplianceintermediatePython · Shell27.6k repo

Deobfuscating PowerShell Malware

mukul975

Reveal hidden payloads in obfuscated PowerShell scripts.

Security & ComplianceintermediatePython27.6k repo

Deploying Honeytokens and Canarytokens

mukul975

Enhance intrusion detection with decoy artifacts.

Security & ComplianceintermediatePython · Shell27.6k repo

Analyzing Cobalt Strike Beacon Configuration

mukul975

Extract and analyze Cobalt Strike beacon configurations efficiently.

Security & ComplianceadvancedPython27.6k repo

Hunting Bootkits in EFI

mukul975

Detect and analyze UEFI bootkits on your systems.

Security & ComplianceadvancedPython · Shell27.6k repo

Implementing Ransomware Backup Strategy

mukul975

Create a resilient backup strategy against ransomware attacks.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting SaaS SSO Token Abuse

mukul975

Detect and mitigate token replay attacks in SaaS environments.

Security & ComplianceintermediatePython · Shell27.6k repo

Analyzing LNK Files

mukul975

Extract and analyze Windows LNK and Jump List artifacts.

Security & ComplianceintermediatePython27.6k repo

Detecting Entra Offensive Tools

mukul975

Identify malicious activity in Microsoft Graph logs.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Container Escape Attempts

mukul975

Monitor and detect container escape attempts effectively.

Security & ComplianceintermediatePython · Shell27.6k repo

Analyzing Browser Forensics

mukul975

Extract and correlate browser data for investigations.

Security & ComplianceintermediatePython · Shell27.6k repo

Threat Intelligence Enrichment

mukul975

Automate IOC enrichment in Splunk for enhanced security.

Security & ComplianceintermediatePython27.6k repo

Operationalizing MISP Threat Feeds

mukul975

Enhance threat detection with curated MISP feeds.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Container Escape with Falco Rules

mukul975

Monitor Linux syscalls to detect container escape attempts in real time.

Security & ComplianceintermediatePython · Shell27.6k repo

Building Threat Intelligence Platform

mukul975

Integrate open-source CTI tools for threat intelligence.

Security & ComplianceadvancedPython27.6k repo

Malware Incident Communication Template

mukul975

Streamline your malware incident communications with structured templates.

Security & ComplianceintermediatePython27.6k repo

Analyzing Threat Actor TTPs

mukul975

Map threat actor behavior to the MITRE ATT&CK framework.

Security & ComplianceintermediatePython27.6k repo

Collecting Volatile Evidence

mukul975

Capture critical data from compromised hosts before it's lost.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Evasion Techniques

mukul975

Identify adversary evasion tactics in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Building Incident Timeline with Timesketch

mukul975

Collaboratively analyze forensic timelines for incident investigations.

Security & ComplianceintermediatePython · Shell27.6k repo

Analyzing Campaign Attribution Evidence

mukul975

Systematically evaluate cyber-campaign evidence for attribution.

Security & ComplianceintermediatePython27.6k repo

Analyzing Windows Shellbag Artifacts

mukul975

Reconstruct folder access history from Windows registry.

Security & ComplianceintermediatePython27.6k repo

Implementing Velociraptor for IR Collection

mukul975

Streamline endpoint forensic artifact collection for incident response.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Privilege Escalation in Kubernetes Pods

mukul975

Enhance Kubernetes security by detecting privilege escalation risks.

Security & ComplianceintermediatePython · Shell27.6k repo