briiirussell

60 mods across 1 repository, 371 stars between them.

pci-audit

49

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Heavy emphasis on scope determination (the single most-leveraged variable) plus the engineering-relevant requirements — Req 3 (storage of CHD), Req 4 (transmission), Req 6 (secure SDLC), Req 7-8 (access), Req 10 (logging), Req 11…

371 3mo ago A 180 tokens original MIT

privacy-engineering

50

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Implement and audit privacy controls in product and infrastructure — GDPR, CCPA / CPRA, LGPD, PIPEDA. Covers data minimization, lawful basis, consent management, data subject access requests (DSARs — access, deletion, portability), data processing agreements, DPIA / TIA, breach notification timing, data…

371 3mo ago A 212 tokens original MIT

prompt-injection

51

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Audit applications for AI prompt injection, agent security, and LLM permission boundary vulnerabilities. Use when the user mentions 'prompt injection,' 'LLM security,' 'AI security,' 'jailbreak,' 'indirect prompt injection,' 'prompt leaking,' 'AI red team,' 'LLM vulnerabilities,' 'AI input validation,' 'system prompt…

371 3mo ago B 110 tokens original MIT

recon

52

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs. Use when the user mentions 'recon,' 'reconnaissance,' 'enumerate,' 'attack surface,' 'subdomain enumeration,' 'port scan,' 'fingerprint,' 'asset discovery,' or needs to map a…

371 3mo ago A 74 tokens original MIT

red-team-engagement

53

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Plan, scope, and execute an authorized red-team engagement — distinct from a penetration test. Covers engagement methodology, assumed-breach scenarios, ATT&CK emulation plans, rules of engagement, deconfliction with the blue team, post-engagement debriefs, and the program-level work that makes red teams actually…

371 3mo ago A 162 tokens original MIT

secrets-audit

54

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets…

371 3mo ago A 125 tokens original MIT

security-comms

55

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Covers incident communication, post-mortem narrative, audit-findings-for-stakeholders, risk justification, security spend justification, and…

371 3mo ago A 157 tokens original MIT

siem-detection

56

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Use when the user mentions 'SIEM,' 'detection engineering,' 'detection rules,' 'Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,'…

371 3mo ago A 133 tokens original MIT

soc-operations

57

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs. Use when the user mentions 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage…

371 3mo ago A 140 tokens original MIT

threat-hunting

58

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt…

371 3mo ago C 128 tokens original MIT

threat-modeling

59

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Run a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases. Use when the user mentions 'threat model,' 'threat modeling,' 'STRIDE,' 'attack tree,' 'abuse case,' 'data flow diagram,' 'DFD,' 'security architecture review,' 'security…

371 3mo ago A 111 tokens original MIT

vuln-research

60

briiirussell/cybersecurity-skills

Skill Claude CodeCodex

Research a specific CVE or vulnerability disclosure end-to-end — what version is affected, is your code reachable, is there a public PoC, is there a patch, what's the exposure window, what's the mitigation if you can't patch immediately. Use when the user mentions 'CVE,' 'vulnerability research,' 'is this CVE…

371 3mo ago A 123 tokens original MIT