dandye

35 mods across 2 repositories, 125 stars between them.

hunt-threat

25

dandye/ai-runbooks

Skill Claude CodeCodex

Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation.

124 18d ago A 49 tokens original Apache-2.0

inventory-content

26

dandye/ai-runbooks

Skill Claude CodeCodex

Systematic cataloging of information assets. Creates comprehensive inventories of all content with metadata and characteristics.

124 18d ago A 22 tokens original Apache-2.0

pivot-on-ioc

27

dandye/ai-runbooks

Skill Claude CodeCodex

Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected domains, IPs, files, or threat actors. Takes an IOC and relationship types to query.

124 18d ago A 44 tokens original Apache-2.0

dandye/ai-runbooks

Skill Claude CodeCodex

Respond to a potentially compromised user account. Use when impossible travel, credential stuffing, successful phishing, or suspicious activity indicates account compromise. Investigates activity, contains the account, removes persistence, and restores access.

124 18d ago A 47 tokens original Apache-2.0

respond-malware

29

dandye/ai-runbooks

Skill Claude CodeCodex

Respond to a malware incident following PICERL methodology. Use when malware is detected on endpoints. Orchestrates triage, containment, eradication, and recovery. Works with triage-malware skill for analysis.

124 18d ago A 47 tokens original Apache-2.0

respond-phishing

30

dandye/ai-runbooks

Skill Claude CodeCodex

Respond to a reported phishing email following PICERL methodology. Use when a phishing email is reported or detected. Analyzes artifacts, identifies recipients who clicked, contains malicious IOCs, and removes emails from mailboxes.

124 18d ago A 48 tokens original Apache-2.0

respond-ransomware

31

dandye/ai-runbooks

Skill Claude CodeCodex

Respond to a ransomware incident following PICERL methodology. Use when ransomware is detected or suspected. Orchestrates identification, containment, eradication, and recovery phases. Requires CASEID and initial indicators.

124 18d ago A 45 tokens original Apache-2.0

triage-alert

32

dandye/ai-runbooks

Skill Claude CodeCodex

Triage a security alert or case. Use when given an ALERTID or CASEID to assess if it's a real threat. Enriches IOCs, searches SIEM for context, and determines if the alert should be closed (false positive) or escalated for investigation.

124 18d ago A 59 tokens original Apache-2.0

triage-malware

33

dandye/ai-runbooks

Skill Claude CodeCodex

Triage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, and recommends containment actions.

124 18d ago A 48 tokens original Apache-2.0

dandye/ai-runbooks

Skill Claude CodeCodex

Triage suspicious login alerts like impossible travel, untrusted location, or multiple failures. Use when investigating authentication anomalies. Analyzes user history, source IP reputation, login patterns, and determines if escalation is needed.

124 18d ago A 50 tokens original Apache-2.0

duck-punch-mcp

35

dandye/duck_punch_mcp

MCP server Claude CodeCodexCursor

MCP server "duck-punch-mcp" as configured in dandye/duckpunchmcp. Runs locally from the duck-punch-mcp Python package.

1 8mo ago A tokens not measured