roodlicht

50 mods across 1 repository, 4 stars between them.

detection-engineer

01

roodlicht/accans-sec-skills

Agent Claude Code

Detection-engineering agent — writes Sigma rules, translates to SPL/KQL/EQL, validates via test harness (atomic-red-team / MITRE Caldera / lab replay), with ATT&CK coverage mapping and false-positive discipline. Delivers ready-to-deploy rules plus test evidence per rule.

not rated 4 3mo ago A 63 tokens

recon-agent

02

roodlicht/accans-sec-skills

Agent Claude Code

Attack-surface reconnaissance agent — subdomain enumeration, passive OSINT (Shodan/Censys/crt.sh), port scanning (nmap/masscan/naabu), tech fingerprinting (httpx/wappalyzer), and asset inventory. Produces a scope-mapped surface report for downstream exploit-chain and web-exploit-triage work.

not rated 4 3mo ago A 74 tokens

threat-modeler

03

roodlicht/accans-sec-skills

Agent Claude Code

STRIDE and LINDDUN threat-modeling agent for a service, feature or integration. Builds a DFD, enumerates threats per element, ranks mitigations and flags residual risk.

not rated 4 3mo ago A 43 tokens

security-gate

04

roodlicht/accans-sec-skills

Command Claude Code

Pre-merge security gate on the current branch — runs secrets, SAST and dep-vuln checks on changed code, honors documented exceptions, returns a hard PASS/FAIL verdict.

not rated 4 3mo ago A 37 tokens

threat-hunt

05

roodlicht/accans-sec-skills

Command Claude Code

Hypothesis-driven threat-hunt session scaffolding — scope, hypothesis formulation, data-source binding, query handoff to siem-query, IOC input via ioc-hunter, and structured writeup with findings and handoffs to detection-engineer.

not rated 4 3mo ago A 49 tokens

ad-attacks

06

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Active Directory attack paths — BloodHound path analysis, Kerberos abuse (Kerberoasting/AS-REP roasting/silver/golden ticket classes), delegation flaws (unconstrained/constrained/RBCD), DCSync, ADCS ESC1-8 at pattern level, and Tier-0 hygiene as a defensive model.

not rated 4 3mo ago A 69 tokens

alert-tuning

07

roodlicht/accans-sec-skills

Skill Claude CodeCodex

SOC alert-tuning workflow — false-positive reduction via targeted suppressions (rule-id + reason + expiry), baseline learning, rule retirement, severity recalibration, and metrics (alert volume, mean-time-to-triage, fatigue index). Prevents detection collapse without losing coverage.

not rated 4 3mo ago A 59 tokens

api-security

08

roodlicht/accans-sec-skills

Skill Claude CodeCodex

API security review against OWASP API Top 10 2023. Covers auth (OAuth2/JWT/API-keys), object-level authorization (BOLA/IDOR), schema validation, rate-limiting, CORS, SSRF, and GraphQL-specific concerns (introspection, query depth, batching).

not rated 4 3mo ago B 66 tokens

astro-security

09

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Astro security review — render-mode attack surface (SSG/SSR/hybrid), set:html and MDX content collections (XSS + author trust), API routes and middleware (auth, scope), adapter-specific runtime models (Cloudflare/Vercel/Netlify/Node), env-var hygiene (PUBLIC prefix), and Decap CMS pairing (OAuth backend, token…

not rated 4 3mo ago A 85 tokens

audit-evidence

10

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Evidence collection and packaging for security audits — evidence types (inspection/observation/inquiry/re-performance/automated), cadence per control, chain of custody, period tagging, WORM storage and retention, auditor delivery. Usable for SOC 2, ISO 27001, NIS2, DORA, and internal audits.

not rated 4 3mo ago A 70 tokens

c2-hygiene

11

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Command-and-Control infrastructure hygiene for red teams — redirector architecture (HTTP/HTTPS/DNS), traffic shaping (sleep/jitter/staging), TLS-cert and domain aging, OPSEC checklist, and defensive detection opportunities mapped to ATT&CK Command and Control (TA0011).

not rated 4 3mo ago A 61 tokens

cicd-hardening

12

roodlicht/accans-sec-skills

Skill Claude CodeCodex

CI/CD pipeline hardening for GitHub Actions and GitLab CI — trust-model (pullrequesttarget vs pullrequest), action pinning to SHA, OIDC-based cloud access, permissions minimization, runner isolation, and supply-chain gates (SLSA provenance, signing).

not rated 4 3mo ago B 61 tokens

container-hardening

13

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Docker and OCI image hardening — base-image selection, USER/caps/read-only FS discipline, distroless migration, build-time scanning with trivy/grype, image signing via sigstore, and runtime guardrails (seccomp, AppArmor).

not rated 4 3mo ago B 54 tokens

cve-triage

14

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Triage dependency vulnerabilities against CISA KEV, EPSS, reachability and compensating controls — turn a raw Dependabot/Snyk/osv-scanner dump into fix-now/sprint/quarter/accept decisions with rationale.

not rated 4 3mo ago A 52 tokens

dast-workflow

15

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Dynamic Application Security Testing workflow — OWASP ZAP automation (baseline/full/API scans), Burp Suite Professional playbooks, Burp Collaborator for out-of-band detection, auth-state orchestration, and CI integration with scope-safe active scanning.

not rated 4 3mo ago A 53 tokens

django-security

16

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Django security review — CSRF, ORM-level SQL injection (raw/extra/annotate), template injection via |safe, admin hardening, middleware ordering, settings deploy checklist, and recent Django CVE patterns.

not rated 4 3mo ago A 47 tokens

dora

17

roodlicht/accans-sec-skills

Skill Claude CodeCodex

EU Digital Operational Resilience Act (2022/2554) compliance — scope (financial entities + critical ICT TPPs), five pillars (ICT risk management, incident reporting, resilience testing incl. TLPT, third-party risk, information sharing), and Dutch oversight via DNB/AFM.

not rated 4 3mo ago A 63 tokens

exploit-chain

18

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Exploit-chain assembly methodology — combining multiple medium-impact findings into one high-impact path (Open Redirect + OAuth = ATO, SSRF + cloud-metadata = creds, IDOR + privilege escalation, prototype pollution + downstream gadget). Pattern-level, with chain-aware CVSS scoring and MITRE ATT&CK mapping.

not rated 4 3mo ago B 67 tokens

forensics-assist

19

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Digital-forensics assistant for IR context — memory analysis via Volatility 3, disk-imaging hygiene (write-blocker, hash validation), timeline reconstruction via plaso/log2timeline, file-system artifacts per OS. Audit-grade evidence; courtroom-grade chain of custody requires additional specialized forensics work.

not rated 4 3mo ago A 64 tokens

gdpr-pia

20

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Data Protection Impact Assessment (DPIA / GEB) workflow against AVG Art 35 — trigger check (AP criteria and WP 248), systematic description, necessity, risk analysis from the data subject's perspective, measures and residual risk, prior consultation with the Autoriteit Persoonsgegevens.

not rated 4 3mo ago A 63 tokens

iac-security

21

roodlicht/accans-sec-skills

Skill Claude CodeCodex

IaC misconfig scanning and cloud-aware review for Terraform, CloudFormation, Ansible and Pulumi. Covers tool orchestration (checkov/tfsec/kics/cfn-nag), policy-as-code (OPA/Conftest), CIS benchmark mapping, IAM over-permission detection, drift monitoring.

not rated 4 3mo ago A 64 tokens

ioc-hunter

22

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Threat-intel IOC workflow — feed curation (MISP/OpenCTI/vendor/ENISA/CISA), deduplication, confidence scoring (TLP, source reputation, age, sightings), enrichment pipeline to SIEM/EDR, retro-hunt over an N-day window, and lifecycle (expiry + retirement).

not rated 4 3mo ago A 68 tokens

ir-runbook

23

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Incident Response runbook — NIST SP 800-61 phases (Preparation/Detection-Analysis/Containment-Eradication-Recovery/Lessons-Learned), per-scenario playbooks (ransomware, BEC, data exfil, credential compromise, cloud), regulatory reporting (NIS2 24h/72h, AVG breach 72h, DORA), comms templates, and post-incident review.

not rated 4 3mo ago A 91 tokens

iso27001

24

roodlicht/accans-sec-skills

Skill Claude CodeCodex

ISO/IEC 27001:2022 ISMS implementation and certification prep — clauses 4-10 (context, leadership, planning, support, operation, evaluation, improvement), Annex A 93 controls across four themes, Statement of Applicability, Stage 1/Stage 2 audit prep, and the certification cycle.

not rated 4 3mo ago A 69 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: