briiirussell/cybersecurity-skills

Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex)

This repository also configures its own agents. See what cybersecurity-skills tells them →

387Stars on the repository
59Mods indexed here, across every type
3mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

soc-operations

25

briiirussell/cybersecurity-skills

Cursor rule Cursor

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs. Use when the user mentions 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage…

not rated 387 +7 3mo ago A 136 tokens original MIT

threat-hunting

26

briiirussell/cybersecurity-skills

Cursor rule Cursor

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt…

not rated 387 +7 3mo ago C 123 tokens original MIT

threat-modeling

27

briiirussell/cybersecurity-skills

Cursor rule Cursor

Run a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases. Use when the user mentions 'threat model,' 'threat modeling,' 'STRIDE,' 'attack tree,' 'abuse case,' 'data flow diagram,' 'DFD,' 'security architecture review,' 'security…

not rated 387 +7 3mo ago A 106 tokens original MIT

vuln-research

28

briiirussell/cybersecurity-skills

Cursor rule Cursor

Research a specific CVE or vulnerability disclosure end-to-end — what version is affected, is your code reachable, is there a public PoC, is there a patch, what's the exposure window, what's the mitigation if you can't patch immediately. Use when the user mentions 'CVE,' 'vulnerability research,' 'is this CVE…

not rated 387 +7 3mo ago A 117 tokens original MIT

web-pentest

29

briiirussell/cybersecurity-skills

Cursor rule Cursor

Perform black-box / grey-box web application penetration testing on an authorized target — auth bypass, IDOR, session handling, business-logic flaws, parameter tampering, Burp Suite / OWASP ZAP workflows. Use when the user mentions 'web pentest,' 'web application penetration test,' 'pentesting,' 'bug bounty,' 'Burp…

not rated 387 +7 3mo ago B 114 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: