incident-response skills

169 tagged incident-response, measured the same way as everything else here.

Browse within: cybersecurity 65mitre-attack 41penetration-testing 27blueteaming 22codex-cli 22gemini-cli 22pentesting 22forensics 21appsec 19malware-analysis 18malware 16compliance 14memory-forensics 14Volatility 12

mukul975/Anthropic-Cybersecurity-Skills

Skill Claude CodeCodex

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team…

32k +235 2d ago A 97 tokens original Apache-2.0

mukul975/Anthropic-Cybersecurity-Skills

Skill Claude CodeCodex

Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback domains, dead drops). Use after reverse engineering reveals network traffic needing protocol analysis or when building…

32k +235 2d ago A 81 tokens original Apache-2.0

attackgen-tabletop

04

mrwadams/attackgen

Skill Claude CodeCodex

Turn a MITRE ATT&CK/ATLAS threat group or case study — or a frontier AI agent deployed inside the organisation — into a full incident-response tabletop exercise (MSEL): scenario narrative, kill chain or agent threat scope, timestamped injects, discussion questions, and a detection-coverage scorecard, using the…

1.2k 11d ago A 155 tokens GPL-3.0

aozyildirim/Agena

Skill Claude CodeCodex

Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which deploy caused this bug" without manual tab-switching.

98 1mo ago A 64 tokens original MIT

incident-commander

06

Lethe044/hermes-incident-commander

Skill Claude CodeCodex

Autonomous incident detection, root-cause analysis, and self-healing for Linux/Docker production environments. Activate when the user mentions: server down, high CPU, memory leak, disk full, service crash, deployment failure, alert firing, on-call page, or any infrastructure emergency. Also activates on scheduled…

68 5mo ago A 92 tokens original MIT

config-query

07

shanananana/deepticket

Skill Claude CodeCodex

A template for querying internal configuration systems, service settings, feature flags, and environment variables. A feature flag is a switch that turns software behavior on or off.

56 5d ago A 33 tokens original MIT

log-query

08

shanananana/deepticket

Skill Claude CodeCodex

A read-only log and metrics lookup guide for an ad-agent project. It covers campaign performance logs, budget-change records, time-window comparisons, and tracing errors by identifier.

56 5d ago A 35 tokens original MIT

repo-workspace

09

shanananana/deepticket

Skill Claude CodeCodex

A read-only workspace for inspecting code in Git repositories synchronised by DeepTicket. It tells the agent where to find the project view and which repositories are available.

56 5d ago A 47 tokens original MIT

binary-analysis

10

DeepBitsTechnology/claude-plugins

Skill Claude CodeCodex

Analyze binary files (exe, dll, sys, bin, ocx, scr, cpl, drv, elf, so, macho, apk) to assess if they are malicious, perform decompilation, extract strings/imports/exports, detect malware, and provide threat assessment. Use this skill when user asks to analyze, examine, check, or assess any binary file, asks if a file…

47 +1 1mo ago A 132 tokens original Apache-2.0

kernel-cve-analysis

11

DeepBitsTechnology/claude-plugins

Skill Claude CodeCodex

Query the Android/AOSP kernel CVE database to look up a specific CVE, find CVEs affecting a kernel version or build date, find unpatched CVEs in a branch, or identify exploitable vulnerabilities. Use this skill when the user asks about Android kernel CVEs, AOSP kernel vulnerabilities, which CVEs affect a kernel…

47 +1 1mo ago A 136 tokens original Apache-2.0

detection-engineer

12

gl0bal01/malware-analysis-claude-skills

Skill Claude CodeCodex

Create detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.

45 4mo ago A 59 tokens original MIT

gl0bal01/malware-analysis-claude-skills

Skill Claude CodeCodex

Execute and monitor malware in controlled sandbox environments. Use when you need to observe runtime behavior, capture network traffic, monitor process activity, analyze file/registry changes, or understand actual malware functionality beyond static analysis. Guides safe execution with Procmon, Wireshark, Process…

45 4mo ago A 74 tokens original MIT

malware-triage

14

gl0bal01/malware-analysis-claude-skills

Skill Claude CodeCodex

Rapid assessment, classification, and prioritization of malware samples. Use when you need to perform initial malware assessment, classify a sample's type and family, determine analysis priority, identify quick indicators, or decide on next analysis steps.

45 4mo ago A 51 tokens original MIT

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

23 11d ago A 197 tokens original Apache-2.0

kube-medic

16

cacheforge-ai/cacheforge-skills

Skill Claude CodeCodex

Kubernetes Cluster Triage & Diagnostics — instant AI-powered incident triage via kubectl.

10 6mo ago A 22 tokens original MIT

log-dive

17

cacheforge-ai/cacheforge-skills

Skill Claude CodeCodex

Unified log search across Loki, Elasticsearch, and CloudWatch. Natural language queries translated to LogQL, ES DSL, or CloudWatch filter patterns. Read-only. Never modifies or deletes logs.

10 6mo ago A 42 tokens original MIT

kevinmhorvath/threat-intel-toolkit

Skill Claude CodeCodex

Check whether a working exploit or public PoC exists for a vulnerability. Given a CVE ID (e.g. CVE-2024-3400) or a named vulnerability (e.g. Log4Shell, EternalBlue, BlueKeep, Citrix Bleed), it queries CISA KEV, EPSS, Metasploit, Nuclei, Exploit-DB, and the nomi-sec/trickest GitHub PoC aggregators, then reports an…

5 14d ago A 220 tokens

threat-intel-lookup

19

kevinmhorvath/threat-intel-toolkit

Skill Claude CodeCodex

Aggregate free / open-source threat-intel feeds into a local cache and check indicators (IPs, domains, URLs, CVEs) against them. Trigger whenever the user drops an IP, domain, URL, or CVE and asks "is this malicious", "is this a known bad IP", "check this indicator / IOC", "is this domain on any blocklist", "who's…

5 14d ago A 218 tokens

kismatkunwar89/SAVVYDFIR-MCP

Skill Claude CodeCodex

REQUIRED when the user says "start investigation", "investigate", "analyze case", "Read case-templates/manifest.json", references a manifest.json, or provides a SAVVYDFIR-MCP caseid. Defines the 5-phase DFIR methodology from evidence mounting through report generation, with mandatory tools, decision points, and…

4 2mo ago A 84 tokens original MIT

pivot-methodology

21

kismatkunwar89/SAVVYDFIR-MCP

Skill Claude CodeCodex

Load when you have an initial finding and need to determine what to investigate next. Defines universal pivot chains from each artifact type to related evidence, enabling systematic investigation expansion.

4 2mo ago A 37 tokens original MIT

tools-reference

22

kismatkunwar89/SAVVYDFIR-MCP

Skill Claude CodeCodex

Load when you need exact command syntax for SIFT Workstation tools. Covers Volatility 3, Sleuth Kit, EZ Tools, Plaso, YARA, and Regripper with actual invocation examples and output parsing guidance.

4 2mo ago A 49 tokens original MIT

akashrpatil/awesome-offensive-security-skills

Skill Claude CodeCodex

Analyze and detect synthetic media, including deepfake videos, AI-generated images, and cloned voice audio. Use this skill when investigating potential disinformation campaigns, verifying the authenticity of digital evidence, or assessing social engineering attacks leveraging synthetic media (e.g., vishing with voice…

4 +1 4mo ago A 86 tokens original Apache-2.0

cybersorted

24

cyber-sorted/skills-pro

Skill Claude CodeCodex

Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk…

3 6mo ago A 417 tokens