Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Threat Hunting

Threat Hunting

328 Claude Code skills in the Threat Hunting sub-category of Security.

328 skills · updated 2026-05-27 · showing 1–60 of 328 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

AI Media Generator — generování produktových fotek a B-roll videí přes fal.ai. Expert-level prompting pro food/beverage/FMCG produkty.
Amazon Bedrock Automated Reasoning for mathematical verification of AI responses against formal policy rules with up to 99% accuracy.
Amazon Bedrock Prompt Management for creating, versioning, and managing prompt templates with variables, multi-variant A/B testing, and flow integration.
Creates repository following Clean Architecture with Protocol in domain layer and Implementation in infrastructure layer.
OpenSearch detection engineering: SIGMA authoring, query DSL translation, MITRE ATT&CK mapping, anomaly detection, correlation rules, SOC incident escalation.
Enforce Input/Output Guardrails at the LLM Gateway layer — PII redaction, Prompt Injection defense, Jailbreak detection, Toxicity filter, and Tool Allow-list.
IOC pivots for a CVE — top IPs, ASNs, geo distribution, ATT&CK technique chain, Shadowserver scan counts (1d/7d/30d/90d averages), CrowdSec community sightings, merged in-the-wild…
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir.
SOC daily-pull triage feed — Vulnetix''s score-driven queue cross-referenced with installed dependencies.
Daily threat-intel digest — AI-discovered vulnerabilities, AI-in-the-wild exploitation observations, AI-authored malware families, exploit-trends rollup, vendor-trends…
MITRE ATT&CK framework mapping and analysis
Pipedrive CRM integration optimized for SMB sales teams
STIX/TAXII threat intelligence format and sharing
Soc2 Compliance Checker - Auto-activating skill for Security Advanced. Triggers on: soc2 compliance checker, soc2 compliance checker Part of the Security Advanced skill category.
Generates complete FAERS pharmacovigilance study designs for multi-drug or class-level safety comparison inside one predefined SOC or AE family using active comparators,…
Guide the user to add a data source, connection, or API connector to a Canvas App via Power Apps Studio, then verify and continue.
Adds Excel Online (Business) connector to a Power Apps code app. Use when reading or writing Excel workbook data from OneDrive or SharePoint.
Adds OneDrive for Business connector to a Power Apps code app. Use when uploading, downloading, listing, or managing files in OneDrive.
AI Agent System Designer for 0xagentprivacy. Activates for dual-agent TEE architecture, separation matrix physical enforcement, agent lifecycle design, Oracle architecture,…
Dihedral group foundation for dual-agent separation. Activates when discussing the D₂ₙ group structure, Swordsman as negation generator, Mage as complement generator, Φ_agent as…
Dihedral convergence navigator persona. Activates when discussing UOR-grimoire convergence, 2D to manifold transitions, the dihedral mirror pattern, or cross-framework translation…
Tetrahedral sovereignty model and 4×4 separation matrix for 0xagentprivacy. Activates when discussing Φ(Σ), det(Σ), the four forces (Protect, Project, Reflect, Connect),…
Use when adding capabilities to an existing agent project — memory, app integration, VPC, multi-agent, migration, model changes, browser, code interpreter, or resource removal.
Generate PNG images using AI (multiple models via OpenRouter including Gemini, FLUX.2, Riverflow, SeedDream, GPT-5 Image, GPT-5.4 Image 2, proxied through Cloudflare AI Gateway…
All-in-one academic research với 28 tools. Kết nối arXiv, PubMed, Semantic Scholar, bioRxiv, medRxiv, Google Scholar. Hỗ trợ auto-cite và AI scientific figure generation.
Analyzes SIEM alert pipelines for rule optimization, alert fatigue reduction, criticality scoring, asset-based prioritization, and correlation rule design using NIST CSF and…
Alibaba Cloud Security Center incident management skill. Query security incidents, threat trends, and incident details.
Builds generative AI applications on Amazon Bedrock. Covers model invocation (Converse API, InvokeModel), RAG with Knowledge Bases, Bedrock Agents, Guardrails, and AgentCore.
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures,
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)
Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework
Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,
Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics,
Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege
Plausibilisiert die in `annahmen-sammeln-fortfuehrung` gesammelten Annahmen. Pruefraster Konsistenz mit Vergangenheit (BWA SuSa Jahresabschluss) Marktentwicklung (Branche…
Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.
Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using
KI-Situationsbewusstsein — interne Bedrohungserkennung fuer Halluzinations- risiko, Scope-Creep und Kontextdegradation.
Review Amazon Bedrock agents, AgentCore, Guardrails, knowledge bases, action groups, memory, MCP/tool integrations, prompt-injection and prompt-leakage defenses, PII handling,…
AWS CloudFormation patterns for Amazon Bedrock resources including agents, knowledge bases, data sources, guardrails, prompts, flows, and inference profiles.
Amazon Bedrock patterns using AWS SDK for Java 2.x. Use when working with foundation models (listing, invoking), text generation, image generation, embeddings, streaming…
AI image generation with OpenAI GPT Image 2, Azure OpenAI, Google, OpenRouter, DashScope, Z.AI GLM-Image, MiniMax, Jimeng, Seedream and Replicate APIs.
AWS Bedrock foundation models for generative AI. Use when invoking foundation models, building AI applications, creating embeddings, configuring model access, or implementing RAG…
Amazon Bedrock AgentCore platform for building, deploying, and operating production AI agents. Covers Runtime, Gateway, Browser, Code Interpreter, and Identity services.
Amazon Bedrock AgentCore deployment patterns for production AI agents. Covers starter toolkit, direct code deploy, container deploy, CI/CD pipelines, and infrastructure as code.
Amazon Bedrock AgentCore Memory for persistent agent knowledge across sessions. Episodic memory for learning from interactions, short-term for session context.
Amazon Bedrock AgentCore multi-agent orchestration with Agent-to-Agent (A2A) protocol. Supervisor-worker patterns, agent collaboration, and hierarchical delegation.
Amazon Bedrock AgentCore Policy for defining agent boundaries using natural language and Cedar. Deterministic policy enforcement at the Gateway level.
Amazon Bedrock Agents for building autonomous AI agents with foundation model orchestration, action groups, knowledge bases, and session management.
Bedrock is a WordPress boilerplate with Composer-based dependency management, environment-specific configuration via .env files, and an improved folder structure.
Apply David Bianco's threat hunting frameworks including the Pyramid of Pain and Threat Hunting Maturity Model.
Query bioRxiv/medRxiv preprints via REST API. Search by DOI, category, or date range; retrieve metadata (title, abstract, authors, category, DOI, version history) and PDFs.
Add better-route 0.5.0 ownership checks for user-owned REST resources. Use when a route or Resource DSL endpoint must ensure the authenticated user owns the order, record, token,…
Implements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring.
Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify
Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms
All Security skills →
More in SecurityWeb Security (479) · Red Team (244) · Identity Access (223) · Appsec Tools (219) · Network Security (196) · Compliance (110) · Malware Analysis (106) · Forensics (63) · Cloud Security (62) · Appsec Build (37) · Crypto Keymgmt (33) · Zero Trust (26) · Incident Response (12) · Ot Ics Security (6)