Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Threat Hunting › Page 3

Threat Hunting (Page 3 of 10)

588 Claude Code skills in the Threat Hunting sub-category of Security.

588 skills · updated 2026-07-27 · showing 121–180 of 588 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Build production-grade, security-first network security applications (e.g., security modules like MCP/NCM/NPM/IPAM/STIG Manager/Syslog/IDS/IPS/SIEM/SOAR/), using Dockerized…
Run 150+ AI apps via inference.sh CLI (infsh) — image generation, video creation, LLMs, search, 3D, social automation. Uses the terminal tool.
Set up a Cloud OS — your second brain hosted either in a synced cloud folder (Google Drive, OneDrive, iCloud, Dropbox) or as a Notion workspace.
Cross-platform cloud storage path resolution — OneDrive, iCloud, Dropbox path discovery and normalization
Sets up and optimizes OpenAI Codex CLI + GPT-5.5 on Amazon Bedrock (GA June 2026). Handles AWS credential wiring (API key or SDK chain), region selection, VPC endpoint isolation,…
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
SOC2, HIPAA, GDPR, PCI-DSS, FedRAMP compliance implementation in code. Audit logging, data encryption, access controls, privacy by design, and regulatory requirement mapping.
Automate Google Drive tasks via Rube MCP (Composio). Always search tools first for current schemas. — from phamlongh230-lgtm/yamtam-engine
SharePoint Automation: manage sites, lists, documents, folders, pages, and search content across SharePoint and OneDrive — from phamlongh230-lgtm/yamtam-engine
Internal fetcher module for Confluence pages. Fetches content via Atlassian MCP (preferred), REST API with Basic Auth (fallback), or browser DOM extraction via Claude in Chrome…
Maps NIST controls to FedRAMP requirements and documents. Use when helping with control implementation, compliance mapping, security baseline alignment, or understanding control…
Inspecteur des finances publiques IA. Simule un contrôle fiscal DGFIP complet sur les comptes d'une entreprise française (SASU, EURL, SAS, SARL).
Convierte archivos a Markdown usando MarkItDown. Úsala siempre que el usuario agregue, suba, arrastre o mencione un PDF, un audio (mp3, wav, m4a), un Word (docx), un Excel (xlsx),…
Build, review, or improve Core Data persistence in apps that have not adopted SwiftData. Use when working with NSManagedObject subclasses, NSFetchedResultsController for…
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks,
Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify
Garnish — Craft CMS's built-in JavaScript UI toolkit for the control panel. Covers the full Garnish surface: class system (Garnish.Base.extend, init, setSettings, addListener,…
Crea nuevas skills de Claude Code desde cero. Es la skill que hace skills. Usa esta skill cuando el usuario quiera crear su propia skill, automatizar un flujo de trabajo, hacer…
Create a new packet analyzer for Minecraft Bedrock logs. Generates template code, provides documentation links, and guides testing workflow.
Setup observability platform configuration (Datadog, Prometheus, Splunk) with REQ-* dashboards and alerts. Creates monitors for each requirement with SLA tracking.
Expert guidance for creating Claude Code slash commands. Use when working with slash commands, creating custom commands, understanding command structure, or learning YAML — from…
Expert guidance for creating, building, and using Claude Code subagents and the Task tool. Use when working with subagents, setting up agent configurations, understanding — from…
Use when you have a pretrained RT-Transformer model checkpoint from a large, well-characterized chromatographic dataset (e.g., SMRT) and need to predict retention times for a…
Signals scout that watches a PostHog project's most-viewed dashboards and insights for recent anomalies — sudden bursts, drops, flat-lines, and trend breaks at the daily or hourly…
Create and manage TMDD threat models grounded in actual codebase architecture. Use when the user wants to threat-model a system, add a feature, create security threat mappings,…
Use when designing or implementing a custom logging framework in Apex: log sObject schema, log level gating, retention policies, batch purge jobs, and forwarding logs to external…
Extrae parámetros críticos de datasheets técnicos de componentes electrónicos y microcontroladores, y los resume en lenguaje natural accesible para estudiantes.
DBA Deutschland Bulgarien 2010. Anwendungsfall Outsourcing IT Pflege Holding Beteiligungen. EU-MTRL ergaenzend. Niedrige KSt 10 Prozent. Methodenartikel Anrechnung.
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
Detects arbitrary read vulnerabilities by identifying unchecked array indexing and out-of-bounds memory access.
Detects arbitrary write vulnerabilities by identifying unchecked array indexing and out-of-bounds memory writes.
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration
Detects stack and heap buffer overflow vulnerabilities in binary code by identifying unsafe memory operations.
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
Detects OS command injection vulnerabilities by identifying unsafe system/popen/exec calls with user-controlled input.
Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
Detects double free vulnerabilities by identifying attempts to free the same memory block twice. Use when analyzing memory management, cleanup paths, or investigating heap…
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files
Detects format string vulnerabilities by identifying unsafe printf family function calls with user-controlled format strings.
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
Detects information disclosure vulnerabilities including sensitive data in logs, error message exposure, and memory leaks.
Detects various injection vulnerabilities including SQL injection, LDAP injection, XPath injection, and code injection.
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
Detects integer overflow and underflow vulnerabilities in arithmetic operations used for buffer sizing or allocation.
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process
Detects logic bypass vulnerabilities including authentication bypass, authorization bypass, and business logic flaws.
Detects various memory corruption vulnerabilities beyond simple buffer overflows including heap overflow, stack smashing, and double free.
Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming…
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Forensics (200) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)