Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Threat Hunting › Page 8

Threat Hunting (Page 8 of 10)

588 Claude Code skills in the Threat Hunting sub-category of Security.

588 skills · updated 2026-07-27 · showing 421–480 of 588 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Usar siempre que el usuario escriba, redacte, revise o traduzca texto científico/académico en ESPAÑOL — artículos, papers, tesis, abstracts, introducciones, metodologías,…
Use Red Rocket public read-only market data for China index valuation, ETF/fund discovery, related product lookup, and fund profile context.
Detailed evasion pack for AV/EDR, WAF, 403/CSP bypass, and sandbox-oriented analysis.
Advanced Regle form validation patterns — collection validation with `$each`, async rules and `$pending`, server/`externalErrors`, `$reset` options, global config with…
Relationship Red Flags: steuert Warnzeichen: Funkstille, Überraschungsrechnung, Scope-Unklarheit, Strategiedrift, Fristdruck zwischen Kanzlei, Mandant und Rechtsabteilung mit…
Auditoría defensiva para repositorios AI-native. Usar SIEMPRE que el usuario quiera revisar un repo antes de lanzar, mergear, actualizar dependencias, migrar package manager,…
Implements Microsoft SharePoint access — sites, lists, document libraries, and file operations — using generated clients and MCP tools.
Skill para el proyecto Flutter "catalogo_productos". Úsala SIEMPRE que el usuario pida implementar la pantalla de detalle de producto (producto_detalle_screen.dart), agregar…
Authoring and debugging scripts for Rhinoceros 3D (Rhino 8 and later). Use when asked to write RhinoScript (VBScript / .rvb / .vbs), RhinoPython, or RhinoCommon-based scripts;…
Apply Roberto Rodriguez's threat hunting methodology with the Threat Hunter Playbook and HELK. Emphasizes documented hunts, open source infrastructure, and data-driven hunting.
Roo Code's Bedrock provider silently disables caching for custom ARNs. Populate cachableFields to fix.
Use ai-runbooks to give AI assistants role-specific SOC personas, investigation steps, and incident-response procedures for structured security triage.
Activa SecurityAudit SIEMPRE que el usuario quiera verificar la seguridad de un skill antes de instalarlo.
Activa SecurityAudit SIEMPRE que el usuario quiera verificar la seguridad de un skill antes de instalarlo.
Sage theme with Acorn (Laravel IoC for WordPress) and Lando — lando start, lando info, lando acorn, Service Providers, View Composers, Blade components, ACF Composer blocks and…
Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP. Use when: deploying generative AI models, building orchestration workflows with…
Scaledrone integration. Manage data, records, and automate workflows. Use when the user wants to interact with Scaledrone data.
Interpreta diagramas esquemáticos de circuitos electrónicos y los convierte en explicaciones didácticas organizadas por bloques funcionales.
Massive multi-source academic literature search via subagent orchestration. Fans out parallel searchers across every available scholarly source — arXiv, Semantic Scholar,…
Literature search and citation management for medical research. Searches PubMed, Semantic Scholar, and bioRxiv/medRxiv with verified citations.
Use for defensive security workflows that design, assess, or run AI-assisted alert triage, incident investigation, log enrichment, SIEM/EDR query orchestration, security…
Analyze Web3 security risks with SpoonOS agents. Use when checking token safety (honeypots, rugs), simulating transactions, detecting MEV, or auditing contracts.
Führt Produktteam durch Security-by-Design: Bedrohungsmodell, Updatekanal, SBOM, Schwachstellenprozess, Logging und Notfallplan. — from Klotzkette/claude-fuer-deutsches-recht
Chief Information Security Officer (CISO) level GRC expertise. Governance, Risk, and Compliance for SaaS platforms.
Master security ioc enrichment with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Walk the current diff (or the whole repo) against SECURITY.md's trust-boundary table and "Where I'd look" list, invariant by invariant, delegating the adversarial review to the…
Guide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse.
Scans code for security vulnerabilities and unsafe patterns. Use when the user asks about security, mentions OWASP, credentials, secrets, XSS, SQL injection, or wants to audit…
Modélisation des menaces pour applications et systèmes — identification des surfaces d'attaque, classification STRIDE, arbres d'attaque et stratégies de mitigation.
Out-of-the-box Seedance 2.0 API skill — just one API key to generate AI videos. Builds storyboards, generates reference images with Seedream 4.5, submits video tasks, and polls…
Generate and edit AI images with Seedream (ByteDance) via AceDataCloud API. Use when creating images from text prompts, editing existing images, or working with high-resolution…
Teaches the agent how to perform advanced web automation using Python, Selenium WebDriver, and ChromeDriver.
Generates production-grade Selenium WebDriver automation scripts and tests in Java, Python, JavaScript, C#, Ruby, or PHP.
Rosetta CRITICAL MUST skill. MUST activate when you suspect, there is a slight chance, encounter, read, process, or are about to output any sensitive or possibly sensitive data…
Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials.
Generates and reviews Salesforce Apex code (Brite edition) with 150-point scoring. TRIGGER when user writes, reviews, or fixes Apex classes, triggers, test classes,…
Audit a fleet of AWS security groups for the multi-hop lateral-movement path that no single ingress rule reveals.
Añadir y usar componentes de shadcn/ui en este repo — CLI de instalación, alias `#/components/ui`, estilo `new-york`, iconos `lucide`, util `cn` y Tailwind v4.
SharePoint Automation: manage sites, lists, documents, folders, pages, and search content across SharePoint and OneDrive — from security/threat-hunting
Siem Rule Generator - Auto-activating skill for Security Advanced. Triggers on: siem rule generator, siem rule generator Part of the Security Advanced skill category.
Authenticate against the Sigma Computing REST API and obtain a bearer token. Use whenever the user wants to call the Sigma API directly with curl/HTTP, exchange OAuth client…
Create, retrieve, or modify a Sigma data model spec (the JSON/YAML semantic-layer definition with sources, columns, metrics, relationships, filters, controls, folder groupings,…
Apply Sigma rules against log sources for threat hunting; convert rules to Elasticsearch, Splunk, and grep queries
Buenas prácticas para crear commits de git claros, atómicos y bien estructurados en español. Activa esta skill siempre que el usuario pida hacer un commit, confirmar cambios,…
Es un motor de gestión de versiones que transforma cambios de código complejos en un historial atómico y semántico mediante la disección de fragmentos (hunks) y el cumplimiento…
Audit Slack channel threads for untracked work items — checks each thread against GH issues/PRs, reports gaps, and optionally redrives dropped threads by posting a status reply to…
Use when the user asks about SOC 2 — Trust Services Criteria (TSC), Type 1 vs Type 2, evidence collection, gap assessments, control design, auditor preparation, or readiness for a…
Guide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse.
Use when composing an SoC from peripherals and a bus fabric, or when generating device trees, ACPI tables, docs, or pin lists from a hardware description and they keep drifting…
Soc2 Compliance Checker - Auto-activating skill for Security Advanced. Triggers on: soc2 compliance checker, soc2 compliance checker Part of the Security Advanced skill c — from…
SOC 2 Type I and Type II compliance management. Use when conducting SOC 2 readiness assessments, performing gap analysis against Trust Services Criteria, collecting audit…
When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "complia — from…
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent,…
SOC 2 readiness for Rails apps — the 5 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy), audit log requirements, access reviews,…
Klasy ORM i wzorce kodu biznesowego enova365 / Soneta Enterprise / Triva: Row/Table/Module, sesja i transakcje (Session, Commit/CommitUI, Save, optimistic lock),…
Modo de execução contínua — Claude executa um plano ou tarefa multi-etapa do começo ao fim sem pausas, sem checkpoints, sem perguntas de confirmação.
Interactive speedrun loop for small, low-risk changes. Delegates each request to a general sub-agent. Redirects larger work to /build-fast or /build.
Medr: Mandantenkommunikation und Entscheidungsvorlage: konkreter Spezialworkflow mit Sachverhaltsklärung, Rechtsrahmen, Belegen, Risikoampel und verwertbarem Output.
Splunk integration. Manage data, records, and automate workflows. Use when the user wants to interact with Splunk data.
Deploy and validate Splunk Connect for SNMP (SC4SNMP) for Splunk Enterprise or Splunk Cloud. Prepares Splunk indexes and HEC, renders Docker Compose or Kubernetes Helm…
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Forensics (200) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)