Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Threat Hunting › Page 8

Threat Hunting (Page 8 of 13)

754 Claude Code skills in the Threat Hunting sub-category of Security.

754 skills · updated 2026-08-26 · showing 421–480 of 754 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

NIST 800-53 control framework expert. Provides guidance on control families, baseline selection, tailoring, and federal compliance requirements including FedRAMP alignment.
Applies a standing safety guardrail. No file, folder, email or calendar item is deleted, overwritten or moved without explicit user approval, new versioned files are written…
Build and manage automations across Make.com, n8n, Zapier, and Pipedream — onboarding, support tickets, content
Use when creating, modernizing, or production-hardening a Node.js backend service after backend architecture is approved or intentionally deferred.
Nodriver is the official successor to Undetected-Chromedriver, providing async browser automation that communicates directly with Chrome DevTools Protocol without Selenium or…
Prüft notarielle Amtspflichten im Bauträgervertrag: § 17 BeurkG, § 14 BNotO, § 19 BNotO, MaBV-/AGB-Klauselkontrolle, Preisanpassung, § 650m-Sicherheit, Niedrig-Grundstücksanteil,…
Bring up NVIDIA HGX/DGX datacenter GPU hosts on Ubuntu 24.04 LTS — air-gapped or connected, Secure Boot enabled.
Off-Label bei seltener Erkrankung: moderner Medizinrechts-Skill für Off-Label-Use, Seltenheit, Datenlage, lebensbedrohliche Erkrankung und GKV-Erstattung: Off-Label bei seltener…
Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth…
Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode…
Extract manually supplied Microsoft Copilot and Microsoft 365 Copilot chats into standalone, actionable Markdown.
Formuleer team-OKRs die aligned zijn met bedrijfsdoelen. Scherpe Objectives met meetbare Key Results, inclusief kwaliteitscheck en veelgemaakte fouten.
Automate OneDrive file management, search, uploads, downloads, sharing, permissions, and folder operations via Rube MCP (Composio). Always search tools first for current schemas.
MS OneDrive integration. Manage Accounts. Use when the user wants to interact with MS OneDrive data.
Render data visualizations with Canvas2D. Use when the visualization needs high mark counts, fast redraws, immediate-mode rendering, custom hit testing, or a hybrid Canva — from…
Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a…
Diagnose and fix "This model does not support assistant message prefill. The conversation must end with a user message." errors when running Anthropic models through OpenRouter…
Instrument multi-agent swarms with OpenTelemetry spans, semantic drift monitoring, anomaly detection, distributed trace propagation across 87 agents, and SIEM bridge export for…
Run MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
Orquestador maestro del Financial Intelligence System. ACTÍVALO SIEMPRE como primer paso ante cualquier consulta financiera de mediana o alta complejidad.
Evita errores por comandos incompatibles verificando SIEMPRE el SO antes de sugerir instalaciones. Trigger: "instalar", "upgrade", "apt", "brew", "winget", "configurar sistema",…
Find unclaimed open source issues that match the user's skills and experience level. Searches for issues created by maintainers/org admins, checks contribution eligibility, and…
Pandektenwissenschaft und Begriffsjurisprudenz im 19. Jahrhundert. Georg Friedrich Puchta, Bernhard Windscheid, Hauptvertreter. Begriffspyramide und logisches Ableitungsmodell.
Inspecteur des finances publiques IA. Simule un contrôle fiscal DGFIP complet sur les comptes d'une entreprise française (SASU, EURL, SAS, SARL).
Use this when working in the guided-experience-service repository and the user wants to run all unit tests and integration tests in parallel.
Systematically identify and classify technical and business risks using the risk-centric PASTA framework across seven stages: 1. Define the Objectives, 2.
Use when authoring or editing a Power BI report theme JSON under Report.Report/StaticResources/SharedResources/BaseThemes/ or RegisteredResources/.
Analiza textos aplicando pensamiento crítico — el marco de los 8 elementos del pensamiento y los estándares intelectuales universales de Richard Paul y Linda Elder — y detecta las…
Estima de forma orientativa la pensión de alimentos y la pensión compensatoria en procesos de familia. Usa las tablas orientadoras del CGPJ para alimentos y los criterios del art.
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy,
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security
Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement,
Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan,
Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization,
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to
Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.
Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack
Genera fragmentos de código inicial funcionales para Arduino IDE y ESP-IDF a partir del mapeo de pines y periféricos de un microcontrolador ESP32.
Threat library for physical-access threats that STRIDE and OWASP Top 10 don't cover — evil-maid, DMA, hostile peripheral, travel-host, coercion, cold-boot, supply-chain implant,…
Control Pi agent sessions, models, tools, and workflows. Gebruik dit om Pi's gedrag te beheren, sessies te navigeren, en workflows te automatiseren.
Helps configure and use the GoBilda Pinpoint odometry computer for robot localization. Use when setting up Pinpoint, configuring pod offsets, troubleshooting LED status, tuning…
Pipedream is a developer-focused workflow platform for connecting APIs and running automation logic in hosted workflows.
Connect 2,000+ APIs with managed OAuth via Pipedream. Includes full UI integration for OpenClaw Gateway dashboard with per-agent app isolation.
Pipedream serverless workflows — triggers, code steps, pre-built actions, data stores, HTTP
Pipedrive integration. Manage crm and sales data, records, and workflows. Use when the user wants to interact with Pipedrive data.
Use Pipedrive REST API v1 from an integration. Use when reading or writing deals, persons, organizations, leads, or activities.
Automate Pipedrive CRM operations including deals, contacts, organizations, activities, notes, and pipeline management via Rube MCP (Composio).
Receive and authenticate Pipedrive webhooks. Use when setting up Pipedrive webhook handlers, debugging HTTP Basic Auth verification, or handling CRM events like create.deal,…
Documenta progreso y marca tareas completadas en PLAN_MEJORAS.md. Usa SIEMPRE después de completar cualquier tarea del plan de mejoras.
Expertise in FedRAMP POA&M lifecycle management, FedRAMP 20x VDR generation, and vulnerability classification using CISA KEV, EPSS, N-ratings, LEV/IRV, and NIST 800-53 control…
Produce a proposed marked-up policy redraft that closes a gap found by /regulatory-legal:gaps or /regulatory-legal:policy-diff.
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir.
Transform one existing image into a new image through the PopiArt runtime baseline. Use this when the user already has a source image and wants the most direct image-to-image path…
Recurring engagement harvest for Pedro's social posts. Opens a browser, sweeps a week or month of his LinkedIn and/or Twitter/X posts, reads each post's impressions, reactions,…
Use when Power BI sources include APM, observability, logs, metrics, traces, IT Ops, Splunk, Datadog, Dynatrace, New Relic, Azure Monitor, Grafana, Prometheus, or data platform…
Use any time the user wants to author, debug, optimize, explain, or run a SentinelOne PowerQuery (PQ) — Deep Visibility / Event Search queries, XDR/EDR threat hunting,…
Use when you have a small training dataset for molecular property prediction (e.g., <500 samples from PredRet or MoNA databases) and a pre-trained GNN model is available that was…
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Identity Access (496) · Network Security (414) · Appsec Tools (381) · Forensics (295) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Zero Trust (82) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)