All categories
Business & Operations
Operations, strategy, finance, sales, support, management, and planning
- 35,228
- 1,468
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse business & operations skills
Showing 16,945–16,968 of 35,228 skills
- Cyber Reverse Engineering Malware With GhidraReverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals.Votes: 0GitHub stars: 2
- Cyber Reverse Engineering Android Malware With JadxReverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investiVotes: 0GitHub stars: 2
- Cyber Performing Asset Criticality Scoring For VulnsDevelop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.Votes: 0GitHub stars: 2
- Cyber Performing Access Review And CertificationConduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles. This skill covers review campaign design, reviewer selection, risk-based pVotes: 0GitHub stars: 2
- Cyber Mapping Mitre Attack TechniquesMaps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involviVotes: 0GitHub stars: 2
- Cyber Managing Third Party Vendor Risk>- Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, andVotes: 0GitHub stars: 2
- Cyber Implementing Anti Phishing Training ProgramSecurity awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positivVotes: 0GitHub stars: 2
- Cyber Implementing Alert Fatigue ReductionImplements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.Votes: 0GitHub stars: 2
- Cyber Generating Threat Intelligence ReportsGenerates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involviVotes: 0GitHub stars: 2
- Cyber Extracting Iocs From Malware SamplesExtracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection contenVotes: 0GitHub stars: 2
- Cyber Executing Phishing Simulation CampaignExecutes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests iVotes: 0GitHub stars: 2
- Cyber Executing Nist Rmf Authorization To Operate>- Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously. Use when a system needs an ATO or a renewal, when working a FISMA/FedRAMP authorization package, when building or reviVotes: 0GitHub stars: 2
- Cyber Evaluating Threat Intelligence PlatformsEvaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requestsVotes: 0GitHub stars: 2
- Cyber Detecting Business Email CompromiseBusiness Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,Votes: 0GitHub stars: 2
- Cyber Deploying Ransomware Canary FilesDeploys and monitors ransomware canary files across critical directories using Python''s watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files andVotes: 0GitHub stars: 2
- Cyber Deploying Decoy Files For Ransomware DetectionDeploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or fileVotes: 0GitHub stars: 2
- Cyber Building Incident Response DashboardBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.Votes: 0GitHub stars: 2
- Cyber Achieving Cmmc Level 2 Compliance>- Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoDVotes: 0GitHub stars: 2
- Cyber Exploiting Race Condition VulnerabilitiesDetect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.Votes: 0GitHub stars: 2
- Sales PsychologyAnalyze sales conversations, buyer signals, omissions, objections, positive momentum, retention, referrals, and depth-psychology hypotheses with evidence-tiered ethical guardrails. Use when the user asks for sales strategy, sales scripts, buyer psychology, closing, objection handling, NEPQ, Raving Fans, Jungian sales reads, or customer delight.Votes: 0GitHub stars: 2
- Objection Source DiagnoserDiagnose WHY a deal is accumulating objections by tracing each one back to its root-cause seller behavior. Use this skill when a customer keeps pushing back, when you're getting too many price objections, when the prospect raised concerns you don't know how to address, when a rep asks 'why does my pitch generate so much resistance?', or when someone asks 'what's wrong with my presentation?'. Invoke when someone says 'diagnose these objections', 'we keep getting price objections', 'why does th...Votes: 0GitHub stars: 2
- Nex DeliverablesClient deliverable tracking and project management system for web agencies, design studios, marketing firms, and freelancers managing multiple simultaneous projects and client relationships. Use when the user says \"track deliverables\", \"what's overdue\", \"send a status update to client\", \"add a new project deliverable\", \"I need to see what's in review\", or when managing multiple client projects with deadlines and status tracking.Votes: 0GitHub stars: 2
- Cyber Managing Third Party Vendor Risk>- Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, andVotes: 0GitHub stars: 2
- Cyber Managing Intelligence LifecycleManages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligVotes: 0GitHub stars: 2