All categories
Research
Research, evidence gathering, literature, reports, investigation, and synthesis
- 21,377
- 891
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse research skills
Showing 12,361–12,384 of 21,377 skills
- Cyber Investigating Phishing Email IncidentInvestigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.Votes: 0GitHub stars: 2
- Cyber Investigating Insider Threat IndicatorsInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.Votes: 0GitHub stars: 2
- Cyber Implementing Attack Surface ManagementImplements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM prograVotes: 0GitHub stars: 2
- Cyber Hunting Advanced Persistent ThreatsProactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITVotes: 0GitHub stars: 2
- Cyber Extracting Browser History ArtifactsExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.Votes: 0GitHub stars: 2
- Cyber Detecting Azure Service Principal AbuseDetect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.Votes: 0GitHub stars: 2
- Cyber Correlating Security Events In QradarCorrelates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.Votes: 0GitHub stars: 2
- Cyber Conducting Memory Forensics With VolatilityPerforms memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigatVotes: 0GitHub stars: 2
- Cyber Conducting Cloud Penetration TestingThis skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK CloudVotes: 0GitHub stars: 2
- Cyber Collecting Volatile Evidence From Compromised HostCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.Votes: 0GitHub stars: 2
- Cyber Building Attack Pattern Library From Cti ReportsExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.Votes: 0GitHub stars: 2
- Cyber Attacking Entra Id With Roadtools[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.Votes: 0GitHub stars: 2
- Cyber Analyzing Docker Container ForensicsInvestigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.Votes: 0GitHub stars: 2
- Cyber Acquiring Disk Image With Dd And DcflddCreate forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.Votes: 0GitHub stars: 2
- Claude Output LaneRoutes reusable Claude output (plans, ideas, findings, reviews, draft artifacts, diff proposals, questions, decisions, evidence packets) for Codex/main inspection. Use when Claude produces structured output that another lane must inspect, or when mentioning 'Claude output', 'lane handoff', 'output routing', or 'cross-lane artifact'.Votes: 0GitHub stars: 2
- Bankai ManifestFull Externalize Mode — on CRITICAL complexity tasks, externalizes cognitive state as a structured manifest (goal tree, risk map, evidence chain, failure modes, advisor consensus) before acting. Use when a task reaches CRITICAL complexity and needs full externalized reasoning before action, or when mentioning 'bankai', 'externalize', 'manifest mode', or 'full cognitive dump'.Votes: 0GitHub stars: 2
- Activate Yuri SkillsRecall and load the minimal canonical YURI skill set before every substantive YURI task, including implementation, analysis, research, planning, review, or verification. Do not use for trivial acknowledgements or status-only replies.Votes: 0GitHub stars: 2
- Ln 814 Optimization ExecutorMulti-file hypothesis testing with keep/discard loop, compound baselines, and experiment loggingVotes: 0GitHub stars: 17
- Ln 641 Pattern AnalyzerAnalyzes single pattern implementation, calculates 4 scores (compliance, completeness, quality, implementation), identifies gaps. Invoked by ln-640 or standalone.Votes: 0GitHub stars: 17
- Ln 640 Pattern Evolution AuditorAudits architectural patterns against best practices. Maintains patterns catalog, calculates 4 scores per pattern. Output: patterns_catalog.md.Votes: 0GitHub stars: 17
- Google Cloud Networking ObservabilityInvestigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics.Votes: 0GitHub stars: 17
- Decisions Harness OptimizeUse after a verified Decisions harness audit when the user asks to apply safe fixes to harness drift, dead references, stale projected skills, duplicate routing, bloated state files, or invalid local config.Votes: 0GitHub stars: 17
- HumanizerRemove signs of AI-generated writing from text. Use when editing or reviewing text to make it sound more natural and human-written. Based on Wikipedia's comprehensive "Signs of AI writing" guide. Detects and fixes patterns including: inflated symbolism, promotional language, superficial -ing analyses, vague attributions, em dash overuse, rule of three, AI vocabulary words, passive voice, negative parallelisms, and filler phrases.Votes: 0GitHub stars: 17
- Web Search PlusUnified multi-provider web search and URL extraction skill with intelligent auto-routing across Serper, Brave, Tavily, Querit, Linkup, Exa, Firecrawl, Perplexity, You.com, and SearXNG.Votes: 0GitHub stars: 11