Category

Research

Research, evidence gathering, literature, reports, investigation, and synthesis

20,833
skills in category
869
pages available
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browser

Browse research skills

Showing 14,977–15,000 of 20,833 skills

Hunting For Shadow Copy DeletionA

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.

researchshellsecurity
0
61
Hunting For Scheduled Task PersistenceA

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

researchshellsecurity
0
61
Hunting For Registry Persistence MechanismsA

Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.

researchgoshell
0
61
Hunting For Living Off The Land BinariesA

Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.

researchrustshell
0
61
Hunting Advanced Persistent ThreatsA

Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.

researchgoshell
0
61
Hatchery PapersA

Chicken Scheme Hatchery eggs and academic papers for color logic, 2TDX,

researchpythongo
0
61
Glass Bead GameA

Hesse-inspired interdisciplinary synthesis game with Badiou triangle

researchgoruby
0
61
Gh InteractomeA

GitHub author interaction network discovery. Maps cobordisms between

researchpythongo
0
61
Geiser ChickenA

Geiser REPL integration for Chicken Scheme with SplitMixTernary 3-coloring and crdt.el sexp patterns.

researchgobash
0
61
Frustration EradicationA

Frustration Eradication Skill

researchpythonrust
0
61
Forward Forward LearningA

Hinton's Forward-Forward algorithm for local learning without backpropagation.

researchpythongo
0
61
FfmpegA

Media processing (10 man pages).

researchgobash
0
61
ExternalA

External skill interface for integration with external systems

researchgo
0
61
Exa SearchA

Use Exa for semantic/neural web search. Exa understands context and returns high-quality results. Use this skill when you need to search the web for documentation, research, or any information that requires understanding meaning rather than just keyword matching. NEVER substitute web_search for Exa - they serve completely different purposes.

researchgodocumentation
0
61
Epistemic ArbitrageA

Propagator-based parallel structure for exploiting knowledge differentials

researchgoruby
0
61
ElispA

Emacs Lisp reference (106K lines info).

researchgo
0
61
Duck AgentA

DuckDB file discovery agent with verified absolute paths

researchgobash
0
61
Directed IntervalA

Directed interval type 2 axiomatizing (0 → 1). Time-directed homotopy

researchgoruby
0
61
Detecting Suspicious Powershell ExecutionA

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

researchshellsecurity
0
61
Detecting Service Account AbuseA

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

researchgosql
0
61
Detecting Privilege Escalation AttemptsA

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

researchsecurity
0
61
Detecting Pass The Hash AttacksA

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

researchgosecurity
0
61
Detecting Mimikatz Execution PatternsA

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

researchgoshell
0
61
Detecting Kerberoasting AttacksA

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.

researchgosecurity
0
61