正在加载项目…
正在加载项目…
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Conduct external recon using OSINT techniques to map an organization's external attack surface without touching target systems, gathering DNS records, certifica
其他仓库内容 · 未声明插件包归属
Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to ev
其他仓库内容 · 未声明插件包归属
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of proce
其他仓库内容 · 未声明插件包归属
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vecto
其他仓库内容 · 未声明插件包归属
Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collecto
其他仓库内容 · 未声明插件包归属
Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing cont
其他仓库内容 · 未声明插件包归属
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for te
其他仓库内容 · 未声明插件包归属
Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft fro
其他仓库内容 · 未声明插件包归属
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabil
其他仓库内容 · 未声明插件包归属
Conducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulner
其他仓库内容 · 未声明插件包归属
Perform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS tickets from LSASS memory on a compromised host and injecting them into another se
其他仓库内容 · 未声明插件包归属
Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining ma
其他仓库内容 · 未声明插件包归属
Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future i
其他仓库内容 · 未声明插件包归属
Design and execute a social engineering penetration test combining OSINT-driven target profiling with phishing, vishing, smishing, and physical pretexting campa
其他仓库内容 · 未声明插件包归属
Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness contr
其他仓库内容 · 未声明插件包归属
Run a targeted spearphishing simulation for initial access by developing OSINT-derived pretexts, building payloads (HTML smuggling, macro docs, ISO/LNK, OneNote
其他仓库内容 · 未声明插件包归属
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal by
其他仓库内容 · 未声明插件包归属
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged ac
其他仓库内容 · 未声明插件包归属
Configure AWS Verified Access to provide VPN-less zero trust network access to internal apps, combining identity trust providers (IAM Identity Center, Okta/OIDC
其他仓库内容 · 未声明插件包归属
Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering
其他仓库内容 · 未声明插件包归属
Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Us
其他仓库内容 · 未声明插件包归属
Configures Hardware Security Modules for cryptographic key storage using the PKCS#11 standard interface, covering key generation, signing, encryption, and key m
其他仓库内容 · 未声明插件包归属
Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, in
其他仓库内容 · 未声明插件包归属
Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding
其他仓库内容 · 未声明插件包归属