SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

mcp-security
Expert, tool-aware guidance for proactive threat hunting: formulate SIEM/UDM queries, iterate searches, enrich findings, and produce case or report outputs.

MITRE ATT&CK Agent Skills
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi

MITRE ATT&CK Agent Skills
Defensive analysis aid for MITRE ATT&CK T1564.001 to help triage, detection engineering, hunting, and incident response around hidden files and directories.

MITRE ATT&CK Agent Skills
Defensive analysis skill for MITRE ATT&CK T1557.001: helps triage, detection engineering, hunting, and incident response for name-resolution poisoning and SMB r

MITRE ATT&CK Agent Skills
Defensive analysis skill for MITRE ATT&CK T1633.001 (System Checks) — aids triage, detection engineering, hunting, and emulation planning for mobile platforms.

MITRE ATT&CK Agent Skills
Defensive analysis skill for MITRE ATT&CK T1560.003: helps map observations, produce detection ideas, and create triage and mitigation briefs for custom archive

MITRE ATT&CK Agent Skills
Defensive analysis skill for MITRE ATT&CK T1569.001 (Launchctl): detection, triage, and mitigation guidance for macOS adversary activity.

claude-skill-registry
Guided procedures and tool-aware workflows for proactive threat hunting (IOCs, TTPs, SIEM queries) and producing triage reports.

Anthropic Cybersecurity Skills
Detect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP profile matching, and timing analysis in Zeek/Su

xalgorix
Framework and workflow to turn threat intelligence and telemetry into testable, falsifiable threat-hunting hypotheses for proactive detection.

MITRE ATT&CK Agent Skills
Analyze and detect the T1074 'Data Staged' technique in enterprise environments, supporting TTP triage and detection engineering.

MITRE ATT&CK Agent Skills
Analyzes the T1583.006 sub-technique (Web Services) for triage, detection engineering, and incident response mapping.