Agent Skills by riparino
Showing 69 vetted skills indexed across 1 GitHub repositories.
defensive-cloud-hardening
Implement Azure baseline security controls for identities, access, and resources.
defensive-race-condition
Detect TOCTOU, symlink, and parallel transaction race conditions with Sigma and KQL guidance.
defensive-open-redirect
Detect open redirect abuses and protocol-relative bypasses in web applications.
defensive-threat-intelligence
Enrich and correlate threat intel data to surface actionable indicators for SOC operations.
defensive-basic-exploitation
Detect basic exploitation crashes from stack/heap overflows, use-after-free, and format-string indicators.
defensive-fast-triage
Automate SOC alert triage with severity matrices and escalation triggers.
defensive-ai-security
Detect prompt injections and jailbreak attempts in AI systems.
defensive-vuln-classes
Map vulnerability classes to defensive skills and detection coverage gaps.
defensive-incident-response
Guides security teams through structured incident response using the PICERL lifecycle and KQL queries.
defensive-threat-hunting
Run hypothesis-driven threat hunts with KQL queries and MITRE mappings.
defensive-soc-workflows
Standardize SOC triage, escalation, and shift handoff workflows.
defensive-exposure-management
Discover internet-facing assets and detect exposure risks across cloud and on-prem environments.
defensive-ssrf
Detect SSRF exploitation attempts across cloud metadata endpoints and internal network calls.
defensive-detection-engineering
Automates Sigma rule development, validation, and deployment with MITRE Navigator mapping and FP tuning for SIEM pipelines.
defensive-sqli
Correlate web, WAF, and database logs to detect SQL injection attempts.
defensive-oauth
Detect OAuth abuse and consent-related security incidents in Entra ID environments.
defensive-graphql
Detect GraphQL introspection abuse, batch attacks, and deep-nested queries.
defensive-log-analysis
Reference KQL log tables and retention policies for Sentinel deployments.
defensive-shellcode
Detect shellcode in memory using YARA rules and KQL telemetry.
defensive-exploit-detection
Correlate Windows application crashes with shell launches to detect exploit attempts.
defensive-xxe
Detect and triage XXE vulnerabilities in XML processing pipelines.
defensive-file-upload
Detect webshell uploads using YARA, Sigma, and KQL queries.
defensive-vulnerability-management
Automates vulnerability prioritization and remediation using KQL enrichment and patch verification.
defensive-keylogger-detection
Detect keylogger activity using YARA rules and API hook detection.