Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
127 results
Skill

hunting-for-dns-tunneling-with-zeek

Detects DNS tunneling and covert-channel data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, abnormally long query lengths, and unusual DNS record t

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-domain-fronting-c2-traffic

Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. Use when hunting for command-and-control t

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-lateral-movement-via-wmi

Detects WMI-based lateral movement (e.g. wmic process call create, Win32_Process.Create()) by analyzing Windows Event ID 4688 and Sysmon Event ID 1 for WmiPrvSE.exe spawning suspicious child processes

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-living-off-the-cloud-techniques

Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. "living off the cloud" tradecraft that blends

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-lolbins-execution-in-endpoint-logs

Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries used

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-persistence-mechanisms-in-windows

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use whe

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-persistence-via-wmi-subscriptions

Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003) by monitoring the creation of WMI event filters, consumers, and filter-to-consumer bindings that trigger malicious code ex

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-process-injection-techniques

Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10 (Process

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-registry-persistence-mechanisms

Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image File Execution Options (IFEO) debugger i

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-registry-run-key-persistence

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-scheduled-task-persistence

Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual sc

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-shadow-copy-deletion

Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. Use when huntin

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-spearphishing-indicators

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-startup-folder-persistence

Detects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for real-t

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-supply-chain-compromise

Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and tampe

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-suspicious-scheduled-tasks

Hunts for adversary persistence and execution via Windows scheduled tasks (T1053.005) by analyzing Security Event ID 4698 task-creation events, suspicious task properties, and unusual execution patter

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-t1098-account-manipulation

Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-unusual-network-connections

Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and unusual

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-unusual-service-installations

Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms v

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-webshell-activity

Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server pr

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-saas-sso-token-abuse

Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session events to spot impos

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-velociraptor-for-ir-collection

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS en

by mukul975skills.sh
Not rated yet
Free
Skill

performing-cloud-native-threat-hunting-with-aws-detective

Investigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entity timelines and profile IAM users, roles

by mukul975skills.sh
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.