Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
45 results
Skill

conducting-internal-network-penetration-test

Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within t

by mukul975skills.sh
Not rated yet
Free
Skill

conducting-pass-the-ticket-attack

Perform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS tickets from LSASS memory on a compromised host and injecting them into another session to impersonate the ticket owner wi

by mukul975skills.sh
Not rated yet
Free
Skill

configuring-microsegmentation-for-zero-trust

Configures microsegmentation policies to enforce least-privilege workload-to-workload access using tools such as VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architecture

by mukul975skills.sh
Not rated yet
Free
Skill

containing-active-breach

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segme

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-attacks-on-historian-servers

Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement indic

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-azure-lateral-movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, to

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-lateral-movement-in-network

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to det

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-lateral-movement-with-splunk

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. Use when hunting for MITRE ATT&C

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-lateral-movement-with-zeek

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfe

by mukul975skills.sh
Not rated yet
Free
Skill

exploiting-constrained-delegation-abuse

Exploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4U2Proxy and imperson

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-dcom-lateral-movement

Hunt for DCOM-based lateral movement (MITRE ATT&CK T1021.003) by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects via Sysmon Event ID 1/3 correlation, WMI event a

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-lateral-movement-via-wmi

Detects WMI-based lateral movement (e.g. wmic process call create, Win32_Process.Create()) by analyzing Windows Event ID 4688 and Sysmon Event ID 1 for WmiPrvSE.exe spawning suspicious child processes

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-microsegmentation-with-guardicore

Implements microsegmentation with Akamai Guardicore Segmentation to map application dependencies, visualize east-west traffic flows, and create granular, least-privilege network policies across VMs, c

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-network-deception-with-honeypots

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-network-segmentation-with-firewall-zones

Designs and implements network segmentation using firewall security zones, VLANs, inter-zone ACLs, and workload-level microsegmentation to restrict east-west lateral movement and enforce least-privile

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-siem-correlation-rules-for-apt

Write multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1), an

by mukul975skills.sh
Not rated yet
Free
Skill

moving-laterally-with-netexec

Use NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, password-spray safely across lockout thresholds, execute commands, and dump SAM/LSA/NTDS credentials across SMB, WinRM, LD

by mukul975skills.sh
Not rated yet
Free
Skill

performing-active-directory-compromise-investigation

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movemen

by mukul975skills.sh
Not rated yet
Free
Skill

performing-credential-access-with-lazagne

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team

by mukul975skills.sh
Not rated yet
Free
Skill

performing-deception-technology-deployment

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive

by mukul975skills.sh
Not rated yet
Free
Skill

performing-lateral-movement-detection

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading by correlating Windows Security/Sysmon event logs, network flow data (NetFlow/

by mukul975skills.sh
Not rated yet
Free
Skill

performing-lateral-movement-with-wmiexec

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-siem-correlation-rules-for-apt

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL a

by 26zlGitHub
Not rated yet
Free
Skill

implementing-siem-correlation-rules-for-apt

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL a

by megawesley2015-langGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.