Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
127 results
Skill

analyzing-azure-activity-logs-for-threats

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds

by mukul975skills.sh
Not rated yet
Free
Skill

analyzing-cobalt-strike-beacon-configuration

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.

by mukul975skills.sh
Not rated yet
Free
Skill

analyzing-cobaltstrike-malleable-c2-profiles

Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sle

by mukul975skills.sh
Not rated yet
Free
Skill

analyzing-persistence-mechanisms-in-linux

Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlat

by mukul975skills.sh
Not rated yet
Free
Skill

analyzing-powershell-empire-artifacts

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded

by mukul975skills.sh
Not rated yet
Free
Skill

building-threat-hunt-hypothesis-framework

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, S

by mukul975skills.sh
Not rated yet
Free
Skill

deploying-osquery-for-endpoint-monitoring

Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visib

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-azure-lateral-movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, to

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-beaconing-patterns-with-zeek

Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standa

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-dcsync-attack-in-active-directory

Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs a

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-dll-sideloading-attacks

Detect DLL side-loading and search-order hijacking (MITRE T1574) where adversaries plant malicious DLLs for legitimate signed applications to load, by analyzing Sysmon Event ID 7 DLL-load events, chec

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-email-forwarding-rules-attack

Detect malicious inbox/mail-flow forwarding rules that adversaries create to maintain persistent access to email communications for intelligence collection and business email compromise. Use when hunt

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-entra-offensive-tools-in-graph-logs

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and AzureHou

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-evasion-techniques-in-endpoint-logs

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoin

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-exfiltration-over-dns-with-zeek

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains, oversized TXT/NULL records, and anomalous query volume or patterns. Use when investigating suspected DNS tunne

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-golden-ticket-attacks-in-kerberos-logs

Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible t

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-insider-threat-behaviors

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft. Use when proactively threat-

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-kerberoasting-attacks

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests (Event ID 4769) targeting service accounts with SPNs, which attackers request offline to crack service account passwords.

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-lateral-movement-with-splunk

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. Use when hunting for MITRE ATT&C

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-living-off-the-land-with-lolbas

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis with Sysmon endpoint

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-malicious-scheduled-tasks-with-sysmon

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst c

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-mimikatz-execution-patterns

Detect Mimikatz credential-dumping activity via command-line pattern matching, LSASS access signatures, binary/hash indicators, and in-memory detection of known Mimikatz modules. Use when threat hunti

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-network-anomalies-with-zeek

Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for organizati

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-ntlm-relay-with-event-correlation

Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDAP signing, and flagg

by mukul975skills.sh
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.