Skip to main content

Skills neste repositório

oyi77/1ai-skills - Página 2

O SkillsMP coletou 1.311 skills de oyi77/1ai-skills. Abra uma skill para revisar a origem e os detalhes.

oyi77/1ai-skills

Mostrando 40 de 1.311 skills coletadas.

ocupação
Outras ocupações de informática
descrição

Use when automatically discover, evaluate, and activate community skills when local skills don't cover user needs. Includes credibility scoring and safety checks for complete OpenClaw self-sufficiency.

Idioma do texto original: inglês

atualizado
ocupação
Outras ocupações de informática
descrição

Use when knowledge base and memory system for AI agents. Covers company KB, persistent memory, session recall, and brain architecture for context preservation.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when generating and managing vector embeddings for semantic search and RAG retrieval across knowledge bases.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when using the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when executing malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when identifying and unpacking UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when parsing Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculating risk scores,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when querying Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when detecting typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when analyzing UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when this skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when building an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when this skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when building an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when openCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when implementing a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when building a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when deploying MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when building automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Use when systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when this skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when responding to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Conducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security posture of network…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when responding to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when implementing Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative f

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when a Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when hardening LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when deploying Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when configuring secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when parsing and analyzing Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Use when mapping advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations,…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 1.311 skills coletadas.