# sectinel

Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.

- Tier: Indexed (plain plugin)
- Category: Security
- Page: https://www.flowy.sh/listings/mikaru0mystic-sectinel
- Source: https://github.com/Mikaru0Mystic/sectinel
- Price: free and open source

## Summary
sectinel is a Claude Code plugin with 200 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes acquiring-disk-image-with-dd-and-dcfldd, analyzing-active-directory-acl-abuse, analyzing-android-malware-with-apktool. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.

## Install (Claude Code)
```
npx -y skills add mikaru0mystic/sectinel
```

## Skills
- acquiring-disk-image-with-dd-and-dcfldd
- analyzing-active-directory-acl-abuse
- analyzing-android-malware-with-apktool
- analyzing-api-gateway-access-logs
- analyzing-apt-group-with-mitre-navigator
- analyzing-azure-activity-logs-for-threats
- analyzing-bootkit-and-rootkit-samples
- analyzing-browser-forensics-with-hindsight
- analyzing-campaign-attribution-evidence
- analyzing-certificate-transparency-for-phishing
- analyzing-cloud-storage-access-patterns
- analyzing-cobalt-strike-beacon-configuration
- analyzing-cobaltstrike-malleable-c2-profiles
- analyzing-command-and-control-communication
- analyzing-cyber-kill-chain
- analyzing-disk-image-with-autopsy
- analyzing-dns-logs-for-exfiltration
- analyzing-docker-container-forensics
- analyzing-email-headers-for-phishing-investigation
- analyzing-ethereum-smart-contract-vulnerabilities
- analyzing-golang-malware-with-ghidra
- analyzing-heap-spray-exploitation
- analyzing-indicators-of-compromise
- analyzing-ios-app-security-with-objection
- analyzing-kubernetes-audit-logs
- analyzing-linux-audit-logs-for-intrusion
- analyzing-linux-elf-malware
- analyzing-linux-kernel-rootkits
- analyzing-linux-system-artifacts
- analyzing-lnk-file-and-jump-list-artifacts
- analyzing-macro-malware-in-office-documents
- analyzing-malicious-pdf-with-peepdf
- analyzing-malicious-url-with-urlscan
- analyzing-malware-behavior-with-cuckoo-sandbox
- analyzing-malware-family-relationships-with-malpedia
- analyzing-malware-persistence-with-autoruns
- analyzing-malware-sandbox-evasion-techniques
- analyzing-memory-dumps-with-volatility
- analyzing-memory-forensics-with-lime-and-volatility
- analyzing-mft-for-deleted-file-recovery
- analyzing-network-covert-channels-in-malware
- analyzing-network-flow-data-with-netflow
- analyzing-network-packets-with-scapy
- analyzing-network-traffic-for-incidents
- analyzing-network-traffic-of-malware
- analyzing-network-traffic-with-wireshark
- analyzing-office365-audit-logs-for-compromise
- analyzing-outlook-pst-for-email-forensics
- analyzing-packed-malware-with-upx-unpacker
- analyzing-pdf-malware-with-pdfid
- analyzing-persistence-mechanisms-in-linux
- analyzing-powershell-empire-artifacts
- analyzing-powershell-script-block-logging
- analyzing-prefetch-files-for-execution-history
- analyzing-ransomware-encryption-mechanisms
- analyzing-ransomware-leak-site-intelligence
- analyzing-ransomware-network-indicators
- analyzing-ransomware-payment-wallets
- analyzing-sbom-for-supply-chain-vulnerabilities
- analyzing-security-logs-with-splunk
- analyzing-slack-space-and-file-system-artifacts
- analyzing-supply-chain-malware-artifacts
- analyzing-threat-actor-ttps-with-mitre-attack
- analyzing-threat-actor-ttps-with-mitre-navigator
- analyzing-threat-intelligence-feeds
- analyzing-threat-landscape-with-misp
- analyzing-tls-certificate-transparency-logs
- analyzing-typosquatting-domains-with-dnstwist
- analyzing-uefi-bootkit-persistence
- analyzing-usb-device-connection-history
- analyzing-web-server-logs-for-intrusion
- analyzing-windows-amcache-artifacts
- analyzing-windows-event-logs-in-splunk
- analyzing-windows-lnk-files-for-artifacts
- analyzing-windows-prefetch-with-python
- analyzing-windows-registry-for-artifacts
- analyzing-windows-shellbag-artifacts
- auditing-aws-s3-bucket-permissions
- auditing-azure-active-directory-configuration
- auditing-cloud-with-cis-benchmarks
- auditing-gcp-iam-permissions
- auditing-kubernetes-cluster-rbac
- auditing-terraform-infrastructure-for-security
- auditing-tls-certificate-transparency-logs
- automating-ioc-enrichment
- building-adversary-infrastructure-tracking-system
- building-attack-pattern-library-from-cti-reports
- building-automated-malware-submission-pipeline
- building-c2-infrastructure-with-sliver-framework
- building-cloud-siem-with-sentinel
- building-detection-rule-with-splunk-spl
- building-detection-rules-with-sigma
- building-devsecops-pipeline-with-gitlab-ci
- building-identity-federation-with-saml-azure-ad
- building-identity-governance-lifecycle-process
- building-incident-response-dashboard
- building-incident-response-playbook
- building-incident-timeline-with-timesketch
- building-ioc-defanging-and-sharing-pipeline
- building-ioc-enrichment-pipeline-with-opencti
- building-malware-incident-communication-template
- building-patch-tuesday-response-process
- building-phishing-reporting-button-workflow
- building-ransomware-playbook-with-cisa-framework
- building-red-team-c2-infrastructure-with-havoc
- building-role-mining-for-rbac-optimization
- building-soc-escalation-matrix
- building-soc-metrics-and-kpi-tracking
- building-soc-playbook-for-ransomware
- building-threat-actor-profile-from-osint
- building-threat-feed-aggregation-with-misp
- building-threat-hunt-hypothesis-framework
- building-threat-intelligence-enrichment-in-splunk
- building-threat-intelligence-feed-integration
- building-threat-intelligence-platform
- building-vulnerability-aging-and-sla-tracking
- building-vulnerability-dashboard-with-defectdojo
- building-vulnerability-exception-tracking-system
- building-vulnerability-scanning-workflow
- bypassing-authentication-with-forced-browsing
- collecting-indicators-of-compromise
- collecting-open-source-intelligence
- collecting-threat-intelligence-with-misp
- collecting-volatile-evidence-from-compromised-host
- conducting-api-security-testing
- conducting-cloud-incident-response
- conducting-cloud-penetration-testing
- conducting-domain-persistence-with-dcsync
- conducting-external-reconnaissance-with-osint
- conducting-full-scope-red-team-engagement
- conducting-internal-network-penetration-test
- conducting-internal-reconnaissance-with-bloodhound-ce
- conducting-malware-incident-response
- conducting-man-in-the-middle-attack-simulation
- conducting-memory-forensics-with-volatility
- conducting-mobile-app-penetration-test
- conducting-network-penetration-test
- conducting-pass-the-ticket-attack
- conducting-phishing-incident-response
- conducting-post-incident-lessons-learned
- conducting-social-engineering-penetration-test
- conducting-social-engineering-pretext-call
- conducting-spearphishing-simulation-campaign
- conducting-wireless-network-penetration-test
- configuring-active-directory-tiered-model
- configuring-aws-verified-access-for-ztna
- configuring-certificate-authority-with-openssl
- configuring-host-based-intrusion-detection
- configuring-hsm-for-key-storage
- configuring-identity-aware-proxy-with-google-iap
- configuring-ldap-security-hardening
- configuring-microsegmentation-for-zero-trust
- configuring-multi-factor-authentication-with-duo
- configuring-network-segmentation-with-vlans
- configuring-oauth2-authorization-flow
- configuring-pfsense-firewall-rules
- configuring-snort-ids-for-intrusion-detection
- configuring-suricata-for-network-monitoring
- configuring-tls-1-3-for-secure-communications
- configuring-windows-defender-advanced-settings
- configuring-windows-event-logging-for-detection
- configuring-zscaler-private-access-for-ztna
- containing-active-breach
- correlating-security-events-in-qradar
- correlating-threat-campaigns
- deobfuscating-javascript-malware
- deobfuscating-powershell-obfuscated-malware
- deploying-active-directory-honeytokens
- deploying-cloudflare-access-for-zero-trust
- deploying-decoy-files-for-ransomware-detection
- deploying-edr-agent-with-crowdstrike
- deploying-osquery-for-endpoint-monitoring
- deploying-palo-alto-prisma-access-zero-trust
- deploying-ransomware-canary-files
- deploying-software-defined-perimeter
- deploying-tailscale-for-zero-trust-vpn
- detecting-ai-model-prompt-injection-attacks
- detecting-anomalies-in-industrial-control-systems
- detecting-anomalous-authentication-patterns
- detecting-api-enumeration-attacks
- detecting-arp-poisoning-in-network-traffic
- detecting-attacks-on-historian-servers
- detecting-attacks-on-scada-systems
- detecting-aws-cloudtrail-anomalies
- detecting-aws-credential-exposure-with-trufflehog
- detecting-aws-guardduty-findings-automation
- detecting-aws-iam-privilege-escalation
- detecting-azure-lateral-movement
- detecting-azure-service-principal-abuse
- detecting-azure-storage-account-misconfigurations
- detecting-beaconing-patterns-with-zeek
- detecting-bluetooth-low-energy-attacks
- detecting-broken-object-property-level-authorization
- detecting-business-email-compromise-with-ai
- detecting-business-email-compromise
- detecting-cloud-threats-with-guardduty
- detecting-command-and-control-over-dns
- detecting-compromised-cloud-credentials
- detecting-container-drift-at-runtime
- detecting-container-escape-attempts

## FAQ

### What is sectinel?
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.

### How do I install sectinel?
Run these in Claude Code: npx -y skills add mikaru0mystic/sectinel. Then prompt normally.

### Does sectinel auto-invoke its skills?
Not yet. It is indexed on Flowy as a plain plugin. Request auto-invocation on its page and Flowy will route its skills for you as you prompt.

### Is sectinel free?
Yes. Flowy is free and open source, with nothing gated. You can read every skill in full before you install.
