acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
$ npx -y skills add Mikaru0Mystic/sectinel --skill building-patch-tuesday-response-process --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/building-patch-tuesday-response-processContext preview
The summary Claude sees to decide when to auto-load this skill.
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
name: building-patch-tuesday-response-process description: Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs. domain: cybersecurity subdomain: vulnerability-management tags: - patch-management - patch-tuesday - microsoft - wsus - sccm - vulnerability-remediation - windows-update version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - ID.RA-01 - ID.RA-02 - ID.IM-02 - ID.RA-06
Microsoft releases security updates on the second Tuesday of each month ("Patch Tuesday"), addressing vulnerabilities across Windows, Office, Exchange, SQL Server, Azure services, and other products. In 2025, Microsoft patched over 1,129 vulnerabilities across the year -- an 11.9% increase from 2024 -- making a structured response process critical. The leading risk types include elevation of privilege (49%), remote code execution (34%), and information disclosure (7%). This skill covers building a repeatable Patch Tuesday response workflow from initial advisory review through testing, deployment, and validation.
| Day | Activity | Owner | |-----|----------|-------| | T+0 (Tuesday 10 AM PT) | Microsoft releases patches and advisories | Microsoft | | T+0 (Tuesday afternoon) | Security team reviews advisories and triages | Security Ops | | T+1 (Wednesday) | Qualys/vendor scan signatures updated | VM Platform | | T+1-T+2 | Emergency patches deployed for zero-days | IT Operations | | T+2-T+5 | Test patches in staging environment | QA/IT Ops | | T+5-T+7 | Deploy to Pilot group (5-10% of fleet) | IT Operations | | T+7-T+14 | Deploy to Production Ring 1 (servers) | IT Operations | | T+14-T+21 | Deploy to Production Ring 2 (workstations) | IT Operations | | T+21-T+30 | Validation scanning and compliance reporting | Security Ops |
| Category | Criteria | Response SLA | |----------|----------|-------------| | Zero-Day / Exploited | Active exploitation confirmed, CISA KEV listed | 24-48 hours | | Critical RCE | CVSS >= 9.0, remote code execution, no auth required | 3-5 days | | Critical with Exploit | Public exploit code or EPSS > 0.7 | 7 days | | High Severity | CVSS 7.0-8.9, privilege escalation | 14 days | | Medium Severity | CVSS 4.0-6.9 | 30 days | | Low / Informational | CVSS < 4.0, defense-in-depth | Next maintenance window |
| Category | Products | Risk Level | |----------|----------|------------| | Windows OS | Windows 10, 11, Server 2016-2025 | Critical | | Exchange Server | Exchange 2016, 2019, Online | Critical | | SQL Server | SQL 2016-2022 | High | | Office Suite | Microsoft 365, Office 2019-2024 | High | | .NET Framework | .NET 4.x, .NET 6-9 | Medium | | Azure Services | Azure AD, Entra ID, Azure Stack | High | | Edge/Browser | Edge Chromium, IE mode | Medium | | Development Tools | Visual Studio, VS Code | Low |
Preparation Checklist: [ ] Confirm WSUS/SCCM sync schedules are active [ ] Verify test environment is available and current [ ] Review outstanding patches from previous month [ ] Confirm monitoring dashboards are operational [ ] Pre-stage communication templates [ ] Ensure rollback procedures are documented [ ] Verify backup jobs ran successfully on critical servers
Triage Process: 1. Monitor MSRC Update Guide (https://msrc.microsoft.com/update-guide) 2. Review Microsoft Security Blog for advisory summaries 3. Cross-reference with CISA KEV additions (same day) 4. Check vendor advisories (Qualys, Rapid7, CrowdStrike analysis) 5. Identify zero-day and actively exploited vulnerabilities 6. Classify each CVE by severity and applicability 7. Determine deployment rings and timeline for each patch 8. Submit emergency change request for zero-day patches 9. Communicate triage results to IT Operations and management
# Post-Patch-Tuesday scan workflow
def run_patch_tuesday_scan(scanner_api, target_groups):
"""Trigger vulnerability scans after Patch Tuesday updates."""
for group in target_groups:
print(f"[*] Scanning {group['name']}...")
scan_id = scanner_api.launch_scan(
target=group["targets"],
template="patch-tuesday-focused",
credentials=group["creds"]
)
print(f" Scan launched: {scan_id}")
# Wait for scan completion, then generate report
results = scanner_api.get_scan_results(scan_id)
missing_patches = [r for r in results if r["status"] == "missing"]
# Categorize by Patch Tuesday release
current_month = [p for p in missing_patches
if p["vendor_advisory_date"] >= patch_tuesday_date]
return {
"total_missing": len(missing_patches),
"current_month": len(current_month),
"zero_day": [p for p in current_month if p.get("actively_exploited")],
"critical": [p for p in current_month if p["cvss"] >= 9.0],
}Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative