reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
$ npx -y skills add zhaoxuya520/reverse-skill --skill threat-hunting --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/threat-huntingContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
name: threat-hunting description: Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
1. `NOW`: 确认蓝队/狩猎授权与数据源范围(SIEM、EDR 导出) 2. `NOW`: 明确假说(hypothesis)再查数,避免无脑刷告警 3. `NEXT`: 工具与数据接入方式 4. `ACT`: 假说 → 查询 → 验证 → 规则化
例:攻击者用 living-off-the-land 做横向 → 数据源:Sysmon 1/3/10、Windows Security 4624/4648 → 成功标准:发现异常父进程或罕见账户日志源
□ 基线:正常管理员行为时段与主机 □ 异常:新服务、编码 PowerShell、异常出站 □ 关联:同账号多主机短时登录
# Sigma 骨架见 malware-analysis;本 skill 强调: # - 误报面 # - 数据源字段映射 # - 响应 playbook 链接
□ 原子测试(Atomic Red Team)仅在授权实验室 □ 回放历史日志验证召回
| 工具 | 用途 | |------|------| | Sigma CLI / sigmac | 规则转换 | | YARA | 文件/内存 | | SIEM(ELK/Splunk 等) | 查询 | | osquery | 端点狩猎 | | Atomic Red Team | 检测验证(实验室) |
**上游**: MASTER R27 **下游**: 确认入侵 → forensics;恶意样本 → malware-analysis **MUST NOT**: 在无授权生产环境跑攻击模拟
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…