building-ioc-defanging…
Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing
A skill ships inside a plugin. Install the plugin, and a skill that gets Auto-invokedWhat is this?This plugin ships a FLOW.md router the engine fires, so the matching skill runs itself. No slash command to remember.Learn how → runs itself when your prompt calls for it.
40,077 skills across 2,408 plugins. 1,867 of them fire as you prompt.
Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing
Look up the safe idiom and known-risky API/library for a language or framework (Python, JS/TS/Node, Java, Go, C/C++, Ruby) before or while writing code — a…
Review or design the security of a CI/CD pipeline: shift-left scanning gates (SAST/SCA/secret/IaC), software supply-chain integrity (SBOM, pinning, signing/…
Manual, adversarial secure code review focused on exploitable vulnerabilities — OWASP Top 10, injection, authn/authz, business-logic abuse, crypto, SSRF,…
Builds an automated malware submission and analysis pipeline that collects
Deploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulation framework) with multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard),…
Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile,…
Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits,…
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when…
XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.
Creates a GitHub repository for the website project, initializes git, and pushes the code.
Use `wiz-inspector` when Wiz CNAPP is the source of cloud posture, vulnerability, toxic-combination, or inventory evidence.
OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its
Build structured communication templates for malware incidents including stakeholder notifications, executive
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
Review a system or architecture design for security — trust boundaries, control selection, secure-by-design principles, defense-in-depth, and security…
Drive a security investigation from a lead or hypothesis to an evidence-backed conclusion — correlate telemetry across sources, enrich with intel, reconstruct…
Build or assess a security program strategy and roadmap — current-vs-target maturity, gaps, prioritized initiatives aligned to business objectives and risk…
Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries,…
Build effective detection rules using Splunk Search Processing Language
Builds vendor-agnostic detection rules using the Sigma rule format for
XXE playbook. Use when XML, SVG, OOXML, SOAP, or parser-driven imports may resolve external entities, files, or internal network resources.
Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported
Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for
Run a STRIDE threat model over a system: build/ingest a DFD, then enumerate Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and…
Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A…
Profile a threat actor or campaign — their TTPs (mapped to MITRE ATT&CK), targeting, tooling, infrastructure, and likely intent — to support threat-informed…
Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret…
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models…
Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML)…
Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission
Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification
Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to
Run a hypothesis-driven threat hunt: form a hypothesis (often from ATT&CK or threat intel), query telemetry for evidence, analyze findings, and convert results…
Draw a Data Flow Diagram with trust boundaries for threat modeling: external entities, processes, data stores, data flows, and the boundaries between them. Use…
Inventory the tools/functions an AI agent can call and audit their privileges, side effects, and approval requirements to find excessive-agency and…
Builds real-time incident response dashboards in Splunk, Elastic, or
Designs and documents structured incident response playbooks with step-by-step
Build collaborative forensic incident timelines using Timesketch to ingest,
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication,
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence
Test that retrieval enforces per-user / per-tenant authorization so one user cannot retrieve another's documents through the RAG system. Use on an authorized…
Rank a set of vulnerabilities by real-world risk using CVSS (severity), EPSS (exploit probability), CISA KEV (known exploited), and asset/exposure context — so…
Triage raw vulnerability-scanner output (Nessus/Qualys/Trivy/Grype/OpenVAS, cloud or container scans): normalize, deduplicate, validate, and cut false…
Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains,
Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic