building-malware-incid…
Build structured communication templates for malware incidents (ransomware,
A skill ships inside a plugin. Install the plugin, and a skill that gets Auto-invokedWhat is this?This plugin ships a FLOW.md router the engine fires, so the matching skill runs itself. No slash command to remember.Learn how → runs itself when your prompt calls for it.
40,077 skills across 2,408 plugins. 1,867 of them fire as you prompt.
Build structured communication templates for malware incidents (ransomware,
Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular
Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat
Establish a repeatable operational process for triaging, testing, and
Implement a phishing report button (Microsoft 365 built-in Report button
Builds a structured ransomware incident response playbook aligned with
Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified
Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against
Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,
Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB
Apply bottom-up and top-down role mining techniques, including clustering
Build a structured SOC escalation matrix defining severity tiers, response
Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing
Builds SOC performance metrics and KPI tracking dashboards measuring
Builds a structured SOC incident response playbook for ransomware attacks
Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py,
Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security
Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators,…
Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence,…
Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via…
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory,
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against…
Builds automated threat intelligence feed integration pipelines connecting
Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed…
This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP
Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting
Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s
Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g. 14 days critical, 30…
Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks…
Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration…
Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify
Builds a structured vulnerability scanning workflow using tools like
Discovering and accessing unprotected pages, APIs, and administrative
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes,…
Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
Systematically collects, categorizes, and distributes indicators of
Collects and synthesizes open-source intelligence (OSINT) about threat
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic