collecting-threat-inte…
Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs,…
A skill ships inside a plugin. Install the plugin, and a skill that gets Auto-invokedWhat is this?This plugin ships a FLOW.md router the engine fires, so the matching skill runs itself. No slash command to remember.Learn how → runs itself when your prompt calls for it.
40,077 skills across 2,408 plugins. 1,867 of them fire as you prompt.
Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs,…
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security
Conducts comprehensive network penetration tests against authorized target environments by performing host discovery,
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate
Collect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and…
Conducts security testing of REST, GraphQL, and gRPC APIs to identify
Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit…
Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce
Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical
This skill outlines methodologies for performing authorized penetration
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and…
Perform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extract KRBTGT, Domain…
Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social
Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing
Conduct external recon using OSINT techniques to map an organization's external attack surface without touching target systems, gathering DNS records,…
Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to…
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of…
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory.
Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking
Execute an internal network penetration test simulating an insider threat
Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID)…
Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing…
Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and
Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and
Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap
Performs memory forensics analysis using Volatility 3 to extract evidence
Conducts penetration testing of iOS and Android mobile applications
Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous
Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like
Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points.
Conducts comprehensive network penetration tests against authorized
Perform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS tickets from LSASS memory on a compromised host and injecting them into another…
Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining…
Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce
Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and
Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation,
Facilitate structured post-incident reviews to identify root causes,
Design and execute a social engineering penetration test combining OSINT-driven target profiling with phishing, vishing, smishing, and physical pretexting…
Plan and execute authorized vishing (voice phishing) pretext calls to
Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious
Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements
Run a targeted spearphishing simulation for initial access by developing OSINT-derived pretexts, building payloads (HTML smuggling, macro docs, ISO/LNK,…
Conducts authorized wireless network penetration tests to assess the
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic