configuring-active-dir…
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
A skill ships inside a plugin. Install the plugin, and a skill that gets Auto-invokedWhat is this?This plugin ships a FLOW.md router the engine fires, so the matching skill runs itself. No slash command to remember.Learn how → runs itself when your prompt calls for it.
40,077 skills across 2,408 plugins. 1,867 of them fire as you prompt.
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying
Configure AWS Verified Access to provide VPN-less zero trust network
Build a two-tier PKI Certificate Authority hierarchy (offline Root CA
Configures host-based intrusion detection systems (HIDS) to monitor
Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks,
Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify
Configures Hardware Security Modules for cryptographic key storage
Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce
Hardens LDAP directory services against credential harvesting, LDAP
Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing
Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like
Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1,
Configures microsegmentation policies to enforce least-privilege workload-to-workload
Deploys Cisco Duo multi-factor authentication across enterprise applications,
Designs and implements VLAN-based (802.1Q) network segmentation on
Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications,
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Configures secure OAuth 2.0 authorization flows, including Authorization
Configures pfSense firewall rules, NAT policies, IPsec/OpenVPN tunnels,
Installs, configures, and tunes Snort 3 to monitor network traffic
Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents,
Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for
Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets,
Configures TLS 1.3 (RFC 8446) on servers, covering cipher suite and
Configures Microsoft Defender for Endpoint (MDE) advanced protection
Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,
Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
Configures Windows Event Logging with advanced audit policies to generate
Configures Zscaler Private Access (ZPA) to replace traditional VPN
Executes containment strategies to stop active adversary operations
This skill covers deploying anomaly detection systems for industrial control environments using machine learning
Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets,…
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query
Correlates disparate security incidents, IOCs, and adversary behaviors
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems
Deploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialogue rails, and LLM Guard input/output scanner pipelines as complementary runtime…
Deobfuscates malicious JavaScript found in phishing pages, web skimmers, and dropper scripts by reversing encoding layers, eval chains, string manipulation,…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic