.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/26zl/cybersec-toolkit
home/skills/26zl/cybersec-toolkit
26zl avatar

26zl/cybersec-toolkit

58 skills

View on GitHub
$npx skills add 26zl/cybersec-toolkit
SkillInstalls
acquiring-disk-image-with-dd-and-dcflddCreate forensically sound bit-for-bit disk images using dd and dcfldd—add-toolUse when adding a new cybersecurity tool to this installer. Walks through editing the right module file, adding to tools_config.json, running validators, and…—ai-llm-security-reviewUse for AI/LLM security assessments, prompt injection, RAG security, agent/tool permissioning, model supply chain, LLM red teaming, AI governance, eval design,…—ai-threat-testingOffensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection,…—analyzing-active-directory-acl-abuseDetect dangerous ACL misconfigurations in Active Directory using ldap3—analyzing-android-malware-with-apktoolPerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source—analyzing-api-gateway-access-logsParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect—analyzing-apt-group-with-mitre-navigatorAnalyze advanced persistent threat (APT) group techniques using MITRE—analyzing-azure-activity-logs-for-threatsQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query—analyzing-bootkit-and-rootkit-samplesAnalyzes bootkit and advanced rootkit malware that infects the Master—analyzing-browser-forensics-with-hindsightAnalyze Chromium-based browser artifacts using Hindsight to extract browsing—analyzing-campaign-attribution-evidenceCampaign attribution analysis involves systematically evaluating evidence—analyzing-certificate-transparency-for-phishingMonitor Certificate Transparency logs using crt.sh and Certstream to—analyzing-cloud-storage-access-patternsDetect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage—analyzing-cobalt-strike-beacon-configurationExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,—analyzing-cobaltstrike-malleable-c2-profilesParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike—analyzing-command-and-control-communicationAnalyzes malware command-and-control (C2) communication protocols to—analyzing-cyber-kill-chainAnalyzes intrusion activity against the Lockheed Martin Cyber Kill Chain—analyzing-disk-image-with-autopsyPerform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and—analyzing-dns-logs-for-exfiltrationAnalyzes DNS query logs to detect data exfiltration via DNS tunneling,—analyzing-docker-container-forensicsInvestigate compromised Docker containers by analyzing images, layers,—analyzing-email-headers-for-phishing-investigationParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify—analyzing-ethereum-smart-contract-vulnerabilitiesPerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,—analyzing-golang-malware-with-ghidraReverse engineer Go-compiled malware using Ghidra with specialized scripts—analyzing-heap-spray-exploitationDetect and analyze heap spray attacks in memory dumps using Volatility3—analyzing-indicators-of-compromiseAnalyzes indicators of compromise (IOCs) including IP addresses, domains,—analyzing-ios-app-security-with-objectionPerforms runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that—analyzing-kubernetes-audit-logsParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,—analyzing-linux-audit-logs-for-intrusionUses the Linux Audit framework (auditd) with ausearch and aureport utilities—analyzing-linux-elf-malwareAnalyzes malicious Linux ELF (Executable and Linkable Format) binaries—analyzing-linux-kernel-rootkitsDetect kernel-level rootkits in Linux memory dumps using Volatility3—analyzing-linux-system-artifactsExamine Linux system artifacts including auth logs, cron jobs, shell—analyzing-lnk-file-and-jump-list-artifactsAnalyze Windows LNK shortcut files and Jump List artifacts to establish—analyzing-macro-malware-in-office-documentsAnalyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download—analyzing-malicious-pdf-with-peepdfPerform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,—analyzing-malicious-url-with-urlscanURLScan.io is a free service for scanning and analyzing suspicious URLs.—analyzing-malware-behavior-with-cuckoo-sandboxExecutes malware samples in Cuckoo Sandbox to observe runtime behavior—analyzing-malware-family-relationships-with-malpediaUse the Malpedia platform and API to research malware family relationships,—analyzing-malware-persistence-with-autorunsUse Sysinternals Autoruns to systematically identify and analyze malware—analyzing-malware-sandbox-evasion-techniquesDetect sandbox evasion techniques in malware samples by analyzing timing—analyzing-memory-dumps-with-volatilityAnalyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,—analyzing-memory-forensics-with-lime-and-volatilityPerforms Linux memory acquisition using LiME (Linux Memory Extractor)—analyzing-mft-for-deleted-file-recoveryAnalyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record—analyzing-network-covert-channels-in-malwareDetect and analyze covert communication channels used by malware including—analyzing-network-flow-data-with-netflowParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port—analyzing-network-packets-with-scapyCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and—analyzing-network-traffic-for-incidentsAnalyzes network traffic captures and flow data to identify adversary activity during security incidents, including—analyzing-network-traffic-of-malwareAnalyzes network traffic generated by malware during sandbox execution—analyzing-network-traffic-with-wiresharkCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,—analyzing-office365-audit-logs-for-compromiseParse Office 365 Unified Audit Logs via Microsoft Graph API to detect—analyzing-outlook-pst-for-email-forensicsAnalyze Microsoft Outlook PST and OST files for email forensic evidence—analyzing-packed-malware-with-upx-unpackerIdentifies and unpacks UPX-packed and other packed malware samples to—analyzing-pdf-malware-with-pdfidAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to—analyzing-persistence-mechanisms-in-linuxDetect and analyze Linux persistence mechanisms including crontab entries,—analyzing-powershell-empire-artifactsDetect PowerShell Empire framework artifacts in Windows event logs by—analyzing-powershell-script-block-loggingParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX—analyzing-prefetch-files-for-execution-historyParse Windows Prefetch files to determine program execution history including—analyzing-ransomware-encryption-mechanismsAnalyzes encryption algorithms, key management, and file encryption—