Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
114 results
Skill

detecting-service-account-abuse

Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk, Elast

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-suspicious-powershell-execution

Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft Defender

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-wmi-persistence

Detect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation, cross-reference

by mukul975skills.sh
Not rated yet
Free
Skill

emulating-cloud-attacks-with-stratus-red-team

Install and run Stratus Red Team to detonate granular, MITRE ATT&CK-mapped AWS, Azure, GCP, and Kubernetes attack techniques through their warmup-detonate-revert-cleanup lifecycle, then verify the tel

by mukul975skills.sh
Not rated yet
Free
Skill

executing-red-team-engagement-planning

Build the foundational red team engagement plan - scope definition, Rules of Engagement (restrictions, communication plan, emergency stop procedures, legal authorization), MITRE ATT&CK-aligned threat

by mukul975skills.sh
Not rated yet
Free
Skill

exploiting-active-directory-with-bloodhound

BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac

by mukul975skills.sh
Not rated yet
Free
Skill

exploiting-ms17-010-eternalblue-vulnerability

Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's ms17_010_eterna

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-command-and-control-beaconing

Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-data-exfiltration-indicators

Hunt for data exfiltration by analyzing Zeek and Suricata network telemetry for unusual data flows, DNS tunneling via large/frequent TXT queries, uploads to personal cloud storage, and encrypted-chann

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-lateral-movement-via-wmi

Detects WMI-based lateral movement (e.g. wmic process call create, Win32_Process.Create()) by analyzing Windows Event ID 4688 and Sysmon Event ID 1 for WmiPrvSE.exe spawning suspicious child processes

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-living-off-the-cloud-techniques

Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. "living off the cloud" tradecraft that blends

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-persistence-mechanisms-in-windows

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use whe

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-registry-persistence-mechanisms

Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image File Execution Options (IFEO) debugger i

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-registry-run-key-persistence

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-scheduled-task-persistence

Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual sc

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-shadow-copy-deletion

Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. Use when huntin

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-spearphishing-indicators

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-supply-chain-compromise

Runs a hypothesis-driven threat hunt for supply-chain compromise (T1195) by querying SIEM/EDR logs for trojanized software updates, compromised dependencies, unauthorized code modifications, and tampe

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-t1098-account-manipulation

Hunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-unusual-network-connections

Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and unusual

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-webshell-activity

Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server pr

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-continuous-security-validation-with-bas

Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and incident-res

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-diamond-model-analysis

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill c

by mukul975skills.sh
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.