Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
79 results
Skill

designing-adversary-engagement-with-mitre-engage

Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare

by mukul975skills.sh
Not rated yet
Free
Skill

extracting-iocs-from-malware-samples

Extracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators (IPs, domains, URLs, PCAP indicators), host artifacts (file paths, registry keys, mutexes), and

by mukul975skills.sh
Not rated yet
Free
Skill

generating-threat-intelligence-reports

Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical anal

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-diamond-model-analysis

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill c

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-dragos-platform-for-ot-monitoring

Deploys and configures Dragos Platform sensors and detection analytics for OT/ICS network monitoring, using industrial protocol parsers and threat-intel packs to detect groups like VOLTZITE, CHERNOVIT

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-stix-taxii-feed-integration

Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and standing

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-threat-intelligence-lifecycle-management

Build out a full CTI program around the six-phase threat intelligence lifecycle (direction, collection, processing, analysis, dissemination, feedback), including defining intelligence requirements, bu

by mukul975skills.sh
Not rated yet
Free
Skill

modeling-threats-with-opencti

Deploy OpenCTI (Filigran) via Docker Compose and use the pycti Python client to model threat actors, intrusion sets, campaigns, and indicators as a STIX 2.1 knowledge graph with relationships (uses, a

by mukul975skills.sh
Not rated yet
Free
Skill

operationalizing-misp-threat-feeds

Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-gener

by mukul975skills.sh
Not rated yet
Free
Skill

performing-ai-driven-osint-correlation

Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unif

by mukul975skills.sh
Not rated yet
Free
Skill

performing-brand-monitoring-for-impersonation

Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organizat

by mukul975skills.sh
Not rated yet
Free
Skill

performing-cve-prioritization-with-kev-catalog

Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog, enrich it with EPSS scores and CVSS metrics, and build a multi-factor prioritization engine and report that ranks CVE remediatio

by mukul975skills.sh
Not rated yet
Free
Skill

performing-dark-web-monitoring-for-threats

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

by mukul975skills.sh
Not rated yet
Free
Skill

performing-indicator-lifecycle-management

Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and automated

by mukul975skills.sh
Not rated yet
Free
Skill

performing-ioc-enrichment-automation

Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition rec

by mukul975skills.sh
Not rated yet
Free
Skill

performing-ip-reputation-analysis-with-shodan

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.

by mukul975skills.sh
Not rated yet
Free
Skill

performing-malware-hash-enrichment-with-virustotal

Enrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal API v3 to retrieve multi-engine detection rates, sandbox behavioral analysis, YARA rule matches, related indicators, and community

by mukul975skills.sh
Not rated yet
Free
Skill

performing-malware-ioc-extraction

Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist

by mukul975skills.sh
Not rated yet
Free
Skill

performing-osint-with-spiderfoot

Automate OSINT collection with the SpiderFoot REST API and CLI (sf.py/spiderfoot-cli) across 200+ modules, selecting scan modes (footprint, investigate, passive) and parsing results for domains, IPs,

by mukul975skills.sh
Not rated yet
Free
Skill

performing-paste-site-monitoring-for-credentials

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.

by mukul975skills.sh
Not rated yet
Free
Skill

performing-threat-intelligence-sharing-with-misp

Uses PyMISP (the official MISP REST API library) to create events with structured IOCs (IPs, domains, hashes, URLs), enrich them with MITRE ATT&CK tags and galaxy clusters, manage sharing groups and d

by mukul975skills.sh
Not rated yet
Free
Skill

performing-threat-landscape-assessment-for-sector

Conducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the att

by mukul975skills.sh
Not rated yet
Free
Skill

processing-stix-taxii-feeds

Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding

by mukul975skills.sh
Not rated yet
Free
Skill

tracking-threat-actor-infrastructure

Discovers and maps adversary-controlled infrastructure (C2 servers, phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive DNS, certificate transparency logs, Shodan/Cens

by mukul975skills.sh
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.