Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
114 results
Skill

hunting-for-spearphishing-indicators

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

by 26zlGitHub
Not rated yet
Free
Skill

hunting-for-spearphishing-indicators

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

by henriquescastilhoGitHub
Not rated yet
Free
Skill

hunting-for-spearphishing-indicators

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

by megawesley2015-langGitHub
Not rated yet
Free
Skill

detecting-privilege-escalation-attempts

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

by HenriqueMC17GitHub
Not rated yet
Free
Skill

detecting-privilege-escalation-attempts

Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. Use when threat hunti

by gabrielmoreiraGitHub
Not rated yet
Free
Skill

conducting-pass-the-ticket-attack

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

by momo0410GitHub
Not rated yet
Free
Skill

T1584.006_web-services

Adversaries may compromise access to third-party web services that can be used during targeting.

by CyberStrikeusGitHub
Not rated yet
Free
Skill

writing-a-malware-analysis-report

Structures a clear, actionable malware analysis report covering summary, sample identity, capabilities, IOCs, ATT&CK mapping, and detection guidance for both technical and decision-making audiences. A

by meltedinhexGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Use when proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection. Use when working with hunting for living off the land binar

by oyi77GitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by costrict-plugins-repoGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by RanuK12GitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by bfoxhoundGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by thewongdirectionGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by AliffZulhelmiGitHub
Not rated yet
Free
Skill

T1003.005_cached-domain-credentials

Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.

by CyberStrikeusGitHub
Not rated yet
Free
Skill

implementing-diamond-model-analysis

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill c

by theheavenlyd3monGitHub
Not rated yet
Free
Skill

executing-red-team-engagement-planning

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

by Yenn503GitHub
Not rated yet
Free
Skill

T1189_drive-by-compromise

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.

by CyberStrikeusGitHub
Not rated yet
Free
Skill

analyzing-campaign-attribution-evidence

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

by Razor25000GitHub
Not rated yet
Free
Skill

analyzing-campaign-attribution-evidence

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP co

by SSZcreateGitHub
Not rated yet
Free
Skill

analyzing-campaign-attribution-evidence

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP co

by SSZcreateGitHub
Not rated yet
Free
Skill

performing-threat-hunting-with-elastic-siem

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams nee

by aibot88GitHub
Not rated yet
Free
Skill

performing-dark-web-monitoring-for-threats

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

by gabrielmoreiraGitHub
Not rated yet
Free
Skill

implementing-continuous-security-validation-with-bas

Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.

by andycungkrinx91GitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.