Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
19 results
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. via Mimikatz) using Sysmon Event ID 10 process-access logging, Windows Security logs, and SIEM correlation rules. Use

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-dll-sideloading-attacks

Detect DLL side-loading and search-order hijacking (MITRE T1574) where adversaries plant malicious DLLs for legitimate signed applications to load, by analyzing Sysmon Event ID 7 DLL-load events, chec

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-evasion-techniques-in-endpoint-logs

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoin

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-process-injection-techniques

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, AP

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-t1055-process-injection-with-sysmon

Detect process injection techniques (T1055) - including DLL injection, process hollowing, and APC injection - by analyzing Sysmon Event IDs 1, 7, 8, 10, and 25 for cross-process memory operations, rem

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-defense-evasion-via-timestomping

Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patter

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by mukul975skills.sh
Not rated yet
Free
Skill

hunting-for-lolbins-execution-in-endpoint-logs

Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries used

by mukul975skills.sh
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

by luokai0GitHub
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

by kyssta-exeGitHub
Not rated yet
Free
Skill

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. via Mimikatz) using Sysmon Event ID 10 process-access logging, Windows Security logs, and SIEM correlation rules. Use

by gabrielmoreiraGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Use when proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection. Use when working with hunting for living off the land binar

by oyi77GitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by costrict-plugins-repoGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by RanuK12GitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by bfoxhoundGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by thewongdirectionGitHub
Not rated yet
Free
Skill

hunting-for-living-off-the-land-binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and

by AliffZulhelmiGitHub
Not rated yet
Free
Skill

detecting-t1055-process-injection-with-sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation

by Molly-agiGitHub
Not rated yet
Free
Skill

cb-hunting-for-lolbins-execution-in-endpoint-logs

Cold-box analyst playbook — Hunting For Lolbins Execution In Endpoint Logs. Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspiciou

by at-srcGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.