askill
dandye

dandye

Publisher on askill

2k total stars
Skills34
Updated 3/4/2026
GitHub
find-relevant-case
find-relevant-case
dandye2/20/2026

Search for existing cases related to specific indicators or entities. Use to find correlation with other investigations before starting new analysis. Takes search terms and returns matching case IDs.

86
AI 82
hunt-lateral-movement
hunt-lateral-movement
dandye2/4/2026

Hunt for lateral movement using PsExec, WMI, or similar techniques. Use when proactively searching for attackers moving through your network using admin tools. Searches for service installations, remo...

85
AI 95
respond-malware
respond-malware
dandye2/4/2026

Respond to a malware incident following PICERL methodology. Use when malware is detected on endpoints. Orchestrates triage, containment, eradication, and recovery. Works with triage-malware skill for...

85
AI 95
respond-phishing
respond-phishing
dandye2/4/2026

Respond to a reported phishing email following PICERL methodology. Use when a phishing email is reported or detected. Analyzes artifacts, identifies recipients who clicked, contains malicious IOCs, an...

85
AI 95
hunt-ioc
hunt-ioc
dandye2/4/2026

Hunt for specific IOCs across your environment. Use when you have a list of IPs, domains, hashes, or URLs from threat intel and want to check if they appear in your SIEM. Systematic searching with enr...

85
AI 95
deep-dive-ioc
deep-dive-ioc
dandye2/4/2026

Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and t...

85
AI 95
respond-compromised-account
respond-compromised-account
dandye2/4/2026

Respond to a potentially compromised user account. Use when impossible travel, credential stuffing, successful phishing, or suspicious activity indicates account compromise. Investigates activity, con...

85
AI 95
respond-ransomware
respond-ransomware
dandye2/4/2026

Respond to a ransomware incident following PICERL methodology. Use when ransomware is detected or suspected. Orchestrates identification, containment, eradication, and recovery phases. Requires CASE_I...

85
AI 92
hunt-credential-access
hunt-credential-access
dandye2/4/2026

Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence of credential harvesting. Takes MITRE technique IDs and searches for behavioral in...

85
AI 92
inventory-content
inventory-content
dandye2/4/2026

Systematic cataloging of information assets. Creates comprehensive inventories of all content with metadata and characteristics.

85
correlate-ioc
correlate-ioc
dandye2/4/2026

Check for existing SIEM alerts and case management entries related to IOCs. Use to understand if an indicator has triggered previous alerts or is part of ongoing investigations. Takes IOC list and ret...

85
design-metadata-schema
design-metadata-schema
dandye2/4/2026

Design comprehensive metadata frameworks. Develops structured metadata templates and tagging systems.

85
triage-malware
triage-malware
dandye2/4/2026

Triage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, an...

85
audit-content
audit-content
dandye2/4/2026

Comprehensive content quality and maintenance assessment. Evaluates documentation quality, relevance, maintenance needs, and provides actionable recommendations.

85
generate-report
generate-report
dandye2/4/2026

Save investigation findings to a markdown report file. Use after completing triage, enrichment, or investigation to create a permanent record. Generates timestamped files in ./reports/ directory.

85
document-in-case
document-in-case
dandye2/4/2026

Add a comment to a case to document findings, actions, or recommendations. Use to maintain audit trail during investigations. Requires CASE_ID and comment text.

85
enrich-ioc
enrich-ioc
dandye2/4/2026

Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summ...

85
triage-alert
triage-alert
dandye2/4/2026

Triage a security alert or case. Use when given an ALERT_ID or CASE_ID to assess if it's a real threat. Enriches IOCs, searches SIEM for context, and determines if the alert should be closed (false po...

85

Showing 18 of 34