Data & Analytics
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
-
mukul975 Bundle Analyzing Network Covert Channels In MalwareDetect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and protocol abuse for C2 and data exfiltration.
24.6k -
mukul975 Bundle Hunting For Defense Evasion Via TimestompingDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT using analyzeMFT and Python.
24.6k -
mukul975 Bundle Implementing Aes Encryption For Data At RESTImplement AES-256-GCM encryption for files and data at rest, including key derivation, IV management, and authenticated encryption.
Audited 24.6k -
mukul975 Bundle Performing Linux Log Forensics InvestigationAnalyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
24.6k -
mukul975 Bundle Performing Memory Forensics With Volatility3Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
24.6k -
mukul975 Bundle Building Vulnerability Aging And Sla TrackingTrack vulnerability aging and SLA compliance with severity-based remediation timelines, automated escalations, and compliance metrics.
Audited 24.6k -
mukul975 Bundle Detecting Entra Offensive Tools In Graph LogsHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
24.6k -
mukul975 Bundle Hunting For Beaconing With Frequency AnalysisIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
Audited 24.6k -
mukul975 Bundle Performing Timeline Reconstruction With PlasoBuild comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
24.6k -
mukul975 Bundle Analyzing Malware Behavior With Cuckoo SandboxExecutes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.
24.6k -
mukul975 Bundle Analyzing Prefetch Files For Execution HistoryParse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
24.6k -
mukul975 Bundle Implementing Dragos Platform For Ot MonitoringDeploy and configure the Dragos Platform for OT network monitoring, leveraging industrial protocol parsers, threat detection analytics, and asset visibility to protect ICS environments.
24.6k -
mukul975 Bundle Performing Asset Criticality Scoring For VulnsBuild a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
24.6k -
mukul975 Bundle Performing Web Application Scanning With NiktoScan web servers and applications for vulnerabilities, misconfigurations, and outdated software using the Nikto open-source scanner.
24.6k -
mukul975 Bundle Analyzing Certificate Transparency For PhishingMonitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
24.6k -
mukul975 Bundle Performing Network Traffic Analysis With TsharkAutomates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
24.6k -
mukul975 Bundle Detecting Golden Ticket Attacks In Kerberos LogsDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
Audited 24.6k -
mukul975 Bundle Detecting Anomalies In Industrial Control SystemsDeploys anomaly detection for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications.
24.6k -
mukul975 Bundle Performing Cloud Asset Inventory With CartographyMap cloud infrastructure assets and relationships into a Neo4j graph using Cartography to discover attack paths, IAM permission chains, and security gaps across AWS, GCP, and Azure.
24.6k -
mukul975 Bundle Performing Static Malware Analysis With Pe StudioPerforms static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary.
24.6k -
mukul975 Bundle Performing Threat Landscape Assessment For SectorConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
24.6k -
mukul975 Bundle Analyzing Email Headers For Phishing InvestigationParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
24.6k -
mukul975 Bundle Detecting Dns Exfiltration With Dns Query AnalysisDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
24.6k -
mukul975 Bundle Performing Mobile Device Forensics With CellebriteAcquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
24.6k -
mukul975 Bundle Analyzing Memory Forensics With Lime And VolatilityAcquires Linux memory using the LiME kernel module and analyzes the image with Volatility 3 to extract processes, network connections, bash history, kernel modules, and injected code for incident response.
24.6k -
mukul975 Bundle Performing Memory Forensics With Volatility3 PluginsAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
24.6k -
mukul975 Bundle Performing Windows Artifact Analysis With Eric Zimmerman TooParse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
24.6k -
wondelai Bundle Ddia SystemsDesign reliable, scalable, and maintainable data systems by applying principles from storage engines, replication, partitioning, transactions, and consistency models.
Audited 1.6k -
wondelai Bundle Lean AnalyticsChoose and audit startup metrics using the Lean Analytics framework: separate actionable metrics from vanity metrics, identify the One Metric That Matters for your business model and stage, set targets, and plan instrumentation.
Audited 1.6k -
wondelai Bundle Improve RetentionDiagnose and fix retention problems using the Fogg Behavior Model (B=MAP), covering motivation, ability, prompts, and tiny habits.
Audited 1.6k -
alphagbm Skill Alphagbm CompareCompares 2-5 stocks or options across GBM Five Pillars scores, options metrics, technicals, and valuations, highlighting winners per category and providing an overall recommendation.
Audited 1.2k -
alphagbm Skill Alphagbm Iv RankCalculates IV Rank and IV Percentile for any ticker to determine whether implied volatility is high or low relative to its 252-day history, and provides trading signals based on IV zones.
1.2k -
alphagbm Skill Alphagbm Vol SmileAnalyzes the volatility smile and skew for a single options expiration, providing implied volatility curves, skew metrics, and shape classification to reveal market pricing of tail risk and directional fear.
1.2k -
alphagbm Skill Alphagbm WatchlistMonitor a list of tickers for key changes in price, IV rank, unusual activity, earnings dates, and score changes. Supports custom watchlists and a default hot options list.
Audited 1.2k -
alphagbm Skill Alphagbm Fear ScoreCalculates a per-ticker panic index (0-100) from six weighted signals including VIX, IV Rank, RSI-14, volume anomaly, put/call ratio, and consecutive down days, triggering Bull Put Spread entry signals at scores ≥60.
1.2k -
alphagbm Skill Alphagbm Macro ViewTrack key macro indicators (VIX, US10Y, DXY, gold, oil, BTC) and get AI-generated impact analysis linked to your portfolio holdings.
1.2k
Frequently asked questions
What are Data & Analytics agent skills?
Data agent skills make AI agents useful for data work: writing SQL, cleaning datasets, building pipelines, working with spreadsheets, and producing analyses. Each skill is a reviewed SKILL.md file that teaches the agent one workflow well, ready to install in seconds.
Which Data & Analytics skills are most installed?
Popular Data & Analytics skills on SkillMD right now include alphagbm-iv-rank, building-vulnerability-aging-and-sla-tracking, performing-timeline-reconstruction-with-plaso. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Data & Analytics skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.