configuring-host-based-intrusion-detection

mukul975/configuring-host-based-intrusion-detection · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploys and configures host-based intrusion detection systems (Wazuh, OSSEC, AIDE) to monitor file integrity, system calls, and configuration changes across endpoints. Includes FIM policies, rootkit detection, custom alert rules, active response, and SIEM integration.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. implementing-file-integrity-monitoring-with-aide · mukul975 bundle
    Configure AIDE for file integrity monitoring, including baseline creation, scheduled integrity checks, change detection, and alerting.
    24.6k
    repo stars
  2. analyzing-memory-dumps-with-volatility · mukul975 bundle
    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
    24.6k
    repo stars
  3. building-vulnerability-scanning-workflow · mukul975 bundle
    Establishes recurring vulnerability scanning workflows using Nessus, Qualys, or OpenVAS, prioritizes findings with risk scoring and CISA KEV data, integrates with SIEM for exploitation detection, and tracks remediation via SLA-based dashboards and automated ticketing.
    24.6k
    repo stars
  4. implementing-endpoint-detection-with-wazuh · mukul975 bundle
    Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    24.6k
    repo stars
  5. implementing-velociraptor-for-ir-collection · mukul975 bundle
    Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
    24.6k
    repo stars
  6. implementing-email-sandboxing-with-proofpoint · mukul975 bundle
    Configure Proofpoint Targeted Attack Protection (TAP) to detonate suspicious attachments and URLs in isolated sandboxes, integrate with email flow, analyze reports, and tune detection policies.
    24.6k
    repo stars

Frequently asked questions

How do I install the configuring-host-based-intrusion-detection skill?

Run npx skillmds add mukul975/configuring-host-based-intrusion-detection in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the configuring-host-based-intrusion-detection skill do?

Deploys and configures host-based intrusion detection systems (Wazuh, OSSEC, AIDE) to monitor file integrity, system calls, and configuration changes across endpoints. Includes FIM policies, rootkit detection, custom alert rules, active response, and SIEM integration. It is listed under Security, Vulnerability Scanning on SkillMD.

Is configuring-host-based-intrusion-detection safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with configuring-host-based-intrusion-detection?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is configuring-host-based-intrusion-detection free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published configuring-host-based-intrusion-detection?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.