← all publishers

sec-link

@sec-link source repo

10 published skills

  1. Phishing Email Triage · sec-link
    Analyze suspicious email indicators, sender authentication, URLs, attachments, user impact, and recommended containment. Never claim a link or attachment is malicious without evidence. Return concise findings and follow-up tasks.
    0
    installs
  2. Cloud Iam Anomaly Triage · sec-link
    Analyze suspicious cloud identity and access events, including role changes, new keys, unusual regions, and privilege escalation. Recommend evidence-preserving response actions.
    0
    installs
  3. Ransomware Response · sec-link
    Triage ransomware indicators such as mass file changes, encryption processes, ransom notes, and lateral movement. Prioritize isolation, evidence preservation, recovery coordination, and safe next tasks.
    0
    installs
  4. Dns Command And Control Investigation · sec-link
    Analyze suspicious DNS behavior such as high entropy, beaconing, rare domains, unusual record types, and query volume. Distinguish indicators from confirmed C2 and recommend safe validation.
    0
    installs
  5. Insider Threat Assessment · sec-link
    Assess possible insider risk from unusual access, downloads, privilege use, and policy violations. Maintain neutral language, minimize personal data, and recommend auditable investigative steps.
    0
    installs
  6. Malware Execution Analysis · sec-link
    Analyze process execution, downloaded files, hashes, parent-child chains, persistence, and host impact. Separate observed facts from hypotheses and propose safe collection and containment steps.
    0
    installs
  7. Data Exfiltration Detection · sec-link
    Assess possible data movement using destinations, protocols, volume, files, and user context. Identify evidence gaps and recommend low-risk validation and containment actions.
    0
    installs
  8. Vulnerability Prioritization · sec-link
    Prioritize vulnerabilities using asset criticality, exploitability, exposure, known exploitation, compensating controls, and business impact. Do not invent CVEs or affected versions.
    0
    installs
  9. Incident Containment Planning · sec-link
    Create a prioritized, reversible containment plan based only on observed evidence. Include owner, verification, rollback, and approval requirements; never perform destructive actions automatically.
    0
    installs
  10. Suspicious Login Investigation · sec-link
    Investigate unusual authentication activity using source IP, account, time, geolocation, MFA, and privilege context. Recommend validation steps and avoid changing ticket status.
    0
    installs