Source

smithery/dandye

27 skills · 0 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
analyze-content-gaps Identify content gaps and organizational opportunities. Analyzes missing content areas, redundancies, and consolidati…
smithery/dandye
0
2
audit-content Comprehensive content quality and maintenance assessment. Evaluates documentation quality, relevance, maintenance nee…
smithery/dandye
0
3
check-duplicates Check for duplicate or similar cases. Use before deep analysis to avoid investigating the same incident twice. Takes …
smithery/dandye
0
4
cluster-documents Automated content similarity and grouping analysis. Groups related documents by topic, purpose, or content similarity.
smithery/dandye
0
5
confirm-action Ask the user to confirm before taking a significant action. Use before containment, remediation, or other impactful o…
smithery/dandye
0
6
deep-dive-ioc Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - …
smithery/dandye
0
7
enrich-ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context f…
smithery/dandye
0
8
find-relevant-case Search for existing cases related to specific indicators or entities. Use to find correlation with other investigatio…
smithery/dandye
0
9
full-alert-triage Complete Tier 1 triage workflow. Orchestrates the full alert triage process: check-duplicates, triage-alert, enrich-i…
smithery/dandye
0
10
full-investigation Complete Tier 2 investigation workflow. Orchestrates deep investigation of escalated cases: deep-dive-ioc, correlate-…
smithery/dandye
0
11
generate-report Save investigation findings to a markdown report file. Use after completing triage, enrichment, or investigation to c…
smithery/dandye
0
12
generate-sitemap Generate hierarchical site structure and navigation maps. Creates visual representations of information architecture …
smithery/dandye
0
13
generate-taxonomy Develop hierarchical classification systems. Creates parent-child categorical structures for content organization.
smithery/dandye
0
14
generate-thesaurus Generate controlled vocabulary thesaurus for content domains. Creates comprehensive thesauri with preferred terms, br…
smithery/dandye
0
15
hunt-apt Hunt for a specific APT/threat actor in your environment. Use when you have a threat actor name or GTI collection ID …
smithery/dandye
0
16
hunt-credential-access Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence…
smithery/dandye
0
17
hunt-ioc Hunt for specific IOCs across your environment. Use when you have a list of IPs, domains, hashes, or URLs from threat…
smithery/dandye
0
18
hunt-lateral-movement Hunt for lateral movement using PsExec, WMI, or similar techniques. Use when proactively searching for attackers movi…
smithery/dandye
0
19
hunt-threat Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligenc…
smithery/dandye
0
20
inventory-content Systematic cataloging of information assets. Creates comprehensive inventories of all content with metadata and chara…
smithery/dandye
0
21
pivot-on-ioc Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected d…
smithery/dandye
0
22
respond-compromised-account Respond to a potentially compromised user account. Use when impossible travel, credential stuffing, successful phishi…
smithery/dandye
0
23
respond-malware Respond to a malware incident following PICERL methodology. Use when malware is detected on endpoints. Orchestrates t…
smithery/dandye
0
24
respond-phishing Respond to a reported phishing email following PICERL methodology. Use when a phishing email is reported or detected.…
smithery/dandye
0
25
respond-ransomware Respond to a ransomware incident following PICERL methodology. Use when ransomware is detected or suspected. Orchestr…
smithery/dandye
0
26
triage-alert Triage a security alert or case. Use when given an ALERT_ID or CASE_ID to assess if it's a real threat. Enriches IOCs…
smithery/dandye
0
27
triage-suspicious-login Triage suspicious login alerts like impossible travel, untrusted location, or multiple failures. Use when investigati…
smithery/dandye
0