Database
Browse 6,168 skills across 448 packs and 38 categories
app-sideload-abuse
47LDetect app sideload abuse, marketplace scams, and unauthorized application distribution
brand-monitoring-automation
48LAutomated brand monitoring, alert triage, and takedown workflow orchestration
counterfeit-detection
46LDetect counterfeit sites, pirated applications, and fake login portals impersonating your brand
ransomware-readiness
47LRansomware resilience testing, backup validation, recovery planning, and readiness assessment
brand-abuse-detection
45LDetect fake domains, spoofed support channels, and counterfeit sites impersonating your brand
crypto-wallet-risk
45LWallet clustering, scam campaign tracking, sanction screening, and payment flow review
deception-testing
46LDeploy honey assets, canary tokens, decoy credentials, and sinkhole infrastructure for threat detection
phishing-intelligence
46LPhishing kit tracking, lure analysis, sender clustering, and landing page fingerprinting
social-impersonation
46LDetect fake social accounts, executive impersonation, and marketplace fraud impersonation
business-email-compromise
54LSimulate BEC attacks to test financial controls, authorization procedures, and executive impersonation defenses
credential-harvesting
56LBuild authorized credential harvesting pages for phishing simulations using GoPhish, Evilginx, and transparent proxies
deepfake-awareness
54LBuild organizational awareness and verification procedures against deepfake voice, video, and AI-generated content threats
helpdesk-exploitation
54LTest helpdesk and IT support social engineering resilience through authorized identity verification bypass assessments
insider-threat-assessment
54LAssess insider threat program maturity through gap analysis of behavioral indicators, DLP, and access controls
Phishing Defense
116LUse this skill when analyzing, preventing, or responding to phishing attacks. Activate when users mention phishing, spear phishing, smishing, vishing, suspicious emails, lookalike domains, credential-theft lures, QR-code phishing (quishing), MFA fatigue, or when they need to build phishing awareness programs, triage a reported message, or harden mail authentication (SPF, DKIM, DMARC).
red-team-social-engineering
57LExecute full-scope red team social engineering campaigns combining email, phone, physical, and technical vectors
social-media-reconnaissance
54LConduct social media OSINT for authorized engagements to map organizational exposure and employee data leakage
supply-chain-social-engineering
54LAssess supply chain and third-party social engineering risks through vendor impersonation and trusted relationship abuse testing