Skip to content

Latest commit

 

History

History
53 lines (50 loc) · 2.82 KB

File metadata and controls

53 lines (50 loc) · 2.82 KB
id security-audit
name Defensive security audit
when_to_use Auditing or hardening a Linux host, Docker/container stack, or network — blue-team review against a baseline.
agents
security-auditor
skills
hardening-linux-endpoint-with-cis-benchmark
analyzing-linux-audit-logs-for-intrusion
detecting-rootkit-activity
hardening-docker-containers-for-production
performing-docker-bench-security-assessment
detecting-container-escape-attempts
analyzing-network-packets-with-scapy
configuring-suricata-for-network-monitoring
building-detection-rules-with-sigma
performing-nist-csf-maturity-assessment
implementing-secret-scanning-with-gitleaks
phases
phase owner_agent skills exit_criteria failure_modes
Scope & baseline
security-auditor
performing-nist-csf-maturity-assessment
Assets, threat model, and the baseline to audit against are stated.
Auditing everything at once with no priority.
phase owner_agent skills exit_criteria failure_modes
Host hardening
security-auditor
hardening-linux-endpoint-with-cis-benchmark
analyzing-linux-audit-logs-for-intrusion
detecting-rootkit-activity
Host findings ranked by severity with exact remediation commands.
Applying changes before confirming they are safe on a live machine.
phase owner_agent skills exit_criteria failure_modes
Container review
security-auditor
hardening-docker-containers-for-production
performing-docker-bench-security-assessment
detecting-container-escape-attempts
Docker daemon + image + runtime posture assessed (Docker Bench, escape checks).
Ignoring 0.0.0.0-bound published ports and UFW rule state.
phase owner_agent skills exit_criteria failure_modes
Network & detection
security-auditor
analyzing-network-packets-with-scapy
configuring-suricata-for-network-monitoring
building-detection-rules-with-sigma
Traffic/monitoring gaps identified; detection rules proposed.
Detection without a hypothesis of what you are hunting.
phase owner_agent skills exit_criteria failure_modes
Supply chain & report
security-auditor
implementing-secret-scanning-with-gitleaks
Secret/SBOM findings folded into one prioritized, read-only report.
Reporting a low score from a tool run without sudo (false negative).

Defensive security audit

Read-only-first posture review: Scope → Host → Container → Network → Supply-chain report. Owned by the security-auditor agent, drawing on the installed defensive-security skills (and the far larger cybersecurity set in the library for specialized techniques — forensics, YARA/Zeek, IR playbooks).

Route in: "audit / harden / is this secure / check open ports / container security." Diagnose and report exact commands; confirm before any system-mutating change on a live host.