DanDye
Community@dandye · Tampa, FL
AI Engineer at Google Cloud Security; Pythonista; Djangster
Agent Skills by DanDye
Showing 93 vetted skills indexed across 2 GitHub repositories.
create-investigation-report
Generates structured incident investigation reports from SOAR case data and security tool findings.
alert-report
Generate standardized Markdown reports summarizing SOAR alert investigations and entity enrichment.
detection-report
Generates Markdown reports summarizing detection rule logic, alert performance, and tuning context.
report-writing-guidelines
Structures and formats cybersecurity incident reports from investigation findings.
case-report
Generates Markdown case investigation reports from SOAR case data with Mermaid workflow diagrams.
basic-endpoint-triage-isolation
Triages potentially compromised endpoints using SIEM and SOAR context, then executes network isolation.
suspicious-login-triage
Triages suspicious login alerts by enriching user, IP, and hostname context from SIEM and SOAR.
cloud-vulnerability-triage
Triages SCC vulnerability findings with GTI enrichment and SIEM exploitation checks.
triage-alerts
Triage incoming security alerts using SOAR context, SIEM searches, and threat intelligence enrichment.
malware-triage
Analyzes suspected malicious file hashes using GTI reports, SIEM event searches, and SOAR case documentation.
domain-lookup-entity-chronicle
Retrieves domain entity activity summaries and related alerts from Chronicle SIEM.
hash-search-process-events-chronicle
Searches Chronicle SIEM for process execution events matching a file hash.
hash-lookup-entity-chronicle
Look up file hash entity activity and related alerts in Chronicle SIEM.
user-search-process-activity-chronicle
Searches Chronicle SIEM for process launch events associated with a specific user.
domain-get-gti-report
Retrieve GTI threat reputation and WHOIS intelligence for a domain name.
user-lookup-entity-chronicle
Retrieves user entity activity summaries from Chronicle SIEM using the lookup_entity tool.
ip-lookup-entity-chronicle
Retrieves IP address activity summaries from Chronicle SIEM using the lookup_entity tool.
hash-get-secops-threat-intel
Retrieves SecOps threat intelligence summaries for MD5, SHA1, or SHA256 file hashes.
url-get-secops-threat-intel
Retrieves threat intelligence summaries for URLs using the Chronicle SecOps MCP get_threat_intel tool.
domain-get-secops-threat-intel
Retrieve Chronicle SecOps threat intelligence summaries and IOC matches for a domain.
url-search-chronicle
Searches Chronicle SIEM proxy and web access logs for HTTP/HTTPS requests to a specific URL.
url-get-gti-report
Retrieves URL reputation reports from Google Threat Intelligence for threat classification.
ip-search-network-traffic-chronicle
Searches Chronicle SIEM for UDM network connection events involving a target IP address.
user-search-login-activity-chronicle
Searches Chronicle SIEM for user login events using natural language security event queries.
Frequently Asked Questions About DanDye
FAQPage SchemaWhat tasks can I perform using DanDye's security skills?▼
You can triage alerts, enrich IOCs with GTI and Chronicle context, hunt threats using MITRE techniques, run PICERL incident response for phishing, malware, ransomware, and compromised accounts, tune YARA-L detection rules, and generate investigation and case closure reports.
Who are these skills designed for?▼
They target SOC analysts, Tier 1-3 incident responders, threat hunters, and detection engineers working in Google SecOps environments. Runbooks cover alert triage, deep-dive IOC analysis, hypothesis-driven hunts, and detection-as-code rule tuning.
What platforms and prerequisites do these skills require?▼
Skills assume access to Chronicle SIEM (UDM logs), Google Threat Intelligence, SecOps MCP threat intel endpoints, and a SOAR platform for case management. Detection engineering skills additionally use Git-based CI/CD repositories for rule authoring and tuning.
How are investigations and reports produced?▼
Skills reconstruct event timelines, correlate IOCs against SIEM alerts and SOAR cases, group duplicate cases, and write timestamped Markdown deliverables including alert summaries, detection coverage assessments, case closure reports, and executive investigation findings.