DanDye avatar

DanDye

Community

@dandye · Tampa, FL

120Followers
|
138Public Repos
|
93Published Skills

AI Engineer at Google Cloud Security; Pythonista; Djangster

Skills Distribution
DomainCybersecurit...Threat Hunting & I.. (30%)Incident Response .. (30%)IOC Investigation .. (20%)Detection Engineer.. (10%)

Agent Skills by DanDye

Showing 93 vetted skills indexed across 2 GitHub repositories.

dandyedandye
85

create-investigation-report

Generates structured incident investigation reports from SOAR case data and security tool findings.

Community
Advanced
dandyedandye
85

alert-report

Generate standardized Markdown reports summarizing SOAR alert investigations and entity enrichment.

Community
Intermediate
dandyedandye
85

detection-report

Generates Markdown reports summarizing detection rule logic, alert performance, and tuning context.

Community
Intermediate
dandyedandye
85

report-writing-guidelines

Structures and formats cybersecurity incident reports from investigation findings.

Community
Basic
dandyedandye
85

case-report

Generates Markdown case investigation reports from SOAR case data with Mermaid workflow diagrams.

Community
Intermediate
dandyedandye
85

basic-endpoint-triage-isolation

Triages potentially compromised endpoints using SIEM and SOAR context, then executes network isolation.

Community
Intermediate
dandyedandye
85

suspicious-login-triage

Triages suspicious login alerts by enriching user, IP, and hostname context from SIEM and SOAR.

Community
Advanced
dandyedandye
85

cloud-vulnerability-triage

Triages SCC vulnerability findings with GTI enrichment and SIEM exploitation checks.

Community
Advanced
dandyedandye
85

triage-alerts

Triage incoming security alerts using SOAR context, SIEM searches, and threat intelligence enrichment.

Community
Advanced
dandyedandye
85

malware-triage

Analyzes suspected malicious file hashes using GTI reports, SIEM event searches, and SOAR case documentation.

Community
Advanced
dandyedandye
85

domain-lookup-entity-chronicle

Retrieves domain entity activity summaries and related alerts from Chronicle SIEM.

Community
Intermediate
dandyedandye
85

hash-search-process-events-chronicle

Searches Chronicle SIEM for process execution events matching a file hash.

Community
Intermediate
dandyedandye
85

hash-lookup-entity-chronicle

Look up file hash entity activity and related alerts in Chronicle SIEM.

Community
Basic
dandyedandye
85

user-search-process-activity-chronicle

Searches Chronicle SIEM for process launch events associated with a specific user.

Community
Intermediate
dandyedandye
85

domain-get-gti-report

Retrieve GTI threat reputation and WHOIS intelligence for a domain name.

Community
Intermediate
dandyedandye
85

user-lookup-entity-chronicle

Retrieves user entity activity summaries from Chronicle SIEM using the lookup_entity tool.

Community
Intermediate
dandyedandye
85

ip-lookup-entity-chronicle

Retrieves IP address activity summaries from Chronicle SIEM using the lookup_entity tool.

Community
Intermediate
dandyedandye
85

hash-get-secops-threat-intel

Retrieves SecOps threat intelligence summaries for MD5, SHA1, or SHA256 file hashes.

Community
Intermediate
dandyedandye
85

url-get-secops-threat-intel

Retrieves threat intelligence summaries for URLs using the Chronicle SecOps MCP get_threat_intel tool.

Community
Intermediate
dandyedandye
85

domain-get-secops-threat-intel

Retrieve Chronicle SecOps threat intelligence summaries and IOC matches for a domain.

Community
Intermediate
dandyedandye
85

url-search-chronicle

Searches Chronicle SIEM proxy and web access logs for HTTP/HTTPS requests to a specific URL.

Community
Intermediate
dandyedandye
85

url-get-gti-report

Retrieves URL reputation reports from Google Threat Intelligence for threat classification.

Community
Intermediate
dandyedandye
85

ip-search-network-traffic-chronicle

Searches Chronicle SIEM for UDM network connection events involving a target IP address.

Community
Intermediate
dandyedandye
85

user-search-login-activity-chronicle

Searches Chronicle SIEM for user login events using natural language security event queries.

Community
Intermediate

Frequently Asked Questions About DanDye

FAQPage Schema
What tasks can I perform using DanDye's security skills?▼

You can triage alerts, enrich IOCs with GTI and Chronicle context, hunt threats using MITRE techniques, run PICERL incident response for phishing, malware, ransomware, and compromised accounts, tune YARA-L detection rules, and generate investigation and case closure reports.

Who are these skills designed for?▼

They target SOC analysts, Tier 1-3 incident responders, threat hunters, and detection engineers working in Google SecOps environments. Runbooks cover alert triage, deep-dive IOC analysis, hypothesis-driven hunts, and detection-as-code rule tuning.

What platforms and prerequisites do these skills require?▼

Skills assume access to Chronicle SIEM (UDM logs), Google Threat Intelligence, SecOps MCP threat intel endpoints, and a SOAR platform for case management. Detection engineering skills additionally use Git-based CI/CD repositories for rule authoring and tuning.

How are investigations and reports produced?▼

Skills reconstruct event timelines, correlate IOCs against SIEM alerts and SOAR cases, group duplicate cases, and write timestamped Markdown deliverables including alert summaries, detection coverage assessments, case closure reports, and executive investigation findings.