Agent Skills
› zakirkun/deep-eye
› blue-team
blue-team
GitHub利用 Deep Eye 生成的攻击语料进行蓝队防御,涵盖检测工程、SIEM/WAF 规则编写、控制验证及 IR 加固。用于威胁狩猎和漏洞复测。
Trigger Scenarios
编写安全检测规则
进行红蓝对抗测试
安全加固与硬ening
SOC 事件调查
Install
npx skills add zakirkun/deep-eye --skill blue-team -g -y
SKILL.md
Frontmatter
{
"name": "blue-team",
"description": "Blue team defense using Deep Eye outputs for detection engineering, IR content, and hardening. Use for blue team, SOC, SIEM, detection engineering, threat hunting, IR triage, hardening, \/blue-team."
}
Deep Eye — Blue Team Skill
Deep Eye = controlled attack corpus for detection and control validation.
Generate corpus
python deep_eye.py -u https://STAGING -v --formats json,sarif
Useful noisy checks: sql_injection, xss, ssrf, ssrf_cloud, log4shell, lfi, crlf_injection, smuggling modules.
Detection loop
- Take High finding (
payload,url,type) - Write SIEM/WAF rule
- Replay scan / single request
- Measure FPs
- Document owner
Control validation
| Finding | Control |
|---|---|
| IDOR/BOLA | Object-level authz |
| JWT | Alg lockdown, signature verify |
| SSRF | Egress / metadata block |
| XSS | CSP + encoding |
| Secrets | Scanner + CI secret scan |
Retest
python deep_eye.py -u URL --retest-new reports/prior.json
Rules
Do not disable prod controls only to silence scans; coordinate SOC windows.
Version History
- dc5059c Current 2026-08-20 02:49


