Agent Skills
› zakirkun/deep-eye
› blue-team
blue-team
GitHub利用 Deep Eye 生成受控攻击语料,执行检测循环以编写 SIEM/WAF 规则并验证控制措施,支持威胁狩猎、事件响应及系统加固。
Trigger Scenarios
编写安全检测规则
进行漏洞复测与误报评估
验证安全防护控制有效性
Install
npx skills add zakirkun/deep-eye --skill blue-team -g -y
SKILL.md
Frontmatter
{
"name": "blue-team",
"description": "Blue team defense using Deep Eye outputs for detection engineering, IR content, and hardening. Use for blue team, SOC, SIEM, detection engineering, threat hunting, IR triage, hardening, \/blue-team."
}
Deep Eye — Blue Team Skill
Deep Eye = controlled attack corpus for detection and control validation.
Generate corpus
python deep_eye.py -u https://STAGING -v --formats json,sarif
Useful noisy checks: sql_injection, xss, ssrf, ssrf_cloud, log4shell, lfi, crlf_injection, smuggling modules.
Detection loop
- Take High finding (
payload,url,type) - Write SIEM/WAF rule
- Replay scan / single request
- Measure FPs
- Document owner
Control validation
| Finding | Control |
|---|---|
| IDOR/BOLA | Object-level authz |
| JWT | Alg lockdown, signature verify |
| SSRF | Egress / metadata block |
| XSS | CSP + encoding |
| Secrets | Scanner + CI secret scan |
Retest
python deep_eye.py -u URL --retest-new reports/prior.json
Rules
Do not disable prod controls only to silence scans; coordinate SOC windows.
Version History
- dc5059c Current 2026-08-20 02:49


