Design review
Threat Model Builder
Describe a system in English → STRIDE threat model with data flow diagram, threats per element, ranked mitigations, residual risks, and a pen-tester validation checklist.
/threat-model-builderProduces STRIDE model
NIST 800-207
Zero Trust Assessor
ZTA gap analysis across 6 pillars (identity, device, network, app, data, infra). Maturity scorecard, prioritised roadmap with cost bands, dependencies map, exec summary.
/zero-trust-assessorProduces ZTA assessment
Detection engineering
SIEM Rule Writer
Describe a detection in English → production-ready rules in KQL, SPL, Elastic EQL/DSL, Sumo Logic, Chronicle YARA-L. With MITRE ATT&CK mapping, noise assessment, and test cases.
/siem-rule-writerProduces multi-SIEM rules
Policy
Security Policy Drafter
Writes governance-ready policy docs: AUP, password, BYOD, remote work, classification, AI use. Testable requirements, exceptions flow, enforcement, review cycle.
/security-policy-drafterProduces policy document
Ruleset review
Firewall Rule Deduplicator
Paste a firewall ruleset → shadowed / redundant / overly-broad / aliasable / unused rules with per-rule remediation and a prioritised cleanup backlog. Cisco / PA / Fortinet / CP / AWS SG / iptables.
/firewall-rule-deduplicatorProduces cleanup backlog
ISO / SOC 2
Access Review
Periodic access certification pack: scope, sampling plan, per-reviewer worksheets, exception register, SoD checks, and an audit-ready evidence bundle.
/access-reviewProduces review pack
PKI audit
Cert Expiry Audit
Paste a cert inventory or scanner output → P0/P1/P2/P3 renewal backlog, weak-crypto flags, missing-owner prompts, comms drafts, monthly metrics. Stops 01:30 Saturday pages.
/cert-expiry-auditProduces renewal backlog
CVE response
CVE Triage
Paste a CVE + vendor bulletin → patch priority (P0/P1/P2/P3), estate impact, targeted runbook, mitigations, comms, rollback, verification checklist. Uses CISA KEV + EPSS signals.
/cve-triageProduces patch decision pack
Identity
MFA Rollout Planner
Produce a phased MFA plan across M365, Workspace, and SSO apps — with break-glass, legacy-auth disablement, Conditional Access policies, comms pack, and rollback.
/mfa-rollout-plannerProduces MFA plan
Awareness
Phishing Sim Campaign Planner
Quarter-long phishing-simulation programme with escalating difficulty, role-tailored lures, ethical guardrails, RAG reporting, and repeat-clicker handling that drives change without shaming.
/phishing-sim-campaign-plannerProduces campaign plan
Mobile / MDM
BYOD Policy Drafter
Bring-Your-Own-Device policy for an SMB — eligibility, MDM enrolment, data-separation model, stipend, leaver selective-wipe, staff FAQ.
/byod-policy-drafterProduces policy document
Secrets
Secrets Rotation Plan
Find and rotate long-lived secrets — API keys, service creds, SSH, DB passwords, certs, shared passwords — with discovery, prioritisation, phased rotation, vaulting, ongoing hygiene.
/secrets-rotation-planProduces rotation plan