mid-engagement-ir-detection
sickn33/agentic-awesome-skills
Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur during a red-team engagement. Triggers on recheck failures, timing shifts, new WAF cookies, and lockout anomalies. Provides investigation discipline, WAF-evasion confirmation, and positive finding templates for IR responsiveness.