hermes
  • Analyse raw email headers

    Analyses raw email headers for the delivery path, SPF, DKIM and DMARC results, alignment, spoofing signs and relay anomalies, explaining each finding in plain words for analysts and support staff.

  • Analyse a packet capture summary

    Analyses a packet capture summary from a tool's output to identify protocols, suspicious connections, beaconing and data transfer patterns, and suggests filters and checks to inspect next.

  • Analyse a suspicious script for defenders

    Explains what a suspicious script or obfuscated command does for defenders, deobfuscating step by step, extracting defanged indicators and rating risk, without improving or weaponising it.

  • Build a forensic timeline

    Builds a forensic timeline from parsed host and log artefacts, normalising time zones, correlating events, separating attacker actions from normal activity and listing evidence gaps.

  • Coach a CTF challenge

    Coaches a learner through an authorised capture-the-flag challenge with graded hints, asking what they have tried and teaching the underlying concept and its defence without handing over the flag.

  • Detection engineer

    Acts as a detection engineer who writes detections as code, tests them against real and synthetic data, tunes false positives and tracks coverage against attacker techniques.

  • Investigate cloud audit logs

    Investigates AWS, GCP or Azure audit logs for suspicious activity such as new access keys, privilege changes, unusual regions, logging tampering or data exports, and recommends containment steps.

  • Investigate a reported phishing email

    Investigates a phishing email reported by staff - extracts defanged indicators, reaches a verdict, scopes who received, clicked or replied, and lists blocking, reset and user communication steps.

  • Map detection coverage to attack techniques

    Maps an organisation's existing detections to attack techniques, finds coverage gaps for its threat profile and prioritises new detections by likelihood, impact and data availability.

  • Plan a security tabletop exercise

    Plans a security tabletop exercise with a realistic scenario, timed injects, roles, discussion questions, decision points, a facilitator guide and an after-action report template.

  • Prioritise a vulnerability backlog

    Prioritises a vulnerability scan backlog by severity, exploitation evidence, exposure and asset value, grouping fixes into patch waves with owners, deadlines and time-limited exceptions.

  • Ransomware response track

    Guides a team through a ransomware incident in gated steps - contain, preserve evidence, scope, choose a recovery path, restore safely, then communicate and learn - with decisions logged.

  • Review firewall and security group rules

    Reviews a firewall or cloud security group rule set for overly permissive, shadowed and unused rules, missing egress controls and documentation gaps, and plans a safe staged cleanup.

  • SOC analyst

    Acts as a seasoned security operations analyst who triages on evidence, documents everything, escalates early when impact is possible and stays calm under alert floods.

  • Triage a SOC alert

    Walks a SOC analyst through triaging a security alert turn by turn, asking for the enrichment that matters, weighing benign explanations, reaching an evidenced verdict and writing the escalation note.

  • Write a bug bounty report

    Writes a clear bug bounty or disclosure report for an in-scope finding, with summary, affected asset, reproduction steps, honest impact, evidence and remediation in the programme's format.

  • Write an incident response playbook

    Writes an incident response playbook for one scenario, such as business email compromise or a lost laptop, with triggers, roles, containment, evidence, communication, recovery and review steps.

  • Write a security awareness module

    Writes a short security awareness module for staff on one topic, such as phishing, MFA fatigue or safe file sharing, with realistic examples, clear actions, a quiz and a one-page reminder.

  • Write a SIEM investigation query

    Writes a SIEM or log query for an investigation question in the platform's query language, stating field assumptions, explaining each step, and adding performance tips and a way to validate results.

  • Write a Sigma detection rule

    Writes a Sigma detection rule from an attack behaviour or log samples, with log source, selection and filter logic, false-positive notes, ATT&CK tags and positive and negative test events.

  • Write a threat hunting plan

    Writes a hypothesis-driven threat hunting plan with data sources, queries to run, expected benign baselines, what a finding looks like and how to turn results into detections.

  • Write a threat intelligence brief

    Writes a threat intelligence brief from supplied reports, summarising the threat, its relevance to the organisation, defanged indicators, recommended actions and a stated confidence level.

  • Write a YARA rule

    Writes a YARA rule for a malware family or suspicious file pattern from defender-supplied indicators, balancing strings and conditions to limit false positives, with test and tuning guidance.

Not: building secure software, secure review and hardening (security); personal account safety (digital-safety); outages with no attacker (incident).