Blue Team — Security agent for Claude Code
Defensive security and hardening specialist.
How to install Blue Team
Installs to ~/.claude/agents/mukul975-threatswarm-blue-team.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/blue-team.md -o ~/.claude/agents/mukul975-threatswarm-blue-team.md Restart Claude Code, or start a new session, for it to be picked up.
What Blue Team does
name: blue-team description: Defensive security and hardening specialist. Creates detection rules, hardens Linux/Windows systems, writes Sigma rules, configures auditd, fail2ban, Sysmon, and provides CIS benchmark remediation guidance. Triggers on: harden, detection, Sigma rule, Sysmon, auditd, fail2ban, CIS benchmark, SIEM detection, blue team, defensive, firewall rules, access control, Windows hardening, Linux hardening. tools: Bash, Read, Write, Glob model: sonnet
Cybersecurity Sk
Alternatives in Security
- Malware Analyst — You are an elite malware analyst focused on defensive security research 31.9k ★
- Aegis — You are a specialized security agent 3.6k ★
- Config Auditor — Security header and server configuration auditor 812 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Network Security Engineer
Network Security Engineer (Tier 3): hardens the network perimeter and runtime — TLS 1.3/HSTS/ACME, nginx/Caddy
Byok Token Security Expert
BYOK (Bring-Your-Own-Key) and OAuth token security expert. Deep on cross-platform OS keychain integration (mac
Sec Blue Teamer
Defensive security analyst that evaluates security posture — control inventory, consistency, defense-in-depth,
Doc Consistency Reviewer
Audit plugin README parity, platform-specific benchmark evidence and community documentation against Foundry's
Detection Engineer
Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator anal
Hive Hooks
Claude hooks engineer who configures, audits, and debugs .claude/settings.json hooks with security-first disci
Related Skills
Yotta Agent Hardening
YuanSafe (元安全) — defensive hardening workflow for AI agents: static config-facing scan of an agent's own runti
Claudebench
Stop arguing about prompts. Measure them. A reproducible, statistically-honest benchmark harness for Claude Co
Tellbench
Behavioral benchmark for LLM coding agents: what a model reaches for when the task is underspecified — destruc