By drbothen
ICS/OT Security Operations — CVE enrichment, event investigation, MITRE ATT&CK mapping, and adversarial quality review with convergence-driven analysis.
Multi-pass adversarial convergence review of security analyses
Calculate multi-factor priority (P1-P5) for a vulnerability
Create a structured security advisory for a CVE, threat campaign, or vendor bulletin. Supports IT, ICS/OT, and combined audiences with built-in or custom templates.
Complete 8-stage enrichment workflow for a security ticket
Verify factual claims against authoritative sources
Use when creating security advisories, scanning for emerging threats, or drafting advisory bulletins for IT, ICS/OT, or combined audiences.
Orchestrator workflow reference for the 8-stage CVE enrichment pipeline. Loaded by the enrich-ticket skill. Not directly invokable.
Orchestrator workflow reference for the 7-stage security event investigation pipeline. Loaded by the investigate-event skill. Not directly invokable.
Orchestrator workflow reference for the adversarial review convergence loop. Loaded by the adversarial-review-secops skill. Not directly invokable.
Use when performing vulnerability enrichment, CVE research, security ticket analysis, risk assessment, MITRE ATT&CK mapping, or security event investigation for ICS/OT and enterprise environments.
Use when performing multi-pass adversarial convergence review of security analyses. Dispatches security-reviewer in fresh-context passes with strict-binary novelty until convergence. Quality thresholds: >=7.0/10 overall, no dimension <5.0.
Use when calculating multi-factor vulnerability priority. Combines CVSS severity, EPSS exploitation probability, CISA KEV status, asset criticality, system exposure, and exploit availability into P1-P5 with SLA.
Use when creating a structured security advisory for a CVE, threat campaign, or vendor bulletin. Supports IT, ICS/OT, and combined audiences. Accepts built-in or custom templates.
Use when enriching a security ticket with vulnerability intelligence. Executes 8-stage enrichment: triage, CVE research, business context, remediation, ATT&CK mapping, priority assessment, documentation, JIRA update.
Use when verifying factual claims in security analyses against authoritative sources. Supports CVE claim verification and event investigation verification.
Executes bash commands
Hook triggers when Bash tool is used
Modifies files
Hook triggers on file write and edit operations
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Uses power tools
Uses Bash, Write, or Edit tools
Uses power tools
Uses Bash, Write, or Edit tools
ICS/OT security operations plugin for Claude Code -- CVE enrichment, event investigation, and adversarial quality review.
SecOps Factory is a Claude Code plugin that turns Claude into an ICS/OT security operations analyst. It provides structured, repeatable workflows for vulnerability enrichment and security event investigation, backed by authoritative intelligence sources (NVD, CISA KEV, FIRST EPSS, MITRE ATT&CK) via MCP server integrations.
The plugin enforces quality through adversarial convergence review -- a multi-pass review loop where a separate reviewer agent evaluates analysis quality with fresh context each pass, preventing blind spots from compounding. Every analysis is scored across multiple quality dimensions, and cognitive bias detection is mandatory at every stage.
SecOps Factory connects directly to your JIRA instance for ticket intake and enrichment posting, and uses Perplexity for real-time CVE research and threat intelligence. The result is security analysis that is structured, traceable, and auditable -- not freeform text generation.
From the drbothen marketplace (recommended):
drbothen/claude-mp is the shared marketplace for all drbothen plugins (secops-factory, vsdd-factory, ...). Register it once and install/update any plugin from it.
/plugin marketplace add drbothen/claude-mp
/plugin install secops-factory@claude-mp
Update to latest version:
/plugin marketplace update drbothen/claude-mp
/plugin update secops-factory@claude-mp
Alternative: from the secops-factory repo directly:
Useful if you only want secops-factory and don't want the wider drbothen marketplace registered.
/plugin marketplace add drbothen/secops-factory
/plugin install secops-factory@secops-factory
From source (local development):
git clone https://github.com/drbothen/secops-factory.git
claude --plugin-dir ./secops-factory/plugins/secops-factory
SecOps Factory uses jr CLI for JIRA and Perplexity MCP for AI-assisted research.
jr CLI (required):
Install the jira-cli Rust CLI and authenticate with jr auth login. The plugin calls jr issue view, jr issue edit, jr issue comment, jr issue move, jr issue list, and jr issue assets via Bash.
Perplexity MCP (recommended):
Configure the Perplexity MCP server with your API key. The plugin uses perplexity_search, perplexity_ask, perplexity_reason, and perplexity_research at different tiers based on CVE severity. If not configured, skills fall back to web search.
/secops-factory:secops-health
This checks MCP server availability, data files, templates, checklists, and skills.
/secops-factory:enrich-ticket SEC-1234
The plugin reads the JIRA ticket, extracts CVE IDs, researches vulnerability intelligence via Perplexity, assesses business context and priority, maps to MITRE ATT&CK, generates a structured enrichment document, and updates the JIRA ticket.
flowchart LR
A[1. Triage] --> B[2. CVE Research]
B --> C[3. Business Context]
C --> D[4. Remediation]
D --> E[5. ATT&CK Mapping]
E --> F[6. Priority Assessment]
F --> G[7. Documentation]
G --> H[8. JIRA Update]
style A fill:#e1f5fe
style H fill:#e8f5e9
npx claudepluginhub drbothen/claude-mp --plugin secops-factoryVerified Spec-Driven Development (VSDD) dark factory for software — full SDLC pipeline: brownfield ingest, spec crystallization, story decomposition, TDD delivery, adversarial review, holdout evaluation, formal verification, and release gating.
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, and rules evolved over 10+ months of intensive daily use
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Unity Development Toolkit - Expert agents for scripting/refactoring/optimization, script templates, and Agent Skills for Unity C# development