Alternatives

FCL alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

FCL

FCL (Fileless Command Lines) - Known command lines of fileless malicious executions

48
Quality
70
Trust
478
Stars
#1

Fame

Similarity 126Trust 86Excellent 87

FAME Automates Malware Evaluation

941 starsJun 13, 2026 pushdevopsPythonIncident Response
$ npx skills add certsocietegenerale/fame
#2

Volatility3

Similarity 123Trust 89Excellent 100

Volatility 3.0 development

4.2K starsMay 26, 2026 pushdevopsPythonIncident Response
$ npx skills add volatilityfoundation/volatility3
#3

My Arsenal Of Aws Security Tools

Similarity 117Trust 91Excellent 100

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

9.5K starsApr 17, 2026 pushdevopsShellIncident Response
$ npx skills add toniblyx/my-arsenal-of-aws-security-tools
#4

UTMStack

Similarity 117Trust 88Excellent 85

Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

568 starsJun 16, 2026 pushdevopsTypeScriptIncident Response
$ npx skills add utmstack/UTMStack
#5

BlueTeam Tools

Similarity 116Trust 81Strong 72

Tools and Techniques for Blue Team / Incident Response

4.1K starsMar 27, 2025 pushdevopsIncident ResponseClaude Code
$ npx skills add A-poc/BlueTeam-Tools
#6

Hayabusa

Similarity 116Trust 95Excellent 100

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

3.2K starsJun 7, 2026 pushdevopsRustIncident Response
$ npx skills add Yamato-Security/hayabusa
#7

APT Hunter

Similarity 115Trust 86Strong 72

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

1.4K starsNov 7, 2024 pushdevopsPythonIncident Response
$ npx skills add ahmedkhlief/APT-Hunter
#8

Velociraptor

Similarity 115Trust 89Excellent 100

Digging Deeper....

4.0K starsJun 16, 2026 pushdevopsGoIncident Response
$ npx skills add Velocidex/velociraptor
#9

Sleuthkit

Similarity 115Trust 90Excellent 100

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

3.1K starsJun 12, 2026 pushdevopsCIncident Response
$ npx skills add sleuthkit/sleuthkit
#10

Beagle

Similarity 115Trust 84Strong 72

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

1.3K starsDec 13, 2022 pushdevopsPythonIncident Response
$ npx skills add yampelo/beagle
#11

Impacket IoCs

Similarity 114Trust 85Strong 82

This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library

302 starsMay 24, 2026 pushdevopsIncident ResponseClaude Code
$ npx skills add ThatTotallyRealMyth/Impacket-IoCs
#12

Cyberchef Recipes

Similarity 114Trust 79Promising 69

A list of cyber-chef recipes and curated links

2.2K starsJun 14, 2024 pushdevopsIncident ResponseClaude Code
$ npx skills add mattnotmax/cyberchef-recipes
#13

PersistenceSniper

Similarity 114Trust 79Promising 69

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte

2.1K starsDec 11, 2024 pushdevopsPowerShellIncident Response
$ npx skills add last-byte/PersistenceSniper
#14

Iris Web

Similarity 114Trust 93Excellent 100

Collaborative Incident Response platform

1.5K starsJun 8, 2026 pushdevopsPythonIncident Response
$ npx skills add dfir-iris/iris-web
#15

AiSOC

Similarity 114Trust 93Excellent 100

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

1.4K starsJun 15, 2026 pushdevopsPythonIncident Response
$ npx skills add beenuar/AiSOC
#16

SecurityResearcher Note

Similarity 114Trust 70Needs review 48

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

488 starsApr 17, 2025 pushdevopsPowerShellIncident Response
$ npx skills add LearningKijo/SecurityResearcher-Note

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep FCL if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.