π Security Tool Cheatsheet
Alex Morgan — Senior Penetration Tester
Why AI Changes the Game for Security Analysts
AI tools like ChatGPT, Claude, and others have transformed how security analysts operate. From threat intelligence gathering to incident response automation, AI can streamline and enhance various tasks, allowing analysts to focus on higher-level decisions. This cheatsheet provides tailored prompts designed to leverage AI in practical ways for security professionals.
Before You Start: How to Set Context Properly
Effective use of AI involves setting the right context. Begin by specifying the role you want the AI to assume. For example, if you’re looking for a vulnerability assessment, instruct the AI to act like an experienced penetration tester. The more context you provide, the better the response.
Core Prompts Cheatsheet
What it does: This prompt will fetch current vulnerability data and mitigation strategies.
When to use it: When updating security frameworks or conducting training.
How to customize it: Specify the type of web application, e.g., e-commerce, to get tailored insights.
What it does: Produces a threat model outlining potential security risks.
When to use it: During the design phase of new applications.
How to customize it: Specify different environments (cloud vs on-premises).
What it does: Provides a comprehensive list of IoCs relevant to various attacks.
When to use it: For threat hunting or incident response.
How to customize it: Request IoCs specific to malware or phishing.
What it does: Simulates a phishing scenario and describes consequences.
When to use it: For security awareness training for employees.
How to customize it: Provide specific company details for realistic scenarios.
What it does: Provides detailed steps for effective incident response.
When to use it: To develop or refine incident response plans.
How to customize it: Specify the nature of the incident (data breach, DDoS, etc.).
Weak vs Strong Prompt Examples
Advanced Prompt Techniques
Enhancing your AI prompts can yield better results:
- Role Prompting: Specify the role you want the AI to take, such as “Always answer as a security consultant.”
- Chain-of-Thought: Break down complex questions into sequential steps to help the AI think through the problem.
- Few-Shot Examples: Provide sample input-output pairs to illustrate what kind of response you’re seeking.
- Output Formatting: Specify how you want the information structured, e.g., “List this in bullet points.”
Claude vs ChatGPT: Which Works Better For This
Both tools have their strengths. ChatGPT tends to produce more conversational responses, which can be helpful for explanatory prompts. Claude, however, is often better at structured outputs like lists or step-by-step instructions. Choose based on your specific needs.
Tips for Getting Consistent Results
- Be Specific: Provide as much detail as possible in your prompts.
- Iterative Refinement: If the initial response isnβt satisfactory, modify your prompt slightly and try again.
- Feedback Loop: Use the results to fine-tune your prompts over time.
Quick Reference: All Prompts in One Place
- You are an experienced cybersecurity analyst. Provide a list of top vulnerabilities in web applications and their mitigations.
- Generate a threat model for an online banking application.
- List and explain common indicators of compromise (IoCs).
- Simulate a phishing attack against a fictional company and summarize the potential impact.
- Explain the steps for conducting a security incident response.