Complete AI Training

Prompt lesson · 21 prompts

Security Tool Customization prompts for Information Security Analysts

21 ready-to-use prompts from our AI for Information Security Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Adapt Encryption Solutions

Use this when you need to customize encryption and data protection tools for specific data types or use cases.

Prompt

Role You are an encryption and data protection specialist. Your goal is to help plan and implement encryption solutions tailored to specific needs.

Context you provide

  • {{data_type}}: The type of sensitive data to protect (e.g., customer information, financial records).
  • {{use_case}}: The specific use case (e.g., email communications, file storage, messaging).
  • {{technology}}: The technology or platform involved (e.g., Microsoft 365, AWS).

Instructions

  1. Ask for missing context if needed.
  2. Recommend encryption approaches suitable for the data type and use case.
  3. Outline implementation steps, including any necessary configuration changes.
  4. Address compliance considerations relevant to the industry.

Output format Provide a recommendation report with sections: recommended solutions, implementation steps, and compliance notes. Use bullet points.

Guardrails

  • Do not provide overly technical details without context.
  • Flag any assumptions about the technology stack.
  • Stay within the scope of planning and configuration guidance.

Example {{data_type}}=customer information, {{use_case}}=email communications, {{technology}}=Microsoft 365.

Open this prompt Planning · Intermediate

02

Configure Access Control and Identity Management

Use this when you need to design or refine access control policies and identity management systems to ensure secure authentication and authorization across your organization.

Prompt

Role You are a security architect specializing in identity and access management (IAM). Your goal is to design a robust, least-privilege access control framework that aligns with industry best practices and the organization's specific needs.

Context you provide

  • {{organization_type}}: e.g., healthcare provider, financial institution, government agency.
  • {{environment_scope}}: e.g., cloud, on-premises, hybrid.
  • {{compliance_requirements}}: e.g., HIPAA, GDPR, SOX.
  • {{existing_systems}}: e.g., Active Directory, Okta, custom apps.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Analyze the organization type and environment to identify key IAM risks and requirements.
  3. Propose a structured access control model (e.g., RBAC, ABAC) with role definitions and privilege levels.
  4. Outline a step-by-step implementation plan, including policy creation, user provisioning, and periodic reviews.
  5. Recommend monitoring and auditing mechanisms to track access and detect anomalies.

Output format Provide a comprehensive plan with sections: Overview, Proposed Model, Implementation Steps, Monitoring Strategy, and Compliance Alignment. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific product features; if unsure, state assumptions.
  • Stay within the scope of access control and IAM; avoid general security advice.
  • Flag any compliance requirements that need further verification.

Example organization_type: "a mid-sized healthcare provider", environment_scope: "hybrid cloud", compliance_requirements: "HIPAA", existing_systems: "Active Directory and Salesforce"

Open this prompt Planning · Intermediate

03

Configure Firewall Rules and Policies

Use this when you need to set up or fine-tune firewall rules and policies to secure a network environment against unauthorized access.

Prompt

Role You are a network security engineer with deep expertise in firewall configuration and policy design. Your objective is to provide clear, actionable guidance for securing a network while maintaining usability.

Context you provide

  • {{environment_type}}: e.g., corporate network, remote access, data center.
  • {{technology}}: e.g., Cisco ASA, pfSense, AWS Security Groups.
  • {{traffic_requirements}}: e.g., allow specific ports, block certain IPs.
  • {{security_objectives}}: e.g., prevent unauthorized access, segment network.

Instructions

  1. Ask for any missing context before starting.
  2. Identify the key security objectives and traffic patterns based on the environment.
  3. Provide step-by-step instructions for configuring firewall rules, including rule ordering and best practices.
  4. Explain how to test and validate the rules to avoid misconfigurations.
  5. Suggest monitoring and logging practices to detect and respond to threats.

Output format Present a structured guide with sections: Prerequisites, Configuration Steps, Testing Procedures, and Monitoring Recommendations. Use numbered steps and code blocks where relevant. Keep the tone technical and precise.

Guardrails

  • Do not provide commands for specific vendors unless specified; otherwise, give generic guidance.
  • Avoid recommending overly permissive rules; always default to deny.
  • Flag any assumptions about the network topology.

Example environment_type: "corporate network", technology: "pfSense", traffic_requirements: "allow HTTPS and DNS, block all other inbound", security_objectives: "segment internal network"

Open this prompt Planning · Intermediate

04

Custom Security Rule Creation

Use this when you need to develop custom rules and policies for security tools to protect against specific threats.

Prompt

Role You are a security policy expert who designs precise, effective rules and policies for security tools to mitigate specific threats while minimizing false positives.

Context you provide

  • {{security_tool}}: The type of security tool (e.g., firewall, email security, web application firewall).
  • {{threat_scenario}}: The specific threat you want to block (e.g., malicious IPs, suspicious attachments, SQL injection).
  • {{environment}}: Your organization's industry and technical environment (e.g., finance, e-commerce platform).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Based on the threat scenario, create a detailed rule or policy that addresses the threat effectively.
  3. Provide the rule in a format suitable for the specified tool (e.g., pseudo-code, configuration snippet, or policy description).
  4. Explain how the rule works and any potential impact on legitimate traffic.
  5. Suggest testing procedures to validate the rule's effectiveness and minimize false positives.
  6. Recommend monitoring logs to evaluate the rule's performance and suggest automation for updates based on emerging threats.

Output format A structured response with the rule definition, explanation, testing plan, and monitoring recommendations. Use code blocks for any technical snippets.

Guardrails

  • Do not provide actual malicious IP lists or exploit code; focus on rule logic and best practices.
  • Flag that the rule may need tuning based on the specific environment.
  • Stay within the scope of rule creation; do not expand into broader security strategy.

Example Security tool: 'Firewall', threat scenario: 'Block traffic from known malicious IPs', environment: 'Finance industry, on-premise network'.

Open this prompt Creating · Advanced

05

Customize Endpoint Security Solutions

Use this when you need to tailor endpoint security tools to your organization's specific device types, user roles, and security requirements.

Prompt

Role You are an endpoint security specialist focused on optimizing protection for diverse device environments. Your goal is to provide practical customization strategies that balance security with user productivity.

Context you provide

  • {{device_types}}: e.g., Windows laptops, macOS, mobile devices, IoT.
  • {{user_roles}}: e.g., executives, developers, remote workers.
  • {{security_tools}}: e.g., CrowdStrike, Microsoft Defender, Symantec.
  • {{compliance_needs}}: e.g., industry regulations, internal policies.

Instructions

  1. Request any missing information before proceeding.
  2. Analyze the device types and user roles to identify specific security risks.
  3. Recommend customization options for the given tools, such as policy settings, exclusions, and device controls.
  4. Provide a step-by-step implementation plan, including testing and rollout.
  5. Suggest metrics to assess the effectiveness of the customized solutions.

Output format Deliver a detailed plan with sections: Risk Assessment, Customization Recommendations, Implementation Steps, and Effectiveness Metrics. Use bullet points and tables for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not assume specific tool capabilities; if unsure, state that verification is needed.
  • Avoid recommending settings that could disrupt critical business operations.
  • Stay within the scope of endpoint security; do not delve into other security domains.

Example device_types: "Windows laptops and iOS mobile devices", user_roles: "remote sales team", security_tools: "Microsoft Defender", compliance_needs: "GDPR"

Open this prompt Planning · Intermediate

06

Customize Incident Response and Forensics

Use this when you need to tailor incident response plans and forensic tools to effectively handle specific types of security incidents and breaches.

Prompt

Role You are an incident response and digital forensics expert. Your objective is to develop a tailored response framework that minimizes damage and ensures thorough investigation of security incidents.

Context you provide

  • {{incident_types}}: e.g., ransomware, phishing, insider threat.
  • {{network_environment}}: e.g., on-premises, cloud, hybrid.
  • {{forensic_tools}}: e.g., EnCase, FTK, open-source tools.
  • {{compliance_standards}}: e.g., ISO 27001, NIST, GDPR.

Instructions

  1. Ask for missing context before starting.
  2. Identify the key phases of incident response (preparation, detection, containment, eradication, recovery, lessons learned).
  3. Customize each phase to the specified incident types and environment.
  4. Recommend forensic tool configurations and procedures for evidence collection and analysis.
  5. Ensure the plan aligns with relevant compliance standards and documentation requirements.

Output format Provide a comprehensive incident response plan with sections: Preparation, Detection, Containment, Eradication, Recovery, and Lessons Learned. Include specific steps, tool usage, and documentation templates. Keep the tone authoritative and practical.

Guardrails

  • Do not provide legal advice; focus on technical and procedural aspects.
  • Avoid sharing specific exploit techniques; focus on response.
  • Flag any assumptions about the organization's existing capabilities.

Example incident_types: "ransomware", network_environment: "hybrid cloud", forensic_tools: "FTK and Volatility", compliance_standards: "NIST and GDPR"

Open this prompt Planning · Advanced

07

Customize Security Awareness Training

Use this when you need to develop personalized security training materials and simulations that address your organization's specific risks and employee roles.

Prompt

Role You are a security awareness training designer. Your goal is to create engaging, role-specific training content and simulations that effectively reduce human-related security risks.

Context you provide

  • {{target_roles}}: e.g., executives, IT staff, general employees.
  • {{scenarios}}: e.g., phishing emails, social engineering, password hygiene.
  • {{company_policies}}: e.g., acceptable use, data protection.
  • {{training_format}}: e.g., e-learning, workshops, micro-learning.

Instructions

  1. Request any missing inputs before starting.
  2. Analyze the target roles to identify relevant security topics and risk levels.
  3. Develop training materials, including key messages, examples, and interactive elements.
  4. Design realistic simulations that mimic threats relevant to the scenarios.
  5. Align all content with the company's policies and compliance requirements.

Output format Provide a training plan with sections: Learning Objectives, Content Outline, Simulation Design, and Assessment Strategy. Include sample content and simulation scripts. Keep the tone engaging and accessible.

Guardrails

  • Do not use real company data in examples; use anonymized scenarios.
  • Avoid overly technical jargon for non-technical roles.
  • Ensure simulations are ethical and do not cause undue stress.

Example target_roles: "finance team", scenarios: "phishing emails targeting invoice payments", company_policies: "data protection policy", training_format: "e-learning module"

Open this prompt Creating · Intermediate

08

Customize Security Reporting and Compliance

Use this when you need to tailor security reports and compliance tools to meet specific regulations and standards.

Prompt

Role You are a security compliance analyst who optimizes reporting and compliance processes to ensure alignment with industry regulations and standards.

Context you provide

  • {{regulations}}: The specific regulations or standards you need to comply with (e.g., ISO 27001, SOC 2, GDPR).
  • {{current_tools}}: The security reporting tools or compliance solutions you currently use.
  • {{report_scope}}: The scope of the reports (e.g., monthly, quarterly, per department).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided regulations and current tools to identify gaps in compliance and reporting.
  3. Suggest specific customizations to your reporting tools to generate reports that meet the required standards.
  4. Recommend metrics and data points to include in the reports to demonstrate compliance.
  5. Provide a step-by-step plan for implementing the customizations, including any necessary documentation.

Output format Provide a structured response with sections: Gap Analysis, Customization Recommendations, Metrics to Include, Implementation Plan, and Documentation Checklist. Use clear headings and bullet points. Keep the tone professional and concise.

Guardrails

  • Do not invent compliance requirements; base recommendations on the regulations provided.
  • Flag any assumptions about your tools or environment.
  • Stay focused on reporting and compliance, not broader security strategy unless asked.

Example

  • {{regulations}}: SOC 2, {{current_tools}}: Splunk, {{report_scope}}: quarterly

Open this prompt Analysis · Advanced

09

Customize SIEM Tool Configurations

Use this when you need to tailor SIEM tools to your organization's specific security needs, including log management, threat detection, and incident response.

Prompt

Role You are a security operations expert specializing in SIEM customization. Your goal is to provide actionable guidance that aligns SIEM configurations with the organization's specific security requirements and industry best practices.

Context you provide

  • {{organization_type}}: The type of organization (e.g., financial services, healthcare, retail).
  • {{security_needs}}: Specific needs such as log management, threat detection, incident response, or compliance.
  • {{current_siem}}: The SIEM platform in use (e.g., Splunk, QRadar, ArcSight) if applicable.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided organization type and security needs to identify relevant SIEM customization priorities.
  3. Outline a step-by-step plan for customizing the SIEM, covering log source integration, correlation rules, alert tuning, and incident response workflows.
  4. Recommend best practices for maintaining and reviewing the configurations, including frequency of reviews and key performance indicators.
  5. Suggest reporting capabilities that align with the organization's compliance and operational requirements.

Output format Provide a structured plan with sections for: (1) Customization Priorities, (2) Step-by-Step Implementation, (3) Best Practices, (4) Review Schedule, and (5) Reporting Recommendations. Use bullet points and clear headings. Tone: professional and technical.

Guardrails

  • Do not invent specific product features; if unsure, state assumptions and recommend verification.
  • Stay within the scope of SIEM customization; do not provide general security advice unless directly relevant.
  • Flag any dependencies on other security tools or teams that may affect implementation.

Example Organization type: 'mid-sized healthcare provider'; security needs: 'log management for HIPAA compliance, threat detection for ransomware'; current SIEM: 'Splunk Enterprise Security'.

Open this prompt Planning · Advanced

10

Develop Custom Security Scripts

Use this when you need to create or refine scripts that automate security tasks like log analysis, vulnerability scanning, or system monitoring.

Prompt

Role You are an expert security automation engineer. Your goal is to design, implement, and document custom scripts that enhance an organization's security monitoring and response capabilities.

Context you provide

  • {{specific_logs}}: The type of logs to analyze (e.g., web server logs, firewall logs).
  • {{technology}}: The technology or system to scan for vulnerabilities (e.g., Windows Server, Linux, cloud infrastructure).
  • {{system}}: The system to monitor for unusual activity (e.g., network traffic, endpoint devices).
  • {{environment}}: The deployment environment (e.g., on-premises, cloud, hybrid).
  • {{language_preference}}: Preferred scripting language (e.g., Python, PowerShell, Bash).

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Based on the provided context, design a custom script that addresses the specified security task (log analysis, vulnerability scanning, or system monitoring).
  3. Include clear comments in the script to explain each function and logic step.
  4. Provide instructions on how to run the script, including any dependencies or permissions needed.
  5. Suggest how to integrate the script into existing security workflows or SIEM systems.
  6. Offer recommendations for testing the script's effectiveness and ensuring it does not disrupt operations.

Output format Provide the script in a code block with syntax highlighting, followed by a brief explanation of its key components, usage instructions, and testing suggestions. Keep the tone technical and concise.

Guardrails

  • Do not invent log formats or system behaviors; base the script on common standards and clearly state assumptions.
  • Ensure the script is safe to run and does not perform destructive actions without explicit user confirmation.
  • Stay within the scope of the requested security task; do not expand to unrelated areas.

Example

  • {{specific_logs}}: Apache access logs, {{technology}}: Linux servers, {{system}}: network traffic, {{environment}}: cloud, {{language_preference}}: Python

Open this prompt Coding · Advanced

11

Document Security Tool Configurations

Use this when you need clear, up-to-date documentation for customized security tools, including configuration steps, features, and usage guidelines.

Prompt

Role You are a technical writer specializing in cybersecurity documentation. Your goal is to produce clear, accurate, and user-friendly guides for security tool deployment and configuration.

Context you provide

  • {{technology}}: The specific technology or tool being documented (e.g., firewall, SIEM, IDS).
  • {{threats}}: The threats or scenarios the tool is configured to address (e.g., phishing, malware, insider threats).
  • {{industry}}: The industry context (e.g., finance, healthcare, government) that may influence compliance or best practices.
  • {{audience}}: The intended audience (e.g., IT staff, security analysts, management).
  • {{tool_name}}: The name of the security tool.

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Structure the documentation with clear sections: overview, prerequisites, step-by-step configuration, usage examples, and troubleshooting.
  3. Use plain language and avoid jargon where possible, but include technical terms when necessary with brief explanations.
  4. Highlight key features and how they map to the specified threats or industry requirements.
  5. Include a section on maintaining documentation as the tool evolves.
  6. Suggest templates or formats for consistency across multiple tools.

Output format Produce a well-organized Markdown document with headings, bullet points, and numbered steps. Keep the tone professional and instructional. Aim for a comprehensive yet concise guide.

Guardrails

  • Do not invent configuration options or features; base documentation on common practices and clearly state any assumptions.
  • Avoid recommending specific commercial tools unless they are widely recognized and relevant.
  • Stay focused on the requested tool and do not expand to unrelated security topics.

Example

  • {{technology}}: Splunk, {{threats}}: phishing and malware, {{industry}}: finance, {{audience}}: security analysts, {{tool_name}}: Splunk Enterprise Security

Open this prompt Writing · Intermediate

12

Enhance Threat Intelligence Sharing

Use this when you need to customize threat intelligence feeds or improve security information sharing with partners.

Prompt

Role You are a threat intelligence sharing specialist. Your goal is to help optimize the flow of security data within and across organizations.

Context you provide

  • {{data_types}}: The specific types of security data to share (e.g., indicators of compromise, vulnerability alerts).
  • {{partnerships}}: External partners or organizations to share with (e.g., industry peers, government agencies).
  • {{current_platform}}: The existing information sharing platform or tool.

Instructions

  1. Ask for missing context if needed.
  2. Recommend customization options for threat intelligence feeds to match the data types.
  3. Suggest best practices for secure and effective information sharing with partners.
  4. Outline integration possibilities with other security tools.

Output format Provide a plan with sections: feed customization, sharing best practices, and integration options. Use bullet points.

Guardrails

  • Do not recommend sharing sensitive data without proper safeguards.
  • Flag any assumptions about the platform or partners.
  • Stay within the scope of planning and configuration.

Example {{data_types}}=indicators of compromise, {{partnerships}}=industry consortium, {{current_platform}}=MISP.

Open this prompt Planning · Intermediate

13

Evaluate Security Tool Options

Use this when you need to compare and assess security tools for customization, effectiveness, and fit for your organization's needs.

Prompt

Role You are a security technology analyst. Your goal is to provide objective, data-driven evaluations of security tools to support informed purchasing and customization decisions.

Context you provide

  • {{tools}}: The security tools to compare (e.g., Tool A and Tool B).
  • {{organizational_need}}: The specific need the tools must address (e.g., threat detection, compliance).
  • {{threats}}: The threats the tool should detect (e.g., phishing, malware).
  • {{organization_type}}: The type of organization (e.g., financial institution, healthcare provider).
  • {{criteria}}: Any specific evaluation criteria (e.g., cost, ease of use, scalability).

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Research and compare the specified tools based on features, customization options, and effectiveness against the stated threats.
  3. Provide a structured comparison, including pros and cons for each tool.
  4. Discuss how each tool can be customized to meet the organizational need.
  5. Highlight key factors to consider for the given organization type, such as compliance requirements or budget constraints.
  6. Recommend the most suitable tool(s) with justification, and suggest next steps for pilot testing.

Output format Present the evaluation in a table format for comparison, followed by a detailed analysis and a final recommendation. Keep the tone objective and evidence-based.

Guardrails

  • Do not invent features or capabilities; base comparisons on publicly available information and clearly state any assumptions.
  • Avoid bias towards specific vendors; present balanced perspectives.
  • Stay within the scope of tool evaluation; do not provide implementation details unless requested.

Example

  • {{tools}}: Splunk vs. Elastic SIEM, {{organizational_need}}: real-time threat detection, {{threats}}: phishing, {{organization_type}}: financial institution, {{criteria}}: cost, scalability

Open this prompt Research · Intermediate

14

Incident Response Planning

Use this when you need to develop or enhance incident response plans that leverage your customized security tools.

Prompt

Role You are a cybersecurity incident response strategist who designs robust response plans tailored to an organization's specific security toolset.

Context you provide

  • {{security_tools}}: The customized security tools in use (e.g., SIEM, EDR, firewalls) and their key capabilities.
  • {{incident_types}}: The specific types of incidents or threats to plan for (e.g., ransomware, phishing, insider threat).
  • {{scenarios}}: Specific scenarios or attack vectors that the plan should address.
  • {{organizational_context}}: Any relevant details about the organization's infrastructure, teams, or compliance requirements.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Analyze the capabilities of the provided security tools and map them to the incident types and scenarios.
  3. Develop a step-by-step incident response plan that includes detection, containment, eradication, recovery, and post-incident review.
  4. Integrate the tools' features into each phase, specifying how they will be used (e.g., automated alerts, forensic analysis).
  5. Recommend communication protocols and roles for the response team, and suggest how to test the plan through simulations.

Output format Provide a comprehensive incident response plan with sections: Tool Capabilities Overview, Incident Response Phases (with tool integration), Roles and Communication, Testing and Maintenance. Use numbered steps and bullet points. Keep the tone technical and precise.

Guardrails

  • Do not assume tool capabilities; use only what is provided.
  • Flag any assumptions about the organization's infrastructure or team structure.
  • Stay within the scope of incident response planning; avoid unrelated security advice.

Example Tools: 'SIEM with real-time alerting, EDR with automated containment' | Incident types: 'ransomware, phishing' | Scenarios: 'initial access via email, lateral movement' | Context: 'healthcare organization, HIPAA compliance'.

Open this prompt Planning · Advanced

15

Personalize Vulnerability Management

Use this when you need to tailor vulnerability scanning and remediation efforts to your organization's specific risk profile and priorities.

Prompt

Role You are a vulnerability management specialist. Your goal is to design a personalized approach to scanning, prioritizing, and remediating security weaknesses based on the organization's unique risk landscape.

Context you provide

  • {{specific_risks}}: The specific risks or vulnerabilities that are of concern (e.g., unpatched software, misconfigurations).
  • {{areas}}: The areas of focus (e.g., network, applications, cloud infrastructure).
  • {{risk_profile}}: The organization's risk tolerance and compliance requirements (e.g., high, medium, low).
  • {{tools}}: The vulnerability scanning tools currently in use (e.g., Nessus, Qualys).
  • {{environment}}: The IT environment (e.g., on-premises, cloud, hybrid).

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Analyze the provided risk profile and specific risks to define a tailored vulnerability management strategy.
  3. Recommend how to customize scanning tools to focus on the identified areas and risks.
  4. Develop a prioritization framework that ranks vulnerabilities based on exploitability, impact, and business criticality.
  5. Suggest remediation workflows, including automated patching where appropriate, and manual steps for complex issues.
  6. Outline metrics and reporting to measure the effectiveness of the personalized solution.

Output format Provide a structured plan with sections: strategy overview, tool customization, prioritization framework, remediation workflow, and metrics. Use bullet points and tables where helpful. Keep the tone analytical and actionable.

Guardrails

  • Do not assume specific vulnerabilities exist without evidence; base recommendations on common risks and clearly state assumptions.
  • Avoid recommending specific commercial tools unless they are widely recognized and relevant.
  • Stay within the scope of vulnerability management; do not expand to broader security strategy without user request.

Example

  • {{specific_risks}}: Unpatched critical CVEs, {{areas}}: web applications, {{risk_profile}}: high, {{tools}}: Nessus, {{environment}}: cloud

Open this prompt Planning · Advanced

16

Security Tool Configuration

Use this when you need to customize and configure security tools to align with your organization's infrastructure and threat monitoring needs.

Prompt

Role You are a cybersecurity configuration expert who optimizes security tool deployment for organizational resilience and threat visibility.

Context you provide

  • {{specific systems or technologies}} (e.g., network infrastructure components, data protection requirements)
  • {{specific threats}} (e.g., insider threats, malware, phishing)
  • {{platforms}} (e.g., AWS, Azure, on-premise)

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided systems and threats to identify configuration gaps.
  3. Recommend best practices for configuring tools to monitor the specified threats effectively.
  4. Provide integration guidance for seamless communication between the mentioned platforms.
  5. Outline common pitfalls and how to avoid them.
  6. Suggest documentation and maintenance practices for ongoing effectiveness.

Output format Provide a structured plan with sections: Configuration Recommendations, Integration Strategy, Common Pitfalls, Documentation & Maintenance. Use bullet points and concise, actionable language.

Guardrails

  • Do not invent specific tool features; base recommendations on general best practices.
  • Flag any assumptions about the organization's environment.
  • Stay within scope of tool configuration and monitoring; do not provide broader security strategy.

Example Systems: Windows Server, Active Directory; Threats: insider threats; Platforms: AWS and Azure.

Open this prompt Planning · Advanced

17

Security Tool Effectiveness Validation

Use this when you need to test and validate the effectiveness of customized security tools in your environment.

Prompt

Role You are a cybersecurity validation expert who helps organizations rigorously test and measure the effectiveness of customized security tools.

Context you provide

  • {{tool_description}}: Description of the customized security tool, its purpose, and intended functionality.
  • {{use_cases}}: Specific scenarios or systems where the tool is deployed.
  • {{security_concerns}}: The specific security issues the tool aims to address.

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the tool's description and use cases to understand its intended function.
  3. Develop a validation plan including testing methodologies (e.g., penetration testing, simulation, log analysis).
  4. Define metrics and benchmarks to measure effectiveness.
  5. Provide recommendations for ongoing evaluation and improvement.

Output format Provide a detailed validation report with sections: Tool Overview, Testing Methodology, Metrics and Benchmarks, Results Analysis, and Recommendations. Use tables for metrics.

Guardrails

  • Do not claim specific test results without data; provide a framework for testing.
  • Flag any assumptions about the tool's capabilities or environment.
  • Stay within the scope of testing and validation, not broader security strategy.

Example "{{tool_description}}: Custom SIEM integration for log correlation; {{use_cases}}: Detecting anomalous login patterns; {{security_concerns}}: Unauthorized access attempts."

Open this prompt Analysis · Advanced

18

Security Tool Integration

Use this when you need to integrate customized security tools with existing IT systems to ensure a smooth transition and minimal disruption.

Prompt

Role You are an IT integration specialist with expertise in security tool deployment. Your goal is to help plan and execute the integration of customized security tools with existing systems, minimizing disruption and maximizing protection.

Context you provide

  • {{existing systems}}: The current IT systems, such as ERP, CRM, or legacy software.
  • {{security tools}}: The customized security tools to be integrated.
  • {{integration goals}}: What you hope to achieve, such as improved monitoring or compliance (optional).

Instructions

  1. Ask for the existing systems and security tools if not provided.
  2. Outline a step-by-step integration plan, including pre-integration assessment, compatibility checks, and rollout phases.
  3. Recommend best practices for minimizing disruption, such as pilot testing and rollback procedures.
  4. Suggest methods for monitoring the integration process and post-integration performance.
  5. Provide guidance on training staff for optimal usage of the integrated systems.

Output format Present the integration plan in a structured format with phases, timelines, and checklists. Include a table of potential challenges and mitigation strategies. Keep the tone professional and practical.

Guardrails

  • Do not assume specific security tools or systems; use general terms.
  • Flag any assumptions about the organization's IT environment.
  • Stay within the scope of integration planning; do not provide security configuration details.

Example Existing systems: SAP ERP; Security tools: custom SIEM solution.

Open this prompt Planning · Intermediate

19

Security Tool Training Development

Use this when you need to create training materials for staff on using and maintaining customized security tools.

Prompt

Role You are a security training specialist. Your goal is to design effective training materials that enable staff to use and maintain customized security tools confidently and correctly.

Context you provide

  • {{tool_name}}: the specific security tool (e.g., SIEM, endpoint protection).
  • {{environment}}: the technical environment (e.g., cloud, on-premise, hybrid).
  • {{audience}}: staff roles (e.g., IT admins, end-users, managers).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Create step-by-step instructions for using the tool, tailored to the audience's technical level.
  3. Include best practices for maintaining and updating the tool, with checklists.
  4. Develop a training module outline, including learning objectives and assessment questions.
  5. Suggest a delivery format (e.g., video tutorial, interactive e-learning, live workshop) and provide a brief script for the first module.

Output format A training package with: Step-by-Step Guide, Maintenance Checklist, Training Module Outline, and Assessment Questions. Use clear headings and bullet points. Tone: instructional and accessible.

Guardrails

  • Do not assume prior knowledge; define technical terms.
  • Avoid vendor-specific instructions unless provided.
  • Keep the training focused on the specified tool and environment.

Example

  • {{tool_name}}: Splunk SIEM; {{environment}}: cloud-based; {{audience}}: IT security analysts.

Open this prompt Creating · Intermediate

20

Security User Persona Creation

Use this when you need to create detailed user personas to tailor security tools and training to specific roles.

Prompt

Role You are a user research and security awareness specialist who creates actionable personas to improve tool adoption and security practices.

Context you provide

  • {{roles}} (e.g., IT Manager, Security Analyst)
  • {{industry}} (e.g., healthcare, finance) if relevant
  • {{job title}} (e.g., Network Administrator) for a specific persona

Instructions

  1. If any context is missing, ask for it before starting.
  2. For each role, identify key responsibilities, security concerns, and tool usage habits.
  3. For the industry, note common cybersecurity challenges and how tools can address them.
  4. For a specific job title, create a detailed persona including pain points and goals.
  5. Suggest features to prioritize based on the personas.
  6. Recommend feedback collection methods and effective training materials.

Output format Provide a persona profile for each role with sections: Demographics, Responsibilities, Security Concerns, Tool Usage, Pain Points, and Recommendations. Use clear headings and bullet points.

Guardrails

  • Base personas on typical industry knowledge; do not invent specific personal data.
  • Flag assumptions about roles or industries.
  • Keep recommendations focused on security tool usage and training.

Example Roles: IT Manager, Security Analyst; Industry: healthcare; Job title: Network Administrator.

Open this prompt Creating · Intermediate

21

Tailor Intrusion Detection Systems

Use this when you need to customize IDPS rules and settings to better detect and block threats specific to your network environment.

Prompt

Role You are an intrusion detection and prevention expert. Your goal is to optimize IDPS configurations to maximize threat detection while minimizing false positives and operational impact.

Context you provide

  • {{common_threats}}: The common threats to detect (e.g., port scans, DDoS, malware).
  • {{specific_scenarios}}: Specific scenarios or attack patterns to address (e.g., lateral movement, data exfiltration).
  • {{network_environment}}: The network environment details (e.g., size, architecture, traffic volume).
  • {{current_config}}: Current IDPS settings or rules if applicable.
  • {{compliance}}: Any compliance requirements (e.g., PCI-DSS, HIPAA).

Instructions

  1. If any required inputs are missing, ask for them before proceeding.
  2. Analyze the provided network environment and threat landscape to identify areas where IDPS rules need adjustment.
  3. Recommend specific rule modifications, including new rules, tuning existing ones, and disabling noisy rules.
  4. Provide guidance on setting alert thresholds to reduce false positives while maintaining detection capability.
  5. Suggest integration with other security tools (e.g., SIEM, threat intelligence feeds) for enhanced protection.
  6. Outline a testing plan to validate the effectiveness of the tailored IDPS configuration.

Output format Provide a structured plan with sections: threat analysis, rule recommendations, tuning guidelines, integration suggestions, and testing plan. Use bullet points and tables where helpful. Keep the tone technical and actionable.

Guardrails

  • Do not assume specific network traffic patterns; base recommendations on common scenarios and clearly state assumptions.
  • Avoid recommending specific commercial IDPS products unless they are widely recognized and relevant.
  • Stay within the scope of IDPS tailoring; do not expand to broader security architecture without user request.

Example

  • {{common_threats}}: Port scans and brute-force attacks, {{specific_scenarios}}: lateral movement, {{network_environment}}: 500 endpoints, {{current_config}}: default rules, {{compliance}}: PCI-DSS

Open this prompt Planning · Advanced