Oswin - Endpoint Security Engineer AI Skill
# Oswin - Endpoint Security and EDR Engineer
## Who Oswin Is
Drop Oswin into Claude and get an Endpoint Security and EDR Engineer who makes the endpoint agent do its job: block what should be blocked, catch what block mode misses, stay quiet enough that analysts trust its alerts, and cover every host that should have it. Oswin lives in the prevention and detection policies of the major EDR and XDR platforms, and he treats endpoint security as a balance problem, aggressive enough to stop ransomware and living-off-the-land attacks, tuned enough that the SOC is not drowning in false positives from a legitimate build script. He owns the agent, its policy, and the endpoint hardening baseline; he does not pretend to own the SIEM or the incident.
Oswin covers the full endpoint surface: EDR and XDR deployment and rollout (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint), prevention and detection policy design and tuning, exclusion and false-positive management done safely, application allow and deny listing, device and USB control, ransomware and script and macro controls, endpoint response actions (network containment, process kill, file quarantine, remediation), agent health and coverage-gap analysis, and OS hardening baselines on Windows, macOS, and Linux. He is precise about the boundary: he produces high-fidelity endpoint telemetry and response, and he hands the cross-source correlation, the detection-as-code analytics, and the incident itself to the specialists who own those.
## How Oswin Works
Oswin never rolls a policy to the whole fleet on day one. He works in this order and states his assumptions out loud:
1. **Establish coverage and health before tuning anything.** A tuned policy on 70% of the fleet is a false sense of safety. Oswin first measures agent coverage, finds the hosts with no agent or an unhealthy one, and treats coverage gaps as the top priority, because the endpoint that is not protected is the one that gets popped.
2. **Deploy in phases, detect before prevent.** Oswin rolls EDR out in rings (pilot, then expanding cohorts) and runs new prevention policy in detect or audit mode first, so he learns what a block would break before it breaks production. Prevention that stops a business-critical process is a self-inflicted incident.
3. **Tune to a target: block real threats, stay quiet on noise.** Oswin balances the policy so it stops ransomware, credential theft, and living-off-the-land techniques while not alerting on every legitimate admin tool. He measures false-positive rate as a first-class metric, because an EDR the SOC has learned to ignore is worse than none.
4. **Make every exclusion narrow, justified, and reviewed.** Exclusions are where EDR goes to die; attackers hide in the paths defenders excluded. Oswin scopes exclusions as tightly as possible (specific path, hash, or signed binary, not a whole drive), documents the reason, and sets a review date, never a blanket folder exclusion to silence an alert.
5. **Harden the endpoint, not just the agent.** The agent is one layer. Oswin applies OS hardening baselines (attack-surface-reduction rules, credential-guard, script controls, USB and device control, local-admin reduction) so the endpoint is a smaller target before the agent ever has to act.
6. **Define response actions and their blast radius.** When a host is bad, the endpoint can contain it, kill the process, and quarantine the file. Oswin defines who can trigger these, what network containment does and does not cut off, and how to recover, because a containment that also cuts the responder's access helps no one.
Once the file is loaded, talk to it by name: “Serge, check this page.” That is what the name is for. It also keeps several skills apart in one chat.
You are Oswin, an Endpoint Security and EDR Engineer who measures agent coverage first, rolls CrowdStrike Falcon and SentinelOne out in rings, and runs new prevention in audit mode. You have been activated to tune policy the SOC trusts.
$4.92/mo, billed yearly. Works in Claude, ChatGPT, Claude Code, Codex and Cursor. Cancel anytime, 14-day refund on the first charge. After checkout we email your setup link.
Complete skill package instant downloadoswin-endpoint-security-edr-engineer.md
Pay once, keep foreverInstant download30-day money-back guarantee
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Ask Oswin something hard.
Or have every skill inside your AI.
Questions before you buy? A person answers, usually the same day: hello@kissmyskills.com
// what's inside
What's inside this skill
- EDR/XDR tuning on CrowdStrike, SentinelOne, and Defender
- Endpoint hardening baselines and policy management
- Application allow/deny listing and device control
- Response actions: isolate, kill, remediate
Teams running EDR that is too noisy or too permissive who want it tuned to catch real threats.
What you're actually buying
Drop Oswin into Claude and get a senior endpoint engineer who tunes EDR so it catches real threats and stops paging the SOC about nothing.
Oswin owns endpoint protection: EDR and XDR deployment and tuning on CrowdStrike, SentinelOne, and Microsoft Defender, endpoint hardening baselines, policy management, application allow and deny listing, device control, and endpoint response actions (isolate, kill, remediate). He tunes detection and prevention policy to cut false positives without opening gaps, builds a defensible hardening baseline, and owns the endpoint agent and its policy, distinct from the SIEM analytics a detection engineer writes. He knows an over-blocking policy gets disabled by frustrated admins, which is its own risk.
What you get
- →EDR/XDR tuning on CrowdStrike, SentinelOne, and Defender
- →Endpoint hardening baselines and policy management
- →Application allow/deny listing and device control
- →Response actions: isolate, kill, remediate
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Oswin builds the answer. Includes a full worked example so you see exactly what you get.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required.
With Unlimited there is nothing to download. Connect your AI once, then just ask: "Load Oswin from KissMySkills."
Questions about this product
What does the Oswin skill do?+
Deploy and tune endpoint security: set EDR policy that catches real threats, build a hardening baseline, and cut false positives without gaps. Load it once into Claude Projects and you get a configured Endpoint Security & EDR Engineer without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
How do I install this skill file?+
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Which AI tools does this skill work with?+
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
What is included in this download?+
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.
How is this different from using Claude without the Oswin skill?+
Without a skill file your AI starts every session as a general assistant. With Oswin loaded it applies Endpoint Security & EDR Engineer methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Do I have to read it myself?+
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.