mukul975/Anthropic-Cybersecurity-Skills
这个仓库里有 818 个技能,GitHub 星标 ★ 32,865。
- abusing-dpapi-for-credential-accessExtract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser
- abusing-shadow-credentials-for-privescTake over Active Directory accounts by writing attacker-controlled public keys t
- achieving-cmmc-level-2-compliance>-
- acquiring-disk-image-with-dd-and-dcflddCreate forensically sound bit-for-bit disk images with dd or dcfldd on a Linux f
- analyzing-active-directory-acl-abuseDetect dangerous ACL misconfigurations in Active Directory using ldap3
- analyzing-android-malware-with-apktoolPerform static analysis of Android APK malware using apktool for resource decomp
- analyzing-api-gateway-access-logsParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
- analyzing-apt-group-with-mitre-navigatorQuery ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITR
- analyzing-azure-activity-logs-for-threatsQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query
- analyzing-bootkit-and-rootkit-samplesAnalyzes bootkit and advanced rootkit malware infecting the Master
- analyzing-browser-forensics-with-hindsightParse Chromium-based browser databases with Hindsight to extract and correlate b
- analyzing-campaign-attribution-evidenceSystematically evaluate cyber-campaign evidence to attribute an operation to a t
- analyzing-certificate-transparency-for-phishingMonitor Certificate Transparency logs using crt.sh and Certstream to
- analyzing-cloud-storage-access-patternsDetect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing Cloud
- analyzing-cobalt-strike-beacon-configurationExtract and analyze Cobalt Strike beacon configuration from PE files
- analyzing-cobaltstrike-malleable-c2-profilesParse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike
- analyzing-command-and-control-communicationAnalyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
- analyzing-cyber-kill-chainAnalyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
- analyzing-disk-image-with-autopsyPerform comprehensive forensic analysis of raw (dd), E01, or AFF disk images wit
- analyzing-dns-logs-for-exfiltrationAnalyzes DNS query logs to detect data exfiltration via DNS tunneling,
- analyzing-docker-container-forensicsInvestigate compromised Docker containers by analyzing images, layers,
- analyzing-email-headers-for-phishing-investigationParse and analyze email headers (Received chain, Return-Path, Message-ID)
- analyzing-ethereum-smart-contract-vulnerabilitiesPerform static and symbolic analysis of Solidity smart contracts using
- analyzing-golang-malware-with-ghidraReverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo
- analyzing-heap-spray-exploitationDetect and analyze heap spray attacks in memory dumps using Volatility3
- analyzing-indicators-of-compromiseAnalyzes indicators of compromise (IOCs) including IP addresses, domains,
- analyzing-ios-app-security-with-objection>-
- analyzing-kubernetes-audit-logs>-
- analyzing-linux-audit-logs-for-intrusionUses the Linux Audit framework (auditd) with ausearch and aureport utilities
- analyzing-linux-elf-malwareAnalyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,
- analyzing-linux-kernel-rootkitsDetect kernel-level rootkits in Linux memory dumps using Volatility3
- analyzing-linux-system-artifactsExamine Linux system artifacts (auth logs, cron/systemd persistence,
- analyzing-lnk-file-and-jump-list-artifactsAnalyze Windows LNK shortcut files and Jump List artifacts with LECmd,
- analyzing-macro-malware-in-office-documentsAnalyzes malicious VBA macros embedded in Microsoft Office documents
- analyzing-malicious-pdf-with-peepdfPerform static analysis of malicious PDF documents using peepdf, pdfid,
- analyzing-malicious-url-with-urlscanURLScan.io is a free service for scanning and analyzing suspicious URLs.
- analyzing-malware-behavior-with-cuckoo-sandboxDetonate malware samples in Cuckoo Sandbox to observe runtime behavior
- analyzing-malware-family-relationships-with-malpediaQuery the Malpedia API to look up malware family aliases and naming
- analyzing-malware-persistence-with-autorunsUse Sysinternals Autoruns to systematically enumerate and analyze malware
- analyzing-malware-sandbox-evasion-techniquesDetect sandbox and VM evasion techniques in malware samples by analyzing
- analyzing-memory-dumps-with-volatilityAnalyzes RAM memory dumps from compromised systems using the Volatility framewor
- analyzing-memory-forensics-with-lime-and-volatilityPerforms Linux memory acquisition using LiME (Linux Memory Extractor)
- analyzing-mft-for-deleted-file-recoveryAnalyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,
- analyzing-network-covert-channels-in-malwareDetect and analyze covert communication channels used by malware, including
- analyzing-network-flow-data-with-netflowParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
- analyzing-network-packets-with-scapyUse Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze p
- analyzing-network-traffic-for-incidentsAnalyzes network traffic captures and flow data to identify adversary activity d
- analyzing-network-traffic-of-malwareAnalyzes network traffic generated by malware during sandbox execution
- analyzing-network-traffic-with-wiresharkCaptures and analyzes network packet data using Wireshark and tshark
- analyzing-office365-audit-logs-for-compromiseParse Office 365 Unified Audit Logs via Microsoft Graph API to detect
- analyzing-outlook-pst-for-email-forensicsParse Microsoft Outlook PST and OST files using libpff and pst-utils to extract
- analyzing-packed-malware-with-upx-unpackerIdentifies and unpacks UPX-packed malware samples, including binaries with modif
- analyzing-pdf-malware-with-pdfidAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
- analyzing-persistence-mechanisms-in-linuxScan Linux systems for persistence mechanisms including crontab/systemd entries,
- analyzing-powershell-empire-artifactsDetect PowerShell Empire post-exploitation framework artifacts in Windows Script
- analyzing-powershell-script-block-loggingParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
- analyzing-prefetch-files-for-execution-historyParse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, Wi
- analyzing-ransomware-encryption-mechanismsAnalyzes encryption algorithms, key management, and file encryption
- analyzing-ransomware-leak-site-intelligenceSafely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and
- analyzing-ransomware-network-indicatorsIdentify ransomware-related network indicators, including C2 beaconing patterns,
- analyzing-ransomware-payment-walletsTraces ransomware cryptocurrency payment flows using blockchain analysis tools s
- analyzing-sbom-for-supply-chain-vulnerabilitiesParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
- analyzing-security-logs-with-splunkLeverages Splunk Enterprise Security and SPL (Search Processing Language)
- analyzing-slack-space-and-file-system-artifactsExamine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Dat
- analyzing-supply-chain-malware-artifactsInvestigate supply chain attack artifacts including trojanized software
- analyzing-threat-actor-ttps-with-mitre-attackSystematically map threat actor behavior and observed IOCs to the MITRE ATT&CK f
- analyzing-threat-actor-ttps-with-mitre-navigatorMap advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework us
- analyzing-threat-intelligence-feedsAnalyzes structured and unstructured threat intelligence feeds to extract
- analyzing-threat-landscape-with-mispQuery a MISP (Malware Information Sharing Platform) instance via PyMISP
- analyzing-tls-certificate-transparency-logsQueries Certificate Transparency logs via crt.sh and pycrtsh to detect
- analyzing-typosquatting-domains-with-dnstwistGenerate domain permutations with dnstwist and check DNS resolution
- analyzing-uefi-bootkit-persistenceAnalyzes UEFI bootkit persistence (SPI flash implants, ESP modifications,
- analyzing-usb-device-connection-historyCorrelate Windows registry keys (USBSTOR, MountedDevices), Event Logs,
- analyzing-web-server-logs-for-intrusionParse Apache and Nginx access logs to detect SQL injection attempts,
- analyzing-windows-amcache-artifactsParses the Windows Amcache.hve registry hive with Eric Zimmerman''s
- analyzing-windows-event-logs-in-splunkAnalyzes Windows Security, System, and Sysmon event logs in Splunk to
- analyzing-windows-lnk-files-for-artifactsParse Windows LNK shortcut files to extract target paths, MAC timestamps,
- analyzing-windows-prefetch-with-pythonParse Windows Prefetch (.pf) files with the windowsprefetch Python
- analyzing-windows-registry-for-artifactsExtract and analyze Windows Registry hives with tools like RegRipper
- analyzing-windows-shellbag-artifactsAnalyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and
- assessing-vector-and-embedding-weaknessesTest RAG vector stores (Pinecone, Qdrant, Weaviate, Chroma, pgvector,
- attacking-entra-id-with-roadtoolsEnumerate Microsoft Entra ID (Azure AD) tenants with ROADrecon and
- attacking-oauth-with-device-code-phishingRun OAuth 2.0 device-code and illicit-consent phishing attacks against
- auditing-aws-s3-bucket-permissionsSystematically audit AWS S3 bucket permissions to identify publicly
- auditing-azure-active-directory-configurationAuditing Microsoft Entra ID (Azure Active Directory) configuration to
- auditing-cloud-with-cis-benchmarksAudit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by
- auditing-entra-id-with-aadinternalsDrive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant r
- auditing-foundry-smart-contract-security>-
- auditing-gcp-iam-permissionsAuditing Google Cloud Platform IAM permissions to identify overly permissive
- auditing-kubernetes-cluster-rbacAuditing Kubernetes cluster RBAC configurations to identify overly permissive
- auditing-kubernetes-rbac-privilege-escalation>-
- auditing-mcp-servers-for-tool-poisoningAudit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unaut
- auditing-terraform-infrastructure-for-securityAuditing Terraform infrastructure-as-code for security misconfigurations
- auditing-tls-certificate-transparency-logsMonitors Certificate Transparency (CT) logs to detect unauthorized certificate
- auditing-uefi-firmware-with-chipsecUse Intel CHIPSEC to assess platform firmware configuration, SPI flash write pro
- automating-ioc-enrichmentAutomates the enrichment of raw indicators of compromise with multi-source
- benchmarking-kubernetes-with-kube-bench>-
- building-adversary-infrastructure-tracking-systemBuild an automated adversary infrastructure tracking system in Python (dnspython
- building-attack-pattern-library-from-cti-reportsParse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft
- building-automated-malware-submission-pipelineBuilds an automated malware submission and analysis pipeline that collects
- building-c2-infrastructure-with-sliver-frameworkDeploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulat
- building-c2-redirector-infrastructureBuild dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and
- building-cloud-siem-with-sentinelDeploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud
- building-detection-rule-with-splunk-splBuild effective detection rules using Splunk Search Processing Language
- building-detection-rules-with-sigmaBuilds vendor-agnostic detection rules using the Sigma rule format for
- building-devsecops-pipeline-with-gitlab-ciConfigure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Ba
- building-identity-federation-with-saml-azure-adConfigure SAML 2.0 identity federation between on-premises Active Directory (via
- building-identity-governance-lifecycle-processDesign identity governance and lifecycle (IGA) programs on platforms like SailPo
- building-incident-response-dashboardBuilds real-time incident response dashboards in Splunk, Elastic, or
- building-incident-response-playbookDesigns and documents structured incident response playbooks with step-by-step
- building-incident-timeline-with-timesketchBuild collaborative forensic incident timelines using Timesketch to ingest,
- building-ioc-defanging-and-sharing-pipelineBuild an automated pipeline that ingests raw IOCs (URLs, IPs, domains,
- building-ioc-enrichment-pipeline-with-openctiBuild an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native
- building-malware-incident-communication-templateBuild structured communication templates for malware incidents (ransomware,
- building-patch-tuesday-response-processEstablish a repeatable operational process for triaging, testing, and
- building-phishing-reporting-button-workflowImplement a phishing report button (Microsoft 365 built-in Report button
- building-ransomware-playbook-with-cisa-frameworkBuilds a structured ransomware incident response playbook aligned with
- building-red-team-c2-infrastructure-with-havocDeploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB
- building-role-mining-for-rbac-optimizationApply bottom-up and top-down role mining techniques, including clustering
- building-soc-escalation-matrixBuild a structured SOC escalation matrix defining severity tiers, response
- building-soc-metrics-and-kpi-trackingBuilds SOC performance metrics and KPI tracking dashboards measuring
- building-soc-playbook-for-ransomwareBuilds a structured SOC incident response playbook for ransomware attacks
- building-super-timelines-with-plasoGenerate forensic super-timelines with Plaso's log2timeline.py, pinfo.py,
- building-threat-actor-profile-from-osintBuild threat actor profiles by collecting OSINT from vendor reports, paste sites
- building-threat-feed-aggregation-with-mispDeploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVaul
- building-threat-hunt-hypothesis-frameworkBuild a systematic threat-hunt workflow that turns threat intelligence and ATT&C
- building-threat-intelligence-enrichment-in-splunkBuild automated IOC enrichment pipelines in Splunk Enterprise Security by ingest
- building-threat-intelligence-feed-integrationBuilds automated threat intelligence feed integration pipelines connecting
- building-threat-intelligence-platformDesign and deploy a Threat Intelligence Platform (TIP) by integrating open-sourc
- building-vulnerability-aging-and-sla-trackingImplement a vulnerability aging dashboard and SLA tracking system that measures
- building-vulnerability-dashboard-with-defectdojoDeploy DefectDojo as a centralized vulnerability management dashboard that inges
- building-vulnerability-exception-tracking-systemBuild a vulnerability exception and risk acceptance tracking system covering app
- building-vulnerability-scanning-workflowBuilds a structured vulnerability scanning workflow using tools like
- bypassing-authentication-with-forced-browsingDiscovering and accessing unprotected pages, APIs, and administrative
- coercing-authentication-with-coercer-petitpotamTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS
- collecting-indicators-of-compromiseSystematically collects, categorizes, and distributes indicators of
- collecting-open-source-intelligenceCollects and synthesizes open-source intelligence (OSINT) about threat
- collecting-threat-intelligence-with-mispDeploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and
- collecting-volatile-evidence-from-compromised-hostCollect volatile forensic evidence from a compromised host by following the orde
- conducting-api-security-testingConducts security testing of REST, GraphQL, and gRPC APIs to identify
- conducting-cloud-incident-responseRespond to security incidents in AWS, Azure, and GCP via identity-based containm
- conducting-cloud-penetration-testingThis skill outlines methodologies for performing authorized penetration
- conducting-cyber-risk-assessment-with-nist-800-30>-
- conducting-domain-persistence-with-dcsyncPerform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get
- conducting-external-reconnaissance-with-osintConduct external recon using OSINT techniques to map an organization's external
- conducting-full-scope-red-team-engagementPlan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spann
- conducting-gdpr-compliance-assessment>-
- conducting-internal-network-penetration-testExecute an internal network penetration test simulating an insider threat
- conducting-internal-reconnaissance-with-bloodhound-ceConduct internal Active Directory reconnaissance using BloodHound Community Edit
- conducting-malware-incident-responseRespond to malware infections across enterprise endpoints by identifying the mal
- conducting-man-in-the-middle-attack-simulationSimulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap
- conducting-memory-forensics-with-volatilityPerforms memory forensics analysis using Volatility 3 to extract evidence
- conducting-mobile-app-penetration-testConducts penetration testing of iOS and Android mobile applications
- conducting-network-penetration-testConducts comprehensive network penetration tests against authorized
- conducting-pass-the-ticket-attackPerform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS ti
- conducting-phishing-incident-responseRespond to phishing incidents by analyzing reported emails, extracting indicator
- conducting-post-incident-lessons-learnedFacilitate structured post-incident reviews to identify root causes,
- conducting-social-engineering-penetration-testDesign and execute a social engineering penetration test combining OSINT-driven
- conducting-social-engineering-pretext-callPlan and execute authorized vishing (voice phishing) pretext calls to
- conducting-spearphishing-simulation-campaignRun a targeted spearphishing simulation for initial access by developing OSINT-d
- conducting-wireless-network-penetration-testConducts authorized wireless network penetration tests to assess the
- configuring-active-directory-tiered-modelImplement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
- configuring-aws-verified-access-for-ztnaConfigure AWS Verified Access to provide VPN-less zero trust network
- configuring-certificate-authority-with-opensslBuild a two-tier PKI Certificate Authority hierarchy (offline Root CA
- configuring-host-based-intrusion-detectionConfigures host-based intrusion detection systems (HIDS) to monitor
- configuring-hsm-for-key-storageConfigures Hardware Security Modules for cryptographic key storage
- configuring-identity-aware-proxy-with-google-iapConfigures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce
- configuring-ldap-security-hardeningHardens LDAP directory services against credential harvesting, LDAP
- configuring-microsegmentation-for-zero-trustConfigures microsegmentation policies to enforce least-privilege workload-to-wor
- configuring-multi-factor-authentication-with-duoDeploys Cisco Duo multi-factor authentication across enterprise applications,
- configuring-network-segmentation-with-vlansDesigns and implements VLAN-based (802.1Q) network segmentation on
- configuring-oauth2-authorization-flowConfigures secure OAuth 2.0 authorization flows, including Authorization
- configuring-pfsense-firewall-rulesConfigures pfSense firewall rules, NAT policies, IPsec/OpenVPN tunnels,
- configuring-snort-ids-for-intrusion-detectionInstalls, configures, and tunes Snort 3 to monitor network traffic
- configuring-suricata-for-network-monitoringDeploys and configures Suricata IDS/IPS with Emerging Threats rulesets,
- configuring-tls-1-3-for-secure-communicationsConfigures TLS 1.3 (RFC 8446) on servers, covering cipher suite and
- configuring-windows-defender-advanced-settingsConfigures Microsoft Defender for Endpoint (MDE) advanced protection
- configuring-windows-event-logging-for-detectionConfigures Windows Event Logging with advanced audit policies to generate
- configuring-zscaler-private-access-for-ztnaConfigures Zscaler Private Access (ZPA) to replace traditional VPN
- containing-active-breachExecutes containment strategies to stop active adversary operations
- continuous-llm-red-teaming-with-promptfooWires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of
- correlating-security-events-in-qradarCorrelates security events in IBM QRadar SIEM using AQL (Ariel Query
- correlating-threat-campaignsCorrelates disparate security incidents, IOCs, and adversary behaviors
- defending-llms-with-guardrailsDeploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialog
- deobfuscating-javascript-malwareDeobfuscates malicious JavaScript found in phishing pages, web skimmers, and dro
- deobfuscating-powershell-obfuscated-malwareSystematically deobfuscates multi-layer PowerShell malware using AST analysis, d
- deploying-active-directory-honeytokensDeploys deception-based honeytokens in Active Directory including fake
- deploying-cloud-deception-with-decoy-resources>-
- deploying-cloudflare-access-for-zero-trustDeploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-h
- deploying-decoy-files-for-ransomware-detectionDeploys canary files (honeytokens) across file systems to detect ransomware
- deploying-edr-agent-with-crowdstrikeDeploys and configures CrowdStrike Falcon EDR agents across enterprise
- deploying-honeytokens-and-canarytokensPlants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bu
- deploying-osquery-for-endpoint-monitoringDeploys and configures osquery for real-time endpoint monitoring using
- deploying-palo-alto-prisma-access-zero-trustDeploys Palo Alto Networks Prisma Access for SASE-based zero trust network acces
- deploying-ransomware-canary-filesDeploys and monitors ransomware canary files using Python's watchdog library, pl
- deploying-software-defined-perimeterDeploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring
- deploying-tailscale-for-zero-trust-vpnDeploys and configures Tailscale (or self-hosted Headscale) as a WireGuard-based
- designing-adversary-engagement-with-mitre-engage>-
- detecting-ai-model-prompt-injection-attacksDetects prompt injection using regex signature matching, heuristic scoring for s
- detecting-anomalies-in-industrial-control-systemsDeploys anomaly detection for OT/ICS environments using machine learning on OT n
- detecting-anomalous-authentication-patternsDetects anomalous authentication patterns using UEBA analytics, statistical
- detecting-api-enumeration-attacksDetect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM
- detecting-arp-poisoning-in-network-trafficDetect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP
- detecting-attacks-on-historian-serversDetect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE
- detecting-attacks-on-scada-systemsThis skill covers detecting cyber attacks targeting Supervisory Control
- detecting-aws-cloudtrail-anomaliesDetect unusual API call patterns in AWS CloudTrail logs using boto3,
- detecting-aws-credential-exposure-with-trufflehogScan source code repositories, CI/CD pipelines, and configuration files
- detecting-aws-guardduty-findings-automationBuild automated AWS GuardDuty finding response pipelines using EventBridge
- detecting-aws-iam-privilege-escalationDetect AWS IAM privilege escalation paths using boto3 and Cloudsplaining
- detecting-azure-lateral-movementDetect lateral movement in Azure AD/Entra ID environments using Microsoft
- detecting-azure-service-principal-abuseDetect Azure service principal abuse in Microsoft Entra ID using KQL detection
- detecting-azure-storage-account-misconfigurationsAudit Azure Blob and ADLS storage accounts for public access exposure, weak
- detecting-beaconing-patterns-with-zeekPerforms statistical analysis of Zeek conn.log connection intervals
- detecting-bluetooth-low-energy-attacksDetects and analyzes Bluetooth Low Energy (BLE) security attacks including
- detecting-broken-object-property-level-authorizationDetect and test for OWASP API3:2023 Broken Object Property Level Authorization
- detecting-business-email-compromiseDetect Business Email Compromise (BEC) fraud, where attackers impersonate
- detecting-business-email-compromise-with-aiDeploy AI and NLP-powered detection systems to identify business email
- detecting-cloud-threats-with-guarddutyDeploy and operationalize Amazon GuardDuty, covering protection plans
- detecting-command-and-control-over-dnsDetect command-and-control (C2) traffic tunneled over DNS from tools like
- detecting-compromised-cloud-credentialsDetect compromised cloud credentials across AWS, Azure, and GCP by analyzing
- detecting-container-drift-at-runtime>-
- detecting-container-escape-attempts>-
- detecting-container-escape-with-falco-rules>-
- detecting-container-runtime-threats-with-falco>-
- detecting-credential-dumping-techniquesDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.
- detecting-cryptomining-in-cloudThis skill teaches security teams how to detect and respond to unauthorized
- detecting-data-and-model-poisoningIdentify poisoned training data and backdoored ML models across the pipeline usi
- detecting-dcsync-attack-in-active-directoryDetect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory
- detecting-deepfake-audio-in-vishing-attacksDetect AI-generated deepfake audio used in voice phishing (vishing) by extractin
- detecting-dependency-confusionDetect and prevent dependency confusion (public-over-private package name resolu
- detecting-dll-sideloading-attacksDetect DLL side-loading and search-order hijacking (MITRE T1574) where adversari
- detecting-dnp3-protocol-anomaliesDetect anomalies in DNP3 communications used in SCADA/ICS systems by monitoring
- detecting-dns-exfiltration-with-dns-query-analysisDetect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp)
- detecting-email-account-compromiseDetect compromised O365 and Google Workspace email accounts by analyzing Unified
- detecting-email-forwarding-rules-attackDetect malicious inbox/mail-flow forwarding rules that adversaries create to mai
- detecting-entra-offensive-tools-in-graph-logsHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/L
- detecting-evasion-techniques-in-endpoint-logsDetects defense evasion techniques used by adversaries in endpoint logs
- detecting-exfiltration-over-dns-with-zeekDetect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy
- detecting-fileless-attacks-on-endpointsDetects fileless malware and in-memory attacks that execute entirely
- detecting-fileless-malware-techniquesDetects and analyzes fileless malware that operates entirely in memory
- detecting-golden-ticket-attacks-in-kerberos-logsDetect Golden Ticket attacks in Active Directory using Splunk and KQL queries
- detecting-golden-ticket-forgeryDetect Kerberos Golden Ticket forgery (e.g. Mimikatz-forged tickets) by analyzin
- detecting-indirect-prompt-injectionDetect and defend against indirect prompt injection hidden in web pages, documen
- detecting-insider-data-exfiltration-via-dlpDetects insider data exfiltration by analyzing DLP policy violations,
- detecting-insider-threat-behaviorsDetect insider threat behavioral indicators including unusual data access,
- detecting-insider-threat-with-uebaImplement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSear
- detecting-kerberoasting-attacksDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS
- detecting-lateral-movement-in-networkIdentifies lateral movement techniques in enterprise networks by analyzing
- detecting-lateral-movement-with-splunkDetect adversary lateral movement across networks using Splunk SPL queries
- detecting-lateral-movement-with-zeekDetect lateral movement in network traffic using Zeek (formerly Bro)
- detecting-living-off-the-land-attacksDetect abuse of legitimate Windows binaries (LOLBins) used for living
- detecting-living-off-the-land-with-lolbasDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including
- detecting-malicious-npm-packagesTriage npm packages and lockfiles for install-script malware, credential exfiltr
- detecting-malicious-scheduled-tasks-with-sysmonDetect malicious scheduled task creation and modification using Sysmon
- detecting-mimikatz-execution-patternsDetect Mimikatz credential-dumping activity via command-line pattern matching, L
- detecting-misconfigured-azure-storageAudit Azure Storage accounts for public blob containers, missing encryption, ove
- detecting-mobile-malware-behaviorDetects and analyzes malicious behavior in mobile applications through
- detecting-modbus-command-injection-attacksDetect command injection against Modbus TCP/RTU in ICS/SCADA environments by mon
- detecting-modbus-protocol-anomaliesDetect anomalies in Modbus/TCP and Modbus RTU industrial traffic via function co
- detecting-model-extraction-attacksDetect MITRE ATLAS AML.T0024 attacks (model stealing, inversion, membership infe
- detecting-network-anomalies-with-zeekDeploy and configure Zeek (formerly Bro) to passively analyze network traffic, g
- detecting-network-scanning-with-ids-signaturesDetect network reconnaissance and port scanning using Suricata and Snort
- detecting-ntlm-relay-with-event-correlationDetect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonTyp
- detecting-oauth-token-theftDetect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure
- detecting-pass-the-hash-attacksDetect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patter
- detecting-pass-the-ticket-attacksDetect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 476
- detecting-port-scanning-with-fail2banConfigures Fail2ban with custom filters and actions to detect port scanning
- detecting-privilege-escalation-attemptsDetect privilege escalation attempts across Windows and Linux, including access
- detecting-privilege-escalation-in-kubernetes-pods>-
- detecting-process-hollowing-techniqueDetect process hollowing (MITRE T1055.012) by analyzing memory-mapped
- detecting-process-injection-techniquesDetects and analyzes process injection techniques used by malware including
- detecting-qr-code-phishing-with-email-securityDetect and prevent QR code phishing (quishing) attacks that embed
- detecting-ransomware-encryption-behaviorDetects ransomware encryption activity in real time using entropy
- detecting-ransomware-precursors-in-networkDetects early-stage ransomware indicators in network traffic before
- detecting-rdp-brute-force-attacksDetect RDP brute force attacks by parsing Windows Security Event Logs
- detecting-rootkit-activityDetects rootkit presence on compromised systems by identifying hidden
- detecting-s3-data-exfiltration-attemptsDetecting data exfiltration attempts from AWS S3 buckets by analyzing
- detecting-secure-boot-bypassDetect UEFI Secure Boot bypasses and bootkits such as BlackLotus and
- detecting-serverless-function-injectionDetects and prevents code injection attacks targeting serverless functions
- detecting-service-account-abuseDetect abuse of service accounts by hunting for anomalous interactive
- detecting-shadow-api-endpointsDiscover and inventory shadow API endpoints that operate outside
- detecting-shadow-it-cloud-usageDetect unauthorized SaaS and cloud service usage (shadow IT) by parsing
- detecting-spearphishing-with-email-gatewayDetect and block spearphishing emails that use personalized, researched
- detecting-sql-injection-via-waf-logsAnalyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection
- detecting-stuxnet-style-attacksDetects sophisticated cyber-physical attacks that follow the Stuxnet
- detecting-supply-chain-attacks-in-ci-cdScans GitHub Actions workflows and CI/CD pipeline configurations for
- detecting-suspicious-oauth-application-consentDetect risky OAuth application consent grants in Azure AD / Microsoft
- detecting-suspicious-powershell-executionHunt for suspicious PowerShell execution (T1059.001) such as encoded commands,
- detecting-t1003-credential-dumping-with-edrDetect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM
- detecting-t1055-process-injection-with-sysmonDetect process injection techniques (T1055) - including DLL injection, process
- detecting-t1548-abuse-elevation-control-mechanismDetect abuse of elevation control mechanisms (T1548), including Windows UAC
- detecting-typosquatting-packagesFlag misspelled, brandjacked, and typosquatted package names across npm, PyPI, a
- detecting-typosquatting-packages-in-npm-pypiDetects typosquatting attacks in npm and PyPI package registries by
- detecting-wmi-persistenceDetect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon
- emulating-cloud-attacks-with-stratus-red-teamInstall and run Stratus Red Team to detonate granular, MITRE ATT&CK-mapped
- enumerating-cloud-with-cloudfoxRun CloudFox's read-only Describe/List/Get enumeration (all-checks,
- eradicating-malware-from-infected-systemsSystematically map and remove malware, backdoors, and attacker persistence
- escaping-containers-to-host>-
- evaluating-threat-intelligence-platformsEvaluates and selects Threat Intelligence Platform (TIP) products based
- executing-active-directory-attack-simulationExecutes authorized attack simulations against Active Directory environments
- executing-nist-rmf-authorization-to-operate>-
- executing-phishing-simulation-campaignExecutes authorized phishing simulation campaigns to assess an organization''s
- executing-red-team-engagement-planningBuild the foundational red team engagement plan - scope definition, Rules
- executing-red-team-exerciseRun a stealthy, MITRE ATT&CK-mapped adversary emulation against an organization'
- exploiting-active-directory-certificate-services-esc1Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1
- exploiting-active-directory-with-bloodhoundBloodHound is a graph-based Active Directory reconnaissance tool that
- exploiting-adcs-with-certipyUse Certipy to enumerate AD CS certificate authorities and templates over LDAP/R
- exploiting-api-injection-vulnerabilities>-
- exploiting-aws-with-pacu>-
- exploiting-bgp-hijacking-vulnerabilitiesAnalyzes and simulates BGP hijacking scenarios in authorized lab environments
- exploiting-broken-function-level-authorization>-
- exploiting-broken-link-hijacking>-
- exploiting-constrained-delegation-abuse>-
- exploiting-deeplink-vulnerabilitiesTests and exploits deep link (URL scheme and App Link) vulnerabilities
- exploiting-excessive-data-exposure-in-api>-
- exploiting-http-request-smuggling>-
- exploiting-idor-vulnerabilities>-
- exploiting-insecure-data-storage-in-mobileIdentifies and exploits insecure local data storage vulnerabilities
- exploiting-insecure-deserializationIdentifying and exploiting insecure deserialization vulnerabilities in
- exploiting-ipv6-vulnerabilitiesIdentifies and exploits IPv6-specific vulnerabilities including SLAAC
- exploiting-jwt-algorithm-confusion-attack>-
- exploiting-kerberoasting-with-impacket>-
- exploiting-mass-assignment-in-rest-apis>-
- exploiting-ms17-010-eternalblue-vulnerability>-
- exploiting-nopac-cve-2021-42278-42287Exploits the noPac Active Directory privilege-escalation chain (CVE-2021-42278
- exploiting-nosql-injection-vulnerabilitiesDetects and exploits NoSQL injection vulnerabilities in MongoDB, CouchDB,
- exploiting-oauth-misconfigurationIdentifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations
- exploiting-prototype-pollution-in-javascriptDetects and exploits JavaScript prototype pollution vulnerabilities
- exploiting-race-condition-vulnerabilitiesDetects and exploits race condition (TOCTOU) vulnerabilities in web
- exploiting-server-side-request-forgeryIdentifying and exploiting SSRF vulnerabilities to access internal services,
- exploiting-smb-vulnerabilities-with-metasploitIdentifies and exploits SMB protocol vulnerabilities using Metasploit
- exploiting-sql-injection-vulnerabilitiesIdentifies and exploits SQL injection vulnerabilities in web applications
- exploiting-sql-injection-with-sqlmapDetecting and exploiting SQL injection vulnerabilities using sqlmap to
- exploiting-template-injection-vulnerabilitiesDetects and exploits Server-Side Template Injection (SSTI) vulnerabilities
- exploiting-type-juggling-vulnerabilitiesExploits PHP type juggling vulnerabilities caused by loose (==) comparison
- exploiting-vulnerabilities-with-metasploit-frameworkUses the Metasploit Framework (msfconsole and its exploit, auxiliary,
- exploiting-websocket-vulnerabilitiesTesting WebSocket implementations for authentication bypass, cross-site
- exploiting-zerologon-vulnerability-cve-2020-1472Exploits the Zerologon vulnerability (CVE-2020-1472) in the Netlogon
- extracting-browser-history-artifactsExtracts and analyzes browser history, cookies, cache, downloads, and
- extracting-config-from-agent-tesla-ratExtracts embedded configuration from Agent Tesla RAT samples, including
- extracting-credentials-from-memory-dumpExtracts cached credentials, password hashes, Kerberos tickets, and
- extracting-iocs-from-malware-samplesExtracts indicators of compromise (IOCs) from malware samples, including
- extracting-memory-artifacts-with-rekallUses Rekall memory forensics framework to analyze memory dumps for process
- extracting-windows-event-logs-artifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw,
- fleet-hunting-with-velociraptorDeploy a Velociraptor server and agents, then author VQL (Velociraptor Query Lan
- generating-and-analyzing-sbomsGenerate CycloneDX and SPDX SBOMs from container images and filesystems with Syf
- generating-forensic-timelines-with-hayabusaRun Hayabusa against collected Windows EVTX files to apply Sigma detection rules
- generating-threat-intelligence-reportsGenerates structured cyber threat intelligence reports at strategic,
- hardening-docker-containers-for-production>-
- hardening-docker-daemon-configuration>-
- hardening-linux-endpoint-with-cis-benchmarkHardens Linux endpoints using CIS Benchmark recommendations for Ubuntu,
- hardening-windows-endpoint-with-cis-benchmarkHardens Windows endpoints using CIS (Center for Internet Security) Benchmark
- hunting-advanced-persistent-threatsProactively hunts for Advanced Persistent Threat (APT) activity within
- hunting-bootkits-in-efi-system-partitionBaseline the EFI System Partition and hunt malicious EFI binaries such as ESPect
- hunting-credential-stuffing-attacksDetects credential stuffing attacks by analyzing authentication logs
- hunting-evtx-with-chainsawRun Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule
- hunting-for-anomalous-powershell-executionHunt for malicious PowerShell activity by analyzing Script Block Logging
- hunting-for-beaconing-with-frequency-analysisIdentify command-and-control beaconing patterns in network traffic by
- hunting-for-cobalt-strike-beaconsDetect Cobalt Strike beacon command-and-control traffic using default TLS certif
- hunting-for-command-and-control-beaconingDetect C2 beaconing patterns in network traffic using frequency analysis,
- hunting-for-data-exfiltration-indicatorsHunt for data exfiltration by analyzing Zeek and Suricata network telemetry for
- hunting-for-data-staging-before-exfiltrationDetect data-staging activity (MITRE ATT&CK T1074) by analyzing EDR/Sysmon proces
- hunting-for-dcom-lateral-movementHunt for DCOM-based lateral movement (MITRE ATT&CK T1021.003) by detecting
- hunting-for-dcsync-attacksDetect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 466
- hunting-for-defense-evasion-via-timestompingDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFO
- hunting-for-dns-based-persistenceHunts for DNS-based persistence mechanisms such as DNS hijacking, dangling
- hunting-for-dns-tunneling-with-zeekDetects DNS tunneling and covert-channel data exfiltration by analyzing
- hunting-for-domain-fronting-c2-trafficDetects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header
- hunting-for-lateral-movement-via-wmiDetects WMI-based lateral movement (e.g. wmic process call create,
- hunting-for-living-off-the-cloud-techniquesHunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP,
- hunting-for-living-off-the-land-binariesProactively hunts for adversary abuse of legitimate, signed system binaries
- hunting-for-lolbins-execution-in-endpoint-logsHunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE
- hunting-for-ntlm-relay-attacksDetects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event
- hunting-for-persistence-mechanisms-in-windowsSystematically hunts for adversary persistence mechanisms across Windows
- hunting-for-persistence-via-wmi-subscriptionsHunts for adversary persistence via WMI event subscriptions (MITRE T1546.003)
- hunting-for-process-injection-techniquesDetects process injection techniques (MITRE T1055) — including
- hunting-for-registry-persistence-mechanismsHunts for registry-based persistence mechanisms (MITRE T1547) in Windows
- hunting-for-registry-run-key-persistenceDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing
- hunting-for-scheduled-task-persistenceRuns a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T10
- hunting-for-shadow-copy-deletionRuns a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by
- hunting-for-spearphishing-indicatorsHunt for spearphishing campaign indicators across email logs, endpoint
- hunting-for-startup-folder-persistenceDetects T1547.001 startup folder persistence by monitoring Windows startup direc
- hunting-for-supply-chain-compromiseRuns a hypothesis-driven threat hunt for supply-chain compromise (T1195) by quer
- hunting-for-suspicious-scheduled-tasksHunts for adversary persistence and execution via Windows scheduled tasks (T1053
- hunting-for-t1098-account-manipulationHunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID h
- hunting-for-unusual-network-connectionsRuns a hypothesis-driven threat hunt for command-and-control activity (T1071) by
- hunting-for-unusual-service-installationsDetects suspicious Windows service installations (MITRE ATT&CK T1543.003) by par
- hunting-for-webshell-activityRuns a hypothesis-driven threat hunt for web shell deployment (T1505.003) on int
- hunting-saas-sso-token-abuseHunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating M
- implementing-aes-encryption-for-data-at-restGuides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data
- implementing-alert-fatigue-reductionImplements strategies to reduce SOC alert fatigue by tuning detection
- implementing-anti-phishing-training-programGuides designing, deploying, and measuring an anti-phishing security awareness p
- implementing-anti-ransomware-group-policyConfigures Windows Group Policy Objects to block ransomware execution
- implementing-api-abuse-detection-with-rate-limitingImplements API abuse detection using token bucket, sliding window, and
- implementing-api-gateway-security-controlsConfigures API gateways such as Kong, AWS API Gateway, Azure APIM,
- implementing-api-key-security-controlsImplements secure API key generation with sufficient entropy, server-side
- implementing-api-rate-limiting-and-throttlingImplements API rate limiting and throttling with token bucket, sliding
- implementing-api-schema-validation-securityImplements API schema validation using OpenAPI Specification and JSON
- implementing-api-security-posture-managementImplements API Security Posture Management (API-SPM) to continuously
- implementing-api-security-testing-with-42crunchImplements API security testing on the 42Crunch platform, combining
- implementing-api-threat-protection-with-apigeeImplements API threat protection using Google Apigee reverse-proxy
- implementing-application-whitelisting-with-applockerImplements application whitelisting using Windows AppLocker to restrict
- implementing-aqua-security-for-container-scanningDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfiguration
- implementing-attack-path-analysis-with-xm-cyberDeploys XM Cyber's continuous exposure management platform to build
- implementing-attack-surface-managementImplements external attack surface management (EASM) using Shodan, Censys,
- implementing-aws-config-rules-for-complianceImplements AWS Config managed and custom rules for continuous compliance
- implementing-aws-iam-permission-boundariesConfigures AWS IAM permission boundaries that cap the maximum permissions
- implementing-aws-macie-for-data-classificationEnable and configure Amazon Macie via AWS CLI/Terraform to discover, classify, a
- implementing-aws-nitro-enclave-securityBuild AWS Nitro Enclave confidential computing environments using nitro-cli
- implementing-aws-security-hubDeploy AWS Security Hub as a centralized CSPM platform, backed by AWS
- implementing-aws-security-hub-complianceDeploy AWS Security Hub, backed by AWS Config, to aggregate findings
- implementing-azure-ad-privileged-identity-managementConfigure Microsoft Entra Privileged Identity Management (PIM) to convert
- implementing-azure-defender-for-cloudEnable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers,
- implementing-beyondcorp-zero-trust-access-modelImplement Google''s BeyondCorp zero trust access model using Cloud
- implementing-bgp-security-with-rpkiImplement RPKI-based BGP route origin validation by creating Route Origin
- implementing-browser-isolation-for-zero-trustDeploys remote browser isolation (RBI) as a core component of a Zero
- implementing-canary-tokens-for-network-intrusionDeploys DNS, HTTP, and AWS API key canary tokens across network infrastructure
- implementing-cisa-zero-trust-maturity-modelAssess, gap-analyze, and progressively implement the CISA Zero Trust
- implementing-cloud-dlp-for-data-protectionImplement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft
- implementing-cloud-security-posture-managementContinuously monitor multi-cloud environments (AWS, Azure, GCP) for
- implementing-cloud-trail-log-analysisImplementing AWS CloudTrail log analysis for security monitoring, threat
- implementing-cloud-vulnerability-posture-managementImplement multi-cloud CSPM to detect cloud-native misconfigurations
- implementing-cloud-waf-rulesDeploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF,
- implementing-cloud-workload-protectionImplements cloud workload protection using boto3 and google-cloud APIs
- implementing-code-signing-for-artifactsImplements code signing for build artifacts (binaries, packages, containers)
- implementing-conditional-access-policies-azure-adConfigures Microsoft Entra ID (Azure AD) Conditional Access policies for
- implementing-conduit-security-for-ot-remote-accessImplements secure conduit architecture for OT remote access under the
- implementing-container-image-minimal-base-with-distroless>-
- implementing-container-network-policies-with-calico>-
- implementing-continuous-security-validation-with-basDeploys Breach and Attack Simulation (BAS) platforms such as SafeBreach,
- implementing-data-loss-prevention-with-microsoft-purviewImplements DLP policies using Microsoft Purview PowerShell cmdlets and
- implementing-ddos-mitigation-with-cloudflareConfigure Cloudflare DDoS protection with managed rulesets, rate limiting,
- implementing-deception-based-detection-with-canarytokenDeploys and monitors Canary Tokens via the Thinkst Canary REST API for
- implementing-delinea-secret-server-for-pamImplements Delinea Secret Server for privileged access management,
- implementing-device-posture-assessment-in-zero-trustImplements device posture assessment as a zero trust access control
- implementing-devsecops-security-scanningIntegrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for
- implementing-diamond-model-analysisThe Diamond Model of Intrusion Analysis provides a structured framework
- implementing-digital-signatures-with-ed25519Implements digital signatures using the Ed25519 algorithm (Curve25519), covering
- implementing-disk-encryption-with-bitlockerImplements full disk encryption using Microsoft BitLocker on Windows
- implementing-dmarc-dkim-spf-email-securityConfigures SPF, DKIM, and DMARC DNS TXT records to authenticate outbound email,
- implementing-dragos-platform-for-ot-monitoringDeploys and configures Dragos Platform sensors and detection analytics for OT/IC
- implementing-ebpf-security-monitoringImplements eBPF-based security monitoring using Cilium Tetragon for
- implementing-email-sandboxing-with-proofpointEmail sandboxing detonates suspicious attachments and URLs in isolated
- implementing-end-to-end-encryption-for-messagingImplements a simplified Signal Protocol-style end-to-end encryption scheme for m
- implementing-endpoint-detection-with-wazuhDeploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent aut
- implementing-endpoint-dlp-controlsImplements endpoint Data Loss Prevention (DLP) controls to detect and
- implementing-envelope-encryption-with-aws-kmsImplements envelope encryption with AWS KMS, encrypting data locally with a data
- implementing-epss-score-for-vulnerability-prioritizationQueries FIRST's Exploit Prediction Scoring System (EPSS) API to fetch exploitati
- implementing-file-integrity-monitoring-with-aideConfigures AIDE (Advanced Intrusion Detection Environment) for file integrity mo
- implementing-fuzz-testing-in-cicd-with-aflplusplusIntegrates AFL++ coverage-guided fuzzing into CI/CD pipelines, covering harness
- implementing-gcp-binary-authorizationImplements GCP Binary Authorization end to end, including creating KMS-backed at
- implementing-gcp-organization-policy-constraintsImplements GCP Organization Policy constraints via gcloud and Terraform, such as
- implementing-gcp-vpc-firewall-rulesImplements and audits GCP VPC firewall rules using gcloud, covering auditing ove
- implementing-gdpr-data-protection-controlsImplements GDPR (EU 2016/679) technical and organizational measures — privacy by
- implementing-gdpr-data-subject-access-requestAutomates GDPR Data Subject Access Request (DSAR) workflows including
- implementing-github-advanced-security-for-code-scanningConfigures GitHub Advanced Security (code scanning with CodeQL, secret scanning,
- implementing-google-workspace-admin-securityHardens a Google Workspace tenant via Admin Console configuration:
- implementing-google-workspace-phishing-protectionConfigures Google Workspace advanced phishing and malware protection settings in
- implementing-google-workspace-sso-configurationConfigures SAML 2.0 single sign-on for Google Workspace against a third-party
- implementing-hardware-security-key-authenticationBuilds a FIDO2/WebAuthn relying party server with the python-fido2
- implementing-hashicorp-vault-dynamic-secretsConfigures HashiCorp Vault dynamic secrets engines for database credentials,
- implementing-hipaa-security-rule-safeguards>-
- implementing-honeypot-for-ransomware-detectionDeploys canary files, honeypot shares, and decoy systems to detect ransomware
- implementing-honeytokens-for-breach-detectionDeploys canary tokens and honeytokens (fake AWS credentials, DNS canaries,
- implementing-ics-firewall-with-tofinoDeploys and configures Tofino industrial firewalls (Belden/Hirschmann)
- implementing-identity-governance-with-sailpointDeploys SailPoint IdentityNow or IdentityIQ for identity governance and
- implementing-identity-verification-for-zero-trustImplements continuous, risk-adaptive identity verification for zero trust
- implementing-iec-62443-security-zonesDesigns security zones and conduits for industrial control systems
- implementing-image-provenance-verification-with-cosign>-
- implementing-immutable-backup-with-resticImplements ransomware-resistant backups using restic with S3-compatible
- implementing-infrastructure-as-code-security-scanningImplements automated security scanning for Infrastructure as Code using
- implementing-iso-27001-information-security-management>-
- implementing-just-in-time-access-provisioning>-
- implementing-jwt-signing-and-verification>-
- implementing-kubernetes-network-policy-with-calico>-
- implementing-kubernetes-pod-security-standards>-
- implementing-llm-guardrails-for-securityImplements input/output validation guardrails for LLM applications using
- implementing-log-forwarding-with-fluentd>-
- implementing-log-integrity-with-blockchain>-
- implementing-memory-protection-with-dep-aslrImplements memory protection mechanisms including DEP (Data Execution
- implementing-microsegmentation-with-guardicoreImplements microsegmentation with Akamai Guardicore Segmentation to map
- implementing-mimecast-targeted-attack-protection>-
- implementing-mitre-attack-coverage-mappingImplement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize
- implementing-mobile-application-managementImplements Mobile Application Management (MAM) policies to protect enterprise
- implementing-mtls-for-zero-trust-servicesConfigures mutual TLS (mTLS) authentication between microservices using
- implementing-nerc-cip-compliance-controlsImplements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset
- implementing-network-access-controlImplements 802.1X port-based network access control using RADIUS authentication,
- implementing-network-access-control-with-cisco-iseDeploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1
- implementing-network-deception-with-honeypotsDeploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie
- implementing-network-intrusion-prevention-with-suricataDeploys and configures Suricata as an inline network intrusion prevention system
- implementing-network-policies-for-kubernetes>-
- implementing-network-segmentation-for-otImplements OT network segmentation using VLANs, OT-aware firewalls, data diodes,
- implementing-network-segmentation-with-firewall-zonesDesigns and implements network segmentation using firewall security zones, VLANs
- implementing-network-traffic-analysis-with-arkimeQueries Arkime (formerly Moloch) full packet capture via its API to search sessi
- implementing-network-traffic-baseliningBuilds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Py
- implementing-next-generation-firewall-with-palo-altoConfigures and deploys Palo Alto Networks next-generation firewalls end-to-end,
- implementing-opa-gatekeeper-for-policy-enforcement>-
- implementing-ot-incident-response-playbookDevelops OT-specific incident response playbooks using a SANS PICERL-based Pytho
- implementing-ot-network-traffic-analysis-with-nozomiDeploy Nozomi Networks Guardian sensors for passive OT network traffic
- implementing-pam-for-database-accessDeploy privileged access management for database systems including Oracle,
- implementing-passwordless-auth-with-microsoft-entraImplements passwordless authentication using Microsoft Entra ID with
- implementing-passwordless-authentication-with-fido2Deploy FIDO2/WebAuthn passwordless authentication using security keys
- implementing-patch-management-for-ot-systemsImplements a structured patch management program for OT/ICS environments
- implementing-patch-management-workflowPatch management is the systematic process of identifying, testing, deploying,
- implementing-pci-dss-compliance-controlsImplements PCI DSS 4.0.1's 12 requirements across 6 control objectives
- implementing-pod-security-admission-controller>-
- implementing-policy-as-code-with-open-policy-agentImplements policy-as-code enforcement with Open Policy Agent (OPA)
- implementing-privileged-access-management-with-cyberarkDeploy CyberArk Privileged Access Management to discover, vault, rotate,
- implementing-privileged-access-workstationDesign and implement Privileged Access Workstations (PAWs) using the
- implementing-privileged-session-monitoringImplements privileged session monitoring and recording using PAM
- implementing-proofpoint-email-security-gatewayDeploy and configure Proofpoint Email Protection as a secure email gateway
- implementing-purdue-model-network-segmentationImplement network segmentation based on the Purdue Enterprise Reference
- implementing-ransomware-backup-strategyDesigns a ransomware-resilient backup strategy using the 3-2-1-1-0
- implementing-ransomware-kill-switch-detectionAnalyzes ransomware kill switch mechanisms, including mutex-based execution
- implementing-rapid7-insightvm-for-scanningDeploy and configure Rapid7 InsightVM Security Console and Scan Engines,
- implementing-rbac-hardening-for-kubernetes>-
- implementing-rsa-key-pair-managementGenerates, stores, rotates, and manages RSA key pairs following NIST
- implementing-runtime-application-self-protectionDeploy Runtime Application Self-Protection (RASP) agents to detect and
- implementing-runtime-security-with-tetragon>-
- implementing-saml-sso-with-oktaImplement SAML 2.0 Single Sign-On using Okta as the Identity Provider,
- implementing-scim-provisioning-with-oktaImplement automated user lifecycle provisioning and deprovisioning using
- implementing-secret-scanning-with-gitleaksThis skill covers implementing Gitleaks for detecting and preventing
- implementing-secrets-management-with-vaultDeploy HashiCorp Vault for centralized secrets management, covering dynamic
- implementing-secrets-scanning-in-ci-cdIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked
- implementing-security-chaos-engineeringImplements security chaos engineering experiments that deliberately
- implementing-security-information-sharing-with-stix2Create, validate, and share STIX 2.1 threat intelligence objects (indicators,
- implementing-security-monitoring-with-datadogImplements security monitoring using Datadog Cloud SIEM, Cloud Security
- implementing-semgrep-for-custom-sast-rulesWrite custom Semgrep SAST rules in YAML to detect application-specific
- implementing-siem-correlation-rules-for-aptWrite multi-event correlation rules in Splunk SPL and Sigma format that
- implementing-siem-use-case-tuningTune SIEM detection rules in Splunk and Elastic to reduce false positives
- implementing-siem-use-cases-for-detectionImplements SIEM detection use cases by designing correlation rules,
- implementing-sigstore-for-software-signingImplements Sigstore-based software signing and verification using Cosign
- implementing-soar-automation-with-phantomImplements Security Orchestration, Automation, and Response (SOAR) workflows
- implementing-soar-playbook-for-phishingAutomates phishing incident response by calling the Splunk SOAR (Phantom)
- implementing-soar-playbook-with-palo-alto-xsoarBuild automated incident response playbooks in Cortex XSOAR (Demisto)
- implementing-stix-taxii-feed-integrationImplements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and
- implementing-supply-chain-security-with-in-toto>-
- implementing-syslog-centralization-with-rsyslogConfigure rsyslog for centralized log collection with TLS encryption,
- implementing-taxii-server-with-opentaxiiDeploy and configure a TAXII 2.1 server (Medallion) with Docker, publish
- implementing-threat-intelligence-lifecycle-managementBuild out a full CTI program around the six-phase threat intelligence
- implementing-threat-modeling-with-mitre-attackImplements threat modeling using the MITRE ATT&CK framework to map adversary
- implementing-ticketing-system-for-incidentsImplements an integrated incident ticketing system connecting SIEM alerts
- implementing-usb-device-control-policyImplements USB device control policies to restrict unauthorized removable
- implementing-velociraptor-for-ir-collectionDeploy and configure Velociraptor for scalable endpoint forensic artifact
- implementing-vulnerability-management-with-greenboneDeploy and operate Greenbone/OpenVAS vulnerability management using the
- implementing-vulnerability-remediation-slaDesign a vulnerability remediation SLA program covering asset tiering,
- implementing-vulnerability-sla-breach-alertingBuild an automated SLA breach alerting system for vulnerability remediation,
- implementing-web-application-logging-with-modsecurityConfigure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web
- implementing-zero-knowledge-proof-for-authenticationImplements the Schnorr identification protocol and a simplified Zero-Knowledge P
- implementing-zero-standing-privilege-with-cyberarkDeploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AW
- implementing-zero-trust-dns-with-nextdnsConfigure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks
- implementing-zero-trust-for-saas-applicationsSecures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/
- implementing-zero-trust-in-cloudGuides zero trust implementation across AWS, Azure, and GCP per NIST SP 800-207
- implementing-zero-trust-network-accessConfigures Zero Trust Network Access (ZTNA) in AWS, Azure, and GCP using identit
- implementing-zero-trust-network-access-with-zscalerConfigures Zero Trust Network Access using Zscaler Private Access (ZPA) to broke
- implementing-zero-trust-with-beyondcorpConfigures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access
- implementing-zero-trust-with-hashicorp-boundaryInstalls and configures HashiCorp Boundary as a default-deny, identity-aware pro
- integrating-dast-with-owasp-zap-in-pipelineIntegrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipeli
- integrating-sast-into-github-actions-pipelineIntegrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans
- intercepting-mobile-traffic-with-burpsuiteIntercepts and analyzes HTTP/HTTPS traffic from mobile applications
- investigating-insider-threat-indicatorsInvestigates insider threat indicators including data exfiltration attempts,
- investigating-phishing-email-incidentInvestigates phishing email incidents from initial user report through
- investigating-ransomware-attack-artifactsForensically preserve memory and disk, collect ransom notes and encrypted file s
- managing-cloud-identity-with-okta>-
- managing-intelligence-lifecycleManages the end-to-end cyber threat intelligence lifecycle from planning
- managing-third-party-vendor-risk>-
- mapping-attack-paths-with-bloodhound-ceCollect Active Directory data with SharpHound and Entra ID data with AzureHound,
- mapping-mitre-attack-techniquesMaps observed adversary behaviors, security alerts, and detection rules
- migrating-to-post-quantum-cryptographyBuild a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quant
- modeling-threats-with-openctiDeploy OpenCTI (Filigran) via Docker Compose and use the pycti Python client to
- monitoring-darkweb-sourcesMonitors dark web forums, marketplaces, paste sites, and ransomware
- monitoring-scada-modbus-traffic-anomaliesMonitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous
- moving-laterally-with-netexecUse NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, pa
- operating-havoc-c2Deploy a Havoc C2 team server with Yaotl malleable profiles, generate evasive De
- operating-sliver-c2Stand up a Sliver C2 server and mTLS listeners, generate cross-platform implants
- operationalizing-misp-threat-feedsStand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tra
- orchestrating-llm-attacks-with-pyritBuild automated multi-turn adversarial attacks against conversational LLM target
- parsing-artifacts-with-eric-zimmerman-toolsParse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry h
- performing-access-recertification-with-saviyntConfigure and execute access recertification campaigns in Saviynt Enterprise
- performing-access-review-and-certificationDesigns and runs access review and certification campaigns-scoping,
- performing-active-directory-bloodhound-analysisUse BloodHound and SharpHound (or AzureHound) to enumerate Active Directory
- performing-active-directory-compromise-investigationInvestigate Active Directory compromise by analyzing authentication logs,
- performing-active-directory-forest-trust-attackEnumerate and audit Active Directory forest trust relationships using
- performing-active-directory-penetration-testConduct a focused Active Directory penetration test using BloodHound,
- performing-active-directory-vulnerability-assessmentAssess Active Directory security posture using PingCastle, BloodHound,
- performing-adversary-in-the-middle-phishing-detectionDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks
- performing-agentless-vulnerability-scanningConfigure and execute agentless vulnerability scanning using network
- performing-ai-driven-osint-correlationUse AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot
- performing-alert-triage-with-elastic-siemPerform systematic alert triage in Elastic Security SIEM—classifying,
- performing-android-app-static-analysis-with-mobsfPerforms automated static analysis of Android applications using Mobile
- performing-api-fuzzing-with-restlerUses Microsoft RESTler to perform stateful REST API fuzzing: compiles
- performing-api-inventory-and-discoveryPerforms API inventory and discovery to identify all API endpoints in
- performing-api-rate-limiting-bypassTests API rate limiting for bypass vulnerabilities using Python (requests/aiohtt
- performing-api-security-testing-with-postmanUses Postman to build structured API security test collections covering
- performing-arp-spoofing-attack-simulationSimulates ARP spoofing/cache-poisoning attacks in authorized lab or
- performing-asset-criticality-scoring-for-vulnsBuild a multi-factor asset criticality scoring model—incorporating data
- performing-authenticated-scan-with-openvasConfigure and execute authenticated (credentialed) vulnerability scans using Ope
- performing-authenticated-vulnerability-scanPlan and run authenticated (credentialed) vulnerability scans with scanners such
- performing-automated-malware-analysis-with-capeDeploy and operate the CAPEv2 malware sandbox (a Cuckoo derivative) to run sampl
- performing-aws-account-enumeration-with-scout-suiteRun the agentless, open-source ScoutSuite tool (via pip install and the `scout`
- performing-aws-privilege-escalation-assessmentPerforming authorized privilege escalation assessments in AWS environments
- performing-bandwidth-throttling-attack-simulationSimulate bandwidth throttling and network degradation attacks using tc,
- performing-binary-exploitation-analysisAnalyze ELF binaries for memory-corruption vulnerabilities and build proof-of-co
- performing-blind-ssrf-exploitationDetect and exploit blind Server-Side Request Forgery (SSRF) using out-of-band
- performing-bluetooth-security-assessmentAssess Bluetooth Low Energy (BLE) device security using Python's bleak asyncio
- performing-brand-monitoring-for-impersonationMonitor for brand impersonation attacks across domains, social media,
- performing-clickjacking-attack-testTesting web applications for clickjacking vulnerabilities by assessing
- performing-cloud-asset-inventory-with-cartographyRun Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database
- performing-cloud-forensics-investigationCollect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud
- performing-cloud-forensics-with-aws-cloudtrailInvestigate AWS account compromise by querying CloudTrail with boto3's LookupEve
- performing-cloud-incident-containment-proceduresExecute cloud-native incident containment across AWS, Azure, and GCP using platf
- performing-cloud-log-forensics-with-athenaUses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs,
- performing-cloud-native-forensics-with-falcoUses Falco YAML rules for runtime threat detection in containers and
- performing-cloud-native-threat-hunting-with-aws-detectiveInvestigate AWS security incidents using Amazon Detective's behavior graphs,
- performing-cloud-penetration-testing-with-pacuRun authorized AWS penetration tests with Pacu, the open-source AWS exploitation
- performing-cloud-storage-forensic-acquisitionPerform forensic acquisition of cloud storage services including Google
- performing-container-escape-detection>-
- performing-container-image-hardeningHarden container images by minimizing attack surface, stripping unnecessary
- performing-container-security-scanning-with-trivy>-
- performing-content-security-policy-bypassAnalyze Content-Security-Policy headers and bypass them to achieve cross-site
- performing-credential-access-with-lazagneExtract stored credentials from compromised endpoints using the LaZagne
- performing-cryptographic-audit-of-applicationA cryptographic audit systematically reviews an application's use of
- performing-csrf-attack-simulationTesting web applications for Cross-Site Request Forgery vulnerabilities
- performing-cve-prioritization-with-kev-catalogFetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog,
- performing-dark-web-monitoring-for-threatsDark web monitoring involves systematically scanning Tor hidden services,
- performing-deception-technology-deploymentDeploys deception technology including honeypots, honeytokens, and decoy
- performing-directory-traversal-testingTest web applications for path traversal and Local/Remote File Inclusion
- performing-disk-forensics-investigationConduct disk forensics investigations using forensic imaging, file system
- performing-dmarc-policy-enforcement-rolloutExecute a phased DMARC rollout by inventorying sending sources, configuring
- performing-dns-enumeration-and-zone-transferEnumerates DNS records, attempts zone transfers, brute-forces subdomains,
- performing-dns-tunneling-detectionDetects DNS tunneling by computing Shannon entropy of DNS query names,
- performing-docker-bench-security-assessment>-
- performing-dynamic-analysis-of-android-appPerforms runtime dynamic analysis of Android applications using Frida,
- performing-dynamic-analysis-with-any-runPerform interactive dynamic malware analysis using the ANY.RUN cloud sandbox
- performing-endpoint-forensics-investigationPerforms digital forensics investigation on compromised endpoints including
- performing-endpoint-vulnerability-remediationPerforms vulnerability remediation on endpoints by prioritizing CVEs
- performing-entitlement-review-with-sailpoint-iiqRuns entitlement review and access certification campaigns in SailPoint
- performing-external-network-penetration-testConduct a comprehensive external network penetration test to identify
- performing-false-positive-reduction-in-siemReduces SIEM false positives through systematic rule tuning, threshold
- performing-file-carving-with-foremostRecovers files from disk images and unallocated space using Foremost's
- performing-firmware-extraction-with-binwalkPerforms firmware image extraction and analysis using binwalk to identify
- performing-firmware-malware-analysisAnalyzes firmware images for embedded malware, backdoors, and unauthorized
- performing-fuzzing-with-aflplusplusPerforms coverage-guided fuzzing of compiled binaries with AFL++, instrumenting
- performing-gcp-penetration-testing-with-gcpbucketbrutePerforms authorized GCP security testing using GCPBucketBrute to enumerate
- performing-gcp-security-assessment-with-forsetiPerforming comprehensive security assessments of Google Cloud Platform
- performing-graphql-depth-limit-attackExecute and test GraphQL depth limit attacks using deeply nested recursive
- performing-graphql-introspection-attackPerforms GraphQL introspection attacks that extract the full API schema
- performing-graphql-security-assessmentAssessing GraphQL API endpoints for introspection leaks, injection attacks,
- performing-hardware-security-module-integrationIntegrates Hardware Security Modules (HSMs) via the PKCS#11 interface
- performing-hash-cracking-with-hashcatCracks password hashes with Hashcat, covering hash-type identification,
- performing-http-parameter-pollution-attackExecutes HTTP Parameter Pollution attacks that inject duplicate request
- performing-ics-asset-discovery-with-clarotyPerforms ICS/OT asset discovery with Claroty xDome, combining passive
- performing-indicator-lifecycle-managementTracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan,
- performing-initial-access-with-evilginx3Perform authorized initial access using EvilGinx3 adversary-in-the-middle
- performing-insider-threat-investigationInvestigates insider threat incidents involving employees, contractors,
- performing-ioc-enrichment-automationAutomates Indicator of Compromise (IOC) enrichment by orchestrating
- performing-ios-app-security-assessmentPerforms comprehensive iOS application security assessments using Frida
- performing-iot-security-assessmentPerforms comprehensive security assessments of IoT devices and their
- performing-ip-reputation-analysis-with-shodanAnalyze IP address reputation using the Shodan API to identify open ports,
- performing-jwt-none-algorithm-attackExecute and test the JWT none algorithm attack, crafting tokens with
- performing-kerberoasting-attackPerform Kerberoasting, a post-exploitation technique that enumerates
- performing-kubernetes-cis-benchmark-with-kube-bench>-
- performing-kubernetes-etcd-security-assessment>-
- performing-kubernetes-penetration-testing>-
- performing-lateral-movement-detectionDetects lateral movement techniques including Pass-the-Hash, PsExec,
- performing-lateral-movement-with-wmiexecPerform lateral movement across Windows networks using WMI-based remote
- performing-linux-log-forensics-investigationPerform forensic investigation of Linux system logs including syslog,
- performing-log-analysis-for-forensic-investigationCollect, parse, and correlate system, application, and security logs
- performing-log-source-onboarding-in-siemPerform structured log source onboarding into SIEM platforms (Splunk,
- performing-malware-hash-enrichment-with-virustotalEnrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal
- performing-malware-ioc-extractionMalware IOC extraction is the process of analyzing malicious software
- performing-malware-persistence-investigationSystematically investigate all persistence mechanisms on Windows and
- performing-malware-triage-with-yaraPerforms rapid malware triage and classification using YARA rules that
- performing-memory-forensics-with-volatility3Analyze volatile memory (RAM) dumps using the Volatility 3 framework
- performing-memory-forensics-with-volatility3-pluginsAnalyze memory dumps using Volatility3 plugins to detect injected code,
- performing-mobile-app-certificate-pinning-bypassBypasses SSL/TLS certificate pinning implementations in Android and
- performing-mobile-device-forensics-with-cellebriteAcquire and analyze mobile device data using Cellebrite UFED Touch/4PC, UFED Phy
- performing-network-forensics-with-wiresharkCapture and analyze network traffic using Wireshark and tshark to reconstruct ne
- performing-network-packet-capture-analysisPerform forensic analysis of network packet captures (PCAP/PCAPNG) using Wiresha
- performing-network-traffic-analysis-with-tsharkAutomate network traffic analysis using tshark (Wireshark CLI) and pyshark to co
- performing-network-traffic-analysis-with-zeekDeploy Zeek (formerly Bro) as a passive network security monitor to generate str
- performing-nist-csf-maturity-assessmentConduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the
- performing-oauth-scope-minimization-reviewPerforms OAuth 2.0 scope minimization review to identify over-permissioned
- performing-oil-gas-cybersecurity-assessmentConduct cybersecurity assessments of upstream, midstream, and downstream oil and
- performing-open-source-intelligence-gatheringOpen Source Intelligence (OSINT) gathering is the first active phase
- performing-osint-with-spiderfootAutomate OSINT collection with the SpiderFoot REST API and CLI (sf.py/spiderfoot
- performing-ot-network-security-assessmentThis skill covers conducting comprehensive security assessments of Operational
- performing-ot-vulnerability-assessment-with-clarotyPerform OT vulnerability assessments using the Claroty xDome platform for asset
- performing-ot-vulnerability-scanning-safelyPerform vulnerability scanning in OT/ICS environments safely using passive
- performing-packet-injection-attackCrafts and injects custom network packets using Scapy, hping3, and Nemesis
- performing-paste-site-monitoring-for-credentialsMonitor paste sites like Pastebin and GitHub Gists for leaked credentials,
- performing-phishing-simulation-with-gophishDeploy and run authorized phishing awareness campaigns with GoPhish, covering ad
- performing-physical-intrusion-assessmentConduct authorized physical penetration testing against facilities, server rooms
- performing-plc-firmware-security-analysisThis skill covers analyzing Programmable Logic Controller (PLC) firmware
- performing-post-quantum-cryptography-migrationAssesses organizational readiness for post-quantum cryptography migration
- performing-power-grid-cybersecurity-assessmentConduct cybersecurity assessments of power grid infrastructure spanning generati
- performing-privacy-impact-assessmentAutomates the Privacy Impact Assessment (PIA) workflow including data
- performing-privilege-escalation-assessmentPerforms privilege escalation assessments on compromised Linux and Windows
- performing-privilege-escalation-on-linuxGuides manual enumeration and automated tooling to escalate from a low-privilege
- performing-privileged-account-access-reviewConducts systematic reviews of privileged accounts to validate access
- performing-privileged-account-discoveryDiscovers and inventories privileged accounts across enterprise infrastructure,
- performing-purple-team-atomic-testingExecutes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam
- performing-purple-team-exercisePerforms purple team exercises by coordinating red team adversary emulation
- performing-ransomware-responseExecutes a structured ransomware incident response from detection through
- performing-ransomware-tabletop-exercisePlans and facilitates tabletop exercises simulating ransomware incidents,
- performing-red-team-phishing-with-gophishAutomates GoPhish phishing simulation campaigns using the Python gophish
- performing-red-team-with-covenantConducts red team operations using the Covenant C2 framework for authorized
- performing-s7comm-protocol-security-analysisPerform security analysis of Siemens S7comm and S7CommPlus protocols
- performing-sca-dependency-scanning-with-snykThis skill covers implementing Software Composition Analysis (SCA) using
- performing-scada-hmi-security-assessmentPerform security assessments of SCADA Human-Machine Interface (HMI)
- performing-second-order-sql-injectionDetect and exploit second-order SQL injection vulnerabilities where malicious
- performing-security-headers-auditAuditing HTTP security headers including CSP, HSTS, X-Frame-Options,
- performing-serverless-function-security-reviewPerforming security reviews of serverless functions across AWS Lambda,
- performing-service-account-auditAudit service accounts across enterprise infrastructure to identify orphaned,
- performing-service-account-credential-rotationAutomates credential rotation for service accounts across Active Directory,
- performing-soap-web-service-security-testingPerforms security testing of SOAP web services by analyzing WSDL definitions
- performing-soc-tabletop-exercisePerforms tabletop exercises for SOC teams simulating security incidents
- performing-soc2-type2-audit-preparationAutomates SOC 2 Type II audit preparation including gap assessment against
- performing-sqlite-database-forensicsPerforms forensic analysis of SQLite databases by examining B-tree page
- performing-ssl-certificate-lifecycle-managementAutomates the full SSL/TLS certificate lifecycle, including generating
- performing-ssl-stripping-attack>-
- performing-ssl-tls-inspection-configuration>-
- performing-ssl-tls-security-assessment>-
- performing-ssrf-vulnerability-exploitation>-
- performing-static-malware-analysis-with-pe-studio>-
- performing-steganography-detection>-
- performing-subdomain-enumeration-with-subfinderEnumerate subdomains of target domains using ProjectDiscovery's Subfinder
- performing-supply-chain-attack-simulation>-
- performing-thick-client-application-penetration-testConduct a thick client application penetration test to identify insecure
- performing-threat-emulation-with-atomic-red-teamExecutes Atomic Red Team tests for MITRE ATT&CK technique validation
- performing-threat-hunting-with-elastic-siemPerforms proactive threat hunting in Elastic Security SIEM using KQL/EQL
- performing-threat-hunting-with-yara-rulesUse YARA pattern-matching rules to hunt for malware, suspicious files,
- performing-threat-intelligence-sharing-with-misp>-
- performing-threat-landscape-assessment-for-sector>-
- performing-threat-modeling-with-owasp-threat-dragon>-
- performing-timeline-reconstruction-with-plaso>-
- performing-user-behavior-analyticsPerforms User and Entity Behavior Analytics (UEBA) to detect anomalous
- performing-vlan-hopping-attack>-
- performing-vulnerability-scanning-with-nessusPerforms authenticated and unauthenticated vulnerability scanning using
- performing-web-application-firewall-bypassBypasses Web Application Firewall protections using encoding tricks,
- performing-web-application-penetration-testPerforms systematic security testing of web applications following the
- performing-web-application-scanning-with-niktoRuns Nikto, an open-source web server and web application scanner,
- performing-web-application-vulnerability-triageTriages web application vulnerability findings from DAST/SAST scanners
- performing-web-cache-deception-attackExecutes web cache deception attacks by exploiting path normalization
- performing-web-cache-poisoning-attackExploiting web cache mechanisms to serve malicious content to other users
- performing-wifi-password-cracking-with-aircrackCaptures WPA/WPA2 handshakes and performs offline password cracking
- performing-windows-artifact-analysis-with-eric-zimmerman-tooPerforms comprehensive Windows forensic artifact analysis using Eric
- performing-wireless-network-penetration-testExecute a wireless network penetration test to assess WiFi security by
- performing-wireless-security-assessment-with-kismetConduct wireless network security assessments using Kismet to detect
- performing-yara-rule-development-for-detectionDevelops precise YARA and YARA-X rules for malware detection by identifying
- post-exploiting-microsoft-graph-with-graphrunnerRuns GraphRunner, a PowerShell post-exploitation toolset built on
- prioritizing-vulnerabilities-with-cvss-scoringThe Common Vulnerability Scoring System (CVSS) is the industry standard
- processing-stix-taxii-feedsProcesses STIX 2.1 threat intelligence bundles delivered via TAXII 2.1
- profiling-threat-actor-groupsDevelops comprehensive threat actor profiles for APT groups, criminal
- recovering-deleted-files-with-photorecRecovers deleted files from disk images and storage media using PhotoRec's
- recovering-from-ransomware-attackExecutes structured ransomware incident recovery following NIST/CISA
- red-teaming-llms-with-garakRuns NVIDIA garak probe suites (jailbreak, prompt injection, data
- relaying-ntlm-for-adcs-esc8Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer,
- remediating-s3-bucket-misconfigurationProvides step-by-step procedures for remediating Amazon S3 bucket
- reverse-engineering-android-malware-with-jadxReverse engineers malicious Android APK files using the JADX decompiler
- reverse-engineering-dotnet-malware-with-dnspyReverse engineers .NET malware samples using the dnSpy decompiler and
- reverse-engineering-ios-app-with-fridaReverse engineers iOS applications using Frida dynamic instrumentation
- reverse-engineering-malware-with-ghidraReverse engineers malware binaries using NSA''s Ghidra disassembler and
- reverse-engineering-ransomware-encryption-routineReverse engineer ransomware encryption routines to identify cryptographic
- reverse-engineering-rust-malwareReverse engineers Rust-compiled malware using IDA Pro and Ghidra, covering
- scanning-container-images-with-grype>-
- scanning-containers-with-trivy-in-cicdIntegrates Aqua Security''s Trivy scanner into CI/CD pipelines to detect
- scanning-docker-images-with-trivy>-
- scanning-iac-and-images-with-trivyScans container images, Infrastructure-as-Code (Terraform, CloudFormation,
- scanning-infrastructure-with-nessusTenable Nessus is the industry-leading vulnerability scanner used to
- scanning-kubernetes-manifests-with-kubesec>-
- scanning-network-with-nmap-advancedPerforms advanced network recon using Nmap''s Scripting Engine (NSE),
- securing-agentic-ai-tool-invocationImplements defense-in-depth controls at an AI agent's tool-invocation
- securing-api-gateway-with-aws-wafSecures AWS API Gateway endpoints with AWS WAF by configuring managed
- securing-aws-iam-permissionsHardens AWS IAM configurations to enforce least-privilege access, covering
- securing-aws-lambda-execution-rolesHardens AWS Lambda execution roles by writing least-privilege IAM policies,
- securing-azure-with-microsoft-defenderDeploys and configures Microsoft Defender for Cloud as a CNAPP for
- securing-container-registry-imagesSecures container registry images (ECR, ACR, GCR, Docker Hub) by scanning
- securing-container-registry-with-harbor>-
- securing-github-actions-workflowsHardens GitHub Actions workflows against supply chain attacks, credential
- securing-helm-chart-deployments>-
- securing-historian-server-in-ot-environmentAudits and hardens process historian servers (OSIsoft PI, Honeywell PHD,
- securing-kubernetes-on-cloudHardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing
- securing-remote-access-to-ot-environmentDesigns and configures secure remote access to OT/ICS environments for
- securing-serverless-functionsHardens serverless compute platforms (AWS Lambda, Azure Functions, Google
- testing-android-intents-for-vulnerabilitiesTests Android inter-process communication (IPC) through intents for
- testing-api-authentication-weaknessesTests API authentication mechanisms for weaknesses including broken
- testing-api-for-broken-object-level-authorizationTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR,
- testing-api-for-mass-assignment-vulnerabilityTests APIs for mass assignment (auto-binding), OWASP API3:2023, by identifying
- testing-api-security-with-owasp-top-10Systematically assesses REST, GraphQL, and gRPC API endpoints against the OWASP
- testing-cors-misconfigurationIdentifying and exploiting Cross-Origin Resource Sharing misconfigurations
- testing-for-broken-access-controlSystematically tests web applications and APIs for broken access control
- testing-for-business-logic-vulnerabilitiesManually identifies flaws in application business logic - price manipulation,
- testing-for-email-header-injectionTests web application email functionality (contact forms, password reset,
- testing-for-host-header-injectionTest web applications for HTTP Host header injection vulnerabilities
- testing-for-json-web-token-vulnerabilitiesTests JWT implementations for algorithm confusion, "none" algorithm bypass,
- testing-for-open-redirect-vulnerabilitiesIdentifies and exploits open redirect vulnerabilities by analyzing URL
- testing-for-sensitive-data-exposureIdentifying sensitive data exposure vulnerabilities including API key
- testing-for-system-prompt-leakageExtracts LLM system prompts using direct requests, jailbreak/instruction-overrid
- testing-for-xml-injection-vulnerabilitiesTest web applications for XML injection vulnerabilities including XXE,
- testing-for-xss-vulnerabilitiesTests web applications for reflected, stored, and DOM-based Cross-Site
- testing-for-xss-vulnerabilities-with-burpsuiteIdentifying and validating cross-site scripting vulnerabilities using
- testing-for-xxe-injection-vulnerabilitiesDiscovering and exploiting XML External Entity injection vulnerabilities
- testing-jwt-token-securityAssessing JSON Web Token implementations for cryptographic weaknesses,
- testing-mobile-api-authenticationTests authentication and authorization mechanisms in mobile application
- testing-oauth2-implementation-flawsTests OAuth 2.0 and OpenID Connect implementations for authorization code
- testing-prompt-injection-in-rag-pipelinesProbes Retrieval-Augmented Generation pipelines for indirect prompt injection
- testing-ransomware-recovery-proceduresTests and validates ransomware recovery procedures - backup restore operations
- testing-websocket-api-securityTests WebSocket API implementations for missing upgrade-handshake authentication
- tracking-threat-actor-infrastructureDiscovers and maps adversary-controlled infrastructure (C2 servers,
- triaging-security-alerts-in-splunkTriages security alerts in Splunk Enterprise Security by classifying
- triaging-security-incidentPerforms initial triage of security incidents using the NIST SP
- triaging-security-incident-with-ir-playbookClassifies and prioritizes security incidents using structured IR
- triaging-vulnerabilities-with-ssvc-frameworkTriages and prioritizes vulnerabilities with CISA's Stakeholder-Specific
- triaging-windows-with-kapeRuns KAPE (Kroll Artifact Parser and Extractor) to collect targeted
- validating-backup-integrity-for-recoveryValidates backup integrity through cryptographic hash verification,
- validating-tpm-measured-boot-attestationVerifies TPM 2.0 measured-boot integrity and remote attestation with
- verifying-build-provenance-with-slsa-sigstoreVerifies artifact signatures and SLSA provenance using Sigstore's
想一次拿到这个仓库的全部技能?
本站把开放许可(MIT / Apache 等)的仓库按整仓打包整理到网盘,点一下转存到你自己的网盘。许可未声明的仓库只给原始仓库链接,不打包。