Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation,
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested
Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications
Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment,
Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields,
Security awareness training is the human layer of phishing defense. An effective anti-phishing training program
Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based
Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility
Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log,
Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger
Flux CD GitOps — source controllers, kustomize/helm controllers, image automation, notifications. Use when working with fluxcd gitops.
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak
Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.
Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned
SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents,
Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation
Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from mahipal
Implementing Google''s BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter,
Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength.
Harbor is an open-source container registry that provides security features including vulnerability scanning
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster…
Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences,
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,
Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and
Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege
Inventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp
Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control
Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native
Conducts comprehensive network penetration tests against authorized target environments by performing host discovery,
Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal,
Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local
Use when multi-platform e-commerce and messaging channel extraction (Shopee, TikTok Shop, WeChat)
Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication,
Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision
Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions,
Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events,
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response
Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions,
Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies,
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking
Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based
Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where
Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,
Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),