Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing
Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches,
Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra
Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts,
Use when foundational core infrastructure skill providing system foundation capabilities for the agent ecosystem.
Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership
Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize
Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains,
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement,
Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement,
Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection,
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics
Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings,
Reduce container attack surface by building application images on Google distroless base images that contain
Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking,
Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,
Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing
Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself
Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,
Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization
URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content,
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while
Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process
Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and
Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate
Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards
Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying
Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging,
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing
Uses Postman to perform structured API security testing by building collections that test for OWASP API Security
Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social
Implements security chaos engineering experiments that deliberately disable or degrade security controls to
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to
Build structured communication templates for malware incidents including stakeholder notifications, executive
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted
Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through
Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming…
Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system
Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with…
Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create
Centralized database for meta-skill operations. Stores performance metrics, feedback, patterns, and skill evolution
Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS — from mahipal
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers,
Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators,
HashiCorp Consul — service discovery, health checking, KV store, service mesh, intentions. Use when working with consul service mesh.
AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket