Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable
Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious
Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify
Integrate Google BigQuery for large-scale data analytics. Write SQL queries, manage datasets, export results, and build data pipelines.
Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK…
Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge
Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct
Implementing device posture assessment as a zero trust access control by integrating endpoint health signals
OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its
Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process
Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify
Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation,
Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events,
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence
Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry
Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group
Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration
Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan,
Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege
Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation,
Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces,
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates,
Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules,
Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion)
Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to
Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract
Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and
Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom
Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments,
Performs API inventory and discovery to identify all API endpoints in an organization''s environment including
Vite build tool configuration — plugins, SSR, library mode, environment variables, dev server proxy. Use when working with vite config.
Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header
Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web
Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent
Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,
Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption
Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts,
Triage npm packages for install-script malware, exfiltration, and worming behavior.
Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate
Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,
Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they
Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request
Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode,
Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials,
Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract
Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol
Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during
Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom)
Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security
Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying
Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based