The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security
Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule
Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced
Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions,
Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses,
Implementing device posture assessment as a zero trust access control by integrating endpoint health signals
Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates
Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon
Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative
Use when find bottleneck companies — the critical constraint in supply chains that have pricing power, low competition, and high returns.
Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and
Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege
Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid
Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s
AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect
Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,
Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware,
Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous
Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify
Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using
Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning…
Deep dive into each oh-my-opencode agent - Sisyphus, Hephaestus, Oracle, Librarian, Explore - their characteristics,
Envoy proxy — L4/L7 filtering, load balancing, circuit breaking, observability, extensibility. Use when working with envoy proxy.
Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts,
Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection,
Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers,
Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event
Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage,
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
Run MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing
Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and
Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass,
Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious
Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based
Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows,
Conducts comprehensive network penetration tests against authorized target environments by performing host discovery,
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit
Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image
Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication,
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source
Run ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns,
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous
Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting
Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from
Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration
Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration
Use when content Kingdom Orchestrator — the BRAIN that coordinates all 12 content phases. Sequences research → plan → script → create → review → schedule → post → engage → analyze…
Systematically testing web applications for broken access control vulnerabilities including privilege escalation,
Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts — from Undermybelt/hermes-skills