Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious
Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure
Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to
Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security,
Analyze DeFi security incidents including flash loan attacks, oracle manipulation, reentrancy exploits,
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device
Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate
Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection,
Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session
Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from
Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries,
Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the
JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS
Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session…
Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications,
Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests
Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time
Automated discovery of affiliate programs, partnership opportunities, and cross-promotion deals with outreach,
Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,
Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified
Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache,…
Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts
Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive
Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,
Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting
Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing
Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts — from Undermybelt/hermes-skills
Monetize bug bounty findings through writeups, tools, and consulting. Use when turning security research into
Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in
Container escape is a critical attack technique where an adversary breaks out of container isolation to access
Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event
Auto-generate 30-day content calendars with pillar rotation, platform-optimized timing, multi-account rotation, — from oyi77/1ai-skills
Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod
Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443,
Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying
This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems
This skill covers implementing a structured patch management program for OT/ICS environments where traditional
This skill guides organizations through implementing zero trust architecture in cloud environments following
This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA
This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions,
This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security
This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO
This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare
This skill covers designing and implementing security zones and conduits for industrial automation and control
This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes
This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including
This skill covers deploying anomaly detection systems for industrial control environments using machine learning