Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting
Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation,
Test web applications using browser DevTools, Playwright, or Puppeteer. Automate E2E testing, visual regression, performance auditing, and accessibility checking.
Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security…
Flowise visual LLM workflow builder — drag-drop chatflows, API endpoints, document loaders, tools. Use when working with flowise builder.
Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for
Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control
Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware
Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications
Vite build tool configuration — plugins, SSR, library mode, environment variables, dev server proxy. Use when working with vite config.
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify
Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,
Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction
MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code
Configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized
Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS — from Undermybelt/hermes-skills
Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance,
Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security,
Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls
PlanetScale MySQL — branching, deploy requests, Vitess sharding, connection handling, schema management. Use when working with planetscale patterns.
Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation
The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7.
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle
Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing
Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit
Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed
Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,
Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged
Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy,
Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for
Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin
Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations,
Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract
Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries,
Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover
This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP
This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS,
This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application
This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for
This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA
This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations
This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection
This skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial
This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards,
This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.
This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout
This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO