Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud
Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring
Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they
Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts
Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces,
SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate
Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch
Build structured communication templates for malware incidents including stakeholder notifications, executive
Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences,
Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure
Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify
Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,
Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and…
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation,
Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for
Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against
Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent
Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based,
Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing
Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs,
Detect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows
Master Git workflows including branching strategies, interactive rebase, cherry-pick, bisect, worktrees, and advanced merge conflict resolution.
Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3
Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate…
Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements
Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership
Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators
Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, — from mahipal
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)
Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains,
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization
Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation,
Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution,
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory.
Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement,
Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation
Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication
Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom
Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process
Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library.
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and
Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries,
Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying
Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments,
Triage npm packages for install-script malware, exfiltration, and worming behavior.
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates
Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested
Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding
Use when industry research and sector rotation for portfolio alpha — TAM/SAM/SOM analysis, competitive dynamics, regulatory tailwinds, and sector timing to beat the market by…
Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry
Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress
Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection,