PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data.
Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate
Storybook for UI component development — stories, addons, controls, a11y testing, visual regression. Use when working with storybook ui.
Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy,
Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iam__privesc_scan, and…
Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation
Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data
Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection
Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task
Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,
Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for
Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing
End-to-end competitive analysis automation that combines product research, video analysis, and storyboard extraction — from oyi77/1ai-skills
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks,
Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates
Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using
Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through
Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and
Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT
Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound,
Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical
Investigate token and NFT scams including rug pulls, honeypot tokens, pump-and-dump schemes,
Performs advanced network reconnaissance using Nmap''s scripting engine, timing controls, evasion techniques,
Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated
Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation,
Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware,
Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32
Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation
Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs,
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to
Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged
Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy
Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate…
Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions,
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file
Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based,
Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant
Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,
Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,
Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify
Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed