Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the
Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library
Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud
Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing
Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for
Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis
Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection,
Data extraction hub — content monitoring, price tracking, web scraping, and social listening for competitive intelligence, market research, and automated revenue generation.
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against
Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt…
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents
Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid
Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning…
Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user
Envoy proxy — L4/L7 filtering, load balancing, circuit breaking, observability, extensibility. Use when working with envoy proxy.
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized
Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms
Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child
Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, — from mahipal
Create, edit, and analyze Word documents programmatically using python-docx or docx.js. Generate reports, proposals, and templates with formatting, tables, images, and styles.
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications,
Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege
Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout
Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry
Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying
Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,
Run AI models on Replicate cloud API. Deploy image generation, video creation, audio processing, and custom models without managing infrastructure.
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify
Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF,
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,
Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration,
Skill: agent-arena-skill. See SKILL.md body for details. Use when this domain is relevant.
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate
Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic
Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI…
Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication
Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and
Performs initial triage of security incidents to determine severity, scope, and required response actions using
Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service
Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security
MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation,
Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures,
Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,
Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing
Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with
Build and manage automations across Make.com, n8n, Zapier, and Pipedream — onboarding, support tickets, content
Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation
Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration