Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and
Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues
Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates
Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control
Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications
Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage…
Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE),
One piece of content becomes 10 — blog to Twitter thread, LinkedIn article, YouTube script, newsletter, TikTok
Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover
Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing
Analyzes network traffic generated by malware during sandbox execution or live incident response to identify
Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for
Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications,
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing
Skill: multi-channel-reminder. See SKILL.md body for details. Use when this domain is relevant.
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and
MCP server for Slack integration. Send messages, manage channels, and automate Slack workflows via standardized protocol.
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable
Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious
Identify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger…
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,
Probe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters,
End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary
Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from Undermybelt/hermes-skills
Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation,
Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates
Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials
MCP server for Stripe payments. Process payments, manage subscriptions, and handle billing via standardized protocol. Use when working with stripe mcp.
Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,
Cryptographic attack techniques for breaking implementations, side-channel attacks, and exploiting crypto weaknesses.
Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs
Discover and connect to MCP servers automatically. Browse available tools and register new server endpoints. Use when working with mcp discover.
Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private
Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring
Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify
Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported
Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat
Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD
Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse
The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7.
Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception
Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, — from mahipal
Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations,
Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts,
Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating
Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus…
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment
Designs and documents structured incident response playbooks that define step-by-step procedures for specific
Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query
Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications,
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary