Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence
Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible
Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
Deploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary…
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies,
Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for
Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying
Designs and documents structured incident response playbooks that define step-by-step procedures for specific
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
Use when multi-platform e-commerce and messaging channel extraction (Shopee, TikTok Shop, WeChat)
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,
Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised — from BloodHoundAD/BloodHound
Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible
Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications,
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response
Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based
Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration
Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file
One piece of content becomes 10 — blog to Twitter thread, LinkedIn article, YouTube script, newsletter, TikTok
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from Undermybelt/hermes-skills
Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral
Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web
Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for
Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources
Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom)
Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying
Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy
Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate
Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge
Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate
Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields,
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against
Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS — from mahipal
Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into
Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates,
Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,
Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging,
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam
Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems,
Auto-generate 30-day content calendars with pillar rotation, platform-optimized timing, multi-account rotation, — from oyi77/1ai-skills
Deploy a Velociraptor server and agents, then author VQL (Velociraptor Query Language) artifacts and run them as fleet-wide hunts, on-demand forensic collections, or standalone…
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing