Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting
Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using
Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding
Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse
Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families
Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized
Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control
Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active
Executes authorized attack simulations against Active Directory environments to identify misconfigurations,
Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows
Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous
Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect,
Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection,
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack
Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations,
Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance,
Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for
Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,
Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive
Use when content Kingdom Orchestrator — the BRAIN that coordinates all 12 content phases. Sequences research → plan → script → create → review → schedule → post → engage → analyze…
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,
Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with
Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence
Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing
Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID)
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting
Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven
Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy,
Use when industry research and sector rotation for portfolio alpha — TAM/SAM/SOM analysis, competitive dynamics, regulatory tailwinds, and sector timing to beat the market by…
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security
Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services,
Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure
Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to
Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases
Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,
Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution,
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn
Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations,
Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for…
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like…
Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary…
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware,
Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication,
Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences
Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on
Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and
Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset
Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis,
Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules),
Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and