Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation,
Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across
Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across
Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for
Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration
Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and
Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities,
Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis,
Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library.
Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses,
Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points.
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations,
Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security…
Configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized
Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode
Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations,
Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,
Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and
Plants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bug URLs, AWS keys, documents, kubeconfigs) using Thinkst's open-source Canarytokens project and…
Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy,…
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,
Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface,
Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin
Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI
BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns,
Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication
Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to
Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based
Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction,
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud
Deep dive into each oh-my-opencode agent - Sisyphus, Hephaestus, Oracle, Librarian, Explore - their characteristics,
Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation,
Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable
Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit
Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into
Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary
PlanetScale MySQL — branching, deploy requests, Vitess sharding, connection handling, schema management. Use when working with planetscale patterns.
Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source
Flowise visual LLM workflow builder — drag-drop chatflows, API endpoints, document loaders, tools. Use when working with flowise builder.
Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity