Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users
Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace
STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)
Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and
Detect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.
Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines,
Run kube-bench (Aqua Security) against a Kubernetes cluster's control-plane, kubelet, and node configuration to check compliance with the CIS Kubernetes Benchmark and remediate…
Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual
Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant
Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,
Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized
Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling,
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and…
Produce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.
Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying
Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,
Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies,
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network
Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,
Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning,
Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files
Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,
Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress
Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with
Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug
Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener
Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application
Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring
Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular
Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts — from mahipal
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like
Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map
Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker,
MCP server for Supabase databases. Query tables, manage auth, and handle storage through standardized protocol. Use when working with supabase mcp.
Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates
Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations
Parse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.
Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs,
Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent
Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking
Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems
Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,
Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless
Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,
Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps
Use when trade earnings reports for profit — pre-earnings positioning, post-earnings momentum, and management quality scoring.
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation,
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover
Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through