Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout
Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline
Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter,
Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based
Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records)
Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure
Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process
Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,
Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group
Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters,
Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis,
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across
STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)
Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud
Run kube-bench (Aqua Security) against a Kubernetes cluster's control-plane, kubelet, and node configuration to check compliance with the CIS Kubernetes Benchmark and remediate…
Create, edit, and analyze Word documents programmatically using python-docx or docx.js. Generate reports, proposals, and templates with formatting, tables, images, and styles.
Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack
Storybook for UI component development — stories, addons, controls, a11y testing, visual regression. Use when working with storybook ui.
Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate
Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests
Analyze DeFi security incidents including flash loan attacks, oracle manipulation, reentrancy exploits,
Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI
MCP server for Stripe payments. Process payments, manage subscriptions, and handle billing via standardized protocol. Use when working with stripe mcp.
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing
Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable
Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications,
Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,
Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring
Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata
Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP
Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
MCP server for Supabase databases. Query tables, manage auth, and handle storage through standardized protocol. Use when working with supabase mcp.
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device
Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and
Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task
Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant
Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket
Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to
Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure
Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised
Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration,
Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply…
Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or…
Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing
Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Inventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,
Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for…
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract
Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using
Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,
Identify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger…
Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for