Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,
Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK…
Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session…
Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning,
Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates
Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis
Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface,
Skill: multi-channel-reminder. See SKILL.md body for details. Use when this domain is relevant.
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster…
Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous
Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent
MCP servers for cloud infrastructure. Connect AI agents to AWS, GCP, and Azure for deployment, management, and
Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents
Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse,
Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS
Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF,
Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create
Container escape is a critical attack technique where an adversary breaks out of container isolation to access
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized
Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,
Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized
Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify
Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation
Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,
Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry
Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs
Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral
Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using
Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in
Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant
Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin
Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls,
Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or
Plants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bug URLs, AWS keys, documents, kubeconfigs) using Thinkst's open-source Canarytokens project and…
Use when activate an AI general manager persona with full context awareness and multi-user adaptation.
Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow
Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and
Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across
Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks,
Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine
BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation,
Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, — from Undermybelt/hermes-skills
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing
Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test
Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation,
Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying