Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute
Executes a structured ransomware incident response from initial detection through containment, forensic analysis,
Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG)
Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using
Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution
Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised
Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain
Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing
Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine
Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible
Deploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary…
Run ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate
Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral
Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,
Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden…
Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify
Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous
Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral
Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon
Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing
Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources
Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding,
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs)
Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques
Deploy a Velociraptor server and agents, then author VQL (Velociraptor Query Language) artifacts and run them as fleet-wide hunts, on-demand forensic collections, or standalone…
Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image
Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel
Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle
Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure
Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed
Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply…
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous
Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware
Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API
RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other…
Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record
Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring
Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect
Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0,
Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.
Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated
Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware
Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and
Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting
Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation
Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware