Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure
Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement,
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers,
Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security,
Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service
Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions,
Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service
Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength.
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting
Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session
Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized
Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan,
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection
Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces,
Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities,
Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header
Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration,
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines
Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization,
Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches,
Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives
Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences,
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts,
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct
Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection,
Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations,
Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries,
Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device
Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards.
Executes a structured ransomware incident response from initial detection through containment, forensic analysis,
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with
Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener
Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities
Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and
Analyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the security-pro-pack plugin, including vulnerability…
Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing
Test automate security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues.
Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,
Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to
Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode
SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,
Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test
Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for
Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains,
Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services,
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file
Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance,
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,