Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect,
Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure
Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate
Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets,
Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies
Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies,
Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for
Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn
Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across
Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware,
Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies,
Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital
Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application
Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon
Implements security chaos engineering experiments that deliberately disable or degrade security controls to
Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators,
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events,
Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics
Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom)
Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger
Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC
STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information)
Implement software supply chain integrity verification for container builds using the in-toto framework to create
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates
Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from mahipal
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets,
Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for
Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or…
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation
Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false
Scan for reports that have not yet been copied into as tracking issues, present the proposed imports to the user, and — defaulting to *import un — from…
Open one or more `` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party — from…
Open a tracking issue in for a security-relevant fix that has already been opened (or merged) as a public PR in , in the case where there is no inboun — from…
Convert impostor syndrome from a career liability into strategic fuel — diagnosing the specific competence gap behind the feeling, building a personal development strategy around…
Improve adoption criterion A7 (Proactive Quality Management) by configuring automated dependency updates, security scanning, and agent-driven tech debt PRs.
Improve readiness criterion C6.1 (Static Analysis) in the current project by adding linting, type checking, or security scanning. Raises the fulfillment level by one step.
Ameliore le hook pre-commit LIA-SEC (.claude/hooks/security_check.sh) pour detecter les hardcodings (localhost, URLs en dur, fmt.Println, console.log, print) dans le CODE et dans…
Run only the security and threat-model lens from the improve workflow on a target file, directory, or glob, producing read-only adversarial findings.
Expert at automatically applying improvements to Claude Code components based on quality analysis. Enhances descriptions, optimizes tool permissions, strengthens security, and…
Multi-agent code review of the current branch or a PR — parallel engineering, minimalist, conventions, and AntiSlop reviewers plus conditional security, database, and frontend…
Apply IN10 Red Teaming to organize adversarial review to find vulnerabilities through simulated attack.
Maintainer-only. Use when triaging inbound GitHub issues and pull requests on skyf0xx/hedgehog — "triage the issues", "check the PRs", "review inbound", "what's in the queue".
Expert guidance for building and maintaining the Para Obsidian inbox processing system - a security-hardened automation framework for processing PDFs and attachments with…
Composite skill — runs the postmortem chain after any production incident (`/hotfix`, rollback, or prod outage acknowledged).
Structure and record a cybersecurity incident materiality determination, and run the disclosure clocks that follow from it.
Baut die Incident-Meldekaskade mit Frühwarnung, Folgemeldung und Abschlussbericht im Nis2 Cybersecurity Compliance.
Write a single clear, honest public statement about an incident. Use when asked to draft a public statement, a press statement, or an official response to a security breach,…
Use when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across t — from…
Use when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across t — from…
Use when user needs security incident response, operational incident management, evidence collection, forensic analysis, or coordinated response for outages and breaches.
Guides teams through IT outages and security incidents, providing structured workflows for detection, containment, eradication, and post-mortem analysis.