Data Analysis
-
mukul975 Bundle Implementing Cloud Dlp For Data ProtectionDiscover, classify, and protect sensitive data across cloud storage, databases, and data pipelines using Amazon Macie, Azure Information Protection, and Google Cloud DLP API.
24.6k -
mukul975 Bundle Performing Cloud Log Forensics With AthenaQuery AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
24.6k -
mukul975 Bundle Performing Network Packet Capture AnalysisAnalyze network packet captures (PCAP/PCAPNG) using Wireshark, tshark, tcpdump, and Python to reconstruct communications, extract files, and identify malicious traffic.
24.6k -
mukul975 Bundle Analyzing Macro Malware In Office DocumentsExtracts and analyzes malicious VBA macros, XLM macros, DDE, and remote template injections in Microsoft Office documents using olevba, oledump, and deobfuscation techniques to identify download cradles, payload execution, and persistence mechanisms.
24.6k -
mukul975 Bundle Detecting Anomalous Authentication PatternsDetects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs.
24.6k -
mukul975 Bundle Detecting Insider Data Exfiltration Via DlpDetects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs using pandas for behavioral analytics and statistical baselines.
24.6k -
mukul975 Bundle Generating Forensic Timelines With HayabusaGenerate Sigma-based forensic timelines from Windows EVTX files using Hayabusa for incident response triage.
24.6k -
mukul975 Bundle Parsing Artifacts With Eric Zimmerman ToolsParse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
24.6k -
mukul975 Bundle Performing Ics Asset Discovery With ClarotyDiscover and inventory ICS/OT assets using Claroty xDome, including passive monitoring, active queries, and integration with CMDB tools.
24.6k -
mukul975 Bundle Performing Network Forensics With WiresharkCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
24.6k -
mukul975 Bundle Analyzing Cobalt Strike Beacon ConfigurationExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
24.6k -
mukul975 Bundle Analyzing Cobaltstrike Malleable C2 ProfilesParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
24.6k -
mukul975 Bundle Analyzing Malware Sandbox Evasion TechniquesDetect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
Audited 24.6k -
mukul975 Bundle Analyzing Network Covert Channels In MalwareDetect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and protocol abuse for C2 and data exfiltration.
24.6k -
mukul975 Bundle Hunting For Defense Evasion Via TimestompingDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT using analyzeMFT and Python.
24.6k -
mukul975 Bundle Performing Linux Log Forensics InvestigationAnalyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
24.6k -
mukul975 Bundle Detecting Entra Offensive Tools In Graph LogsHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
24.6k -
mukul975 Bundle Hunting For Beaconing With Frequency AnalysisIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
Audited 24.6k -
mukul975 Bundle Performing Timeline Reconstruction With PlasoBuild comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
24.6k -
mukul975 Bundle Analyzing Malware Behavior With Cuckoo SandboxExecutes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.
24.6k -
mukul975 Bundle Analyzing Prefetch Files For Execution HistoryParse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
24.6k -
mukul975 Bundle Performing Asset Criticality Scoring For VulnsBuild a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
24.6k -
mukul975 Bundle Analyzing Certificate Transparency For PhishingMonitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
24.6k -
mukul975 Bundle Performing Network Traffic Analysis With TsharkAutomates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
24.6k -
mukul975 Bundle Detecting Golden Ticket Attacks In Kerberos LogsDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
Audited 24.6k -
mukul975 Bundle Detecting Anomalies In Industrial Control SystemsDeploys anomaly detection for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications.
24.6k -
mukul975 Bundle Performing Static Malware Analysis With Pe StudioPerforms static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary.
24.6k -
mukul975 Bundle Analyzing Email Headers For Phishing InvestigationParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
24.6k -
mukul975 Bundle Detecting Dns Exfiltration With Dns Query AnalysisDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
24.6k -
mukul975 Bundle Performing Memory Forensics With Volatility3 PluginsAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
24.6k -
mukul975 Bundle Performing Windows Artifact Analysis With Eric Zimmerman TooParse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
24.6k -
wondelai Bundle Ddia SystemsDesign reliable, scalable, and maintainable data systems by applying principles from storage engines, replication, partitioning, transactions, and consistency models.
Audited 1.6k -
wondelai Bundle Lean AnalyticsChoose and audit startup metrics using the Lean Analytics framework: separate actionable metrics from vanity metrics, identify the One Metric That Matters for your business model and stage, set targets, and plan instrumentation.
Audited 1.6k -
alphagbm Skill Alphagbm CompareCompares 2-5 stocks or options across GBM Five Pillars scores, options metrics, technicals, and valuations, highlighting winners per category and providing an overall recommendation.
Audited 1.2k -
alphagbm Skill Alphagbm Iv RankCalculates IV Rank and IV Percentile for any ticker to determine whether implied volatility is high or low relative to its 252-day history, and provides trading signals based on IV zones.
1.2k -
alphagbm Skill Alphagbm Vol SmileAnalyzes the volatility smile and skew for a single options expiration, providing implied volatility curves, skew metrics, and shape classification to reveal market pricing of tail risk and directional fear.
1.2k