Incident Response
-
alirezarezvani Bundle Ciso AdvisorQuantify security risks in dollars, build compliance roadmaps (SOC 2, ISO 27001, HIPAA, GDPR), and justify security budgets for growth-stage companies.
Audited 20.4k -
alirezarezvani Bundle Senior SecopsRun security audits, vulnerability scans, compliance checks, and incident response workflows for application security.
Audited 20.4k -
alirezarezvani Bundle Senior SecurityRoutes security requests to specialist skills and performs STRIDE/DREAD threat modeling with a quick secret scan.
Audited 20.4k -
alirezarezvani Bundle Incident ResponseClassify, triage, and manage declared security incidents from initial triage through forensic evidence collection and escalation routing.
Audited 20.4k -
google Skill Detection Engineering Coverage EvaluationAutomates detection engineering workflows in Google SecOps by extracting threat intelligence, generating detection opportunities, simulating attacker behavior with synthetic events, evaluating rule coverage, and creating new YARA-L 2.0 rules to close gaps.
14.4k -
microsoft Bundle Azure DiagnosticsDebug and troubleshoot Azure production issues using AppLens, Azure Monitor, resource health, and systematic diagnosis flows for services like App Service, Functions, AKS, Container Apps, and Messaging.
Audited 2.7k -
nvidia Bundle Vss Manage AlertsOperate the VSS alert pipeline for real-time monitoring, Alert-Bridge subscriptions, Slack notifications, incident queries, and camera onboarding.
Audited 2.2k -
antigravity Bundle 007Performs security audits, hardening, threat modeling (STRIDE/PASTA), red/blue team exercises, OWASP checks, code review, incident response, and infrastructure security for any project.
42.4k -
oracle Bundle Oke TroubleshooterDiagnose and root-cause issues with OCI Kubernetes Engine clusters and workloads through evidence-driven investigation.
736 -
adobe Bundle Incident ResponseInvestigate and triage runtime incidents involving the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration in AEM 6.5 LTS environments using MCP tools.
Audited 142 -
github Bundle Data Breach Blast RadiusQuantifies the business and regulatory impact of a potential data breach by inventorying sensitive data, tracing data flows, scoring exposure vectors, and estimating regulatory fines using law-sourced figures.
36.2k -
bankrbot Bundle Aeon On Chain MonitorMonitors EVM blockchain addresses and contracts for large transfers, new approvals, contract upgrades, unusual gas spends, MEV interactions, and first-time interactions with new contracts.
1.2k -
mukul975 Bundle Containing Active BreachExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach, using network segmentation, endpoint isolation, credential revocation, and access control modifications.
24.6k -
mukul975 Bundle Automating Ioc EnrichmentAutomates enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs.
24.6k -
mukul975 Bundle Detecting Wmi PersistenceDetect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
Audited 24.6k -
mukul975 Bundle Analyzing Cyber Kill ChainMaps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention.
Audited 24.6k -
mukul975 Bundle Detecting Rootkit ActivityDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.
24.6k -
mukul975 Bundle Hunting Evtx With ChainsawHunt for threats in Windows Event Logs using Chainsaw, a fast Rust-based forensic tool that runs Sigma rules, keyword searches, and artifact analysis offline.
24.6k -
mukul975 Bundle Hunting For Dcsync AttacksDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
Audited 24.6k -
mukul975 Bundle Monitoring Darkweb SourcesMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence.
24.6k -
mukul975 Bundle Triaging Security IncidentTriages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
24.6k -
mukul975 Bundle Triaging Windows With KapeCollect and parse forensic artifacts from Windows systems using KAPE for rapid DFIR triage.
24.6k -
mukul975 Bundle Detecting OAUTH Token TheftDetects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
24.6k -
mukul975 Bundle Executing Red Team ExerciseSimulates real-world adversary operations to test an organization's detection and response capabilities through the full attack lifecycle, from reconnaissance to objective completion.
24.6k -
mukul975 Bundle Processing Stix Taxii FeedsProcesses STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
24.6k -
mukul975 Bundle Correlating Threat CampaignsCorrelates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
Audited 24.6k -
mukul975 Bundle Hunting Saas Sso Token AbuseDetect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
24.6k -
mukul975 Bundle Hunting For Webshell ActivityHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
Audited 24.6k -
mukul975 Bundle Building Soc Escalation MatrixBuild a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
Audited 24.6k -
mukul975 Bundle Hunting For Ntlm Relay AttacksDetect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
Audited 24.6k -
mukul975 Bundle Performing Ransomware ResponseExecutes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
24.6k -
mukul975 Bundle Analyzing Kubernetes Audit LogsParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns.
24.6k -
mukul975 Bundle Analyzing Linux Kernel RootkitsDetect kernel-level rootkits in Linux memory dumps using Volatility3 plugins and live system scanners to identify hooked syscalls, hidden modules, and tampered structures.
24.6k -
mukul975 Bundle Detecting Cryptomining In CloudDetect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
24.6k -
mukul975 Bundle Detecting Golden Ticket ForgeryDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades, abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM.
Audited 24.6k -
mukul975 Bundle Detecting Kerberoasting AttacksDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
Audited 24.6k