Secure Coding
-
mukul975 Bundle Deobfuscating Javascript MalwareDeobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic.
24.6k -
mukul975 Bundle Detecting Malicious NPM PackagesTriage npm packages for install-script malware, exfiltration, and worming behavior using GuardDog, manual inspection, and safe detonation.
24.6k -
mukul975 Bundle Securing Github Actions WorkflowsHardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
Audited 24.6k -
mukul975 Bundle Testing For Broken Access ControlSystematically test web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
24.6k -
mukul975 Bundle Securing Container Registry ImagesScan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
24.6k -
mukul975 Bundle Configuring Ldap Security HardeningHarden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP signing, access control lists, and monitoring for LDAP-based attacks.
Audited 24.6k -
mukul975 Bundle Implementing Bgp Security With RpkiCreate Route Origin Authorizations (ROAs) at RIRs, deploy RPKI validator software, and configure Route Origin Validation (ROV) on Cisco and Juniper routers to prevent BGP route hijacking.
24.6k -
mukul975 Bundle Securing Agentic AI Tool InvocationApply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
24.6k -
mukul975 Bundle Securing AWS Lambda Execution RolesAudit and harden AWS Lambda execution roles by implementing least-privilege IAM policies, permission boundaries, and SCP enforcement.
24.6k -
mukul975 Bundle Testing Oauth2 Implementation FlawsTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass.
24.6k -
mukul975 Bundle Deploying Software Defined PerimeterDeploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
Audited 24.6k -
mukul975 Bundle Implementing Rsa Key Pair ManagementGenerate, store, rotate, and manage RSA key pairs following NIST SP 800-57 guidelines, including key serialization, passphrase protection, and key strength validation.
Audited 24.6k -
mukul975 Bundle Performing Container Image HardeningHarden container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations.
24.6k -
mukul975 Bundle Configuring Oauth2 Authorization FlowConfigure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
Audited 24.6k -
mukul975 Bundle Hardening Docker Daemon ConfigurationHardens the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
24.6k -
mukul975 Bundle Implementing Iec 62443 Security ZonesDesign and implement security zones and conduits for industrial automation and control systems per IEC 62443-3-2, including zone partitioning, firewall configuration, and validation through traffic analysis and penetration testing.
24.6k -
mukul975 Bundle Implementing API Key Security ControlsGenerates, stores, validates, rotates, and revokes API keys with secure hashing, scoping, rate limiting, and leak monitoring.
24.6k -
mukul975 Bundle Migrating To Post Quantum CryptographyInventory cryptographic assets, deploy hybrid X25519 and ML-KEM key exchange, and prioritize migration of harvest-now-decrypt-later data.
24.6k -
mukul975 Bundle Building Detection Rule With Splunk SplBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
Audited 24.6k -
mukul975 Bundle Detecting Serverless Function InjectionDetects and prevents code injection attacks targeting serverless functions through static analysis, event source poisoning detection, and IAM policy auditing.
24.6k -
mukul975 Bundle Detecting Supply Chain Attacks In CI CDScans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.
24.6k -
mukul975 Bundle Implementing Code Signing For ArtifactsSign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
24.6k -
mukul975 Bundle Reverse Engineering Malware With GhidraReverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.
24.6k -
mukul975 Bundle Securing Container Registry With HarborConfigure and manage Harbor container registry with security features including vulnerability scanning, image signing, RBAC, content trust, and audit logging.
24.6k -
mukul975 Bundle Analyzing Supply Chain Malware ArtifactsInvestigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
24.6k -
mukul975 Bundle Auditing Foundry Smart Contract SecurityRuns a pre-deployment security audit of Solidity smart contracts in a Foundry project, combining static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing to catch reentrancy, access-control, and arithmetic bugs before deploying to an EVM chain.
24.6k -
mukul975 Bundle Implementing LLM Guardrails For SecurityBuilds input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs using NeMo Guardrails, Presidio, and Guardrails AI.
24.6k -
mukul975 Bundle Implementing Scim Provisioning With OktaBuild a SCIM 2.0-compliant API server and integrate it with Okta for automated user provisioning, deprovisioning, profile updates, and group management.
24.6k -
mukul975 Bundle Implementing Anti Ransomware Group PolicyHardens Windows Active Directory environments against ransomware by configuring Group Policy Objects with AppLocker rules, Controlled Folder Access, Attack Surface Reduction rules, and lateral movement restrictions.
24.6k -
mukul975 Bundle Implementing JWT Signing And VerificationImplement secure JWT signing and verification with HMAC-SHA256, RSA-PSS, and EdDSA, including token expiration, claims validation, and defense against common JWT attacks.
Audited 24.6k -
mukul975 Bundle Implementing Mtls For Zero Trust ServicesGenerates CA and service certificates, then configures mutual TLS authentication between microservices using Python's cryptography and ssl modules.
24.6k -
mukul975 Bundle Analyzing Ransomware Encryption MechanismsAnalyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts.
24.6k -
mukul975 Bundle Hardening Docker Containers For ProductionApply CIS Docker Benchmark v1.8.0 security best practices to harden Docker containers for production, covering daemon configuration, image building, runtime controls, and auditing.
24.6k -
mukul975 Bundle Implementing API Gateway Security ControlsConfigures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) as a centralized security enforcement point with authentication, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection.
24.6k -
mukul975 Bundle Implementing Rbac Hardening For KubernetesHarden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
24.6k -
mukul975 Bundle Implementing Semgrep For Custom Sast RulesWrite custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.
24.6k