Secure Coding
-
mukul975 Bundle Implementing Sigstore For Software SigningSigns and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls.
24.6k -
mukul975 Bundle Configuring Network Segmentation With VlansDesigns and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
24.6k -
mukul975 Bundle Deobfuscating Powershell Obfuscated MalwareSystematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
24.6k -
mukul975 Bundle Implementing API Schema Validation SecurityEnforce API input/output contracts using OpenAPI specifications and JSON Schema to prevent injection, mass assignment, and data leakage attacks.
Audited 24.6k -
mukul975 Bundle Performing Dmarc Policy Enforcement RolloutExecute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
Audited 24.6k -
mukul975 Bundle Securing Historian Server In Ot EnvironmentHardens and secures process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments, covering network placement, access control, data replication through DMZ, SQL injection prevention, and data integrity protection.
Audited 24.6k -
mukul975 Bundle Implementing Aes Encryption For Data At RESTImplement AES-256-GCM encryption for files and data at rest, including key derivation, IV management, and authenticated encryption.
Audited 24.6k -
mukul975 Bundle Implementing Digital Signatures With Ed25519Implement Ed25519 digital signatures for document signing, code signing, and API authentication using Python.
Audited 24.6k -
mukul975 Bundle Implementing Google Workspace Admin SecurityHardens Google Workspace environments by configuring super admin accounts, phishing-resistant MFA, email authentication (SPF/DKIM/DMARC), DLP policies, OAuth app controls, and external sharing restrictions.
24.6k -
mukul975 Bundle Implementing Memory Protection With Dep AslrConfigures memory protection mechanisms including DEP, ASLR, CFG, and Windows Exploit Protection to harden endpoints against buffer overflows, ROP chains, and code injection.
24.6k -
mukul975 Bundle Implementing Network Policies For KubernetesCreate and apply Kubernetes NetworkPolicies to enforce pod-level network segmentation, restrict traffic between pods and namespaces, and block access to cloud metadata endpoints.
24.6k -
mukul975 Bundle Performing API Security Testing With PostmanBuilds repeatable API security test suites in Postman covering OWASP API Security Top 10 vulnerabilities, with automated authentication, multi-role testing, and CI/CD integration via Newman.
24.6k -
mukul975 Bundle Configuring Tls 1 3 For Secure CommunicationsConfigure TLS 1.3 on nginx, Apache, and Python applications, validate configurations with openssl and testssl.sh, and disable legacy TLS versions.
24.6k -
mukul975 Bundle Implementing API Rate Limiting And ThrottlingProtect APIs from abuse and resource exhaustion by implementing rate limiting with token bucket, sliding window, and fixed window algorithms using Redis-backed counters, API gateway plugins, or application middleware.
Audited 24.6k -
mukul975 Bundle Implementing Browser Isolation For Zero TrustDeploys remote browser isolation (RBI) as a core component of a Zero Trust architecture, implementing isolation policies with URL categorization, risk-based routing, content disarming and reconstruction (CDR), and data loss prevention controls.
Audited 24.6k -
mukul975 Bundle Implementing Envelope Encryption With AWS KmsEncrypt large data volumes locally using envelope encryption with AWS KMS, generating data keys and managing encrypted keys alongside ciphertext.
Audited 24.6k -
mukul975 Bundle Integrating Sast Into Github Actions PipelineIntegrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
24.6k -
mukul975 Bundle Performing Cryptographic Audit Of ApplicationSystematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations.
Audited 24.6k -
mukul975 Bundle Reverse Engineering Dotnet Malware With DnspyAnalyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.
24.6k -
mukul975 Bundle Verifying Build Provenance With Slsa SigstoreVerify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
Audited 24.6k -
mukul975 Bundle Auditing Terraform Infrastructure For SecurityAudit Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
24.6k -
mukul975 Bundle Configuring Certificate Authority With OpensslBuild a two-tier PKI hierarchy (Root CA + Intermediate CA) using OpenSSL and Python, including certificate issuance, CRL distribution, OCSP responder configuration, and certificate policy management.
24.6k -
mukul975 Bundle Configuring Windows Defender Advanced SettingsHardens Windows endpoints by configuring Microsoft Defender for Endpoint advanced settings, including attack surface reduction rules, controlled folder access, network protection, and exploit protection.
24.6k -
mukul975 Bundle Implementing API Threat Protection With ApigeeConfigure Google Apigee security policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security to defend against OWASP API Top 10 threats.
24.6k -
mukul975 Bundle Implementing Kubernetes Pod Security StandardsEnforce Pod Security Standards (Privileged, Baseline, Restricted) in Kubernetes 1.25+ using the Pod Security Admission controller with namespace labels and compliant pod specs.
24.6k -
mukul975 Bundle Implementing Pod Security Admission ControllerEnforce Kubernetes Pod Security Standards at the namespace level using the built-in admission controller, with support for baseline and restricted profiles.
Audited 24.6k -
mukul975 Bundle Performing Yara Rule Development For DetectionDevelop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
24.6k -
mukul975 Bundle Implementing Supply Chain Security With In TotoVerify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations.
24.6k -
mukul975 Bundle Performing Hardware Security Module IntegrationIntegrate Hardware Security Modules (HSMs) using the PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.
24.6k -
mukul975 Bundle Implementing End To End Encryption For MessagingImplements a simplified version of the Signal Protocol's Double Ratchet algorithm using X25519, HKDF, and AES-256-GCM for end-to-end encrypted messaging.
Audited 24.6k -
mukul975 Bundle Analyzing Ethereum Smart Contract VulnerabilitiesPerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
24.6k -
mukul975 Bundle Implementing Hardware Security Key AuthenticationImplements FIDO2/WebAuthn hardware security key authentication with registration, authentication, YubiKey enrollment, and passkey migration using the python-fido2 library.
Audited 24.6k -
mukul975 Bundle Reverse Engineering Ransomware Encryption RoutineIdentify cryptographic algorithms, key generation flaws, and potential decryption opportunities in ransomware samples using static and dynamic analysis.
24.6k -
mukul975 Bundle Implementing Opa Gatekeeper For Policy EnforcementEnforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
24.6k -
mukul975 Bundle Implementing Policy As Code With Open Policy AgentEnforce organizational security policies across Kubernetes clusters and CI/CD pipelines using Open Policy Agent (OPA) and Gatekeeper, including writing Rego policies, deploying admission controllers, and testing policies locally.
24.6k -
mukul975 Bundle Implementing Passwordless Auth With Microsoft EntraDeploys passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks.
24.6k