Anthropic Cybersecurity Skills
by @mukul975 · plugin · 817 skills
Anthropic Cybersecurity Skills from mukul975/Anthropic-Cybersecurity-Skills.
Install the whole plugin (CLI)
npx skillmds add mukul975/operating-havoc-c2
npx skillmds add mukul975/operating-sliver-c2
npx skillmds add mukul975/containing-active-breach
npx skillmds add mukul975/exploiting-aws-with-pacu
npx skillmds add mukul975/automating-ioc-enrichment
npx skillmds add mukul975/detecting-wmi-persistence
npx skillmds add mukul975/analyzing-cyber-kill-chain
npx skillmds add mukul975/detecting-rootkit-activity
npx skillmds add mukul975/hunting-for-dcsync-attacks
npx skillmds add mukul975/hunting-evtx-with-chainsaw
npx skillmds add mukul975/monitoring-darkweb-sources
npx skillmds add mukul975/testing-jwt-token-security
npx skillmds add mukul975/triaging-security-incident
npx skillmds add mukul975/triaging-windows-with-kape
npx skillmds add mukul975/analyzing-linux-elf-malware
npx skillmds add mukul975/detecting-oauth-token-theft
npx skillmds add mukul975/escaping-containers-to-host
npx skillmds add mukul975/executing-red-team-exercise
npx skillmds add mukul975/processing-stix-taxii-feeds
npx skillmds add mukul975/red-teaming-llms-with-garak
npx skillmds add mukul975/relaying-ntlm-for-adcs-esc8
npx skillmds add mukul975/auditing-gcp-iam-permissions
npx skillmds add mukul975/correlating-threat-campaigns
npx skillmds add mukul975/detecting-secure-boot-bypass
npx skillmds add mukul975/exploiting-adcs-with-certipy
npx skillmds add mukul975/hunting-saas-sso-token-abuse
npx skillmds add mukul975/implementing-cloud-waf-rules
npx skillmds add mukul975/securing-aws-iam-permissions
npx skillmds add mukul975/securing-kubernetes-on-cloud
npx skillmds add mukul975/hunting-for-webshell-activity
npx skillmds add mukul975/implementing-aws-security-hub
npx skillmds add mukul975/modeling-threats-with-opencti
npx skillmds add mukul975/moving-laterally-with-netexec
npx skillmds add mukul975/profiling-threat-actor-groups
npx skillmds add mukul975/securing-serverless-functions
npx skillmds add mukul975/building-soc-escalation-matrix
npx skillmds add mukul975/defending-llms-with-guardrails
npx skillmds add mukul975/testing-cors-misconfiguration
npx skillmds add mukul975/detecting-dependency-confusion
npx skillmds add mukul975/detecting-shadow-api-endpoints
npx skillmds add mukul975/generating-and-analyzing-sboms
npx skillmds add mukul975/hunting-for-ntlm-relay-attacks
npx skillmds add mukul975/performing-ransomware-response
npx skillmds add mukul975/performing-vlan-hopping-attack
npx skillmds add mukul975/analyzing-kubernetes-audit-logs
npx skillmds add mukul975/analyzing-linux-kernel-rootkits
npx skillmds add mukul975/configuring-hsm-for-key-storage
npx skillmds add mukul975/testing-websocket-api-security
npx skillmds add mukul975/detecting-cryptomining-in-cloud
npx skillmds add mukul975/detecting-golden-ticket-forgery
npx skillmds add mukul975/detecting-kerberoasting-attacks
npx skillmds add mukul975/conducting-api-security-testing
npx skillmds add mukul975/detecting-pass-the-hash-attacks
npx skillmds add mukul975/detecting-service-account-abuse
npx skillmds add mukul975/detecting-shadow-it-cloud-usage
npx skillmds add mukul975/detecting-stuxnet-style-attacks
npx skillmds add mukul975/enumerating-cloud-with-cloudfox
npx skillmds add mukul975/exploiting-idor-vulnerabilities
npx skillmds add mukul975/exploiting-ipv6-vulnerabilities
npx skillmds add mukul975/fleet-hunting-with-velociraptor
npx skillmds add mukul975/implementing-saml-sso-with-okta
npx skillmds add mukul975/managing-intelligence-lifecycle
npx skillmds add mukul975/mapping-mitre-attack-techniques
npx skillmds add mukul975/performing-kerberoasting-attack
npx skillmds add mukul975/performing-purple-team-exercise
npx skillmds add mukul975/performing-ssl-stripping-attack
npx skillmds add mukul975/securing-helm-chart-deployments
npx skillmds add mukul975/testing-for-xss-vulnerabilities
npx skillmds add mukul975/analyzing-linux-system-artifacts
npx skillmds add mukul975/auditing-kubernetes-cluster-rbac
npx skillmds add mukul975/detecting-azure-lateral-movement
npx skillmds add mukul975/detecting-malicious-npm-packages
npx skillmds add mukul975/detecting-typosquatting-packages
npx skillmds add mukul975/exploiting-broken-link-hijacking
npx skillmds add mukul975/analyzing-pdf-malware-with-pdfid
npx skillmds add mukul975/hunting-for-shadow-copy-deletion
npx skillmds add mukul975/implementing-zero-trust-in-cloud
npx skillmds add mukul975/deobfuscating-javascript-malware
npx skillmds add mukul975/managing-third-party-vendor-risk
npx skillmds add mukul975/performing-osint-with-spiderfoot
npx skillmds add mukul975/performing-service-account-audit
npx skillmds add mukul975/performing-soc-tabletop-exercise
npx skillmds add mukul975/reverse-engineering-rust-malware
npx skillmds add mukul975/achieving-cmmc-level-2-compliance
npx skillmds add mukul975/analyzing-api-gateway-access-logs
npx skillmds add mukul975/analyzing-disk-image-with-autopsy
npx skillmds add mukul975/analyzing-heap-spray-exploitation
npx skillmds add mukul975/attacking-entra-id-with-roadtools
npx skillmds add mukul975/building-cloud-siem-with-sentinel
npx skillmds add mukul975/conducting-pass-the-ticket-attack
npx skillmds add mukul975/deploying-ransomware-canary-files
npx skillmds add mukul975/detecting-api-enumeration-attacks
npx skillmds add mukul975/detecting-dll-sideloading-attacks
npx skillmds add mukul975/detecting-dnp3-protocol-anomalies
npx skillmds add mukul975/detecting-pass-the-ticket-attacks
npx skillmds add mukul975/detecting-rdp-brute-force-attacks
npx skillmds add mukul975/exploiting-http-request-smuggling
npx skillmds add mukul975/exploiting-oauth-misconfiguration
npx skillmds add mukul975/hunting-for-cobalt-strike-beacons
npx skillmds add mukul975/hunting-for-dns-based-persistence
npx skillmds add mukul975/implementing-siem-use-case-tuning
npx skillmds add mukul975/detecting-mobile-malware-behavior
npx skillmds add mukul975/managing-cloud-identity-with-okta
npx skillmds add mukul975/performing-malware-ioc-extraction
npx skillmds add mukul975/performing-red-team-with-covenant
npx skillmds add mukul975/performing-security-headers-audit
npx skillmds add mukul975/recovering-from-ransomware-attack
npx skillmds add mukul975/scanning-docker-images-with-trivy
npx skillmds add mukul975/hunting-for-dcom-lateral-movement
npx skillmds add mukul975/securing-api-gateway-with-aws-waf
npx skillmds add mukul975/testing-for-broken-access-control
npx skillmds add mukul975/testing-for-host-header-injection
npx skillmds add mukul975/testing-for-system-prompt-leakage
npx skillmds add mukul975/performing-csrf-attack-simulation
npx skillmds add mukul975/testing-mobile-api-authentication
npx skillmds add mukul975/analyzing-indicators-of-compromise
npx skillmds add mukul975/analyzing-uefi-bootkit-persistence
npx skillmds add mukul975/auditing-aws-s3-bucket-permissions
npx skillmds add mukul975/auditing-cloud-with-cis-benchmarks
npx skillmds add mukul975/conducting-cloud-incident-response
npx skillmds add mukul975/configuring-pfsense-firewall-rules
npx skillmds add mukul975/securing-github-actions-workflows
npx skillmds add mukul975/detecting-attacks-on-scada-systems
npx skillmds add mukul975/detecting-aws-cloudtrail-anomalies
npx skillmds add mukul975/detecting-data-and-model-poisoning
npx skillmds add mukul975/detecting-email-account-compromise
npx skillmds add mukul975/detecting-insider-threat-behaviors
npx skillmds add mukul975/detecting-insider-threat-with-ueba
npx skillmds add mukul975/detecting-model-extraction-attacks
npx skillmds add mukul975/implementing-endpoint-dlp-controls
npx skillmds add mukul975/operationalizing-misp-threat-feeds
npx skillmds add mukul975/performing-blind-ssrf-exploitation
npx skillmds add mukul975/performing-dns-tunneling-detection
npx skillmds add mukul975/performing-iot-security-assessment
npx skillmds add mukul975/performing-packet-injection-attack
npx skillmds add mukul975/performing-steganography-detection
npx skillmds add mukul975/performing-user-behavior-analytics
npx skillmds add mukul975/scanning-iac-and-images-with-trivy
npx skillmds add mukul975/securing-container-registry-images
npx skillmds add mukul975/testing-for-email-header-injection
npx skillmds add mukul975/triaging-security-alerts-in-splunk
npx skillmds add mukul975/abusing-dpapi-for-credential-access
npx skillmds add mukul975/analyzing-dns-logs-for-exfiltration
npx skillmds add mukul975/analyzing-malicious-pdf-with-peepdf
npx skillmds add mukul975/analyzing-security-logs-with-splunk
npx skillmds add mukul975/analyzing-threat-intelligence-feeds
npx skillmds add mukul975/analyzing-windows-amcache-artifacts
npx skillmds add mukul975/auditing-entra-id-with-aadinternals
npx skillmds add mukul975/auditing-uefi-firmware-with-chipsec
npx skillmds add mukul975/building-detection-rules-with-sigma
npx skillmds add mukul975/building-incident-response-playbook
npx skillmds add mukul975/building-super-timelines-with-plaso
npx skillmds add mukul975/collecting-indicators-of-compromise
npx skillmds add mukul975/collecting-open-source-intelligence
npx skillmds add mukul975/conducting-network-penetration-test
npx skillmds add mukul975/configuring-ldap-security-hardening
npx skillmds add mukul975/detecting-business-email-compromise
npx skillmds add mukul975/detecting-container-escape-attempts
npx skillmds add mukul975/detecting-indirect-prompt-injection
npx skillmds add mukul975/detecting-modbus-protocol-anomalies
npx skillmds add mukul975/exploiting-insecure-deserialization
npx skillmds add mukul975/hunting-advanced-persistent-threats
npx skillmds add mukul975/hunting-credential-stuffing-attacks
npx skillmds add mukul975/hunting-for-supply-chain-compromise
npx skillmds add mukul975/implementing-bgp-security-with-rpki
npx skillmds add mukul975/implementing-diamond-model-analysis
npx skillmds add mukul975/implementing-gcp-vpc-firewall-rules
npx skillmds add mukul975/implementing-network-access-control
npx skillmds add mukul975/performing-api-fuzzing-with-restler
npx skillmds add mukul975/performing-api-rate-limiting-bypass
npx skillmds add mukul975/performing-fuzzing-with-aflplusplus
npx skillmds add mukul975/exploiting-deeplink-vulnerabilities
npx skillmds add mukul975/performing-malware-triage-with-yara
npx skillmds add mukul975/scanning-infrastructure-with-nessus
npx skillmds add mukul975/scanning-network-with-nmap-advanced
npx skillmds add mukul975/securing-agentic-ai-tool-invocation
npx skillmds add mukul975/hunting-for-dns-tunneling-with-zeek
npx skillmds add mukul975/securing-aws-lambda-execution-roles
npx skillmds add mukul975/testing-oauth2-implementation-flaws
npx skillmds add mukul975/analyzing-active-directory-acl-abuse
npx skillmds add mukul975/analyzing-docker-container-forensics
npx skillmds add mukul975/analyzing-golang-malware-with-ghidra
npx skillmds add mukul975/analyzing-malicious-url-with-urlscan
npx skillmds add mukul975/analyzing-network-packets-with-scapy
npx skillmds add mukul975/analyzing-network-traffic-of-malware
npx skillmds add mukul975/performing-clickjacking-attack-test
npx skillmds add mukul975/analyzing-ransomware-payment-wallets
npx skillmds add mukul975/analyzing-threat-landscape-with-misp
npx skillmds add mukul975/analyzing-windows-shellbag-artifacts
npx skillmds add mukul975/building-incident-response-dashboard
npx skillmds add mukul975/building-soc-playbook-for-ransomware
npx skillmds add mukul975/conducting-cloud-penetration-testing
npx skillmds add mukul975/conducting-malware-incident-response
npx skillmds add mukul975/testing-for-sensitive-data-exposure
npx skillmds add mukul975/deploying-edr-agent-with-crowdstrike
npx skillmds add mukul975/deploying-software-defined-perimeter
npx skillmds add mukul975/detecting-container-drift-at-runtime
npx skillmds add mukul975/detecting-sql-injection-via-waf-logs
npx skillmds add mukul975/exploiting-sql-injection-with-sqlmap
npx skillmds add mukul975/extracting-browser-history-artifacts
npx skillmds add mukul975/extracting-iocs-from-malware-samples
npx skillmds add mukul975/hunting-for-lateral-movement-via-wmi
npx skillmds add mukul975/hunting-for-spearphishing-indicators
npx skillmds add mukul975/implementing-alert-fatigue-reduction
npx skillmds add mukul975/implementing-pam-for-database-access
npx skillmds add mukul975/implementing-rsa-key-pair-management
npx skillmds add mukul975/orchestrating-llm-attacks-with-pyrit
npx skillmds add mukul975/performing-container-image-hardening
npx skillmds add mukul975/performing-firmware-malware-analysis
npx skillmds add mukul975/performing-ioc-enrichment-automation
npx skillmds add mukul975/performing-jwt-none-algorithm-attack
npx skillmds add mukul975/performing-privacy-impact-assessment
npx skillmds add mukul975/detecting-lateral-movement-with-zeek
npx skillmds add mukul975/performing-sqlite-database-forensics
npx skillmds add mukul975/scanning-container-images-with-grype
npx skillmds add mukul975/tracking-threat-actor-infrastructure
npx skillmds add mukul975/exploiting-websocket-vulnerabilities
npx skillmds add mukul975/analyzing-bootkit-and-rootkit-samples
npx skillmds add mukul975/analyzing-powershell-empire-artifacts
npx skillmds add mukul975/building-c2-redirector-infrastructure
npx skillmds add mukul975/building-soc-metrics-and-kpi-tracking
npx skillmds add mukul975/building-threat-intelligence-platform
npx skillmds add mukul975/conducting-phishing-incident-response
npx skillmds add mukul975/configuring-oauth2-authorization-flow
npx skillmds add mukul975/correlating-security-events-in-qradar
npx skillmds add mukul975/detecting-fileless-malware-techniques
npx skillmds add mukul975/detecting-living-off-the-land-attacks
npx skillmds add mukul975/detecting-mimikatz-execution-patterns
npx skillmds add mukul975/detecting-misconfigured-azure-storage
npx skillmds add mukul975/detecting-port-scanning-with-fail2ban
npx skillmds add mukul975/detecting-process-hollowing-technique
npx skillmds add mukul975/exploiting-nopac-cve-2021-42278-42287
npx skillmds add mukul975/hardening-docker-daemon-configuration
npx skillmds add mukul975/implementing-azure-defender-for-cloud
npx skillmds add mukul975/implementing-cloud-trail-log-analysis
npx skillmds add mukul975/implementing-ebpf-security-monitoring
npx skillmds add mukul975/implementing-gcp-binary-authorization
npx skillmds add mukul975/implementing-ics-firewall-with-tofino
npx skillmds add mukul975/implementing-iec-62443-security-zones
npx skillmds add mukul975/investigating-phishing-email-incident
npx skillmds add mukul975/performing-container-escape-detection
npx skillmds add mukul975/performing-file-carving-with-foremost
npx skillmds add mukul975/performing-hash-cracking-with-hashcat
npx skillmds add mukul975/detecting-lateral-movement-in-network
npx skillmds add mukul975/performing-lateral-movement-detection
npx skillmds add mukul975/performing-purple-team-atomic-testing
npx skillmds add mukul975/performing-second-order-sql-injection
npx skillmds add mukul975/performing-web-cache-deception-attack
npx skillmds add mukul975/detecting-network-anomalies-with-zeek
npx skillmds add mukul975/performing-web-cache-poisoning-attack
npx skillmds add mukul975/testing-api-authentication-weaknesses
npx skillmds add mukul975/abusing-shadow-credentials-for-privesc
npx skillmds add mukul975/analyzing-android-malware-with-apktool
npx skillmds add mukul975/analyzing-memory-dumps-with-volatility
npx skillmds add mukul975/analyzing-windows-event-logs-in-splunk
npx skillmds add mukul975/analyzing-windows-prefetch-with-python
npx skillmds add mukul975/deploying-active-directory-honeytokens
npx skillmds add mukul975/deploying-honeytokens-and-canarytokens
npx skillmds add mukul975/deploying-tailscale-for-zero-trust-vpn
npx skillmds add mukul975/detecting-attacks-on-historian-servers
npx skillmds add mukul975/detecting-aws-iam-privilege-escalation
npx skillmds add mukul975/detecting-beaconing-patterns-with-zeek
npx skillmds add mukul975/detecting-bluetooth-low-energy-attacks
npx skillmds add mukul975/performing-graphql-depth-limit-attack
npx skillmds add mukul975/detecting-cloud-threats-with-guardduty
npx skillmds add mukul975/detecting-lateral-movement-with-splunk
npx skillmds add mukul975/detecting-process-injection-techniques
npx skillmds add mukul975/executing-phishing-simulation-campaign
npx skillmds add mukul975/executing-red-team-engagement-planning
npx skillmds add mukul975/exploiting-kerberoasting-with-impacket
npx skillmds add mukul975/exploiting-server-side-request-forgery
npx skillmds add mukul975/extracting-config-from-agent-tesla-rat
npx skillmds add mukul975/generating-threat-intelligence-reports
npx skillmds add mukul975/hunting-for-domain-fronting-c2-traffic
npx skillmds add mukul975/hunting-for-scheduled-task-persistence
npx skillmds add mukul975/hunting-for-startup-folder-persistence
npx skillmds add mukul975/hunting-for-suspicious-scheduled-tasks
npx skillmds add mukul975/conducting-mobile-app-penetration-test
npx skillmds add mukul975/hunting-for-t1098-account-manipulation
npx skillmds add mukul975/implementing-api-key-security-controls
npx skillmds add mukul975/implementing-attack-surface-management
npx skillmds add mukul975/implementing-cloud-workload-protection
npx skillmds add mukul975/implementing-patch-management-workflow
npx skillmds add mukul975/implementing-secrets-scanning-in-ci-cd
npx skillmds add mukul975/implementing-usb-device-control-policy
npx skillmds add mukul975/implementing-zero-trust-network-access
npx skillmds add mukul975/migrating-to-post-quantum-cryptography
npx skillmds add mukul975/detecting-command-and-control-over-dns
npx skillmds add mukul975/performing-ai-driven-osint-correlation
npx skillmds add mukul975/performing-api-inventory-and-discovery
npx skillmds add mukul975/performing-directory-traversal-testing
npx skillmds add mukul975/performing-graphql-security-assessment
npx skillmds add mukul975/performing-ios-app-security-assessment
npx skillmds add mukul975/performing-ssl-tls-security-assessment
npx skillmds add mukul975/recovering-deleted-files-with-photorec
npx skillmds add mukul975/remediating-s3-bucket-misconfiguration
npx skillmds add mukul975/scanning-containers-with-trivy-in-cicd
npx skillmds add mukul975/securing-azure-with-microsoft-defender
npx skillmds add mukul975/testing-api-security-with-owasp-top-10
npx skillmds add mukul975/testing-ransomware-recovery-procedures
npx skillmds add mukul975/acquiring-disk-image-with-dd-and-dcfldd
npx skillmds add mukul975/analyzing-campaign-attribution-evidence
npx skillmds add mukul975/analyzing-cloud-storage-access-patterns
npx skillmds add mukul975/analyzing-mft-for-deleted-file-recovery
npx skillmds add mukul975/analyzing-network-traffic-for-incidents
npx skillmds add mukul975/analyzing-ransomware-network-indicators
npx skillmds add mukul975/analyzing-usb-device-connection-history
npx skillmds add mukul975/analyzing-web-server-logs-for-intrusion
npx skillmds add mukul975/auditing-mcp-servers-for-tool-poisoning
npx skillmds add mukul975/benchmarking-kubernetes-with-kube-bench
npx skillmds add mukul975/building-detection-rule-with-splunk-spl
npx skillmds add mukul975/building-patch-tuesday-response-process
npx skillmds add mukul975/detecting-azure-service-principal-abuse
npx skillmds add mukul975/detecting-compromised-cloud-credentials
npx skillmds add mukul975/detecting-credential-dumping-techniques
npx skillmds add mukul975/detecting-email-forwarding-rules-attack
npx skillmds add mukul975/detecting-fileless-attacks-on-endpoints
npx skillmds add mukul975/detecting-privilege-escalation-attempts
npx skillmds add mukul975/reverse-engineering-ios-app-with-frida
npx skillmds add mukul975/detecting-s3-data-exfiltration-attempts
npx skillmds add mukul975/detecting-serverless-function-injection
npx skillmds add mukul975/detecting-supply-chain-attacks-in-ci-cd
npx skillmds add mukul975/exploiting-constrained-delegation-abuse
npx skillmds add mukul975/exploiting-mass-assignment-in-rest-apis
npx skillmds add mukul975/extracting-credentials-from-memory-dump
npx skillmds add mukul975/extracting-memory-artifacts-with-rekall
npx skillmds add mukul975/extracting-windows-event-logs-artifacts
npx skillmds add mukul975/hunting-for-unusual-network-connections
npx skillmds add mukul975/implementing-aws-nitro-enclave-security
npx skillmds add mukul975/implementing-code-signing-for-artifacts
npx skillmds add mukul975/implementing-network-traffic-baselining
npx skillmds add mukul975/implementing-ransomware-backup-strategy
npx skillmds add mukul975/implementing-security-chaos-engineering
npx skillmds add mukul975/implementing-soar-playbook-for-phishing
npx skillmds add mukul975/implementing-zero-trust-with-beyondcorp
npx skillmds add mukul975/investigating-insider-threat-indicators
npx skillmds add mukul975/mapping-attack-paths-with-bloodhound-ce
npx skillmds add mukul975/performing-binary-exploitation-analysis
npx skillmds add mukul975/performing-disk-forensics-investigation
npx skillmds add mukul975/performing-graphql-introspection-attack
npx skillmds add mukul975/performing-insider-threat-investigation
npx skillmds add mukul975/performing-nist-csf-maturity-assessment
npx skillmds add mukul975/performing-privileged-account-discovery
npx skillmds add mukul975/performing-ransomware-tabletop-exercise
npx skillmds add mukul975/performing-soc2-type2-audit-preparation
npx skillmds add mukul975/reverse-engineering-malware-with-ghidra
npx skillmds add mukul975/securing-container-registry-with-harbor
npx skillmds add mukul975/analyzing-apt-group-with-mitre-navigator
npx skillmds add mukul975/analyzing-linux-audit-logs-for-intrusion
npx skillmds add mukul975/analyzing-network-flow-data-with-netflow
npx skillmds add mukul975/analyzing-network-traffic-with-wireshark
npx skillmds add mukul975/analyzing-supply-chain-malware-artifacts
npx skillmds add mukul975/analyzing-windows-registry-for-artifacts
npx skillmds add mukul975/auditing-foundry-smart-contract-security
npx skillmds add mukul975/building-threat-actor-profile-from-osint
npx skillmds add mukul975/building-vulnerability-scanning-workflow
npx skillmds add mukul975/collecting-threat-intelligence-with-misp
npx skillmds add mukul975/conducting-post-incident-lessons-learned
npx skillmds add mukul975/configuring-aws-verified-access-for-ztna
npx skillmds add mukul975/detecting-ransomware-encryption-behavior
npx skillmds add mukul975/evaluating-threat-intelligence-platforms
npx skillmds add mukul975/exploiting-api-injection-vulnerabilities
npx skillmds add mukul975/exploiting-bgp-hijacking-vulnerabilities
npx skillmds add mukul975/exploiting-type-juggling-vulnerabilities
npx skillmds add mukul975/hunting-bootkits-in-efi-system-partition
npx skillmds add mukul975/hunting-for-data-exfiltration-indicators
npx skillmds add mukul975/hunting-for-living-off-the-land-binaries
npx skillmds add mukul975/hunting-for-process-injection-techniques
npx skillmds add mukul975/hunting-for-registry-run-key-persistence
npx skillmds add mukul975/implementing-aws-security-hub-compliance
npx skillmds add mukul975/implementing-devsecops-security-scanning
npx skillmds add mukul975/implementing-llm-guardrails-for-security
npx skillmds add mukul975/implementing-log-forwarding-with-fluentd
npx skillmds add mukul975/implementing-network-segmentation-for-ot
npx skillmds add mukul975/implementing-pci-dss-compliance-controls
npx skillmds add mukul975/implementing-scim-provisioning-with-okta
npx skillmds add mukul975/implementing-stix-taxii-feed-integration
npx skillmds add mukul975/implementing-taxii-server-with-opentaxii
npx skillmds add mukul975/implementing-zero-trust-dns-with-nextdns
npx skillmds add mukul975/performing-bluetooth-security-assessment
npx skillmds add mukul975/performing-cloud-forensics-investigation
npx skillmds add mukul975/performing-dynamic-analysis-with-any-run
npx skillmds add mukul975/performing-initial-access-with-evilginx3
npx skillmds add mukul975/performing-lateral-movement-with-wmiexec
npx skillmds add mukul975/performing-log-source-onboarding-in-siem
npx skillmds add mukul975/performing-physical-intrusion-assessment
npx skillmds add mukul975/exploiting-sql-injection-vulnerabilities
npx skillmds add mukul975/performing-privilege-escalation-on-linux
npx skillmds add mukul975/performing-scada-hmi-security-assessment
npx skillmds add mukul975/securing-remote-access-to-ot-environment
npx skillmds add mukul975/validating-backup-integrity-for-recovery
npx skillmds add mukul975/validating-tpm-measured-boot-attestation
npx skillmds add mukul975/analyzing-azure-activity-logs-for-threats
npx skillmds add mukul975/analyzing-ios-app-security-with-objection
npx skillmds add mukul975/analyzing-outlook-pst-for-email-forensics
npx skillmds add mukul975/analyzing-persistence-mechanisms-in-linux
npx skillmds add mukul975/analyzing-powershell-script-block-logging
npx skillmds add mukul975/analyzing-windows-lnk-files-for-artifacts
npx skillmds add mukul975/assessing-vector-and-embedding-weaknesses
npx skillmds add mukul975/attacking-oauth-with-device-code-phishing
npx skillmds add mukul975/building-threat-hunt-hypothesis-framework
npx skillmds add mukul975/conducting-domain-persistence-with-dcsync
npx skillmds add mukul975/conducting-full-scope-red-team-engagement
npx skillmds add mukul975/configuring-active-directory-tiered-model
npx skillmds add mukul975/continuous-llm-red-teaming-with-promptfoo
npx skillmds add mukul975/detecting-exfiltration-over-dns-with-zeek
npx skillmds add mukul975/detecting-living-off-the-land-with-lolbas
npx skillmds add mukul975/detecting-suspicious-powershell-execution
npx skillmds add mukul975/eradicating-malware-from-infected-systems
npx skillmds add mukul975/exploiting-excessive-data-exposure-in-api
npx skillmds add mukul975/exploiting-jwt-algorithm-confusion-attack
npx skillmds add mukul975/exploiting-race-condition-vulnerabilities
npx skillmds add mukul975/hunting-for-command-and-control-beaconing
npx skillmds add mukul975/hunting-for-unusual-service-installations
npx skillmds add mukul975/implementing-anti-ransomware-group-policy
npx skillmds add mukul975/implementing-immutable-backup-with-restic
npx skillmds add mukul975/implementing-jwt-signing-and-verification
npx skillmds add mukul975/implementing-mtls-for-zero-trust-services
npx skillmds add mukul975/implementing-nerc-cip-compliance-controls
npx skillmds add mukul975/implementing-siem-use-cases-for-detection
npx skillmds add mukul975/implementing-soar-automation-with-phantom
npx skillmds add mukul975/investigating-ransomware-attack-artifacts
npx skillmds add mukul975/monitoring-scada-modbus-traffic-anomalies
npx skillmds add mukul975/performing-alert-triage-with-elastic-siem
npx skillmds add mukul975/performing-arp-spoofing-attack-simulation
npx skillmds add mukul975/performing-credential-access-with-lazagne
npx skillmds add mukul975/performing-indicator-lifecycle-management
npx skillmds add mukul975/performing-kubernetes-penetration-testing
npx skillmds add mukul975/performing-ot-network-security-assessment
npx skillmds add mukul975/deploying-osquery-for-endpoint-monitoring
npx skillmds add mukul975/performing-plc-firmware-security-analysis
npx skillmds add mukul975/performing-red-team-phishing-with-gophish
npx skillmds add mukul975/performing-supply-chain-attack-simulation
npx skillmds add mukul975/performing-threat-hunting-with-yara-rules
npx skillmds add mukul975/testing-for-open-redirect-vulnerabilities
npx skillmds add mukul975/testing-for-xml-injection-vulnerabilities
npx skillmds add mukul975/testing-for-xxe-injection-vulnerabilities
npx skillmds add mukul975/testing-prompt-injection-in-rag-pipelines
npx skillmds add mukul975/analyzing-browser-forensics-with-hindsight
npx skillmds add mukul975/analyzing-lnk-file-and-jump-list-artifacts
npx skillmds add mukul975/analyzing-packed-malware-with-upx-unpacker
npx skillmds add mukul975/auditing-tls-certificate-transparency-logs
npx skillmds add mukul975/building-devsecops-pipeline-with-gitlab-ci
npx skillmds add mukul975/building-incident-timeline-with-timesketch
npx skillmds add mukul975/building-role-mining-for-rbac-optimization
npx skillmds add mukul975/building-threat-feed-aggregation-with-misp
npx skillmds add mukul975/conducting-social-engineering-pretext-call
npx skillmds add mukul975/configuring-host-based-intrusion-detection
npx skillmds add mukul975/deploying-cloudflare-access-for-zero-trust
npx skillmds add mukul975/detecting-arp-poisoning-in-network-traffic
npx skillmds add mukul975/detecting-modbus-command-injection-attacks
npx skillmds add mukul975/performing-content-security-policy-bypass
npx skillmds add mukul975/detecting-spearphishing-with-email-gateway
npx skillmds add mukul975/exploiting-insecure-data-storage-in-mobile
npx skillmds add mukul975/exploiting-nosql-injection-vulnerabilities
npx skillmds add mukul975/hardening-docker-containers-for-production
npx skillmds add mukul975/hunting-for-anomalous-powershell-execution
npx skillmds add mukul975/implementing-api-gateway-security-controls
npx skillmds add mukul975/implementing-aws-iam-permission-boundaries
npx skillmds add mukul975/implementing-cloud-dlp-for-data-protection
npx skillmds add mukul975/implementing-delinea-secret-server-for-pam
npx skillmds add mukul975/implementing-dmarc-dkim-spf-email-security
npx skillmds add mukul975/implementing-endpoint-detection-with-wazuh
npx skillmds add mukul975/implementing-gdpr-data-protection-controls
npx skillmds add mukul975/implementing-log-integrity-with-blockchain
npx skillmds add mukul975/implementing-mitre-attack-coverage-mapping
npx skillmds add mukul975/implementing-mobile-application-management
npx skillmds add mukul975/implementing-ot-incident-response-playbook
npx skillmds add mukul975/analyzing-ransomware-encryption-mechanisms
npx skillmds add mukul975/implementing-privileged-access-workstation
npx skillmds add mukul975/implementing-privileged-session-monitoring
npx skillmds add mukul975/implementing-rapid7-insightvm-for-scanning
npx skillmds add mukul975/implementing-rbac-hardening-for-kubernetes
npx skillmds add mukul975/implementing-secret-scanning-with-gitleaks
npx skillmds add mukul975/implementing-secrets-management-with-vault
npx skillmds add mukul975/implementing-semgrep-for-custom-sast-rules
npx skillmds add mukul975/implementing-sigstore-for-software-signing
npx skillmds add mukul975/implementing-vulnerability-remediation-sla
npx skillmds add mukul975/intercepting-mobile-traffic-with-burpsuite
npx skillmds add mukul975/performing-access-review-and-certification
npx skillmds add mukul975/detecting-ransomware-precursors-in-network
npx skillmds add mukul975/performing-authenticated-scan-with-openvas
npx skillmds add mukul975/performing-dark-web-monitoring-for-threats
npx skillmds add mukul975/performing-deception-technology-deployment
npx skillmds add mukul975/performing-http-parameter-pollution-attack
npx skillmds add mukul975/performing-network-packet-capture-analysis
npx skillmds add mukul975/performing-oauth-scope-minimization-review
npx skillmds add mukul975/performing-privilege-escalation-assessment
npx skillmds add mukul975/performing-ssrf-vulnerability-exploitation
npx skillmds add mukul975/performing-web-application-firewall-bypass
npx skillmds add mukul975/scanning-kubernetes-manifests-with-kubesec
npx skillmds add mukul975/testing-for-business-logic-vulnerabilities
npx skillmds add mukul975/testing-for-json-web-token-vulnerabilities
npx skillmds add mukul975/analyzing-command-and-control-communication
npx skillmds add mukul975/analyzing-macro-malware-in-office-documents
npx skillmds add mukul975/analyzing-malware-persistence-with-autoruns
npx skillmds add mukul975/analyzing-ransomware-leak-site-intelligence
npx skillmds add mukul975/analyzing-tls-certificate-transparency-logs
npx skillmds add mukul975/building-ioc-defanging-and-sharing-pipeline
npx skillmds add mukul975/building-phishing-reporting-button-workflow
npx skillmds add mukul975/conducting-memory-forensics-with-volatility
npx skillmds add mukul975/configuring-network-segmentation-with-vlans
npx skillmds add mukul975/configuring-suricata-for-network-monitoring
npx skillmds add mukul975/configuring-zscaler-private-access-for-ztna
npx skillmds add mukul975/deobfuscating-powershell-obfuscated-malware
npx skillmds add mukul975/detecting-ai-model-prompt-injection-attacks
npx skillmds add mukul975/detecting-anomalous-authentication-patterns
npx skillmds add mukul975/detecting-aws-guardduty-findings-automation
npx skillmds add mukul975/detecting-business-email-compromise-with-ai
npx skillmds add mukul975/detecting-container-escape-with-falco-rules
npx skillmds add mukul975/performing-cloud-log-forensics-with-athena
npx skillmds add mukul975/detecting-dcsync-attack-in-active-directory
npx skillmds add mukul975/detecting-deepfake-audio-in-vishing-attacks
npx skillmds add mukul975/detecting-insider-data-exfiltration-via-dlp
npx skillmds add mukul975/performing-dynamic-analysis-of-android-app
npx skillmds add mukul975/detecting-ntlm-relay-with-event-correlation
npx skillmds add mukul975/detecting-t1003-credential-dumping-with-edr
npx skillmds add mukul975/executing-nist-rmf-authorization-to-operate
npx skillmds add mukul975/exploiting-active-directory-with-bloodhound
npx skillmds add mukul975/generating-forensic-timelines-with-hayabusa
npx skillmds add mukul975/hardening-linux-endpoint-with-cis-benchmark
npx skillmds add mukul975/hunting-for-living-off-the-cloud-techniques
npx skillmds add mukul975/hunting-for-registry-persistence-mechanisms
npx skillmds add mukul975/implementing-anti-phishing-training-program
npx skillmds add mukul975/implementing-api-schema-validation-security
npx skillmds add mukul975/implementing-cisa-zero-trust-maturity-model
npx skillmds add mukul975/implementing-disk-encryption-with-bitlocker
npx skillmds add mukul975/implementing-hipaa-security-rule-safeguards
npx skillmds add mukul975/implementing-runtime-security-with-tetragon
npx skillmds add mukul975/implementing-siem-correlation-rules-for-apt
npx skillmds add mukul975/implementing-ticketing-system-for-incidents
npx skillmds add mukul975/implementing-velociraptor-for-ir-collection
npx skillmds add mukul975/integrating-dast-with-owasp-zap-in-pipeline
npx skillmds add mukul975/parsing-artifacts-with-eric-zimmerman-tools
npx skillmds add mukul975/performing-agentless-vulnerability-scanning
npx skillmds add mukul975/performing-authenticated-vulnerability-scan
npx skillmds add mukul975/performing-dmarc-policy-enforcement-rollout
npx skillmds add mukul975/performing-docker-bench-security-assessment
npx skillmds add mukul975/performing-endpoint-forensics-investigation
npx skillmds add mukul975/performing-false-positive-reduction-in-siem
npx skillmds add mukul975/performing-firmware-extraction-with-binwalk
npx skillmds add mukul975/performing-ics-asset-discovery-with-claroty
npx skillmds add mukul975/performing-network-forensics-with-wireshark
npx skillmds add mukul975/performing-oil-gas-cybersecurity-assessment
npx skillmds add mukul975/performing-ot-vulnerability-scanning-safely
npx skillmds add mukul975/performing-phishing-simulation-with-gophish
npx skillmds add mukul975/performing-privileged-account-access-review
npx skillmds add mukul975/performing-ssl-tls-inspection-configuration
npx skillmds add mukul975/performing-threat-hunting-with-elastic-siem
npx skillmds add mukul975/performing-web-application-penetration-test
npx skillmds add mukul975/securing-historian-server-in-ot-environment
npx skillmds add mukul975/triaging-security-incident-with-ir-playbook
npx skillmds add mukul975/analyzing-cobalt-strike-beacon-configuration
npx skillmds add mukul975/analyzing-cobaltstrike-malleable-c2-profiles
npx skillmds add mukul975/analyzing-malware-sandbox-evasion-techniques
npx skillmds add mukul975/analyzing-network-covert-channels-in-malware
npx skillmds add mukul975/conducting-internal-network-penetration-test
npx skillmds add mukul975/conducting-spearphishing-simulation-campaign
npx skillmds add mukul975/conducting-wireless-network-penetration-test
npx skillmds add mukul975/configuring-microsegmentation-for-zero-trust
npx skillmds add mukul975/deploying-palo-alto-prisma-access-zero-trust
npx skillmds add mukul975/detecting-typosquatting-packages-in-npm-pypi
npx skillmds add mukul975/executing-active-directory-attack-simulation
npx skillmds add mukul975/exploiting-prototype-pollution-in-javascript
npx skillmds add mukul975/hunting-for-data-staging-before-exfiltration
npx skillmds add mukul975/hunting-for-defense-evasion-via-timestomping
npx skillmds add mukul975/implementing-aes-encryption-for-data-at-rest
npx skillmds add mukul975/implementing-api-security-posture-management
npx skillmds add mukul975/implementing-aws-config-rules-for-compliance
npx skillmds add mukul975/implementing-ddos-mitigation-with-cloudflare
npx skillmds add mukul975/implementing-digital-signatures-with-ed25519
npx skillmds add mukul975/implementing-google-workspace-admin-security
npx skillmds add mukul975/implementing-hashicorp-vault-dynamic-secrets
npx skillmds add mukul975/implementing-memory-protection-with-dep-aslr
npx skillmds add mukul975/implementing-network-policies-for-kubernetes
npx skillmds add mukul975/implementing-patch-management-for-ot-systems
npx skillmds add mukul975/performing-active-directory-penetration-test
npx skillmds add mukul975/performing-cloud-native-forensics-with-falco
npx skillmds add mukul975/performing-dns-enumeration-and-zone-transfer
npx skillmds add mukul975/performing-external-network-penetration-test
npx skillmds add mukul975/performing-linux-log-forensics-investigation
npx skillmds add mukul975/testing-android-intents-for-vulnerabilities
npx skillmds add mukul975/performing-malware-persistence-investigation
npx skillmds add mukul975/performing-memory-forensics-with-volatility3
npx skillmds add mukul975/performing-s7comm-protocol-security-analysis
npx skillmds add mukul975/performing-sca-dependency-scanning-with-snyk
npx skillmds add mukul975/performing-soap-web-service-security-testing
npx skillmds add mukul975/performing-wireless-network-penetration-test
npx skillmds add mukul975/triaging-vulnerabilities-with-ssvc-framework
npx skillmds add mukul975/analyzing-office365-audit-logs-for-compromise
npx skillmds add mukul975/analyzing-threat-actor-ttps-with-mitre-attack
npx skillmds add mukul975/analyzing-typosquatting-domains-with-dnstwist
npx skillmds add mukul975/auditing-azure-active-directory-configuration
npx skillmds add mukul975/auditing-kubernetes-rbac-privilege-escalation
npx skillmds add mukul975/building-ioc-enrichment-pipeline-with-opencti
npx skillmds add mukul975/building-threat-intelligence-feed-integration
npx skillmds add mukul975/building-vulnerability-aging-and-sla-tracking
npx skillmds add mukul975/bypassing-authentication-with-forced-browsing
npx skillmds add mukul975/conducting-external-reconnaissance-with-osint
npx skillmds add mukul975/configuring-snort-ids-for-intrusion-detection
npx skillmds add mukul975/configuring-tls-1-3-for-secure-communications
npx skillmds add mukul975/detecting-entra-offensive-tools-in-graph-logs
npx skillmds add mukul975/detecting-evasion-techniques-in-endpoint-logs
npx skillmds add mukul975/detecting-t1055-process-injection-with-sysmon
npx skillmds add mukul975/emulating-cloud-attacks-with-stratus-red-team
npx skillmds add mukul975/exploiting-ms17-010-eternalblue-vulnerability
npx skillmds add mukul975/exploiting-template-injection-vulnerabilities
npx skillmds add mukul975/hardening-windows-endpoint-with-cis-benchmark
npx skillmds add mukul975/hunting-for-beaconing-with-frequency-analysis
npx skillmds add mukul975/performing-api-security-testing-with-postman
npx skillmds add mukul975/hunting-for-persistence-mechanisms-in-windows
npx skillmds add mukul975/hunting-for-persistence-via-wmi-subscriptions
npx skillmds add mukul975/implementing-api-rate-limiting-and-throttling
npx skillmds add mukul975/implementing-browser-isolation-for-zero-trust
npx skillmds add mukul975/implementing-email-sandboxing-with-proofpoint
npx skillmds add mukul975/implementing-envelope-encryption-with-aws-kms
npx skillmds add mukul975/implementing-gdpr-data-subject-access-request
npx skillmds add mukul975/implementing-honeytokens-for-breach-detection
npx skillmds add mukul975/implementing-just-in-time-access-provisioning
npx skillmds add mukul975/implementing-network-deception-with-honeypots
npx skillmds add mukul975/implementing-ransomware-kill-switch-detection
npx skillmds add mukul975/implementing-security-monitoring-with-datadog
npx skillmds add mukul975/implementing-zero-trust-for-saas-applications
npx skillmds add mukul975/integrating-sast-into-github-actions-pipeline
npx skillmds add mukul975/performing-brand-monitoring-for-impersonation
npx skillmds add mukul975/performing-cloud-storage-forensic-acquisition
npx skillmds add mukul975/performing-cryptographic-audit-of-application
npx skillmds add mukul975/performing-endpoint-vulnerability-remediation
npx skillmds add mukul975/performing-ip-reputation-analysis-with-shodan
npx skillmds add mukul975/performing-open-source-intelligence-gathering
npx skillmds add mukul975/performing-timeline-reconstruction-with-plaso
npx skillmds add mukul975/performing-vulnerability-scanning-with-nessus
npx skillmds add mukul975/reverse-engineering-android-malware-with-jadx
npx skillmds add mukul975/testing-api-for-mass-assignment-vulnerability
npx skillmds add mukul975/verifying-build-provenance-with-slsa-sigstore
npx skillmds add mukul975/analyzing-malware-behavior-with-cuckoo-sandbox
npx skillmds add mukul975/analyzing-prefetch-files-for-execution-history
npx skillmds add mukul975/auditing-terraform-infrastructure-for-security
npx skillmds add mukul975/building-automated-malware-submission-pipeline
npx skillmds add mukul975/building-identity-governance-lifecycle-process
npx skillmds add mukul975/building-red-team-c2-infrastructure-with-havoc
npx skillmds add mukul975/conducting-man-in-the-middle-attack-simulation
npx skillmds add mukul975/conducting-social-engineering-penetration-test
npx skillmds add mukul975/configuring-certificate-authority-with-openssl
npx skillmds add mukul975/configuring-windows-defender-advanced-settings
npx skillmds add mukul975/deploying-cloud-deception-with-decoy-resources
npx skillmds add mukul975/deploying-decoy-files-for-ransomware-detection
npx skillmds add mukul975/detecting-container-runtime-threats-with-falco
npx skillmds add mukul975/detecting-network-scanning-with-ids-signatures
npx skillmds add mukul975/detecting-qr-code-phishing-with-email-security
npx skillmds add mukul975/detecting-suspicious-oauth-application-consent
npx skillmds add mukul975/exploiting-broken-function-level-authorization
npx skillmds add mukul975/exploiting-smb-vulnerabilities-with-metasploit
npx skillmds add mukul975/hunting-for-lolbins-execution-in-endpoint-logs
npx skillmds add mukul975/implementing-api-threat-protection-with-apigee
npx skillmds add mukul975/implementing-aws-macie-for-data-classification
npx skillmds add mukul975/implementing-cloud-security-posture-management
npx skillmds add mukul975/implementing-dragos-platform-for-ot-monitoring
npx skillmds add mukul975/implementing-honeypot-for-ransomware-detection
npx skillmds add mukul975/implementing-kubernetes-pod-security-standards
npx skillmds add mukul975/implementing-microsegmentation-with-guardicore
npx skillmds add mukul975/performing-network-traffic-analysis-with-zeek
npx skillmds add mukul975/implementing-pod-security-admission-controller
npx skillmds add mukul975/implementing-proofpoint-email-security-gateway
npx skillmds add mukul975/implementing-purdue-model-network-segmentation
npx skillmds add mukul975/implementing-threat-modeling-with-mitre-attack
npx skillmds add mukul975/performing-access-recertification-with-saviynt
npx skillmds add mukul975/reverse-engineering-dotnet-malware-with-dnspy
npx skillmds add mukul975/performing-asset-criticality-scoring-for-vulns
npx skillmds add mukul975/performing-aws-privilege-escalation-assessment
npx skillmds add mukul975/performing-cloud-forensics-with-aws-cloudtrail
npx skillmds add mukul975/performing-cloud-penetration-testing-with-pacu
npx skillmds add mukul975/performing-cve-prioritization-with-kev-catalog
npx skillmds add mukul975/performing-kubernetes-etcd-security-assessment
npx skillmds add mukul975/performing-post-quantum-cryptography-migration
npx skillmds add mukul975/performing-power-grid-cybersecurity-assessment
npx skillmds add mukul975/performing-serverless-function-security-review
npx skillmds add mukul975/performing-service-account-credential-rotation
npx skillmds add mukul975/performing-web-application-scanning-with-nikto
npx skillmds add mukul975/performing-yara-rule-development-for-detection
npx skillmds add mukul975/prioritizing-vulnerabilities-with-cvss-scoring
npx skillmds add mukul975/analyzing-certificate-transparency-for-phishing
npx skillmds add mukul975/analyzing-sbom-for-supply-chain-vulnerabilities
npx skillmds add mukul975/analyzing-slack-space-and-file-system-artifacts
npx skillmds add mukul975/coercing-authentication-with-coercer-petitpotam
npx skillmds add mukul975/configuring-windows-event-logging-for-detection
npx skillmds add mukul975/detecting-malicious-scheduled-tasks-with-sysmon
npx skillmds add mukul975/implementing-api-security-testing-with-42crunch
npx skillmds add mukul975/implementing-attack-path-analysis-with-xm-cyber
npx skillmds add mukul975/implementing-beyondcorp-zero-trust-access-model
npx skillmds add mukul975/implementing-google-workspace-sso-configuration
npx skillmds add mukul975/implementing-identity-governance-with-sailpoint
npx skillmds add mukul975/implementing-soar-playbook-with-palo-alto-xsoar
npx skillmds add mukul975/implementing-supply-chain-security-with-in-toto
npx skillmds add mukul975/implementing-syslog-centralization-with-rsyslog
npx skillmds add mukul975/implementing-zero-trust-with-hashicorp-boundary
npx skillmds add mukul975/performing-active-directory-bloodhound-analysis
npx skillmds add mukul975/performing-active-directory-forest-trust-attack
npx skillmds add mukul975/performing-automated-malware-analysis-with-cape
npx skillmds add mukul975/performing-gcp-security-assessment-with-forseti
npx skillmds add mukul975/performing-hardware-security-module-integration
npx skillmds add mukul975/implementing-vulnerability-sla-breach-alerting
npx skillmds add mukul975/performing-network-traffic-analysis-with-tshark
npx skillmds add mukul975/performing-ssl-certificate-lifecycle-management
npx skillmds add mukul975/performing-subdomain-enumeration-with-subfinder
npx skillmds add mukul975/performing-web-application-vulnerability-triage
npx skillmds add mukul975/performing-wifi-password-cracking-with-aircrack
npx skillmds add mukul975/analyzing-threat-actor-ttps-with-mitre-navigator
npx skillmds add mukul975/building-attack-pattern-library-from-cti-reports
npx skillmds add mukul975/building-c2-infrastructure-with-sliver-framework
npx skillmds add mukul975/building-malware-incident-communication-template
npx skillmds add mukul975/building-ransomware-playbook-with-cisa-framework
npx skillmds add mukul975/building-vulnerability-dashboard-with-defectdojo
npx skillmds add mukul975/configuring-identity-aware-proxy-with-google-iap
npx skillmds add mukul975/configuring-multi-factor-authentication-with-duo
npx skillmds add mukul975/designing-adversary-engagement-with-mitre-engage
npx skillmds add mukul975/detecting-golden-ticket-attacks-in-kerberos-logs
npx skillmds add mukul975/testing-for-xss-vulnerabilities-with-burpsuite
npx skillmds add mukul975/exploiting-zerologon-vulnerability-cve-2020-1472
npx skillmds add mukul975/implementing-canary-tokens-for-network-intrusion
npx skillmds add mukul975/implementing-end-to-end-encryption-for-messaging
npx skillmds add mukul975/implementing-file-integrity-monitoring-with-aide
npx skillmds add mukul975/building-identity-federation-with-saml-azure-ad
npx skillmds add mukul975/implementing-gcp-organization-policy-constraints
npx skillmds add mukul975/implementing-mimecast-targeted-attack-protection
npx skillmds add mukul975/implementing-runtime-application-self-protection
npx skillmds add mukul975/performing-cloud-incident-containment-procedures
npx skillmds add mukul975/performing-paste-site-monitoring-for-credentials
npx skillmds add mukul975/performing-threat-emulation-with-atomic-red-team
npx skillmds add mukul975/performing-threat-intelligence-sharing-with-misp
npx skillmds add mukul975/post-exploiting-microsoft-graph-with-graphrunner
npx skillmds add mukul975/analyzing-ethereum-smart-contract-vulnerabilities
npx skillmds add mukul975/building-adversary-infrastructure-tracking-system
npx skillmds add mukul975/building-threat-intelligence-enrichment-in-splunk
npx skillmds add mukul975/conducting-cyber-risk-assessment-with-nist-800-30
npx skillmds add mukul975/detecting-anomalies-in-industrial-control-systems
npx skillmds add mukul975/detecting-aws-credential-exposure-with-trufflehog
npx skillmds add mukul975/detecting-azure-storage-account-misconfigurations
npx skillmds add mukul975/detecting-privilege-escalation-in-kubernetes-pods
npx skillmds add mukul975/detecting-t1548-abuse-elevation-control-mechanism
npx skillmds add mukul975/implementing-aqua-security-for-container-scanning
npx skillmds add mukul975/implementing-conditional-access-policies-azure-ad
npx skillmds add mukul975/implementing-google-workspace-phishing-protection
npx skillmds add mukul975/implementing-hardware-security-key-authentication
npx skillmds add mukul975/implementing-identity-verification-for-zero-trust
npx skillmds add mukul975/implementing-network-traffic-analysis-with-arkime
npx skillmds add mukul975/performing-android-app-static-analysis-with-mobsf
npx skillmds add mukul975/performing-bandwidth-throttling-attack-simulation
npx skillmds add mukul975/performing-cloud-asset-inventory-with-cartography
npx skillmds add mukul975/performing-container-security-scanning-with-trivy
npx skillmds add mukul975/performing-static-malware-analysis-with-pe-studio
npx skillmds add mukul975/performing-threat-landscape-assessment-for-sector
npx skillmds add mukul975/building-vulnerability-exception-tracking-system
npx skillmds add mukul975/reverse-engineering-ransomware-encryption-routine
npx skillmds add mukul975/testing-api-for-broken-object-level-authorization
npx skillmds add mukul975/analyzing-email-headers-for-phishing-investigation
npx skillmds add mukul975/collecting-volatile-evidence-from-compromised-host
npx skillmds add mukul975/detecting-dns-exfiltration-with-dns-query-analysis
npx skillmds add mukul975/implementing-conduit-security-for-ot-remote-access
npx skillmds add mukul975/implementing-kubernetes-network-policy-with-calico
npx skillmds add mukul975/implementing-network-access-control-with-cisco-ise
npx skillmds add mukul975/implementing-opa-gatekeeper-for-policy-enforcement
npx skillmds add mukul975/implementing-policy-as-code-with-open-policy-agent
npx skillmds add mukul975/implementing-zero-standing-privilege-with-cyberark
npx skillmds add mukul975/performing-log-analysis-for-forensic-investigation
npx skillmds add mukul975/performing-malware-hash-enrichment-with-virustotal
npx skillmds add mukul975/performing-entitlement-review-with-sailpoint-iiq
npx skillmds add mukul975/performing-mobile-device-forensics-with-cellebrite
npx skillmds add mukul975/performing-mobile-app-certificate-pinning-bypass
npx skillmds add mukul975/analyzing-memory-forensics-with-lime-and-volatility
npx skillmds add mukul975/implementing-api-abuse-detection-with-rate-limiting
npx skillmds add mukul975/implementing-cloud-vulnerability-posture-management
npx skillmds add mukul975/implementing-container-network-policies-with-calico
npx skillmds add mukul975/implementing-passwordless-auth-with-microsoft-entra
npx skillmds add mukul975/implementing-passwordless-authentication-with-fido2
npx skillmds add mukul975/implementing-zero-trust-network-access-with-zscaler
npx skillmds add mukul975/performing-aws-account-enumeration-with-scout-suite
npx skillmds add mukul975/performing-kubernetes-cis-benchmark-with-kube-bench
npx skillmds add mukul975/performing-ot-vulnerability-assessment-with-claroty
npx skillmds add mukul975/performing-threat-modeling-with-owasp-threat-dragon
npx skillmds add mukul975/performing-wireless-security-assessment-with-kismet
npx skillmds add mukul975/analyzing-malware-family-relationships-with-malpedia
npx skillmds add mukul975/detecting-broken-object-property-level-authorization
npx skillmds add mukul975/exploiting-vulnerabilities-with-metasploit-framework
npx skillmds add mukul975/implementing-application-whitelisting-with-applocker
npx skillmds add mukul975/implementing-azure-ad-privileged-identity-management
npx skillmds add mukul975/implementing-continuous-security-validation-with-bas
npx skillmds add mukul975/implementing-device-posture-assessment-in-zero-trust
npx skillmds add mukul975/implementing-next-generation-firewall-with-palo-alto
npx skillmds add mukul975/implementing-ot-network-traffic-analysis-with-nozomi
npx skillmds add mukul975/implementing-security-information-sharing-with-stix2
npx skillmds add mukul975/implementing-vulnerability-management-with-greenbone
npx skillmds add mukul975/implementing-zero-knowledge-proof-for-authentication
npx skillmds add mukul975/performing-active-directory-compromise-investigation
npx skillmds add mukul975/performing-memory-forensics-with-volatility3-plugins
npx skillmds add mukul975/performing-thick-client-application-penetration-test
npx skillmds add mukul975/conducting-internal-reconnaissance-with-bloodhound-ce
npx skillmds add mukul975/exploiting-active-directory-certificate-services-esc1
npx skillmds add mukul975/implementing-infrastructure-as-code-security-scanning
npx skillmds add mukul975/implementing-network-segmentation-with-firewall-zones
npx skillmds add mukul975/implementing-threat-intelligence-lifecycle-management
npx skillmds add mukul975/implementing-fuzz-testing-in-cicd-with-aflplusplus
npx skillmds add mukul975/implementing-web-application-logging-with-modsecurity
npx skillmds add mukul975/performing-adversary-in-the-middle-phishing-detection
npx skillmds add mukul975/implementing-image-provenance-verification-with-cosign
npx skillmds add mukul975/implementing-iso-27001-information-security-management
npx skillmds add mukul975/performing-gcp-penetration-testing-with-gcpbucketbrute
npx skillmds add mukul975/implementing-deception-based-detection-with-canarytoken
npx skillmds add mukul975/implementing-github-advanced-security-for-code-scanning
npx skillmds add mukul975/implementing-network-intrusion-prevention-with-suricata
npx skillmds add mukul975/implementing-privileged-access-management-with-cyberark
npx skillmds add mukul975/implementing-data-loss-prevention-with-microsoft-purview
npx skillmds add mukul975/implementing-epss-score-for-vulnerability-prioritization
npx skillmds add mukul975/implementing-container-image-minimal-base-with-distroless
npx skillmds add mukul975/performing-cloud-native-threat-hunting-with-aws-detective
npx skillmds add mukul975/performing-windows-artifact-analysis-with-eric-zimmerman-too
npx skillmds add mukul975/performing-active-directory-vulnerability-assessmentSkills in this plugin
- ▌ operating-havoc-c2 · mukul975 bundleBuild and operate a Havoc C2 framework for authorized red-team engagements, including team server deployment, evasive Demon agent generation, and post-exploitation.
- ▌ operating-sliver-c2 · mukul975 bundleStand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
- ▌ containing-active-breach · mukul975 bundleExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach, using network segmentation, endpoint isolation, credential revocation, and access control modifications.
- ▌ exploiting-aws-with-pacu · mukul975 bundleUse Pacu modules for AWS privilege escalation, persistence, and backdooring during authorized penetration tests.
- ▌ automating-ioc-enrichment · mukul975 bundleAutomates enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs.
- ▌ detecting-wmi-persistence · mukul975 bundleDetect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
- ▌ analyzing-cyber-kill-chain · mukul975 bundleMaps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention.
- ▌ detecting-rootkit-activity · mukul975 bundleDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.
- ▌ hunting-for-dcsync-attacks · mukul975 bundleDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
- ▌ hunting-evtx-with-chainsaw · mukul975 bundleHunt for threats in Windows Event Logs using Chainsaw, a fast Rust-based forensic tool that runs Sigma rules, keyword searches, and artifact analysis offline.
- ▌ monitoring-darkweb-sources · mukul975 bundleMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence.
- ▌ testing-jwt-token-security · mukul975 bundleAssess JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
- ▌ triaging-security-incident · mukul975 bundleTriages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
- ▌ triaging-windows-with-kape · mukul975 bundleCollect and parse forensic artifacts from Windows systems using KAPE for rapid DFIR triage.
- ▌ analyzing-linux-elf-malware · mukul975 bundleAnalyzes malicious Linux ELF binaries including botnets, cryptominers, ransomware, and rootkits targeting servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples.
- ▌ detecting-oauth-token-theft · mukul975 bundleDetects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
- ▌ escaping-containers-to-host · mukul975 bundleExploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
- ▌ executing-red-team-exercise · mukul975 bundleSimulates real-world adversary operations to test an organization's detection and response capabilities through the full attack lifecycle, from reconnaissance to objective completion.
- ▌ processing-stix-taxii-feeds · mukul975 bundleProcesses STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
- ▌ red-teaming-llms-with-garak · mukul975 bundleRun NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
- ▌ relaying-ntlm-for-adcs-esc8 · mukul975 bundleCoerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync.
- ▌ auditing-gcp-iam-permissions · mukul975 bundleAudits Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
- ▌ correlating-threat-campaigns · mukul975 bundleCorrelates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
- ▌ detecting-secure-boot-bypass · mukul975 bundleDetect bootkits such as BlackLotus and Bootkitty and verify Secure Boot bypass via DBX and binary checks.
- ▌ exploiting-adcs-with-certipy · mukul975 bundleEnumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
- ▌ hunting-saas-sso-token-abuse · mukul975 bundleDetect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
- ▌ implementing-cloud-waf-rules · mukul975 bundleDeploy and tune Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks, including managed rule sets, custom rate limiting, bot management, and false positive reduction.
- ▌ securing-aws-iam-permissions · mukul975 bundleHardens AWS IAM configurations to enforce least privilege access across cloud accounts, covering policy scoping, permission boundaries, Access Analyzer integration, and credential rotation.
- ▌ securing-kubernetes-on-cloud · mukul975 bundleHardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring.
- ▌ hunting-for-webshell-activity · mukul975 bundleHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
- ▌ implementing-aws-security-hub · mukul975 bundleDeploy AWS Security Hub as a centralized cloud security posture management platform, aggregate findings from GuardDuty, Inspector, Macie, and third-party tools, enable security standards, configure automated remediation, and build compliance dashboards across multi-account AWS organizations.
- ▌ modeling-threats-with-opencti · mukul975 bundleModel threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
- ▌ moving-laterally-with-netexec · mukul975 bundleEnumerate SMB, WinRM, LDAP, and MSSQL services, validate credentials, spray passwords, and execute commands on remote hosts using NetExec during authorized penetration tests.
- ▌ profiling-threat-actor-groups · mukul975 bundleDevelops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources.
- ▌ securing-serverless-functions · mukul975 bundleHardens serverless compute platforms (AWS Lambda, Azure Functions, Google Cloud Functions) by enforcing least privilege IAM roles, eliminating hardcoded secrets, scanning dependencies for vulnerabilities, validating input, securing function URLs, and enabling runtime monitoring.
- ▌ building-soc-escalation-matrix · mukul975 bundleBuild a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
- ▌ defending-llms-with-guardrails · mukul975 bundleDeploy Llama Guard, NeMo Guardrails, and LLM Guard as runtime input/output scanners to block jailbreaks, prompt injection, and toxic content in production LLM applications.
- ▌ testing-cors-misconfiguration · mukul975 bundleIdentify and exploit Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during authorized security assessments.
- ▌ detecting-dependency-confusion · mukul975 bundleDetect and prevent public-over-private name resolution in npm, PyPI, and Maven dependency manifests.
- ▌ detecting-shadow-api-endpoints · mukul975 bundleDiscover and inventory undocumented API endpoints by comparing live traffic against OpenAPI specs, scanning code repositories, and analyzing cloud configurations.
- ▌ generating-and-analyzing-sboms · mukul975 bundleGenerate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
- ▌ hunting-for-ntlm-relay-attacks · mukul975 bundleDetect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
- ▌ performing-ransomware-response · mukul975 bundleExecutes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
- ▌ performing-vlan-hopping-attack · mukul975 bundleSimulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
- ▌ analyzing-kubernetes-audit-logs · mukul975 bundleParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns.
- ▌ analyzing-linux-kernel-rootkits · mukul975 bundleDetect kernel-level rootkits in Linux memory dumps using Volatility3 plugins and live system scanners to identify hooked syscalls, hidden modules, and tampered structures.
- ▌ configuring-hsm-for-key-storage · mukul975 bundleConfigure Hardware Security Modules (HSMs) using the PKCS#11 standard interface for key generation, signing, encryption, and key management with both physical HSMs and SoftHSM2 for development.
- ▌ testing-websocket-api-security · mukul975 bundleTests WebSocket API implementations for security vulnerabilities including missing authentication, Cross-Site WebSocket Hijacking, injection attacks, and denial-of-service.
- ▌ detecting-cryptomining-in-cloud · mukul975 bundleDetect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
- ▌ detecting-golden-ticket-forgery · mukul975 bundleDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades, abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM.
- ▌ detecting-kerberoasting-attacks · mukul975 bundleDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
- ▌ conducting-api-security-testing · mukul975 bundleConducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using the OWASP API Security Top 10 framework.
- ▌ detecting-pass-the-hash-attacks · mukul975 bundleHunt for Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons where Kerberos is expected, and correlating with credential dumping indicators.
- ▌ detecting-service-account-abuse · mukul975 bundleDetect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
- ▌ detecting-shadow-it-cloud-usage · mukul975 bundleAnalyze proxy logs, DNS query logs, and netflow data to detect unauthorized SaaS and cloud service usage, classify domains, and flag high-risk services.
- ▌ detecting-stuxnet-style-attacks · mukul975 bundleDetect sophisticated cyber-physical attacks that modify PLC logic while spoofing sensor readings, covering PLC integrity monitoring, process anomaly detection, and multi-stage attack chain detection.
- ▌ enumerating-cloud-with-cloudfox · mukul975 bundleMap AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
- ▌ exploiting-idor-vulnerabilities · mukul975 bundleIdentify and exploit Insecure Direct Object Reference vulnerabilities during authorized penetration tests by manipulating object identifiers in API requests and URLs.
- ▌ exploiting-ipv6-vulnerabilities · mukul975 bundleIdentifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
- ▌ fleet-hunting-with-velociraptor · mukul975 bundleDeploy a Velociraptor server and agents, then write and execute VQL hunts across a fleet of endpoints for threat hunting and incident response.
- ▌ implementing-saml-sso-with-okta · mukul975 bundleConfigure Okta as a SAML 2.0 Identity Provider and implement SP-initiated and IdP-initiated SSO flows with attribute mapping, assertion encryption, and security hardening.
- ▌ managing-intelligence-lifecycle · mukul975 bundleGuides the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to establish or mature a CTI program.
- ▌ mapping-mitre-attack-techniques · mukul975 bundleMaps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.
- ▌ performing-kerberoasting-attack · mukul975 bundleEnumerate Active Directory service accounts, request Kerberos TGS tickets, and crack them offline to assess password strength and privilege escalation paths.
- ▌ performing-purple-team-exercise · mukul975 bundleCoordinates purple team exercises by running MITRE ATT&CK-mapped attack scenarios with real-time detection testing and collaborative gap remediation.
- ▌ performing-ssl-stripping-attack · mukul975 bundleSimulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms.
- ▌ securing-helm-chart-deployments · mukul975 bundleSecure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
- ▌ testing-for-xss-vulnerabilities · mukul975 bundleTests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
- ▌ analyzing-linux-system-artifacts · mukul975 bundleExamine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
- ▌ auditing-kubernetes-cluster-rbac · mukul975 bundleAudit Kubernetes RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous bindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
- ▌ detecting-azure-lateral-movement · mukul975 bundleDetect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
- ▌ detecting-malicious-npm-packages · mukul975 bundleTriage npm packages for install-script malware, exfiltration, and worming behavior using GuardDog, manual inspection, and safe detonation.
- ▌ detecting-typosquatting-packages · mukul975 bundleFlag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
- ▌ exploiting-broken-link-hijacking · mukul975 bundleDiscover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.
- ▌ analyzing-pdf-malware-with-pdfid · mukul975 bundleAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis.
- ▌ hunting-for-shadow-copy-deletion · mukul975 bundleHunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
- ▌ implementing-zero-trust-in-cloud · mukul975 bundleGuides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles, covering identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy in AWS, Azure, and GCP.
- ▌ deobfuscating-javascript-malware · mukul975 bundleDeobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic.
- ▌ managing-third-party-vendor-risk · mukul975 bundleBuild and run a third-party/vendor risk management program aligned to NIST SP 800-161 and NIST CSF 2.0: inventory, tier, assess, contract, monitor, and offboard vendors.
- ▌ performing-osint-with-spiderfoot · mukul975 bundleAutomate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources.
- ▌ performing-service-account-audit · mukul975 bundleAudit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts, covering Active Directory, cloud platforms, databases, and applications.
- ▌ performing-soc-tabletop-exercise · mukul975 bundleFacilitates discussion-based tabletop exercises for SOC teams to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems.
- ▌ reverse-engineering-rust-malware · mukul975 bundleAnalyze Rust-compiled malware binaries using IDA Pro and Ghidra, with techniques for extracting crate dependencies, non-null-terminated strings, and Rust-specific control flow patterns.
- ▌ achieving-cmmc-level-2-compliance · mukul975 bundlePrepare a defense-contractor environment for CMMC Level 2 certification by scoping CUI and FCI, implementing NIST SP 800-171 Rev 2 requirements, computing SPRS scores, managing POA&Ms, and readying for C3PAO assessment.
- ▌ analyzing-api-gateway-access-logs · mukul975 bundleParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts using pandas for statistical analysis and anomaly detection.
- ▌ analyzing-disk-image-with-autopsy · mukul975 bundlePerform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
- ▌ analyzing-heap-spray-exploitation · mukul975 bundleDetect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
- ▌ attacking-entra-id-with-roadtools · mukul975 bundleEnumerate Microsoft Entra ID tenants using ROADrecon and acquire/exchange tokens with roadtx for authorized red-team operations.
- ▌ building-cloud-siem-with-sentinel · mukul975 bundleDeploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.
- ▌ conducting-pass-the-ticket-attack · mukul975 bundleExtract Kerberos tickets from LSASS memory, inject them into an attacker session, and perform lateral movement to access remote systems as the impersonated user.
- ▌ deploying-ransomware-canary-files · mukul975 bundleDeploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection, triggering alerts via email, Slack, or syslog when decoy files are accessed.
- ▌ detecting-api-enumeration-attacks · mukul975 bundleDetect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
- ▌ detecting-dll-sideloading-attacks · mukul975 bundleDetect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
- ▌ detecting-dnp3-protocol-anomalies · mukul975 bundleDetect anomalies in DNP3 protocol communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
- ▌ detecting-pass-the-ticket-attacks · mukul975 bundleDetect Kerberos Pass-the-Ticket attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM.
- ▌ detecting-rdp-brute-force-attacks · mukul975 bundleAnalyze Windows Security Event Logs to detect RDP brute force attacks by parsing Event ID 4625 and 4624 entries, identifying source IP frequency, and generating detection reports.
- ▌ exploiting-http-request-smuggling · mukul975 bundleDetect and exploit HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
- ▌ exploiting-oauth-misconfiguration · mukul975 bundleIdentify and exploit OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during authorized security assessments.
- ▌ hunting-for-cobalt-strike-beacons · mukul975 bundleDetect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP C2 profile matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
- ▌ hunting-for-dns-based-persistence · mukul975 bundleHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
- ▌ implementing-siem-use-case-tuning · mukul975 bundleReduce SIEM alert fatigue by systematically tuning detection rules in Splunk and Elastic, using statistical baselines, whitelists, and precision/recall metrics.
- ▌ detecting-mobile-malware-behavior · mukul975 bundleAnalyzes mobile applications for malicious behavior through static analysis, runtime monitoring, and network traffic inspection to identify malware indicators.
- ▌ managing-cloud-identity-with-okta · mukul975 bundleImplement Okta as a centralized identity provider for cloud environments, configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA, automate user lifecycle management, and enforce adaptive access policies.
- ▌ performing-malware-ioc-extraction · mukul975 bundleAnalyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
- ▌ performing-red-team-with-covenant · mukul975 bundleAutomate red team operations using the Covenant C2 framework's REST API for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
- ▌ performing-security-headers-audit · mukul975 bundleAudits HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
- ▌ recovering-from-ransomware-attack · mukul975 bundleExecutes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection.
- ▌ scanning-docker-images-with-trivy · mukul975 bundleScan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
- ▌ hunting-for-dcom-lateral-movement · mukul975 bundleDetect DCOM-based lateral movement by correlating Sysmon process creation and network connection events, WMI event analysis, and RPC endpoint mapper traffic to identify abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects.
- ▌ securing-api-gateway-with-aws-waf · mukul975 bundleProtect API Gateway endpoints with AWS WAF by configuring managed rule groups, rate limiting, bot control, IP reputation filtering, and monitoring.
- ▌ testing-for-broken-access-control · mukul975 bundleSystematically test web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
- ▌ testing-for-host-header-injection · mukul975 bundleTest web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
- ▌ testing-for-system-prompt-leakage · mukul975 bundleTest LLM applications for system prompt leakage using manual payloads, garak, and Promptfoo to extract embedded secrets and routing logic.
- ▌ performing-csrf-attack-simulation · mukul975 bundleTest web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
- ▌ testing-mobile-api-authentication · mukul975 bundleTests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities.
- ▌ analyzing-indicators-of-compromise · mukul975 bundleTriages and enriches indicators of compromise (IPs, domains, file hashes, URLs, email artifacts) from phishing emails, security alerts, or threat feeds, assigning confidence scores and dispositions using VirusTotal, AbuseIPDB, MalwareBazaar, and MISP.
- ▌ analyzing-uefi-bootkit-persistence · mukul975 bundleAnalyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.
- ▌ auditing-aws-s3-bucket-permissions · mukul975 bundleAudit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, Prowler, and IAM Access Analyzer.
- ▌ auditing-cloud-with-cis-benchmarks · mukul975 bundleConduct cloud security audits using CIS benchmarks for AWS, Azure, and GCP, including automated assessments, remediation, and continuous compliance monitoring.
- ▌ conducting-cloud-incident-response · mukul975 bundleResponds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
- ▌ configuring-pfsense-firewall-rules · mukul975 bundleGuides the configuration of pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation and protect network zones.
- ▌ securing-github-actions-workflows · mukul975 bundleHardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
- ▌ detecting-attacks-on-scada-systems · mukul975 bundleDetects cyber attacks targeting SCADA systems, including man-in-the-middle, command injection, HMI compromise, historian manipulation, and DoS, using OT-specific intrusion detection and protocol anomaly analysis.
- ▌ detecting-aws-cloudtrail-anomalies · mukul975 bundleQuery AWS CloudTrail events with boto3, build statistical baselines of normal API activity, and detect anomalies such as unusual event sources, geographic anomalies, high-frequency API calls, and first-time API usage patterns.
- ▌ detecting-data-and-model-poisoning · mukul975 bundleDetect poisoned training data and backdoored models across the ML pipeline using statistical analysis, activation clustering, and spectral signatures.
- ▌ detecting-email-account-compromise · mukul975 bundleDetect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
- ▌ detecting-insider-threat-behaviors · mukul975 bundleDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
- ▌ detecting-insider-threat-with-ueba · mukul975 bundleDetect insider threats by modeling normal user and entity behavior with Elasticsearch, computing anomaly scores, and correlating low-confidence indicators into high-confidence alerts.
- ▌ detecting-model-extraction-attacks · mukul975 bundleDetect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
- ▌ implementing-endpoint-dlp-controls · mukul975 bundleDeploys endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing using Microsoft Purview or Symantec DLP.
- ▌ operationalizing-misp-threat-feeds · mukul975 bundleRun MISP, curate threat feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
- ▌ performing-blind-ssrf-exploitation · mukul975 bundleDetect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
- ▌ performing-dns-tunneling-detection · mukul975 bundleDetects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality using scapy for packet capture analysis.
- ▌ performing-iot-security-assessment · mukul975 bundlePerforms comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications.
- ▌ performing-packet-injection-attack · mukul975 bundleCrafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
- ▌ performing-steganography-detection · mukul975 bundleDetect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
- ▌ performing-user-behavior-analytics · mukul975 bundleDetect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis.
- ▌ scanning-iac-and-images-with-trivy · mukul975 bundleScan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
- ▌ securing-container-registry-images · mukul975 bundleScan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
- ▌ testing-for-email-header-injection · mukul975 bundleTest web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
- ▌ triaging-security-alerts-in-splunk · mukul975 bundleTriages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard.
- ▌ abusing-dpapi-for-credential-access · mukul975 bundleExtract DPAPI-protected secrets such as credentials and browser data from Windows systems during authorized penetration tests.
- ▌ analyzing-dns-logs-for-exfiltration · mukul975 bundleDetects DNS-based data exfiltration, tunneling, and DGA communication by analyzing query logs with entropy analysis, volume anomalies, and subdomain length detection in SIEM platforms.
- ▌ analyzing-malicious-pdf-with-peepdf · mukul975 bundlePerform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
- ▌ analyzing-security-logs-with-splunk · mukul975 bundleInvestigate security incidents by correlating Windows event logs, firewall, proxy, and authentication data using Splunk SPL queries and Enterprise Security.
- ▌ analyzing-threat-intelligence-feeds · mukul975 bundleIngests, normalizes, and enriches structured and unstructured threat intelligence feeds into STIX 2.1 format, evaluating feed quality and deduplicating indicators for distribution to SIEM, firewall, and EDR platforms.
- ▌ analyzing-windows-amcache-artifacts · mukul975 bundleParses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations.
- ▌ auditing-entra-id-with-aadinternals · mukul975 bundleRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
- ▌ auditing-uefi-firmware-with-chipsec · mukul975 bundleAssess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
- ▌ building-detection-rules-with-sigma · mukul975 bundleCreates vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.
- ▌ building-incident-response-playbook · mukul975 bundleDesigns and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.
- ▌ building-super-timelines-with-plaso · mukul975 bundleBuild forensic super timelines from disk images using Plaso (log2timeline) and triage them in Timesketch.
- ▌ collecting-indicators-of-compromise · mukul975 bundleSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.
- ▌ collecting-open-source-intelligence · mukul975 bundleCollects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using passive reconnaissance tools and public data sources.
- ▌ conducting-network-penetration-test · mukul975 bundleConducts comprehensive network penetration tests against authorized target environments using host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation following PTES methodology.
- ▌ configuring-ldap-security-hardening · mukul975 bundleHarden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP signing, access control lists, and monitoring for LDAP-based attacks.
- ▌ detecting-business-email-compromise · mukul975 bundleDetect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
- ▌ detecting-container-escape-attempts · mukul975 bundleDetect container escape attempts using runtime security tools like Falco, Sysdig, and custom seccomp/audit rules.
- ▌ detecting-indirect-prompt-injection · mukul975 bundleDetect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
- ▌ detecting-modbus-protocol-anomalies · mukul975 bundleDetects anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems using Zeek, Suricata, and custom Python analysis.
- ▌ exploiting-insecure-deserialization · mukul975 bundleIdentify and exploit insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications during authorized penetration tests.
- ▌ hunting-advanced-persistent-threats · mukul975 bundleProactively hunts for Advanced Persistent Threat activity using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts.
- ▌ hunting-credential-stuffing-attacks · mukul975 bundleDetects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins using statistical analysis on Splunk or raw log data.
- ▌ hunting-for-supply-chain-compromise · mukul975 bundleHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
- ▌ implementing-bgp-security-with-rpki · mukul975 bundleCreate Route Origin Authorizations (ROAs) at RIRs, deploy RPKI validator software, and configure Route Origin Validation (ROV) on Cisco and Juniper routers to prevent BGP route hijacking.
- ▌ implementing-diamond-model-analysis · mukul975 bundleProvides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
- ▌ implementing-gcp-vpc-firewall-rules · mukul975 bundleAudit, create, and monitor GCP VPC firewall rules to enforce network segmentation and least-privilege access.
- ▌ implementing-network-access-control · mukul975 bundleEnforces identity-based network access with 802.1X, RADIUS authentication, dynamic VLAN assignment, and endpoint posture assessment using PacketFence.
- ▌ performing-api-fuzzing-with-restler · mukul975 bundleAutomates stateful REST API fuzzing using Microsoft RESTler to discover security and reliability bugs by compiling OpenAPI specs, configuring authentication, and running test, fuzz-lean, and full fuzzing modes.
- ▌ performing-api-rate-limiting-bypass · mukul975 bundleTests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls.
- ▌ performing-fuzzing-with-aflplusplus · mukul975 bundlePerform coverage-guided fuzzing of compiled binaries using AFL++ to discover memory corruption, crashes, and security vulnerabilities.
- ▌ exploiting-deeplink-vulnerabilities · mukul975 bundleTests and exploits deep link vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation.
- ▌ performing-malware-triage-with-yara · mukul975 bundleRapidly classify malware samples against known family signatures using YARA rules, covering rule writing, scanning, and integration with analysis pipelines.
- ▌ scanning-infrastructure-with-nessus · mukul975 bundleConfigure and run Nessus vulnerability scans, analyze results, and integrate scanning into continuous vulnerability management workflows.
- ▌ scanning-network-with-nmap-advanced · mukul975 bundlePerforms advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
- ▌ securing-agentic-ai-tool-invocation · mukul975 bundleApply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
- ▌ hunting-for-dns-tunneling-with-zeek · mukul975 bundleDetect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.
- ▌ securing-aws-lambda-execution-roles · mukul975 bundleAudit and harden AWS Lambda execution roles by implementing least-privilege IAM policies, permission boundaries, and SCP enforcement.
- ▌ testing-oauth2-implementation-flaws · mukul975 bundleTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass.
- ▌ analyzing-active-directory-acl-abuse · mukul975 bundleDetect dangerous ACL misconfigurations in Active Directory by querying and parsing nTSecurityDescriptor attributes to identify GenericAll, WriteDACL, WriteOwner, and GenericWrite abuse paths.
- ▌ analyzing-docker-container-forensics · mukul975 bundleInvestigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
- ▌ analyzing-golang-malware-with-ghidra · mukul975 bundleReverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
- ▌ analyzing-malicious-url-with-urlscan · mukul975 bundleInvestigate phishing URLs, credential harvesting pages, and malicious redirects using URLScan.io's safe browsing environment and API.
- ▌ analyzing-network-packets-with-scapy · mukul975 bundleCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing.
- ▌ analyzing-network-traffic-of-malware · mukul975 bundleAnalyzes malware-generated network traffic from PCAP files to identify C2 protocols, data exfiltration, DNS tunneling, and beaconing patterns using Wireshark, Zeek, Suricata, and Python.
- ▌ performing-clickjacking-attack-test · mukul975 bundleTest web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
- ▌ analyzing-ransomware-payment-wallets · mukul975 bundleTraces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution.
- ▌ analyzing-threat-landscape-with-misp · mukul975 bundleQuery MISP event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time to generate threat landscape reports.
- ▌ analyzing-windows-shellbag-artifacts · mukul975 bundleAnalyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
- ▌ building-incident-response-dashboard · mukul975 bundleBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline.
- ▌ building-soc-playbook-for-ransomware · mukul975 bundleBuilds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
- ▌ conducting-cloud-penetration-testing · mukul975 bundlePerform authorized penetration testing against AWS, Azure, and GCP cloud environments using cloud-specific tools and methodologies, with findings mapped to the MITRE ATT&CK Cloud matrix.
- ▌ conducting-malware-incident-response · mukul975 bundleResponds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.
- ▌ testing-for-sensitive-data-exposure · mukul975 bundleIdentify sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
- ▌ deploying-edr-agent-with-crowdstrike · mukul975 bundleDeploys and configures CrowdStrike Falcon EDR sensors across Windows, macOS, and Linux endpoints, sets prevention and response policies, validates deployment, and integrates with SIEM platforms.
- ▌ deploying-software-defined-perimeter · mukul975 bundleDeploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
- ▌ detecting-container-drift-at-runtime · mukul975 bundleDetect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
- ▌ detecting-sql-injection-via-waf-logs · mukul975 bundleAnalyze WAF logs from ModSecurity, AWS WAF, or Cloudflare to detect SQL injection attack campaigns, classify injection types, and generate incident reports with OWASP classification.
- ▌ exploiting-sql-injection-with-sqlmap · mukul975 bundleDetect and exploit SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
- ▌ extracting-browser-history-artifacts · mukul975 bundleExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
- ▌ extracting-iocs-from-malware-samples · mukul975 bundleExtracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators, host artifacts, and behavioral patterns for threat intelligence sharing and detection rule creation.
- ▌ hunting-for-lateral-movement-via-wmi · mukul975 bundleDetect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
- ▌ hunting-for-spearphishing-indicators · mukul975 bundleHunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
- ▌ implementing-alert-fatigue-reduction · mukul975 bundleReduces SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness.
- ▌ implementing-pam-for-database-access · mukul975 bundleDeploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles.
- ▌ implementing-rsa-key-pair-management · mukul975 bundleGenerate, store, rotate, and manage RSA key pairs following NIST SP 800-57 guidelines, including key serialization, passphrase protection, and key strength validation.
- ▌ orchestrating-llm-attacks-with-pyrit · mukul975 bundleAutomate multi-turn adversarial conversations against LLM agents using Microsoft PyRIT, including Crescendo and Tree-of-Attacks-with-Pruning (TAP) attack chains with scorer feedback loops.
- ▌ performing-container-image-hardening · mukul975 bundleHarden container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations.
- ▌ performing-firmware-malware-analysis · mukul975 bundleAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.
- ▌ performing-ioc-enrichment-automation · mukul975 bundleAutomates multi-source enrichment of IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, Shodan, GreyNoise, URLScan.io, and MISP to provide contextual risk scoring and disposition recommendations for SOC analysts.
- ▌ performing-jwt-none-algorithm-attack · mukul975 bundleTest JWT signature verification bypass by crafting tokens with the 'none' algorithm.
- ▌ performing-privacy-impact-assessment · mukul975 bundleAutomates privacy impact assessments including data flow mapping, risk scoring, GDPR/CCPA compliance checks, and remediation planning using the NIST Privacy Framework and ICO DPIA guidance.
- ▌ detecting-lateral-movement-with-zeek · mukul975 bundleAnalyze Zeek network logs to detect lateral movement techniques including SMB admin share access, DCE/RPC remote service creation, NTLM account spray, Kerberos anomalies, and large internal data transfers.
- ▌ performing-sqlite-database-forensics · mukul975 bundleRecover deleted records, analyze freelist pages, WAL files, and unallocated space in SQLite databases for digital forensics and incident response.
- ▌ scanning-container-images-with-grype · mukul975 bundleScan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
- ▌ tracking-threat-actor-infrastructure · mukul975 bundleMonitor and map adversary-controlled assets including C2 servers, phishing domains, and exploit kit hosts using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting.
- ▌ exploiting-websocket-vulnerabilities · mukul975 bundleTest WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
- ▌ analyzing-bootkit-and-rootkit-samples · mukul975 bundleAnalyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
- ▌ analyzing-powershell-empire-artifacts · mukul975 bundleDetect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
- ▌ building-c2-redirector-infrastructure · mukul975 bundleArchitect C2 redirectors with nginx and Apache, derive filter rules from malleable profiles, and apply OPSEC controls for resilient red-team infrastructure.
- ▌ building-soc-metrics-and-kpi-tracking · mukul975 bundleBuilds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data.
- ▌ building-threat-intelligence-platform · mukul975 bundleDeploy and integrate open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified threat intelligence platform for collecting, analyzing, enriching, and disseminating threat intelligence.
- ▌ conducting-phishing-incident-response · mukul975 bundleResponds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
- ▌ configuring-oauth2-authorization-flow · mukul975 bundleConfigure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
- ▌ correlating-security-events-in-qradar · mukul975 bundleCorrelates security events in IBM QRadar SIEM using AQL queries, custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources.
- ▌ detecting-fileless-malware-techniques · mukul975 bundleDetects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk.
- ▌ detecting-living-off-the-land-attacks · mukul975 bundleDetect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks by monitoring process creation, command-line arguments, and parent-child relationships.
- ▌ detecting-mimikatz-execution-patterns · mukul975 bundleHunt for Mimikatz execution using command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
- ▌ detecting-misconfigured-azure-storage · mukul975 bundleAudits Azure Storage accounts for misconfigurations including public blob access, weak network rules, missing encryption, permissive SAS tokens, and disabled logging using Azure CLI, PowerShell, and Defender for Storage.
- ▌ detecting-port-scanning-with-fail2ban · mukul975 bundleConfigures Fail2ban with custom filters and actions to detect port scanning, SSH brute force, and network reconnaissance, automatically banning offending IPs and alerting security teams.
- ▌ detecting-process-hollowing-technique · mukul975 bundleDetect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
- ▌ exploiting-nopac-cve-2021-42278-42287 · mukul975 bundleEscalate from standard domain user to Domain Admin by exploiting the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) in Active Directory environments.
- ▌ hardening-docker-daemon-configuration · mukul975 bundleHardens the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
- ▌ implementing-azure-defender-for-cloud · mukul975 bundleEnables comprehensive security monitoring across Azure subscriptions, including cloud security posture management, workload protection, regulatory compliance assessment, and adaptive security controls.
- ▌ implementing-cloud-trail-log-analysis · mukul975 bundleAnalyze AWS CloudTrail logs for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration.
- ▌ implementing-ebpf-security-monitoring · mukul975 bundleDeploy kernel-level runtime security monitoring on Linux hosts or Kubernetes clusters using eBPF and Cilium Tetragon for process execution tracking, network observability, file access auditing, and runtime enforcement.
- ▌ implementing-gcp-binary-authorization · mukul975 bundleEnforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
- ▌ implementing-ics-firewall-with-tofino · mukul975 bundleDeploy and configure Tofino industrial firewalls to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones.
- ▌ implementing-iec-62443-security-zones · mukul975 bundleDesign and implement security zones and conduits for industrial automation and control systems per IEC 62443-3-2, including zone partitioning, firewall configuration, and validation through traffic analysis and penetration testing.
- ▌ investigating-phishing-email-incident · mukul975 bundleInvestigate phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms.
- ▌ performing-container-escape-detection · mukul975 bundleAudits Kubernetes pods for container escape vectors by analyzing privileged mode, dangerous capabilities, host namespace sharing, and writable hostPath mounts using the Kubernetes Python client.
- ▌ performing-file-carving-with-foremost · mukul975 bundleRecover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
- ▌ performing-hash-cracking-with-hashcat · mukul975 bundleCrack password hashes using Hashcat for authorized penetration testing and password policy assessment, supporting dictionary, brute-force, rule-based, and hybrid attacks.
- ▌ detecting-lateral-movement-in-network · mukul975 bundleIdentifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
- ▌ performing-lateral-movement-detection · mukul975 bundleDetects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
- ▌ performing-purple-team-atomic-testing · mukul975 bundleExecutes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis, and runs detection validation loops to measure blue team visibility.
- ▌ performing-second-order-sql-injection · mukul975 bundleDetect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
- ▌ performing-web-cache-deception-attack · mukul975 bundleExploit path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve authenticated content.
- ▌ detecting-network-anomalies-with-zeek · mukul975 bundleDeploys and configures Zeek network security monitor to passively analyze traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
- ▌ performing-web-cache-poisoning-attack · mukul975 bundleExploit web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
- ▌ testing-api-authentication-weaknesses · mukul975 bundleTests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws.
- ▌ abusing-shadow-credentials-for-privesc · mukul975 bundleTake over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
- ▌ analyzing-android-malware-with-apktool · mukul975 bundlePerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
- ▌ analyzing-memory-dumps-with-volatility · mukul975 bundleAnalyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
- ▌ analyzing-windows-event-logs-in-splunk · mukul975 bundleDetect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement by analyzing Windows Security, System, and Sysmon event logs in Splunk using SPL queries mapped to MITRE ATT&CK techniques.
- ▌ analyzing-windows-prefetch-with-python · mukul975 bundleParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
- ▌ deploying-active-directory-honeytokens · mukul975 bundleDeploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs.
- ▌ deploying-honeytokens-and-canarytokens · mukul975 bundleDeploy honeytokens and canarytokens as decoy artifacts to detect intrusions with near-zero false positives.
- ▌ deploying-tailscale-for-zero-trust-vpn · mukul975 bundleDeploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
- ▌ detecting-attacks-on-historian-servers · mukul975 bundleDetect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
- ▌ detecting-aws-iam-privilege-escalation · mukul975 bundleIdentify AWS IAM privilege escalation paths by analyzing policies for dangerous permission combinations and least-privilege violations using boto3 and Cloudsplaining-style analysis.
- ▌ detecting-beaconing-patterns-with-zeek · mukul975 bundleAnalyzes Zeek conn.log connection intervals using statistical methods to detect C2 beaconing patterns, flagging periodic connections with low jitter.
- ▌ detecting-bluetooth-low-energy-attacks · mukul975 bundleDetects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception using Ubertooth One, nRF52840, bleak, and crackle.
- ▌ performing-graphql-depth-limit-attack · mukul975 bundleTest GraphQL APIs for depth limit vulnerabilities by sending deeply nested recursive queries to identify denial-of-service risks.
- ▌ detecting-cloud-threats-with-guardduty · mukul975 bundleDeploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads, including enabling protection plans, interpreting findings, and building automated response workflows.
- ▌ detecting-lateral-movement-with-splunk · mukul975 bundleDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
- ▌ detecting-process-injection-techniques · mukul975 bundleDetects and analyzes process injection techniques used by malware, including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading, using memory forensics, API monitoring, and behavioral analysis.
- ▌ executing-phishing-simulation-campaign · mukul975 bundleExecutes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks, including scenario design, infrastructure setup, and metric tracking.
- ▌ executing-red-team-engagement-planning · mukul975 bundleDefines scope, objectives, rules of engagement, threat model selection, and operational timelines for red team engagements before any offensive testing begins.
- ▌ exploiting-kerberoasting-with-impacket · mukul975 bundlePerform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
- ▌ exploiting-server-side-request-forgery · mukul975 bundleIdentify and exploit SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
- ▌ extracting-config-from-agent-tesla-rat · mukul975 bundleExtract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
- ▌ generating-threat-intelligence-reports · mukul975 bundleGenerates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts.
- ▌ hunting-for-domain-fronting-c2-traffic · mukul975 bundleDetect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection.
- ▌ hunting-for-scheduled-task-persistence · mukul975 bundleHunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
- ▌ hunting-for-startup-folder-persistence · mukul975 bundleDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
- ▌ hunting-for-suspicious-scheduled-tasks · mukul975 bundleHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns.
- ▌ conducting-mobile-app-penetration-test · mukul975 bundleConducts penetration testing of iOS and Android mobile applications following the OWASP MASTG to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls.
- ▌ hunting-for-t1098-account-manipulation · mukul975 bundleDetect MITRE ATT&CK T1098 account manipulation techniques including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
- ▌ implementing-api-key-security-controls · mukul975 bundleGenerates, stores, validates, rotates, and revokes API keys with secure hashing, scoping, rate limiting, and leak monitoring.
- ▌ implementing-attack-surface-management · mukul975 bundleBuilds an external attack surface management (EASM) program using Shodan, Censys, and ProjectDiscovery tools for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring.
- ▌ implementing-cloud-workload-protection · mukul975 bundleMonitors cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies on EC2 and GCE instances.
- ▌ implementing-patch-management-workflow · mukul975 bundleIdentify, test, deploy, and verify software updates across an organization's IT infrastructure using a structured patch management workflow with phased rollouts and automated assessment.
- ▌ implementing-secrets-scanning-in-ci-cd · mukul975 bundleIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment.
- ▌ implementing-usb-device-control-policy · mukul975 bundleRestricts unauthorized removable media access on endpoints by implementing USB device control policies via Group Policy, Intune, or EDR platforms to prevent data exfiltration and malware introduction.
- ▌ implementing-zero-trust-network-access · mukul975 bundleConfigure identity-aware proxies, micro-segmentation, and continuous verification to replace traditional VPN-based remote access with zero trust network access across AWS, Azure, and GCP.
- ▌ migrating-to-post-quantum-cryptography · mukul975 bundleInventory cryptographic assets, deploy hybrid X25519 and ML-KEM key exchange, and prioritize migration of harvest-now-decrypt-later data.
- ▌ detecting-command-and-control-over-dns · mukul975 bundleDetects command-and-control (C2) communications tunneled through DNS protocol, including DNS tunneling tools, domain generation algorithms, and encoded payload delivery via TXT/CNAME records.
- ▌ performing-ai-driven-osint-correlation · mukul975 bundleCorrelate findings across OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
- ▌ performing-api-inventory-and-discovery · mukul975 bundleBuild a comprehensive catalog of API endpoints including documented, undocumented, shadow, zombie, and deprecated APIs using passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory.
- ▌ performing-directory-traversal-testing · mukul975 bundleTest web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
- ▌ performing-graphql-security-assessment · mukul975 bundleAssess GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
- ▌ performing-ios-app-security-assessment · mukul975 bundleConduct authorized iOS application security assessments using Frida, Objection, and static analysis to evaluate app security posture against OWASP MASTG standards.
- ▌ performing-ssl-tls-security-assessment · mukul975 bundleAssess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
- ▌ recovering-deleted-files-with-photorec · mukul975 bundleRecover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine, regardless of file system damage.
- ▌ remediating-s3-bucket-misconfiguration · mukul975 bundleIdentify and remediate Amazon S3 bucket misconfigurations that expose sensitive data, including enabling Block Public Access, auditing policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation with AWS Config and Lambda.
- ▌ scanning-containers-with-trivy-in-cicd · mukul975 bundleIntegrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates.
- ▌ securing-azure-with-microsoft-defender · mukul975 bundleDeploy Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. Covers enabling Defender plans, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal.
- ▌ testing-api-security-with-owasp-top-10 · mukul975 bundleSystematically assess REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
- ▌ testing-ransomware-recovery-procedures · mukul975 bundleValidate ransomware recovery plans by testing backup restore operations, measuring RTO/RPO targets, verifying data integrity, and documenting recovery gaps in an isolated lab environment.
- ▌ acquiring-disk-image-with-dd-and-dcfldd · mukul975 bundleCreate forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
- ▌ analyzing-campaign-attribution-evidence · mukul975 bundleSystematically evaluates evidence to determine which threat actor is responsible for a cyber operation using the Diamond Model and Analysis of Competing Hypotheses.
- ▌ analyzing-cloud-storage-access-patterns · mukul975 bundleDetect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls, and potential data exfiltration using statistical baselines.
- ▌ analyzing-mft-for-deleted-file-recovery · mukul975 bundleRecover metadata and content of deleted files from NTFS volumes by analyzing the Master File Table, $LogFile, $UsnJrnl, and MFT slack space using forensic tools like MFTECmd and analyzeMFT.
- ▌ analyzing-network-traffic-for-incidents · mukul975 bundleAnalyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts.
- ▌ analyzing-ransomware-network-indicators · mukul975 bundleAnalyze Zeek conn.log and NetFlow data to detect ransomware network indicators including C2 beaconing, TOR exit node connections, data exfiltration, and suspicious DNS patterns.
- ▌ analyzing-usb-device-connection-history · mukul975 bundleInvestigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
- ▌ analyzing-web-server-logs-for-intrusion · mukul975 bundleParse Apache and Nginx access logs to detect SQL injection, LFI, XSS, scanner fingerprints, and brute-force patterns using regex-based detection, GeoIP enrichment, and statistical anomaly analysis.
- ▌ auditing-mcp-servers-for-tool-poisoning · mukul975 bundleScan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
- ▌ benchmarking-kubernetes-with-kube-bench · mukul975 bundleRun CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
- ▌ building-detection-rule-with-splunk-spl · mukul975 bundleBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
- ▌ building-patch-tuesday-response-process · mukul975 bundleEstablish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
- ▌ detecting-azure-service-principal-abuse · mukul975 bundleDetect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
- ▌ detecting-compromised-cloud-credentials · mukul975 bundleDetect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
- ▌ detecting-credential-dumping-techniques · mukul975 bundleDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules.
- ▌ detecting-email-forwarding-rules-attack · mukul975 bundleDetect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
- ▌ detecting-fileless-attacks-on-endpoints · mukul975 bundleDetects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Provides detection rules for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware.
- ▌ detecting-privilege-escalation-attempts · mukul975 bundleDetect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
- ▌ reverse-engineering-ios-app-with-frida · mukul975 bundleDynamically instrument iOS apps with Frida to trace methods, extract secrets, and bypass security controls during authorized penetration testing.
- ▌ detecting-s3-data-exfiltration-attempts · mukul975 bundleAnalyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3.
- ▌ detecting-serverless-function-injection · mukul975 bundleDetects and prevents code injection attacks targeting serverless functions through static analysis, event source poisoning detection, and IAM policy auditing.
- ▌ detecting-supply-chain-attacks-in-ci-cd · mukul975 bundleScans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.
- ▌ exploiting-constrained-delegation-abuse · mukul975 bundleExploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
- ▌ exploiting-mass-assignment-in-rest-apis · mukul975 bundleDiscover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
- ▌ extracting-credentials-from-memory-dump · mukul975 bundleExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
- ▌ extracting-memory-artifacts-with-rekall · mukul975 bundleAnalyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
- ▌ extracting-windows-event-logs-artifacts · mukul975 bundleExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
- ▌ hunting-for-unusual-network-connections · mukul975 bundleHunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
- ▌ implementing-aws-nitro-enclave-security · mukul975 bundleBuilds AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration, and secure vsock communication for processing sensitive data.
- ▌ implementing-code-signing-for-artifacts · mukul975 bundleSign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
- ▌ implementing-network-traffic-baselining · mukul975 bundleBuild network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling.
- ▌ implementing-ransomware-backup-strategy · mukul975 bundleDesigns and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology, including asset classification, immutable storage configuration, credential isolation, and automated restore testing.
- ▌ implementing-security-chaos-engineering · mukul975 bundleDeliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
- ▌ implementing-soar-playbook-for-phishing · mukul975 bundleAutomate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.
- ▌ implementing-zero-trust-with-beyondcorp · mukul975 bundleDeploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
- ▌ investigating-insider-threat-indicators · mukul975 bundleInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation.
- ▌ mapping-attack-paths-with-bloodhound-ce · mukul975 bundleCollect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
- ▌ performing-binary-exploitation-analysis · mukul975 bundleAnalyze ELF binaries for exploitation vectors using checksec, ROPgadget, and pwntools for buffer overflow and ROP chain development during authorized security testing and CTF challenges.
- ▌ performing-disk-forensics-investigation · mukul975 bundleConducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases.
- ▌ performing-graphql-introspection-attack · mukul975 bundleExtracts GraphQL API schemas through introspection attacks, identifies sensitive fields and mutations, and tests for query depth and complexity vulnerabilities.
- ▌ performing-insider-threat-investigation · mukul975 bundleInvestigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case.
- ▌ performing-nist-csf-maturity-assessment · mukul975 bundleConduct a maturity assessment against the NIST Cybersecurity Framework (CSF) 2.0, using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
- ▌ performing-privileged-account-discovery · mukul975 bundleDiscover and inventory privileged accounts across enterprise infrastructure, including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin accounts, with automated scanning, risk classification, and PAM onboarding.
- ▌ performing-ransomware-tabletop-exercise · mukul975 bundlePlans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures.
- ▌ performing-soc2-type2-audit-preparation · mukul975 bundleAutomates SOC 2 Type II audit preparation including gap assessment, evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring.
- ▌ reverse-engineering-malware-with-ghidra · mukul975 bundleReverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.
- ▌ securing-container-registry-with-harbor · mukul975 bundleConfigure and manage Harbor container registry with security features including vulnerability scanning, image signing, RBAC, content trust, and audit logging.
- ▌ analyzing-apt-group-with-mitre-navigator · mukul975 bundleQuery MITRE ATT&CK data programmatically, map APT group TTPs to Navigator layers, create multi-layer overlays for gap analysis, and generate actionable intelligence reports for detection engineering teams.
- ▌ analyzing-linux-audit-logs-for-intrusion · mukul975 bundleDetect intrusion attempts, unauthorized access, and privilege escalation on Linux hosts using the auditd framework with ausearch and aureport utilities.
- ▌ analyzing-network-flow-data-with-netflow · mukul975 bundleParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns using the Python netflow library.
- ▌ analyzing-network-traffic-with-wireshark · mukul975 bundleCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
- ▌ analyzing-supply-chain-malware-artifacts · mukul975 bundleInvestigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
- ▌ analyzing-windows-registry-for-artifacts · mukul975 bundleExtract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
- ▌ auditing-foundry-smart-contract-security · mukul975 bundleRuns a pre-deployment security audit of Solidity smart contracts in a Foundry project, combining static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing to catch reentrancy, access-control, and arithmetic bugs before deploying to an EVM chain.
- ▌ building-threat-actor-profile-from-osint · mukul975 bundleBuild comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
- ▌ building-vulnerability-scanning-workflow · mukul975 bundleEstablishes recurring vulnerability scanning workflows using Nessus, Qualys, or OpenVAS, prioritizes findings with risk scoring and CISA KEV data, integrates with SIEM for exploitation detection, and tracks remediation via SLA-based dashboards and automated ticketing.
- ▌ collecting-threat-intelligence-with-misp · mukul975 bundleDeploy MISP, configure threat feeds, use the PyMISP API for programmatic access, and build automated collection pipelines that aggregate IOCs from multiple community and commercial sources.
- ▌ conducting-post-incident-lessons-learned · mukul975 bundleFacilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
- ▌ configuring-aws-verified-access-for-ztna · mukul975 bundleConfigure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.
- ▌ detecting-ransomware-encryption-behavior · mukul975 bundleDetects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics.
- ▌ evaluating-threat-intelligence-platforms · mukul975 bundleEvaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership.
- ▌ exploiting-api-injection-vulnerabilities · mukul975 bundleTests APIs for injection vulnerabilities including SQL, NoSQL, OS command, LDAP, and SSRF through parameters, headers, and request bodies.
- ▌ exploiting-bgp-hijacking-vulnerabilities · mukul975 bundleSimulates BGP hijacking attacks in isolated lab environments to test RPKI deployment, route origin validation, and BGP monitoring defenses against prefix hijacking and route leak attacks.
- ▌ exploiting-type-juggling-vulnerabilities · mukul975 bundleExploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
- ▌ hunting-bootkits-in-efi-system-partition · mukul975 bundleBaseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
- ▌ hunting-for-data-exfiltration-indicators · mukul975 bundleAnalyze network traffic, logs, and data flows to detect potential data exfiltration via DNS tunneling, cloud storage uploads, encrypted channels, and other indicators of compromise.
- ▌ hunting-for-living-off-the-land-binaries · mukul975 bundleProactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
- ▌ hunting-for-process-injection-techniques · mukul975 bundleDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry.
- ▌ hunting-for-registry-run-key-persistence · mukul975 bundleDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
- ▌ implementing-aws-security-hub-compliance · mukul975 bundleAggregate security findings across AWS accounts, enable compliance standards like CIS and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
- ▌ implementing-devsecops-security-scanning · mukul975 bundleIntegrates SAST, DAST, and SCA security scanning into CI/CD pipelines using open-source tools like Semgrep, Trivy, OWASP ZAP, and Gitleaks.
- ▌ implementing-llm-guardrails-for-security · mukul975 bundleBuilds input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs using NeMo Guardrails, Presidio, and Guardrails AI.
- ▌ implementing-log-forwarding-with-fluentd · mukul975 bundleConfigure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure.
- ▌ implementing-network-segmentation-for-ot · mukul975 bundleDesign and implement network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking, following the Purdue Model and IEC 62443 standards.
- ▌ implementing-pci-dss-compliance-controls · mukul975 bundleImplement PCI DSS 4.0.1 compliance controls across all 12 requirements, including scoping, network security, data protection, access controls, monitoring, and governance.
- ▌ implementing-scim-provisioning-with-okta · mukul975 bundleBuild a SCIM 2.0-compliant API server and integrate it with Okta for automated user provisioning, deprovisioning, profile updates, and group management.
- ▌ implementing-stix-taxii-feed-integration · mukul975 bundleConsume and produce STIX/TAXII 2.1 cyber threat intelligence feeds using Python, including server discovery, collection polling, object parsing, and SIEM/TIP integration.
- ▌ implementing-taxii-server-with-opentaxii · mukul975 bundleDeploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
- ▌ implementing-zero-trust-dns-with-nextdns · mukul975 bundleConfigure NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
- ▌ performing-bluetooth-security-assessment · mukul975 bundleScan for Bluetooth Low Energy devices, enumerate GATT services and characteristics, and detect security vulnerabilities such as unencrypted data exposure and known vulnerable device fingerprints.
- ▌ performing-cloud-forensics-investigation · mukul975 bundleCollect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments.
- ▌ performing-dynamic-analysis-with-any-run · mukul975 bundlePerforms interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes.
- ▌ performing-initial-access-with-evilginx3 · mukul975 bundleConduct authorized red team initial access using EvilGinx3 adversary-in-the-middle phishing to capture session tokens and bypass multi-factor authentication.
- ▌ performing-lateral-movement-with-wmiexec · mukul975 bundleExecute remote commands on Windows targets using WMI-based lateral movement techniques, including Impacket wmiexec.py, CrackMapExec, and native PowerShell WMI commands for red team engagements.
- ▌ performing-log-source-onboarding-in-siem · mukul975 bundleIntegrate new data sources into SIEM platforms by configuring collectors, parsers, normalization, and validation for security monitoring.
- ▌ performing-physical-intrusion-assessment · mukul975 bundleConduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
- ▌ exploiting-sql-injection-vulnerabilities · mukul975 bundleIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.
- ▌ performing-privilege-escalation-on-linux · mukul975 bundleElevate from a low-privilege user account to root access on a compromised Linux system by exploiting misconfigurations, vulnerable services, kernel exploits, and weak permissions.
- ▌ performing-scada-hmi-security-assessment · mukul975 bundleAssess security of SCADA HMI systems by evaluating authentication, communication, web interfaces, and hardening against IEC 62443 and NIST SP 800-82 guidelines.
- ▌ securing-remote-access-to-ot-environment · mukul975 bundleImplements secure remote access architecture for OT/ICS environments with jump servers, MFA, session recording, and privileged access management.
- ▌ validating-backup-integrity-for-recovery · mukul975 bundleValidate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
- ▌ validating-tpm-measured-boot-attestation · mukul975 bundleVerify TPM measured boot integrity and remote attestation using tpm2-tools, including PCR reading, event log replay, quote generation and verification, and golden baseline comparison.
- ▌ analyzing-azure-activity-logs-for-threats · mukul975 bundleQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
- ▌ analyzing-ios-app-security-with-objection · mukul975 bundlePerform runtime iOS app security assessments using Objection and Frida to inspect keychain, filesystem, and memory, bypass client-side protections, and evaluate data storage, network, and authentication controls during authorized penetration tests.
- ▌ analyzing-outlook-pst-for-email-forensics · mukul975 bundleAnalyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
- ▌ analyzing-persistence-mechanisms-in-linux · mukul975 bundleDetect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring.
- ▌ analyzing-powershell-script-block-logging · mukul975 bundleParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.
- ▌ analyzing-windows-lnk-files-for-artifacts · mukul975 bundleParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
- ▌ assessing-vector-and-embedding-weaknesses · mukul975 bundleTest vector stores for embedding inversion, cross-tenant leakage, and poisoning.
- ▌ attacking-oauth-with-device-code-phishing · mukul975 bundleExecute OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services during authorized red-team engagements.
- ▌ building-threat-hunt-hypothesis-framework · mukul975 bundleTransform threat intelligence and attack patterns into testable hunting hypotheses for proactive threat detection.
- ▌ conducting-domain-persistence-with-dcsync · mukul975 bundleExtract Active Directory credentials via DCSync attacks and establish domain persistence by dumping KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
- ▌ conducting-full-scope-red-team-engagement · mukul975 bundlePlan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.
- ▌ configuring-active-directory-tiered-model · mukul975 bundleImplement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations, and credential theft mitigation.
- ▌ continuous-llm-red-teaming-with-promptfoo · mukul975 bundleWire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
- ▌ detecting-exfiltration-over-dns-with-zeek · mukul975 bundleAnalyze Zeek dns.log files to detect DNS-based data exfiltration by computing Shannon entropy, flagging long subdomain labels, and identifying anomalous query patterns.
- ▌ detecting-living-off-the-land-with-lolbas · mukul975 bundleDetect abuse of legitimate Windows binaries (LOLBins) like certutil, regsvr32, mshta, and rundll32 using process telemetry, Sigma rules, and parent-child process analysis.
- ▌ detecting-suspicious-powershell-execution · mukul975 bundleDetect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
- ▌ eradicating-malware-from-infected-systems · mukul975 bundleSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
- ▌ exploiting-excessive-data-exposure-in-api · mukul975 bundleTests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. Maps to OWASP API3:2023 Broken Object Property Level Authorization.
- ▌ exploiting-jwt-algorithm-confusion-attack · mukul975 bundleExploit JWT algorithm confusion vulnerabilities by manipulating the alg header to switch from RS256 to HS256, set alg to none, or inject kid/jku/x5u headers to bypass signature verification.
- ▌ exploiting-race-condition-vulnerabilities · mukul975 bundleDetect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
- ▌ hunting-for-command-and-control-beaconing · mukul975 bundleDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
- ▌ hunting-for-unusual-service-installations · mukul975 bundleDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
- ▌ implementing-anti-ransomware-group-policy · mukul975 bundleHardens Windows Active Directory environments against ransomware by configuring Group Policy Objects with AppLocker rules, Controlled Folder Access, Attack Surface Reduction rules, and lateral movement restrictions.
- ▌ implementing-immutable-backup-with-restic · mukul975 bundleImplements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection, automating backup creation, integrity verification, snapshot retention, and restore testing.
- ▌ implementing-jwt-signing-and-verification · mukul975 bundleImplement secure JWT signing and verification with HMAC-SHA256, RSA-PSS, and EdDSA, including token expiration, claims validation, and defense against common JWT attacks.
- ▌ implementing-mtls-for-zero-trust-services · mukul975 bundleGenerates CA and service certificates, then configures mutual TLS authentication between microservices using Python's cryptography and ssl modules.
- ▌ implementing-nerc-cip-compliance-controls · mukul975 bundleCategorize BES cyber systems and implement NERC CIP compliance controls for high, medium, and low impact assets, including electronic security perimeters, configuration management, and supply chain risk management.
- ▌ implementing-siem-use-cases-for-detection · mukul975 bundleDesign, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
- ▌ implementing-soar-automation-with-phantom · mukul975 bundleAutomates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.
- ▌ investigating-ransomware-attack-artifacts · mukul975 bundleIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
- ▌ monitoring-scada-modbus-traffic-anomalies · mukul975 bundleMonitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns using deep packet inspection with pymodbus, Scapy, and Zeek.
- ▌ performing-alert-triage-with-elastic-siem · mukul975 bundlePerform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.
- ▌ performing-arp-spoofing-attack-simulation · mukul975 bundleSimulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
- ▌ performing-credential-access-with-lazagne · mukul975 bundleExtract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
- ▌ performing-indicator-lifecycle-management · mukul975 bundleTracks indicators of compromise from initial discovery through validation, enrichment, deployment, monitoring, and retirement to maintain a high-quality, actionable indicator database.
- ▌ performing-kubernetes-penetration-testing · mukul975 bundleSystematically evaluates Kubernetes cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets using tools like kube-hunter, Kubescape, and kube-bench.
- ▌ performing-ot-network-security-assessment · mukul975 bundleConduct comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths, addressing the Purdue Reference Model layers and identifying IT/OT convergence risks.
- ▌ deploying-osquery-for-endpoint-monitoring · mukul975 bundleDeploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.
- ▌ performing-plc-firmware-security-analysis · mukul975 bundleAnalyze PLC firmware for security vulnerabilities including hardcoded credentials, insecure updates, backdoors, memory corruption, and undocumented debug interfaces using static and dynamic analysis techniques.
- ▌ performing-red-team-phishing-with-gophish · mukul975 bundleAutomates GoPhish phishing simulation campaigns using the Python gophish library to create email templates, configure SMTP profiles, import targets, launch campaigns, and analyze results for security awareness assessment.
- ▌ performing-supply-chain-attack-simulation · mukul975 bundleSimulate and detect software supply chain attacks including typosquatting via Levenshtein distance, dependency confusion testing, package hash verification, and vulnerability scanning with pip-audit.
- ▌ performing-threat-hunting-with-yara-rules · mukul975 bundleScan files, directories, and memory dumps using YARA rules to identify malware families, suspicious patterns, and IOC matches.
- ▌ testing-for-open-redirect-vulnerabilities · mukul975 bundleIdentify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
- ▌ testing-for-xml-injection-vulnerabilities · mukul975 bundleTest web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
- ▌ testing-for-xxe-injection-vulnerabilities · mukul975 bundleDiscover and exploit XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
- ▌ testing-prompt-injection-in-rag-pipelines · mukul975 bundleProbe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
- ▌ analyzing-browser-forensics-with-hindsight · mukul975 bundleExtract and analyze Chromium-based browser artifacts using Hindsight to reconstruct user web activity for forensic investigations.
- ▌ analyzing-lnk-file-and-jump-list-artifacts · mukul975 bundleAnalyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
- ▌ analyzing-packed-malware-with-upx-unpacker · mukul975 bundleIdentifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis.
- ▌ auditing-tls-certificate-transparency-logs · mukul975 bundleMonitors Certificate Transparency logs to detect unauthorized certificate issuance, discover subdomains, and alert on suspicious certificate activity for owned domains.
- ▌ building-devsecops-pipeline-with-gitlab-ci · mukul975 bundleDesign and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
- ▌ building-incident-timeline-with-timesketch · mukul975 bundleBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
- ▌ building-role-mining-for-rbac-optimization · mukul975 bundleApply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
- ▌ building-threat-feed-aggregation-with-misp · mukul975 bundleDeploy MISP to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
- ▌ conducting-social-engineering-pretext-call · mukul975 bundlePlan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
- ▌ configuring-host-based-intrusion-detection · mukul975 bundleDeploys and configures host-based intrusion detection systems (Wazuh, OSSEC, AIDE) to monitor file integrity, system calls, and configuration changes across endpoints. Includes FIM policies, rootkit detection, custom alert rules, active response, and SIEM integration.
- ▌ deploying-cloudflare-access-for-zero-trust · mukul975 bundleDeploy Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
- ▌ detecting-arp-poisoning-in-network-traffic · mukul975 bundleDetect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom Python monitoring scripts to protect against man-in-the-middle interception.
- ▌ detecting-modbus-command-injection-attacks · mukul975 bundleDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines.
- ▌ performing-content-security-policy-bypass · mukul975 bundleAnalyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
- ▌ detecting-spearphishing-with-email-gateway · mukul975 bundleConfigure email security gateways like Microsoft Defender, Proofpoint, and Mimecast to detect and block targeted spearphishing attacks using impersonation protection, URL detonation, and attachment sandboxing.
- ▌ exploiting-insecure-data-storage-in-mobile · mukul975 bundleIdentifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications, including unencrypted databases, world-readable files, and plaintext credential storage.
- ▌ exploiting-nosql-injection-vulnerabilities · mukul975 bundleDetect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
- ▌ hardening-docker-containers-for-production · mukul975 bundleApply CIS Docker Benchmark v1.8.0 security best practices to harden Docker containers for production, covering daemon configuration, image building, runtime controls, and auditing.
- ▌ hunting-for-anomalous-powershell-execution · mukul975 bundleHunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events from Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles.
- ▌ implementing-api-gateway-security-controls · mukul975 bundleConfigures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) as a centralized security enforcement point with authentication, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection.
- ▌ implementing-aws-iam-permission-boundaries · mukul975 bundleConfigure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.
- ▌ implementing-cloud-dlp-for-data-protection · mukul975 bundleDiscover, classify, and protect sensitive data across cloud storage, databases, and data pipelines using Amazon Macie, Azure Information Protection, and Google Cloud DLP API.
- ▌ implementing-delinea-secret-server-for-pam · mukul975 bundleDeploys and configures Delinea Secret Server for privileged access management, including secret vault setup, role-based access policies, automated password rotation, session recording, and Active Directory integration.
- ▌ implementing-dmarc-dkim-spf-email-security · mukul975 bundlePrevent domain spoofing and phishing by implementing SPF, DKIM, and DMARC email authentication protocols with DNS configuration and validation.
- ▌ implementing-endpoint-detection-with-wazuh · mukul975 bundleDeploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
- ▌ implementing-gdpr-data-protection-controls · mukul975 bundleImplement technical and organizational measures required by GDPR, including data mapping, DPIAs, data subject rights management, breach notification, and cross-border transfer mechanisms.
- ▌ implementing-log-integrity-with-blockchain · mukul975 bundleBuild an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes.
- ▌ implementing-mitre-attack-coverage-mapping · mukul975 bundleMap MITRE ATT&CK coverage to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
- ▌ implementing-mobile-application-management · mukul975 bundleDeploys Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization.
- ▌ implementing-ot-incident-response-playbook · mukul975 bundleDevelop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
- ▌ analyzing-ransomware-encryption-mechanisms · mukul975 bundleAnalyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts.
- ▌ implementing-privileged-access-workstation · mukul975 bundleDesign and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
- ▌ implementing-privileged-session-monitoring · mukul975 bundleConfigure privileged session monitoring and recording using CyberArk PSM or open-source alternatives like Teleport, with keystroke logging, real-time alerts, and compliance audit trails.
- ▌ implementing-rapid7-insightvm-for-scanning · mukul975 bundleDeploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
- ▌ implementing-rbac-hardening-for-kubernetes · mukul975 bundleHarden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
- ▌ implementing-secret-scanning-with-gitleaks · mukul975 bundleDetect and prevent hardcoded secrets in git repositories using Gitleaks, including pre-commit hooks, CI/CD integration, custom rules, baseline management, and remediation workflows.
- ▌ implementing-secrets-management-with-vault · mukul975 bundleCentralize secrets management with HashiCorp Vault, including dynamic secret generation, transit encryption, PKI certificate management, and Kubernetes integration.
- ▌ implementing-semgrep-for-custom-sast-rules · mukul975 bundleWrite custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.
- ▌ implementing-sigstore-for-software-signing · mukul975 bundleSigns and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls.
- ▌ implementing-vulnerability-remediation-sla · mukul975 bundleDefine and enforce vulnerability remediation SLAs based on severity, asset criticality, and exploit availability to drive accountability and track compliance.
- ▌ intercepting-mobile-traffic-with-burpsuite · mukul975 bundleIntercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities.
- ▌ performing-access-review-and-certification · mukul975 bundleConduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles, covering review campaign design, reviewer selection, risk-based prioritization, and remediation tracking for compliance with SOX, HIPAA, and PCI DSS.
- ▌ detecting-ransomware-precursors-in-network · mukul975 bundleDetects early-stage ransomware indicators in network traffic before encryption begins, using Zeek, Suricata, Arkime, SIEM correlation rules, and threat intelligence feeds to identify Cobalt Strike beacons, Mimikatz signatures, and RDP brute-force attempts.
- ▌ performing-authenticated-scan-with-openvas · mukul975 bundleConfigure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.
- ▌ performing-dark-web-monitoring-for-threats · mukul975 bundleScan Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked credentials, data breaches, and threat actor discussions.
- ▌ performing-deception-technology-deployment · mukul975 bundleDeploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates.
- ▌ performing-http-parameter-pollution-attack · mukul975 bundleExecute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
- ▌ performing-network-packet-capture-analysis · mukul975 bundleAnalyze network packet captures (PCAP/PCAPNG) using Wireshark, tshark, tcpdump, and Python to reconstruct communications, extract files, and identify malicious traffic.
- ▌ performing-oauth-scope-minimization-review · mukul975 bundleAudits OAuth 2.0 permissions across identity providers to identify over-privileged third-party integrations, excessive API scopes, and unused token grants, enforcing least-privilege access.
- ▌ performing-privilege-escalation-assessment · mukul975 bundlePerforms privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control.
- ▌ performing-ssrf-vulnerability-exploitation · mukul975 bundleTest for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters.
- ▌ performing-web-application-firewall-bypass · mukul975 bundleBypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
- ▌ scanning-kubernetes-manifests-with-kubesec · mukul975 bundleScan Kubernetes resource manifests with Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
- ▌ testing-for-business-logic-vulnerabilities · mukul975 bundleIdentify flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what automated scanners can detect.
- ▌ testing-for-json-web-token-vulnerabilities · mukul975 bundleTest JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
- ▌ analyzing-command-and-control-communication · mukul975 bundleAnalyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure for detection development and threat intelligence.
- ▌ analyzing-macro-malware-in-office-documents · mukul975 bundleExtracts and analyzes malicious VBA macros, XLM macros, DDE, and remote template injections in Microsoft Office documents using olevba, oledump, and deobfuscation techniques to identify download cradles, payload execution, and persistence mechanisms.
- ▌ analyzing-malware-persistence-with-autoruns · mukul975 bundleIdentify and analyze malware persistence mechanisms on Windows systems using Sysinternals Autoruns, covering registry keys, scheduled tasks, services, drivers, and startup locations.
- ▌ analyzing-ransomware-leak-site-intelligence · mukul975 bundleMonitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
- ▌ analyzing-tls-certificate-transparency-logs · mukul975 bundleQueries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance.
- ▌ building-ioc-defanging-and-sharing-pipeline · mukul975 bundleBuild an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
- ▌ building-phishing-reporting-button-workflow · mukul975 bundleDeploy a phishing report button in email clients and build an automated triage workflow that analyzes user-reported suspicious emails, extracts IOCs, and provides feedback to reporters.
- ▌ conducting-memory-forensics-with-volatility · mukul975 bundleAnalyze RAM dumps with Volatility 3 to detect malware, process injection, network connections, and credential theft during incident response.
- ▌ configuring-network-segmentation-with-vlans · mukul975 bundleDesigns and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
- ▌ configuring-suricata-for-network-monitoring · mukul975 bundleDeploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
- ▌ configuring-zscaler-private-access-for-ztna · mukul975 bundleReplace traditional VPNs with zero trust network access by deploying Zscaler Private Access, configuring App Connectors, defining application segments, and setting identity-based access policies.
- ▌ deobfuscating-powershell-obfuscated-malware · mukul975 bundleSystematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
- ▌ detecting-ai-model-prompt-injection-attacks · mukul975 bundleDetects prompt injection attacks targeting LLM-based applications using regex pattern matching, heuristic scoring, and DeBERTa transformer classification.
- ▌ detecting-anomalous-authentication-patterns · mukul975 bundleDetects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs.
- ▌ detecting-aws-guardduty-findings-automation · mukul975 bundleAutomate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
- ▌ detecting-business-email-compromise-with-ai · mukul975 bundleDeploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
- ▌ detecting-container-escape-with-falco-rules · mukul975 bundleDetect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
- ▌ performing-cloud-log-forensics-with-athena · mukul975 bundleQuery AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
- ▌ detecting-dcsync-attack-in-active-directory · mukul975 bundleDetect DCSync attacks by monitoring Active Directory replication requests from non-domain-controller accounts via Event ID 4662 and associated GUIDs.
- ▌ detecting-deepfake-audio-in-vishing-attacks · mukul975 bundleDetects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features and classifying samples with machine learning models.
- ▌ detecting-insider-data-exfiltration-via-dlp · mukul975 bundleDetects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs using pandas for behavioral analytics and statistical baselines.
- ▌ performing-dynamic-analysis-of-android-app · mukul975 bundlePerforms runtime dynamic analysis of Android applications using Frida, Objection, and ADB to observe behavior, intercept function calls, modify runtime values, and identify vulnerabilities missed by static analysis.
- ▌ detecting-ntlm-relay-with-event-correlation · mukul975 bundleDetect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, and auditing SMB and LDAP signing enforcement.
- ▌ detecting-t1003-credential-dumping-with-edr · mukul975 bundleDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
- ▌ executing-nist-rmf-authorization-to-operate · mukul975 bundleGuide federal systems through the NIST Risk Management Framework (SP 800-37 Rev 2) to achieve an Authorization to Operate (ATO), covering categorization, control selection, assessment, and continuous monitoring.
- ▌ exploiting-active-directory-with-bloodhound · mukul975 bundleGraph-based Active Directory reconnaissance tool that reveals hidden relationships and attack paths from compromised accounts to high-value targets like Domain Admins.
- ▌ generating-forensic-timelines-with-hayabusa · mukul975 bundleGenerate Sigma-based forensic timelines from Windows EVTX files using Hayabusa for incident response triage.
- ▌ hardening-linux-endpoint-with-cis-benchmark · mukul975 bundleHardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.
- ▌ hunting-for-living-off-the-cloud-techniques · mukul975 bundleHunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration across Azure, AWS, GCP, and SaaS platforms.
- ▌ hunting-for-registry-persistence-mechanisms · mukul975 bundleHunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
- ▌ implementing-anti-phishing-training-program · mukul975 bundleDesign, deploy, and measure a comprehensive phishing awareness program using platforms like KnowBe4, Proofpoint, and open-source alternatives.
- ▌ implementing-api-schema-validation-security · mukul975 bundleEnforce API input/output contracts using OpenAPI specifications and JSON Schema to prevent injection, mass assignment, and data leakage attacks.
- ▌ implementing-cisa-zero-trust-maturity-model · mukul975 bundleAssess and implement the CISA Zero Trust Maturity Model v2.0 across identity, devices, networks, applications, and data pillars to achieve progressive zero trust maturity.
- ▌ implementing-disk-encryption-with-bitlocker · mukul975 bundleEncrypts Windows endpoints using Microsoft BitLocker to protect data at rest, covering TPM configuration, GPO settings, Intune deployment, and recovery key management for compliance requirements.
- ▌ implementing-hipaa-security-rule-safeguards · mukul975 bundleConduct HIPAA Security Rule risk analysis, implement administrative, physical, and technical safeguards, manage Business Associate Agreements, and establish breach-notification readiness for covered entities and business associates.
- ▌ implementing-runtime-security-with-tetragon · mukul975 bundleImplement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
- ▌ implementing-siem-correlation-rules-for-apt · mukul975 bundleDetect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
- ▌ implementing-ticketing-system-for-incidents · mukul975 bundleAutomates incident ticketing by connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured tracking, SLA management, escalation workflows, and compliance documentation.
- ▌ implementing-velociraptor-for-ir-collection · mukul975 bundleDeploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
- ▌ integrating-dast-with-owasp-zap-in-pipeline · mukul975 bundleIntegrates OWASP ZAP for Dynamic Application Security Testing in CI/CD pipelines, configuring baseline, full, and API scans, interpreting findings, tuning policies, and establishing quality gates in GitHub Actions and GitLab CI.
- ▌ parsing-artifacts-with-eric-zimmerman-tools · mukul975 bundleParse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
- ▌ performing-agentless-vulnerability-scanning · mukul975 bundleConfigure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
- ▌ performing-authenticated-vulnerability-scan · mukul975 bundleRun authenticated vulnerability scans using valid credentials to deeply inspect target systems for missing patches, misconfigurations, and security weaknesses.
- ▌ performing-dmarc-policy-enforcement-rollout · mukul975 bundleExecute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
- ▌ performing-docker-bench-security-assessment · mukul975 bundleAudits Docker host and daemon configuration against the CIS Docker Benchmark, generating compliance reports with pass/fail/warn results and remediation steps.
- ▌ performing-endpoint-forensics-investigation · mukul975 bundleConducts digital forensics investigations on compromised endpoints, including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction for incident response and evidence collection.
- ▌ performing-false-positive-reduction-in-siem · mukul975 bundleSystematically reduce SIEM false positives through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
- ▌ performing-firmware-extraction-with-binwalk · mukul975 bundleExtracts and analyzes firmware images using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis, recursive extraction, filesystem mounting, and string analysis for credential and configuration discovery.
- ▌ performing-ics-asset-discovery-with-claroty · mukul975 bundleDiscover and inventory ICS/OT assets using Claroty xDome, including passive monitoring, active queries, and integration with CMDB tools.
- ▌ performing-network-forensics-with-wireshark · mukul975 bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
- ▌ performing-oil-gas-cybersecurity-assessment · mukul975 bundleConduct cybersecurity assessments for oil and gas facilities, covering upstream, midstream, and downstream operations, including SCADA, DCS, and safety systems, with compliance mapping to API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST CSF.
- ▌ performing-ot-vulnerability-scanning-safely · mukul975 bundlePerform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
- ▌ performing-phishing-simulation-with-gophish · mukul975 bundleDeploy GoPhish, create phishing scenarios, and analyze campaign results to measure organizational resilience against phishing attacks.
- ▌ performing-privileged-account-access-review · mukul975 bundleConduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
- ▌ performing-ssl-tls-inspection-configuration · mukul975 bundleConfigure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
- ▌ performing-threat-hunting-with-elastic-siem · mukul975 bundleProactively search for threats in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection.
- ▌ performing-web-application-penetration-test · mukul975 bundleSystematically tests web applications for vulnerabilities following the OWASP Web Security Testing Guide (WSTG) methodology, covering authentication, authorization, input validation, session management, and business logic using Burp Suite and manual techniques.
- ▌ securing-historian-server-in-ot-environment · mukul975 bundleHardens and secures process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments, covering network placement, access control, data replication through DMZ, SQL injection prevention, and data integrity protection.
- ▌ triaging-security-incident-with-ir-playbook · mukul975 bundleClassify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
- ▌ analyzing-cobalt-strike-beacon-configuration · mukul975 bundleExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
- ▌ analyzing-cobaltstrike-malleable-c2-profiles · mukul975 bundleParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
- ▌ analyzing-malware-sandbox-evasion-techniques · mukul975 bundleDetect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
- ▌ analyzing-network-covert-channels-in-malware · mukul975 bundleDetect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and protocol abuse for C2 and data exfiltration.
- ▌ conducting-internal-network-penetration-test · mukul975 bundleSimulate an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within a corporate network.
- ▌ conducting-spearphishing-simulation-campaign · mukul975 bundlePlan and execute authorized spearphishing simulations for red team engagements, covering pretext development, payload creation, infrastructure setup, campaign execution, and post-campaign analysis.
- ▌ conducting-wireless-network-penetration-test · mukul975 bundleAssess the security of WiFi infrastructure through authorized penetration testing, including weak encryption detection, handshake capture, evil twin attacks, and network segmentation validation.
- ▌ configuring-microsegmentation-for-zero-trust · mukul975 bundleDesign and enforce microsegmentation policies using workload identity and label-based rules to prevent lateral movement in zero trust architectures, with guidance for tools like VMware NSX, Illumio, and Calico.
- ▌ deploying-palo-alto-prisma-access-zero-trust · mukul975 bundleDeploy Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager.
- ▌ detecting-typosquatting-packages-in-npm-pypi · mukul975 bundleDetects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity, publish date heuristics, and download count anomalies.
- ▌ executing-active-directory-attack-simulation · mukul975 bundleExecutes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
- ▌ exploiting-prototype-pollution-in-javascript · mukul975 bundleDetect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
- ▌ hunting-for-data-staging-before-exfiltration · mukul975 bundleDetect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry.
- ▌ hunting-for-defense-evasion-via-timestomping · mukul975 bundleDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT using analyzeMFT and Python.
- ▌ implementing-aes-encryption-for-data-at-rest · mukul975 bundleImplement AES-256-GCM encryption for files and data at rest, including key derivation, IV management, and authenticated encryption.
- ▌ implementing-api-security-posture-management · mukul975 bundleContinuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.
- ▌ implementing-aws-config-rules-for-compliance · mukul975 bundleDeploy AWS Config rules for continuous compliance monitoring, including managed and custom rules aligned to CIS and PCI DSS frameworks, automatic remediation with SSM Automation, and multi-account compliance aggregation.
- ▌ implementing-ddos-mitigation-with-cloudflare · mukul975 bundleConfigure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
- ▌ implementing-digital-signatures-with-ed25519 · mukul975 bundleImplement Ed25519 digital signatures for document signing, code signing, and API authentication using Python.
- ▌ implementing-google-workspace-admin-security · mukul975 bundleHardens Google Workspace environments by configuring super admin accounts, phishing-resistant MFA, email authentication (SPF/DKIM/DMARC), DLP policies, OAuth app controls, and external sharing restrictions.
- ▌ implementing-hashicorp-vault-dynamic-secrets · mukul975 bundleConfigures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation.
- ▌ implementing-memory-protection-with-dep-aslr · mukul975 bundleConfigures memory protection mechanisms including DEP, ASLR, CFG, and Windows Exploit Protection to harden endpoints against buffer overflows, ROP chains, and code injection.
- ▌ implementing-network-policies-for-kubernetes · mukul975 bundleCreate and apply Kubernetes NetworkPolicies to enforce pod-level network segmentation, restrict traffic between pods and namespaces, and block access to cloud metadata endpoints.
- ▌ implementing-patch-management-for-ot-systems · mukul975 bundleEstablish a structured patch management program for OT/ICS environments, covering vendor compatibility testing, risk-based prioritization, staged deployment, rollback procedures, and compensating controls for unpatchable systems.
- ▌ performing-active-directory-penetration-test · mukul975 bundleEnumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
- ▌ performing-cloud-native-forensics-with-falco · mukul975 bundleDeploys and manages Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Parses Falco alerts for incident response.
- ▌ performing-dns-enumeration-and-zone-transfer · mukul975 bundleEnumerate DNS records, attempt zone transfers, brute-force subdomains, and map DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.
- ▌ performing-external-network-penetration-test · mukul975 bundleConduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.
- ▌ performing-linux-log-forensics-investigation · mukul975 bundleAnalyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
- ▌ testing-android-intents-for-vulnerabilities · mukul975 bundleTests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage.
- ▌ performing-malware-persistence-investigation · mukul975 bundleSystematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
- ▌ performing-memory-forensics-with-volatility3 · mukul975 bundleAnalyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
- ▌ performing-s7comm-protocol-security-analysis · mukul975 bundleAnalyze Siemens S7comm and S7CommPlus protocol traffic to identify vulnerabilities such as replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation in SIMATIC S7 PLCs.
- ▌ performing-sca-dependency-scanning-with-snyk · mukul975 bundleScan open-source dependencies for known vulnerabilities using Snyk, including CI/CD integration, automated fix PRs, license compliance, and continuous monitoring.
- ▌ performing-soap-web-service-security-testing · mukul975 bundleAnalyze WSDL definitions and test SOAP endpoints for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
- ▌ performing-wireless-network-penetration-test · mukul975 bundleExecute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
- ▌ triaging-vulnerabilities-with-ssvc-framework · mukul975 bundleTriage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
- ▌ analyzing-office365-audit-logs-for-compromise · mukul975 bundleParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ analyzing-threat-actor-ttps-with-mitre-attack · mukul975 bundleMap threat actor behavior to the MITRE ATT&CK framework, build technique coverage heatmaps, identify detection gaps, and produce actionable intelligence reports.
- ▌ analyzing-typosquatting-domains-with-dnstwist · mukul975 bundleDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
- ▌ auditing-azure-active-directory-configuration · mukul975 bundleAudit Microsoft Entra ID (Azure Active Directory) configuration for risky authentication policies, over-privileged role assignments, stale accounts, conditional access gaps, and guest user risks using PowerShell, Graph API, and ScoutSuite.
- ▌ auditing-kubernetes-rbac-privilege-escalation · mukul975 bundleFind over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
- ▌ building-ioc-enrichment-pipeline-with-opencti · mukul975 bundleBuild an automated IOC enrichment pipeline using OpenCTI's connector ecosystem to enrich indicators with context from VirusTotal, Shodan, AbuseIPDB, GreyNoise, and other sources.
- ▌ building-threat-intelligence-feed-integration · mukul975 bundleAutomates ingestion, normalization, deduplication, and distribution of threat intelligence feeds from STIX/TAXII, open-source, and commercial sources into SIEM platforms for real-time IOC matching and alerting.
- ▌ building-vulnerability-aging-and-sla-tracking · mukul975 bundleTrack vulnerability aging and SLA compliance with severity-based remediation timelines, automated escalations, and compliance metrics.
- ▌ bypassing-authentication-with-forced-browsing · mukul975 bundleDiscover hidden directories, files, APIs, and administrative interfaces by enumerating URLs and testing authentication enforcement during authorized security assessments.
- ▌ conducting-external-reconnaissance-with-osint · mukul975 bundleMaps an organization's external attack surface using public sources like DNS records, certificate transparency logs, search engines, social media, and data breach databases, without directly interacting with target systems.
- ▌ configuring-snort-ids-for-intrusion-detection · mukul975 bundleInstalls, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments.
- ▌ configuring-tls-1-3-for-secure-communications · mukul975 bundleConfigure TLS 1.3 on nginx, Apache, and Python applications, validate configurations with openssl and testssl.sh, and disable legacy TLS versions.
- ▌ detecting-entra-offensive-tools-in-graph-logs · mukul975 bundleHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
- ▌ detecting-evasion-techniques-in-endpoint-logs · mukul975 bundleDetects defense evasion techniques in endpoint logs, including log tampering, timestomping, process injection, and security tool disabling, using Sysmon, EDR telemetry, and SIEM queries.
- ▌ detecting-t1055-process-injection-with-sysmon · mukul975 bundleDetect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
- ▌ emulating-cloud-attacks-with-stratus-red-team · mukul975 bundleDetonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
- ▌ exploiting-ms17-010-eternalblue-vulnerability · mukul975 bundleExploits the MS17-010 (EternalBlue) vulnerability in Microsoft's SMBv1 implementation for authorized security testing, red team exercises, and penetration testing engagements.
- ▌ exploiting-template-injection-vulnerabilities · mukul975 bundleDetect and exploit Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution during authorized penetration tests.
- ▌ hardening-windows-endpoint-with-cis-benchmark · mukul975 bundleHardens Windows endpoints using CIS Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.
- ▌ hunting-for-beaconing-with-frequency-analysis · mukul975 bundleIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
- ▌ performing-api-security-testing-with-postman · mukul975 bundleBuilds repeatable API security test suites in Postman covering OWASP API Security Top 10 vulnerabilities, with automated authentication, multi-role testing, and CI/CD integration via Newman.
- ▌ hunting-for-persistence-mechanisms-in-windows · mukul975 bundleSystematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
- ▌ hunting-for-persistence-via-wmi-subscriptions · mukul975 bundleHunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
- ▌ implementing-api-rate-limiting-and-throttling · mukul975 bundleProtect APIs from abuse and resource exhaustion by implementing rate limiting with token bucket, sliding window, and fixed window algorithms using Redis-backed counters, API gateway plugins, or application middleware.
- ▌ implementing-browser-isolation-for-zero-trust · mukul975 bundleDeploys remote browser isolation (RBI) as a core component of a Zero Trust architecture, implementing isolation policies with URL categorization, risk-based routing, content disarming and reconstruction (CDR), and data loss prevention controls.
- ▌ implementing-email-sandboxing-with-proofpoint · mukul975 bundleConfigure Proofpoint Targeted Attack Protection (TAP) to detonate suspicious attachments and URLs in isolated sandboxes, integrate with email flow, analyze reports, and tune detection policies.
- ▌ implementing-envelope-encryption-with-aws-kms · mukul975 bundleEncrypt large data volumes locally using envelope encryption with AWS KMS, generating data keys and managing encrypted keys alongside ciphertext.
- ▌ implementing-gdpr-data-subject-access-request · mukul975 bundleAutomates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging.
- ▌ implementing-honeytokens-for-breach-detection · mukul975 bundleDeploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection.
- ▌ implementing-just-in-time-access-provisioning · mukul975 bundleEliminate standing privileges by granting temporary, time-bound access only when needed, covering JIT architecture design, approval workflows, automatic expiration, and integration with PAM and IGA platforms.
- ▌ implementing-network-deception-with-honeypots · mukul975 bundleDeploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
- ▌ implementing-ransomware-kill-switch-detection · mukul975 bundleDetects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing.
- ▌ implementing-security-monitoring-with-datadog · mukul975 bundleDeploys Datadog Cloud SIEM, CSM, and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure.
- ▌ implementing-zero-trust-for-saas-applications · mukul975 bundleEnforce identity verification, device compliance, and data protection for cloud-hosted services using CASB, SSPM, conditional access policies, OAuth app governance, and session controls.
- ▌ integrating-sast-into-github-actions-pipeline · mukul975 bundleIntegrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
- ▌ performing-brand-monitoring-for-impersonation · mukul975 bundleDetect brand impersonation attacks across domains, social media, mobile apps, and dark web channels to identify phishing campaigns, fake sites, and unauthorized brand usage.
- ▌ performing-cloud-storage-forensic-acquisition · mukul975 bundlePerform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
- ▌ performing-cryptographic-audit-of-application · mukul975 bundleSystematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations.
- ▌ performing-endpoint-vulnerability-remediation · mukul975 bundlePrioritizes and remediates endpoint vulnerabilities by importing scan results, applying patches via WSUS/SCCM/Intune, making configuration changes, and validating fixes.
- ▌ performing-ip-reputation-analysis-with-shodan · mukul975 bundleEnrich IP addresses with Shodan API data to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence and incident triage.
- ▌ performing-open-source-intelligence-gathering · mukul975 bundleCollects publicly available information about a target organization to identify attack surfaces, social engineering targets, technology stacks, and credential exposures for authorized security testing.
- ▌ performing-timeline-reconstruction-with-plaso · mukul975 bundleBuild comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
- ▌ performing-vulnerability-scanning-with-nessus · mukul975 bundleConduct authenticated and unauthenticated vulnerability scans using Tenable Nessus to identify known vulnerabilities, misconfigurations, and missing patches, with prioritized remediation guidance.
- ▌ reverse-engineering-android-malware-with-jadx · mukul975 bundleReverse engineer malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks.
- ▌ testing-api-for-mass-assignment-vulnerability · mukul975 bundleTests API endpoints for mass assignment vulnerabilities by injecting privileged fields (role, isAdmin, balance) into request bodies and verifying if the server binds them without filtering.
- ▌ verifying-build-provenance-with-slsa-sigstore · mukul975 bundleVerify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
- ▌ analyzing-malware-behavior-with-cuckoo-sandbox · mukul975 bundleExecutes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.
- ▌ analyzing-prefetch-files-for-execution-history · mukul975 bundleParse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
- ▌ auditing-terraform-infrastructure-for-security · mukul975 bundleAudit Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
- ▌ building-automated-malware-submission-pipeline · mukul975 bundleAutomates the collection of suspicious files from endpoints and email gateways, submission to sandbox and multi-engine scanners, and generation of verdicts with IOCs for SIEM integration.
- ▌ building-identity-governance-lifecycle-process · mukul975 bundleDesigns and automates identity governance lifecycle processes including joiner-mover-leaver workflows, role mining, access requests, periodic recertification, and orphaned account remediation using IGA platforms.
- ▌ building-red-team-c2-infrastructure-with-havoc · mukul975 bundleDeploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
- ▌ conducting-man-in-the-middle-attack-simulation · mukul975 bundleSimulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities.
- ▌ conducting-social-engineering-penetration-test · mukul975 bundleDesign and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
- ▌ configuring-certificate-authority-with-openssl · mukul975 bundleBuild a two-tier PKI hierarchy (Root CA + Intermediate CA) using OpenSSL and Python, including certificate issuance, CRL distribution, OCSP responder configuration, and certificate policy management.
- ▌ configuring-windows-defender-advanced-settings · mukul975 bundleHardens Windows endpoints by configuring Microsoft Defender for Endpoint advanced settings, including attack surface reduction rules, controlled folder access, network protection, and exploit protection.
- ▌ deploying-cloud-deception-with-decoy-resources · mukul975 bundleDeploy cloud-native deception across AWS, Azure, and GCP using decoy resources that generate high-fidelity alerts when attackers interact with them.
- ▌ deploying-decoy-files-for-ransomware-detection · mukul975 bundleDeploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time using file integrity monitoring or OS-level watchdogs.
- ▌ detecting-container-runtime-threats-with-falco · mukul975 bundleWrite and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
- ▌ detecting-network-scanning-with-ids-signatures · mukul975 bundleDetect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
- ▌ detecting-qr-code-phishing-with-email-security · mukul975 bundleDetect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.
- ▌ detecting-suspicious-oauth-application-consent · mukul975 bundleDetect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
- ▌ exploiting-broken-function-level-authorization · mukul975 bundleTests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them.
- ▌ exploiting-smb-vulnerabilities-with-metasploit · mukul975 bundleIdentifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.
- ▌ hunting-for-lolbins-execution-in-endpoint-logs · mukul975 bundleHunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.
- ▌ implementing-api-threat-protection-with-apigee · mukul975 bundleConfigure Google Apigee security policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security to defend against OWASP API Top 10 threats.
- ▌ implementing-aws-macie-for-data-classification · mukul975 bundleAutomatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
- ▌ implementing-cloud-security-posture-management · mukul975 bundleContinuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center.
- ▌ implementing-dragos-platform-for-ot-monitoring · mukul975 bundleDeploy and configure the Dragos Platform for OT network monitoring, leveraging industrial protocol parsers, threat detection analytics, and asset visibility to protect ICS environments.
- ▌ implementing-honeypot-for-ransomware-detection · mukul975 bundleDeploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.
- ▌ implementing-kubernetes-pod-security-standards · mukul975 bundleEnforce Pod Security Standards (Privileged, Baseline, Restricted) in Kubernetes 1.25+ using the Pod Security Admission controller with namespace labels and compliant pod specs.
- ▌ implementing-microsegmentation-with-guardicore · mukul975 bundleMap application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads using Akamai Guardicore Segmentation.
- ▌ performing-network-traffic-analysis-with-zeek · mukul975 bundleDeploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
- ▌ implementing-pod-security-admission-controller · mukul975 bundleEnforce Kubernetes Pod Security Standards at the namespace level using the built-in admission controller, with support for baseline and restricted profiles.
- ▌ implementing-proofpoint-email-security-gateway · mukul975 bundleDeploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
- ▌ implementing-purdue-model-network-segmentation · mukul975 bundleDesign and implement network segmentation for industrial control systems using the Purdue Enterprise Reference Architecture model, separating OT and IT networks into hierarchical security zones with strict traffic control.
- ▌ implementing-threat-modeling-with-mitre-attack · mukul975 bundleMap adversary TTPs against organizational assets using the MITRE ATT&CK framework, assess detection coverage gaps, and prioritize defensive investments.
- ▌ performing-access-recertification-with-saviynt · mukul975 bundleConfigure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
- ▌ reverse-engineering-dotnet-malware-with-dnspy · mukul975 bundleAnalyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.
- ▌ performing-asset-criticality-scoring-for-vulns · mukul975 bundleBuild a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
- ▌ performing-aws-privilege-escalation-assessment · mukul975 bundleIdentify and test IAM misconfigurations that allow privilege escalation in AWS environments using Pacu, CloudFox, Principal Mapper, and manual analysis.
- ▌ performing-cloud-forensics-with-aws-cloudtrail · mukul975 bundleInvestigate AWS account compromises by querying CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
- ▌ performing-cloud-penetration-testing-with-pacu · mukul975 bundleConduct authorized AWS penetration testing using Pacu to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation.
- ▌ performing-cve-prioritization-with-kev-catalog · mukul975 bundleIntegrate the CISA Known Exploited Vulnerabilities catalog with EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.
- ▌ performing-kubernetes-etcd-security-assessment · mukul975 bundleAssess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
- ▌ performing-post-quantum-cryptography-migration · mukul975 bundleAssesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards, performs cryptographic inventory scanning, evaluates hybrid TLS configurations, and validates CRYSTALS-Kyber and CRYSTALS-Dilithium readiness.
- ▌ performing-power-grid-cybersecurity-assessment · mukul975 bundleConduct cybersecurity assessments of electric power grid infrastructure, including NERC CIP compliance verification, substation automation security, and IEC 61850 protocol analysis.
- ▌ performing-serverless-function-security-review · mukul975 bundleAudit serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions for overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
- ▌ performing-service-account-credential-rotation · mukul975 bundleAutomate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
- ▌ performing-web-application-scanning-with-nikto · mukul975 bundleScan web servers and applications for vulnerabilities, misconfigurations, and outdated software using the Nikto open-source scanner.
- ▌ performing-yara-rule-development-for-detection · mukul975 bundleDevelop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
- ▌ prioritizing-vulnerabilities-with-cvss-scoring · mukul975 bundleCalculate CVSS scores, interpret vector strings, and prioritize vulnerabilities using CVSS alongside EPSS and CISA KEV for effective risk-based remediation.
- ▌ analyzing-certificate-transparency-for-phishing · mukul975 bundleMonitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
- ▌ analyzing-sbom-for-supply-chain-vulnerabilities · mukul975 bundleParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API, building dependency graphs, calculating risk scores, and generating compliance reports.
- ▌ analyzing-slack-space-and-file-system-artifacts · mukul975 bundleExamine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.
- ▌ coercing-authentication-with-coercer-petitpotam · mukul975 bundleTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
- ▌ configuring-windows-event-logging-for-detection · mukul975 bundleConfigures Windows Advanced Audit Policy, event log sizes, and Windows Event Forwarding to generate high-fidelity security events for threat detection and SIEM ingestion.
- ▌ detecting-malicious-scheduled-tasks-with-sysmon · mukul975 bundleDetect malicious scheduled task creation and modification using Sysmon Event IDs 1, 11, and Windows Security Event 4698/4702, correlating task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement.
- ▌ implementing-api-security-testing-with-42crunch · mukul975 bundlePerform static audit and dynamic conformance scanning of OpenAPI specifications using the 42Crunch platform to identify OWASP API Security Top 10 vulnerabilities.
- ▌ implementing-attack-path-analysis-with-xm-cyber · mukul975 bundleDeploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
- ▌ implementing-beyondcorp-zero-trust-access-model · mukul975 bundleImplement Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.
- ▌ implementing-google-workspace-sso-configuration · mukul975 bundleConfigure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
- ▌ implementing-identity-governance-with-sailpoint · mukul975 bundleDeploy SailPoint IdentityNow or IdentityIQ for identity governance and administration, covering identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy enforcement, and compliance reporting.
- ▌ implementing-soar-playbook-with-palo-alto-xsoar · mukul975 bundleAutomate incident response workflows in Cortex XSOAR by building playbooks that orchestrate security tools, enrich indicators, and execute containment actions.
- ▌ implementing-supply-chain-security-with-in-toto · mukul975 bundleVerify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations.
- ▌ implementing-syslog-centralization-with-rsyslog · mukul975 bundleConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
- ▌ implementing-zero-trust-with-hashicorp-boundary · mukul975 bundleConfigure and deploy HashiCorp Boundary for identity-aware zero trust infrastructure access with dynamic credential brokering, session recording, and Vault integration.
- ▌ performing-active-directory-bloodhound-analysis · mukul975 bundleEnumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin using BloodHound and SharpHound.
- ▌ performing-active-directory-forest-trust-attack · mukul975 bundleEnumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.
- ▌ performing-automated-malware-analysis-with-cape · mukul975 bundleDeploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
- ▌ performing-gcp-security-assessment-with-forseti · mukul975 bundleAudit Google Cloud Platform environments for security misconfigurations using Forseti, Security Command Center, and gcloud CLI to evaluate IAM policies, firewall rules, storage permissions, and CIS compliance.
- ▌ performing-hardware-security-module-integration · mukul975 bundleIntegrate Hardware Security Modules (HSMs) using the PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.
- ▌ implementing-vulnerability-sla-breach-alerting · mukul975 bundleBuild automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
- ▌ performing-network-traffic-analysis-with-tshark · mukul975 bundleAutomates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
- ▌ performing-ssl-certificate-lifecycle-management · mukul975 bundleAutomates the full lifecycle of SSL/TLS certificates—requesting, issuing, deploying, monitoring, renewing, and revoking—using Python and ACME protocol tools.
- ▌ performing-subdomain-enumeration-with-subfinder · mukul975 bundleEnumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
- ▌ performing-web-application-vulnerability-triage · mukul975 bundleTriage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
- ▌ performing-wifi-password-cracking-with-aircrack · mukul975 bundleCaptures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.
- ▌ analyzing-threat-actor-ttps-with-mitre-navigator · mukul975 bundleMap advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library.
- ▌ building-attack-pattern-library-from-cti-reports · mukul975 bundleExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.
- ▌ building-c2-infrastructure-with-sliver-framework · mukul975 bundleBuild and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.
- ▌ building-malware-incident-communication-template · mukul975 bundleBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
- ▌ building-ransomware-playbook-with-cisa-framework · mukul975 bundleBuilds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists.
- ▌ building-vulnerability-dashboard-with-defectdojo · mukul975 bundleDeploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.
- ▌ configuring-identity-aware-proxy-with-google-iap · mukul975 bundleConfigure Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
- ▌ configuring-multi-factor-authentication-with-duo · mukul975 bundleDeploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points, covering integration methods, adaptive policies, device trust, and phishing-resistant MFA aligned with NIST 800-63B.
- ▌ designing-adversary-engagement-with-mitre-engage · mukul975 bundlePlan, run, and measure adversary engagement operations using the MITRE Engage framework, covering the Engage Matrix, 10-Step Operational Process, and mapping Activities to ATT&CK techniques.
- ▌ detecting-golden-ticket-attacks-in-kerberos-logs · mukul975 bundleDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
- ▌ testing-for-xss-vulnerabilities-with-burpsuite · mukul975 bundleIdentify and validate cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
- ▌ exploiting-zerologon-vulnerability-cve-2020-1472 · mukul975 bundleExploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
- ▌ implementing-canary-tokens-for-network-intrusion · mukul975 bundleDeploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement, with webhook alerting to Slack, Teams, email, or generic HTTP endpoints.
- ▌ implementing-end-to-end-encryption-for-messaging · mukul975 bundleImplements a simplified version of the Signal Protocol's Double Ratchet algorithm using X25519, HKDF, and AES-256-GCM for end-to-end encrypted messaging.
- ▌ implementing-file-integrity-monitoring-with-aide · mukul975 bundleConfigure AIDE for file integrity monitoring, including baseline creation, scheduled integrity checks, change detection, and alerting.
- ▌ building-identity-federation-with-saml-azure-ad · mukul975 bundleEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for cross-domain authentication and SSO to cloud applications.
- ▌ implementing-gcp-organization-policy-constraints · mukul975 bundleEnforce security guardrails across GCP resource hierarchy by configuring organization policy constraints to restrict risky configurations and ensure compliance at organization, folder, and project levels.
- ▌ implementing-mimecast-targeted-attack-protection · mukul975 bundleDeploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
- ▌ implementing-runtime-application-self-protection · mukul975 bundleDeploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.
- ▌ performing-cloud-incident-containment-procedures · mukul975 bundleExecute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
- ▌ performing-paste-site-monitoring-for-credentials · mukul975 bundleMonitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data using automated scraping and keyword matching to detect breaches early.
- ▌ performing-threat-emulation-with-atomic-red-team · mukul975 bundleExecutes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage.
- ▌ performing-threat-intelligence-sharing-with-misp · mukul975 bundleCreate, enrich, and share threat intelligence events on a MISP platform using PyMISP, including IOC management, feed integration, STIX export, and community sharing workflows.
- ▌ post-exploiting-microsoft-graph-with-graphrunner · mukul975 bundlePerform reconnaissance, persistence, privilege escalation, and data pillaging on Microsoft 365/Entra ID tenants via the Microsoft Graph API using the GraphRunner PowerShell toolset.
- ▌ analyzing-ethereum-smart-contract-vulnerabilities · mukul975 bundlePerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
- ▌ building-adversary-infrastructure-tracking-system · mukul975 bundleBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
- ▌ building-threat-intelligence-enrichment-in-splunk · mukul975 bundleBuild automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
- ▌ conducting-cyber-risk-assessment-with-nist-800-30 · mukul975 bundleConduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology, from scoping and threat identification to risk determination and communication.
- ▌ detecting-anomalies-in-industrial-control-systems · mukul975 bundleDeploys anomaly detection for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications.
- ▌ detecting-aws-credential-exposure-with-trufflehog · mukul975 bundleScan source code repositories, CI/CD pipelines, and configuration files for exposed AWS credentials using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
- ▌ detecting-azure-storage-account-misconfigurations · mukul975 bundleAudit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
- ▌ detecting-privilege-escalation-in-kubernetes-pods · mukul975 bundleDetect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
- ▌ detecting-t1548-abuse-elevation-control-mechanism · mukul975 bundleDetect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.
- ▌ implementing-aqua-security-for-container-scanning · mukul975 bundleDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
- ▌ implementing-conditional-access-policies-azure-ad · mukul975 bundleConfigure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance, risk-based authentication, named locations, session controls, and NIST SP 1800-35 integration.
- ▌ implementing-google-workspace-phishing-protection · mukul975 bundleConfigure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
- ▌ implementing-hardware-security-key-authentication · mukul975 bundleImplements FIDO2/WebAuthn hardware security key authentication with registration, authentication, YubiKey enrollment, and passkey migration using the python-fido2 library.
- ▌ implementing-identity-verification-for-zero-trust · mukul975 bundleImplement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
- ▌ implementing-network-traffic-analysis-with-arkime · mukul975 bundleDeploy and query Arkime for full packet capture network traffic analysis, including session search, PCAP download, beaconing detection, DNS tunneling analysis, and TLS anomaly identification.
- ▌ performing-android-app-static-analysis-with-mobsf · mukul975 bundleAutomates static analysis of Android APK/AAB files using MobSF to identify hardcoded secrets, insecure permissions, vulnerable components, and weak cryptography for pre-deployment security assessments or CI/CD integration.
- ▌ performing-bandwidth-throttling-attack-simulation · mukul975 bundleSimulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks.
- ▌ performing-cloud-asset-inventory-with-cartography · mukul975 bundleMap cloud infrastructure assets and relationships into a Neo4j graph using Cartography to discover attack paths, IAM permission chains, and security gaps across AWS, GCP, and Azure.
- ▌ performing-container-security-scanning-with-trivy · mukul975 bundleScan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
- ▌ performing-static-malware-analysis-with-pe-studio · mukul975 bundlePerforms static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary.
- ▌ performing-threat-landscape-assessment-for-sector · mukul975 bundleConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
- ▌ building-vulnerability-exception-tracking-system · mukul975 bundleBuild a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.
- ▌ reverse-engineering-ransomware-encryption-routine · mukul975 bundleIdentify cryptographic algorithms, key generation flaws, and potential decryption opportunities in ransomware samples using static and dynamic analysis.
- ▌ testing-api-for-broken-object-level-authorization · mukul975 bundleTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities by manipulating object identifiers to detect missing per-object authorization checks.
- ▌ analyzing-email-headers-for-phishing-investigation · mukul975 bundleParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
- ▌ collecting-volatile-evidence-from-compromised-host · mukul975 bundleCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
- ▌ detecting-dns-exfiltration-with-dns-query-analysis · mukul975 bundleDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
- ▌ implementing-conduit-security-for-ot-remote-access · mukul975 bundleDesign and deploy IEC 62443-compliant conduit architecture for secure OT remote access, including jump servers, MFA gateways, session recording, and approval-based workflows for vendor and engineer access to industrial control systems.
- ▌ implementing-kubernetes-network-policy-with-calico · mukul975 bundleImplement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.
- ▌ implementing-network-access-control-with-cisco-ise · mukul975 bundleDeploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
- ▌ implementing-opa-gatekeeper-for-policy-enforcement · mukul975 bundleEnforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
- ▌ implementing-policy-as-code-with-open-policy-agent · mukul975 bundleEnforce organizational security policies across Kubernetes clusters and CI/CD pipelines using Open Policy Agent (OPA) and Gatekeeper, including writing Rego policies, deploying admission controllers, and testing policies locally.
- ▌ implementing-zero-standing-privilege-with-cyberark · mukul975 bundleDeploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.
- ▌ performing-log-analysis-for-forensic-investigation · mukul975 bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ performing-malware-hash-enrichment-with-virustotal · mukul975 bundleEnrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
- ▌ performing-entitlement-review-with-sailpoint-iiq · mukul975 bundleRuns entitlement review and access certification campaigns using SailPoint IdentityIQ, including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows.
- ▌ performing-mobile-device-forensics-with-cellebrite · mukul975 bundleAcquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
- ▌ performing-mobile-app-certificate-pinning-bypass · mukul975 bundleBypasses SSL/TLS certificate pinning in Android and iOS apps to intercept HTTPS traffic during authorized security assessments using Frida, Objection, and custom scripts.
- ▌ analyzing-memory-forensics-with-lime-and-volatility · mukul975 bundleAcquires Linux memory using the LiME kernel module and analyzes the image with Volatility 3 to extract processes, network connections, bash history, kernel modules, and injected code for incident response.
- ▌ implementing-api-abuse-detection-with-rate-limiting · mukul975 bundleImplement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.
- ▌ implementing-cloud-vulnerability-posture-management · mukul975 bundleContinuously monitor cloud infrastructure for misconfigurations, compliance violations, and security risks using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite.
- ▌ implementing-container-network-policies-with-calico · mukul975 bundleEnforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.
- ▌ implementing-passwordless-auth-with-microsoft-entra · mukul975 bundleDeploys passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks.
- ▌ implementing-passwordless-authentication-with-fido2 · mukul975 bundleDeploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators, covering WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentication, and migration from password-based systems aligned with NIST SP 800-63B AAL3.
- ▌ implementing-zero-trust-network-access-with-zscaler · mukul975 bundleDeploy Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.
- ▌ performing-aws-account-enumeration-with-scout-suite · mukul975 bundleEnumerate AWS resources and identify misconfigurations using ScoutSuite to generate interactive security reports.
- ▌ performing-kubernetes-cis-benchmark-with-kube-bench · mukul975 bundleAudit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
- ▌ performing-ot-vulnerability-assessment-with-claroty · mukul975 bundleCorrelates OT asset inventory with ICS-CERT advisories and CVE data to identify, prioritize, and track vulnerabilities in operational technology environments using Claroty xDome.
- ▌ performing-threat-modeling-with-owasp-threat-dragon · mukul975 bundleCreate data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review with OWASP Threat Dragon.
- ▌ performing-wireless-security-assessment-with-kismet · mukul975 bundleConduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
- ▌ analyzing-malware-family-relationships-with-malpedia · mukul975 bundleQuery the Malpedia API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
- ▌ detecting-broken-object-property-level-authorization · mukul975 bundleDetect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
- ▌ exploiting-vulnerabilities-with-metasploit-framework · mukul975 bundleValidate and confirm exploitability of vulnerabilities using the Metasploit Framework for risk-based prioritization and patch verification.
- ▌ implementing-application-whitelisting-with-applocker · mukul975 bundleGuides through implementing application whitelisting on Windows using AppLocker, from inventory and rule creation to audit-mode deployment and enforcement.
- ▌ implementing-azure-ad-privileged-identity-management · mukul975 bundleConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
- ▌ implementing-continuous-security-validation-with-bas · mukul975 bundleDeploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.
- ▌ implementing-device-posture-assessment-in-zero-trust · mukul975 bundleIntegrates endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies to enforce device compliance before granting resource access.
- ▌ implementing-next-generation-firewall-with-palo-alto · mukul975 bundleConfigure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
- ▌ implementing-ot-network-traffic-analysis-with-nozomi · mukul975 bundleDeploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve asset visibility, threat detection, and vulnerability assessment across industrial control systems.
- ▌ implementing-security-information-sharing-with-stix2 · mukul975 bundleCreate, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library, covering indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
- ▌ implementing-vulnerability-management-with-greenbone · mukul975 bundleDeploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.
- ▌ implementing-zero-knowledge-proof-for-authentication · mukul975 bundleImplements Schnorr identification protocol and zero-knowledge password proof for authentication where the server never learns the user's password.
- ▌ performing-active-directory-compromise-investigation · mukul975 bundleInvestigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
- ▌ performing-memory-forensics-with-volatility3-plugins · mukul975 bundleAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
- ▌ performing-thick-client-application-penetration-test · mukul975 bundleConduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
- ▌ conducting-internal-reconnaissance-with-bloodhound-ce · mukul975 bundleMap Active Directory attack paths and identify privilege escalation chains using BloodHound Community Edition for authorized security assessments.
- ▌ exploiting-active-directory-certificate-services-esc1 · mukul975 bundleExploit misconfigured Active Directory Certificate Services ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
- ▌ implementing-infrastructure-as-code-security-scanning · mukul975 bundleAutomates security scanning for Infrastructure as Code templates using Checkov, tfsec, and KICS to detect misconfigurations before deployment.
- ▌ implementing-network-segmentation-with-firewall-zones · mukul975 bundleDesign and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.
- ▌ implementing-threat-intelligence-lifecycle-management · mukul975 bundleImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.
- ▌ implementing-fuzz-testing-in-cicd-with-aflplusplus · mukul975 bundleIntegrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.
- ▌ implementing-web-application-logging-with-modsecurity · mukul975 bundleConfigure ModSecurity WAF with OWASP Core Rule Set for web application logging, tune rules to reduce false positives, and analyze audit logs for attack detection.
- ▌ performing-adversary-in-the-middle-phishing-detection · mukul975 bundleDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
- ▌ implementing-image-provenance-verification-with-cosign · mukul975 bundleSign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
- ▌ implementing-iso-27001-information-security-management · mukul975 bundleGuides through the complete ISO/IEC 27001:2022 ISMS lifecycle from scoping and risk assessment to certification and continual improvement, including Annex A control selection and Statement of Applicability creation.
- ▌ performing-gcp-penetration-testing-with-gcpbucketbrute · mukul975 bundleEnumerate and audit GCP storage buckets and IAM policies using GCPBucketBrute and gcloud CLI to identify privilege escalation paths and overly permissive access.
- ▌ implementing-deception-based-detection-with-canarytoken · mukul975 bundleDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
- ▌ implementing-github-advanced-security-for-code-scanning · mukul975 bundleConfigure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
- ▌ implementing-network-intrusion-prevention-with-suricata · mukul975 bundleDeploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.
- ▌ implementing-privileged-access-management-with-cyberark · mukul975 bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure, covering vault architecture, session isolation, credential rotation policies, and NIST 800-53 integration.
- ▌ implementing-data-loss-prevention-with-microsoft-purview · mukul975 bundleConfigures sensitivity labels, DLP policies, and endpoint data protection rules in Microsoft Purview to safeguard sensitive information across Exchange, SharePoint, OneDrive, Teams, and endpoints.
- ▌ implementing-epss-score-for-vulnerability-prioritization · mukul975 bundleIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
- ▌ implementing-container-image-minimal-base-with-distroless · mukul975 bundleReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
- ▌ performing-cloud-native-threat-hunting-with-aws-detective · mukul975 bundleHunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
- ▌ performing-windows-artifact-analysis-with-eric-zimmerman-too · mukul975 bundleParse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
- ▌ performing-active-directory-vulnerability-assessment · mukul975 bundleAssess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.