gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Excel Sheet Filter Export · gabrielmoreira动态统计多Sheet Excel文件行数以判断大文件处理逻辑,并根据特定条件筛选数据、重命名字段后导出为包含下载链接的新Excel文件,适用于多Sheet数据探查与条件过滤导出场景。
- ▌ Dynamic Large File Parquet Analysis · gabrielmoreira动态统计Excel总行数,当数据量过大(≥10000行)时自动转换为Parquet格式加速读取,并对指定目标列进行条件筛选、分类汇总与结果导出,适用于超大体积Excel文件的快速读取与统计分析。
- ▌ Configuring Windows Event Logging For Detection · gabrielmoreiraConfigures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
- ▌ Performing Android App Static Analysis With Mobsf · gabrielmoreiraPerforms automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application. Use when assessing Android APK/AAB files for security vulnerabilities before deployment, during penetration testing, or as part of CI/CD security gates. Activates for requests involving Android static analysis, MobSF scanning, APK security assessment, or mobile application code review.
- ▌ Performing Vulnerability Scanning With Nessus · gabrielmoreiraPerforms authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability detection.
- ▌ Deploying Decoy Files For Ransomware Detection · gabrielmoreiraDeploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
- ▌ Implementing Honeypot For Ransomware Detection · gabrielmoreiraDeploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Activates for requests involving ransomware honeypots, canary files, deception technology for ransomware, or early ransomware alerting.
- ▌ Exploiting Active Directory Certificate Services Esc1 · gabrielmoreiraExploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
- ▌ Implementing Honeytokens For Breach Detection · gabrielmoreiraDeploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection.
- ▌ Implementing Security Monitoring With Datadog · gabrielmoreiraImplements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.
- ▌ Performing Brand Monitoring For Impersonation · gabrielmoreiraMonitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization.
- ▌ Performing Ip Reputation Analysis With Shodan · gabrielmoreiraAnalyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.
- ▌ Performing Cms Specific Security Testing · gabrielmoreiraTesting WordPress, Drupal, Joomla, and other CMS platforms for known vulnerabilities, plugin/theme exploits, misconfigured permissions, and CMS-specific attack vectors during authorized penetration tests.
- ▌ Biomedical Search Strategy Builder · gabrielmoreiraBuilds professional search strategies for PubMed, Embase, Web of Science, and similar databases. Use when a user needs to construct a MeSH-based Boolean query, design a systematic review search, expand a concept with synonyms, apply study-type or date filters, or adapt a query across multiple databases. Also triggers when the user says "help me search for papers on X", "build a search strategy", "what are the MeSH terms for", or "I need a systematic review search string".
- ▌ Confounder And Bias Control Planner · gabrielmoreiraPlans confounder control, variable adjustment logic, and bias mitigation strategies at the protocol stage for clinical, epidemiologic, translational, observational, and biomarker studies. Always use this skill when a user needs to identify major confounders, decide which variables should or should not be adjusted for, compare matching/stratification/weighting approaches, anticipate selection or measurement bias, or pressure-test a study design before execution. Focus on bias sensing, causal structure awareness, variable-role classification, and critical design review rather than generic statistical advice.
- ▌ Quapas Quality Assessment For Prognosis Studies · gabrielmoreiraEvaluates bias in medical literature (prognosis studies) using QUAPAS criteria. Use when the user wants to assess the quality or risk of bias of a medical paper text.
- ▌ Diagnostic Study Quality Assessment Quadas 2 · gabrielmoreiraAnalyzes clinical diagnostic accuracy studies for bias using the QUADAS-2 tool. Use when Claude needs to assess the quality, risk of bias, or applicability of diagnostic accuracy studies (e.g., "Assess this paper using QUADAS-2").
- ▌ Cwicr Data Loader · gabrielmoreiraLoad and parse DDC CWICR construction cost database from multiple formats: Parquet, Excel, CSV, Qdrant snapshots. Foundation for all CWICR operations.
- ▌ Input Validation · gabrielmoreiraValidate construction data inputs before processing: cost estimates, schedules, BIM data, field reports. Catch errors early with domain-specific rules.
- ▌ Enterprise Integration · gabrielmoreiraPatterns for Microsoft Graph, Microsoft Entra ID, and enterprise feature integration in VS Code extensions
- ▌
- ▌ Multi Stage Dockerfile · gabrielmoreiraCreate optimized multi-stage Dockerfiles for any language or framework
- ▌ Executive Storytelling · gabrielmoreiraData-driven narrative construction, stakeholder management, and influencing senior leadership decisions
- ▌ Stakeholder Management · gabrielmoreiraInfluence mapping, communication strategies, and expectation management for complex organizations
- ▌
- ▌ Config Content Separation · gabrielmoreiraMixing structure and content makes both hard to maintain:
- ▌ Terminal Backtick Hazard · gabrielmoreiraBackticks break in all shells — bash treats them as command substitution, PowerShell as escape character
- ▌ Allowlist Over Blocklist · gabrielmoreiraValidate input against an allowlist of permitted values — reject everything else
- ▌ Storytelling Requirements · gabrielmoreiraGuided requirements template for data storytelling projects -- walks users through audience, Big Idea, questions, data sources, and delivery target before any chart is created
- ▌ Buzz Outreach · gabrielmoreiraMedia and podcast outreach personalizer — takes a story angle and target journalist or host list and produces personalized pitch emails per target. Use when asked to "write media pitches", "pitch this story to journalists", "get us on podcasts", "write press outreach", or "personalize pitches for these contacts".
- ▌ Castai Reference Architecture · gabrielmoreiraCAST AI reference architecture for multi-cluster Kubernetes cost optimization. Use when designing CAST AI deployment across environments, planning Terraform module structure, or establishing team standards. Trigger with phrases like "cast ai architecture", "cast ai best practices", "cast ai multi-cluster", "cast ai terraform structure".
- ▌ Cohere Reference Architecture · gabrielmoreiraImplement Cohere reference architecture with layered project layout for RAG and agents. Use when designing new Cohere integrations, reviewing project structure, or establishing architecture standards for Cohere API v2 applications. Trigger with phrases like "cohere architecture", "cohere project structure", "cohere layout", "organize cohere app", "cohere design pattern".
- ▌ Langfuse Deploy Integration · gabrielmoreiraDeploy Langfuse with your application across different platforms. Use when deploying Langfuse to Vercel, AWS, GCP, or Docker, or integrating Langfuse into your deployment pipeline. Trigger with phrases like "deploy langfuse", "langfuse Vercel", "langfuse AWS", "langfuse Docker", "langfuse production deploy".
- ▌ Salesforce Known Pitfalls · gabrielmoreiraIdentify and avoid Salesforce anti-patterns including SOQL N+1, governor limit violations, and API waste. Use when reviewing Salesforce code for issues, onboarding new developers, or auditing existing Salesforce integrations for best practices violations. Trigger with phrases like "salesforce mistakes", "salesforce anti-patterns", "salesforce pitfalls", "salesforce what not to do", "salesforce code review".
- ▌ Together Deploy Integration · gabrielmoreiraTogether AI deploy integration for inference, fine-tuning, and model deployment. Use when working with Together AI's OpenAI-compatible API. Trigger: "together deploy integration".
- ▌ Plan Dangerous Goods Storage Segregation · gabrielmoreiraPlan dangerous-goods storage and segregation research using hazard, quantity, facility, jurisdiction, and qualified-review evidence.
- ▌
- ▌ Time Series And Categorical Analysis · gabrielmoreira对时间序列或分类数据进行多维度趋势分析、百分比清洗、绩效分级建模与预测,并生成高分辨率的可视化综合报告,适用于业务指标监控与预测场景。
- ▌ Excel Threshold Analysis And Styling · gabrielmoreira根据 Excel 数据量级自动判断处理策略,执行数值列清洗、条件过滤,并使用 openpyxl 对符合条件的单元格进行样式标记与导出。
- ▌ Implementing Network Deception With Honeypots · gabrielmoreiraDeploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
- ▌ Performing Soc2 Type2 Audit Preparation · gabrielmoreiraAutomates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.
- ▌ Reverse Engineering Ransomware Encryption Routine · gabrielmoreiraReverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.
- ▌ Detecting Typosquatting Packages In NPM Pypi · gabrielmoreiraDetects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. The analyst queries the PyPI JSON API and npm registry API to gather package metadata for automated comparison. Activates for requests involving package typosquatting detection, dependency confusion analysis, malicious package identification, or software supply chain threat hunting in package registries.
- ▌ Exploiting Client Side Template Injection · gabrielmoreiraExploiting Client-Side Template Injection (CSTI) where a frontend framework (AngularJS, Vue, Mavo, Alpine.js) compiles attacker-controlled template syntax in the browser, turning a reflection into arbitrary JavaScript execution (XSS) often bypassing classic XSS filters and CSP. Activates when user input is reflected into a framework-controlled DOM and template expressions like {{7*7}} are evaluated.
- ▌ Testing For XML Injection Vulnerabilities · gabrielmoreiraTest web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
- ▌ Testing For Xxe Injection Vulnerabilities · gabrielmoreiraDiscovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
- ▌ Cibersort Immune Infiltration Analysis · gabrielmoreiraUse when estimating relative immune cell infiltration from a bulk expression matrix with a CIBERSORT-style nu-SVR deconvolution workflow based on an LM22 signature matrix, comparing one case group against one control group, and generating structured tables plus immune-fraction plots. NOT for single-cell RNA-seq, spatial data, clinical diagnosis, or workflows that require the original hosted CIBERSORT web service.
- ▌ Multi Database Literature Collector · gabrielmoreiraCollects candidate biomedical literature across multiple databases, adapts search logic by database, preserves source metadata, and organizes results into a structured, screening-ready candidate pool. Always use this skill when a user wants cross-database literature collection, search strategy construction, candidate paper aggregation, or first-pass evidence organization before deduplication, screening, layered reading, or review planning. Requires real and verifiable literature records only. Every formal literature item must include a real link and DOI when available; never fabricate citations, titles, authors, years, journals, abstracts, PMIDs, or DOIs. If a DOI is unavailable or cannot be verified, state that explicitly rather than inventing one.
- ▌ Inclusion Exclusion Criteria Builder · gabrielmoreiraBuilds clear, executable, and auditable inclusion and exclusion criteria for biomedical and clinical research protocols. Always use this skill when a user needs to translate a target population into operational screening rules tied to chart fields, time windows, tests, procedures, prior therapies, exclusions, and reviewable edge cases. Focus on protocol-stage precision, ambiguity reduction, auditability, and screening reproducibility rather than generic study design advice.
- ▌ Pcd Immune Oncology Research Planner · gabrielmoreiraGenerates complete programmed-cell-death (PCD) / regulated-cell-death (RCD) bulk-transcriptome oncology research designs from a user-provided disease and mechanism theme. Always use this skill whenever a user wants to design, plan, or structure a cancer bioinformatics study built around cell-death patterns, tumor microenvironment, prognostic modeling, immune landscape analysis, mutation profiling, and computational drug sensitivity. Covers five study patterns (mechanism-gene-set, subtype-discovery, prognostic-signature, immune-response stratification, translational drug-hypothesis) and always outputs four workload configs (Lite / Standard / Advanced / Publication+) with recommended primary plan, step-by-step workflow, figure plan, validation strategy, minimal executable version, publication upgrade path, and a strictly verified reference literature retrieval layer with real references only.
- ▌ Treatment Response Predictor Planner · gabrielmoreiraDesigns studies for predicting treatment response or resistance in biomedical and clinical research. Always use this skill when the user needs a treatment-response or resistance prediction study blueprint rather than a prognostic biomarker protocol, diagnostic test design, causal treatment-effect estimation, or a completed manuscript. Focus on responder definition, treatment context, baseline comparability, feature integration strategy, model development logic, validation architecture, and interpretation boundaries. Do not invent response rates, cohort size, assay readiness, regimen uniformity, literature support, or validation access.
- ▌ Cwicr Bid Analyzer · gabrielmoreiraAnalyze contractor bids against CWICR benchmarks. Identify pricing anomalies, compare bid components, and support bid evaluation decisions.
- ▌ Cwicr Change Order · gabrielmoreiraProcess construction change orders using CWICR data. Calculate cost impact, compare to original estimate, and generate change order documentation.
- ▌ Cwicr Multilingual · gabrielmoreiraWork with CWICR database across 26 languages. Cross-language matching, translation, and regional pricing.
- ▌ Cwicr Rate Updater · gabrielmoreiraUpdate CWICR resource rates with current market prices. Integrate external price data, apply inflation adjustments, and maintain rate history.
- ▌ Rubber Duck Debugging · gabrielmoreiraBe a thinking partner. The answer often emerges when explaining the problem.
- ▌ Component Context Generator · gabrielmoreiraGenerates a CONTEXT.md file for a PrestaShop shared component inside the `.ai/Component/` folder. Trigger this skill when the user asks to "generate a context for [Component]", "document the [X] component", "fill in the CONTEXT.md for [Component]", or when working inside `.ai/Component/` directories. Components live under `src/Core/{Name}/` and/or `src/Adapter/{Name}/` — they are shared infrastructure, not business domains. Examples: Grid, Form, Hook, CQRS, Translation, Router.
- ▌ Ink Distribute · gabrielmoreiraContent distribution plan — takes a completed piece and produces a channel-by-channel plan covering HN, Reddit, LinkedIn, newsletter, and Twitter/X, with timing, per-channel framing, and a repurposing plan. Use when asked to "distribute this post", "how do we promote this article", "write distribution copy for this piece", or "where should we share this".
- ▌ Openevidence Hello World · gabrielmoreiraCreate a minimal working OpenEvidence example. Trigger: "openevidence hello world", "openevidence example", "test openevidence".
- ▌ Replit Upgrade Migration · gabrielmoreiraUpgrade Replit Nix channels, migrate between database types, and update deployment targets. Use when upgrading Nix channel versions, migrating from Replit DB to PostgreSQL, switching deployment types, or updating system dependencies. Trigger with phrases like "upgrade replit", "replit nix upgrade", "migrate replit database", "replit version update", "replit channel update".
- ▌ Salesloft Rate Limits · gabrielmoreiraHandle SalesLoft cost-based rate limiting with backoff and request budgeting. Use when hitting 429 errors, optimizing API throughput, or implementing pagination-aware rate limit strategies. Trigger: "salesloft rate limit", "salesloft 429", "salesloft throttling".
- ▌ Serpapi Core Workflow B · gabrielmoreiraSearch Bing, YouTube, Google Shopping, Google News, and Google Maps with SerpApi. Use when scraping non-Google engines, building multi-engine search, or extracting video/news/shopping/maps data. Trigger: "serpapi youtube", "serpapi bing", "serpapi news", "serpapi shopping".
- ▌ Serpapi Webhooks Events · gabrielmoreiraImplement SerpApi async search callbacks and scheduled search monitoring. Use when setting up search monitoring, SERP tracking pipelines, or async search result retrieval. Trigger: "serpapi webhooks", "serpapi monitoring", "serpapi scheduled search", "serpapi async".
- ▌ Techsmith Cost Tuning · gabrielmoreiraTechSmith cost tuning for Snagit COM API and Camtasia automation. Use when working with TechSmith screen capture and video editing automation. Trigger: "techsmith cost tuning".
- ▌ Techsmith Rate Limits · gabrielmoreiraTechSmith rate limits for Snagit COM API and Camtasia automation. Use when working with TechSmith screen capture and video editing automation. Trigger: "techsmith rate limits".
- ▌ Webflow Core Workflow A · gabrielmoreiraExecute the primary Webflow workflow — CMS content management: list collections, CRUD items, publish items, and manage content lifecycle via the Data API v2. Use when working with Webflow CMS collections and items, managing blog posts, team members, or any dynamic content. Trigger with phrases like "webflow CMS", "webflow collections", "webflow items", "create webflow content", "manage webflow CMS", "webflow content management".
- ▌ Webflow Core Workflow B · gabrielmoreiraExecute Webflow secondary workflows — Sites management, Pages API, Forms submissions, Ecommerce (products/orders/inventory), and Custom Code via the Data API v2. Use when managing sites, reading pages, handling form data, or working with Webflow Ecommerce products and orders. Trigger with phrases like "webflow sites", "webflow pages", "webflow forms", "webflow ecommerce", "webflow products", "webflow orders".
- ▌ Webflow Enterprise Rbac · gabrielmoreiraConfigure Webflow enterprise access control — OAuth 2.0 app authorization, scope-based RBAC, per-site token isolation, workspace member management, and audit logging for compliance. Trigger with phrases like "webflow RBAC", "webflow enterprise", "webflow roles", "webflow permissions", "webflow OAuth scopes", "webflow access control", "webflow workspace members".
- ▌ Webflow Multi Env Setup · gabrielmoreiraConfigure Webflow across development, staging, and production environments with per-environment API tokens, site IDs, and secret management via Vault/AWS/GCP. Trigger with phrases like "webflow environments", "webflow staging", "webflow dev prod", "webflow environment setup", "webflow config by env".
- ▌ Webflow Security Basics · gabrielmoreiraApply Webflow API security best practices — token management, scope least privilege, OAuth 2.0 secret rotation, webhook signature verification, and audit logging. Use when securing API tokens, implementing least privilege access, or auditing Webflow security configuration. Trigger with phrases like "webflow security", "webflow secrets", "secure webflow", "webflow API key security", "webflow token rotation".
- ▌ Webflow Webhooks Events · gabrielmoreiraImplement Webflow webhook registration, signature verification, and event handling for form_submission, site_publish, ecomm_new_order, page_created, and more. Use when setting up webhook endpoints, implementing event-driven workflows, or handling Webflow notifications. Trigger with phrases like "webflow webhook", "webflow events", "webflow webhook signature", "handle webflow events", "webflow notifications".
- ▌ Windsurf Observability · gabrielmoreiraMonitor Windsurf AI adoption, feature usage, and team productivity metrics. Use when tracking AI feature usage, measuring ROI, setting up dashboards, or analyzing Cascade effectiveness across your team. Trigger with phrases like "windsurf monitoring", "windsurf metrics", "windsurf analytics", "windsurf usage", "windsurf adoption".
- ▌ Workhuman Rate Limits · gabrielmoreiraWorkhuman rate limits for employee recognition and rewards API. Use when integrating Workhuman Social Recognition, or building recognition workflows with HRIS systems. Trigger: "workhuman rate limits".
- ▌ Build Logistics Scorecard · gabrielmoreira bundleBuild logistics scorecard designs with KPI definitions, targets, owners, cadence, sources, thresholds, and action rules.
- ▌ Design Conceptual Warehouse Layout · gabrielmoreira bundleDesign conceptual warehouse layouts from building constraints, zones, storage, process requirements, flow, and safety boundaries.
- ▌ Plan Sanitation Sensitive Logistics · gabrielmoreiraPlan sanitation-sensitive food logistics workflows for facilities, equipment, vehicles, packaging, handling, and evidence handoffs.
- ▌ Plan Temperature Controlled Storage · gabrielmoreiraPlan source-backed temperature-controlled food storage workflows, capacity questions, monitoring handoffs, hold states, and qualified-review boundaries.
- ▌ Plan Customs Broker Handoff · gabrielmoreiraPlan customs broker handoffs by lane, party roles, documents, classification evidence, value, origin, release questions, and review boundaries.
- ▌ Research Us Commercial Vehicle Safety · gabrielmoreiraPrepare United States commercial-vehicle safety research briefs for motor carrier, driver, vehicle, maintenance, and hours-of-service context.
- ▌ Research Us Hazardous Materials Rules · gabrielmoreiraPrepare PHMSA and DOT hazardous-materials research briefs for United States logistics without classifying or certifying hazmat.
- ▌ Checking Model Compliance · gabrielmoreiraUse this skill when the user asks to check Simulink model compliance against a standard (MISRA, MAB, JMAAB, ISO, DO, IEC, EN, CERT C/CWE, AUTOSAR, Simulink Code Inspector (SLCI)), wants to run Model Advisor checks, or needs a compliance report with fix suggestions. For JMAAB/MAB, supplement deterministic checks with agentic review of uncheckable guidelines.
- ▌ Bypassing Binary Exploitation Mitigations · gabrielmoreiraMethodology for identifying and defeating common binary hardening mitigations during authorized exploitation — ASLR, PIE, stack canaries, NX/DEP, and RELRO — by leaking addresses, brute-forcing entropy, abusing forked-process behavior, and selecting the right code-reuse primitive for the protections in place.
- ▌ Auditing Terraform Infrastructure For Security · gabrielmoreiraAuditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
- ▌ Detecting Suspicious OAUTH Application Consent · gabrielmoreiraDetect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
- ▌ Performing AWS Privilege Escalation Assessment · gabrielmoreiraPerforming authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.
- ▌ Performing Serverless Function Security Review · gabrielmoreiraPerforming security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
- ▌ Hardening Linux Endpoint With Cis Benchmark · gabrielmoreiraHardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit findings, or establishing security baselines for Linux infrastructure. Activates for requests involving Linux hardening, CIS benchmarks for Linux, server security baselines, or Linux configuration compliance.
- ▌ Implementing Disk Encryption With Bitlocker · gabrielmoreiraImplements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.
- ▌ Performing Endpoint Forensics Investigation · gabrielmoreiraPerforms digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.
- ▌ Performing Firmware Extraction With Binwalk · gabrielmoreiraPerforms firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
- ▌ Conducting Memory Forensics With Volatility · gabrielmoreiraPerforms memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
- ▌ Implementing Velociraptor For Ir Collection · gabrielmoreiraDeploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
- ▌ Analyzing Cobalt Strike Beacon Configuration · gabrielmoreiraExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
- ▌ Implementing Ddos Mitigation With Cloudflare · gabrielmoreiraConfigure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
- ▌ Performing Dns Enumeration And Zone Transfer · gabrielmoreiraEnumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.
- ▌ Performing Network Tunneling And Pivoting · gabrielmoreiraEstablishing tunnels, port forwards, and SOCKS proxies to reach internal networks from a foothold during authorized engagements - covering SSH local/remote/dynamic forwarding, proxychains, chisel, ligolo-ng, socat, plink, sshuttle, Meterpreter/Cobalt Strike routing, and covert DNS/ICMP/cloud tunnels.
- ▌ Detecting Ransomware Precursors In Network · gabrielmoreiraDetects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts. Activates for requests involving pre-ransomware detection, network-based ransomware indicators, or early warning ransomware monitoring.
- ▌ Analyzing Azure Activity Logs For Threats · gabrielmoreiraQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
- ▌ Analyzing Powershell Script Block Logging · gabrielmoreiraParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression abuse, download cradles, and AMSI bypass attempts.
- ▌ Implementing Mtls For Zero Trust Services · gabrielmoreiraConfigures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains, checks expiration, and audits mTLS deployment status. Use when implementing zero-trust service-to-service authentication.