gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Hunting For Beaconing With Frequency Analysis · gabrielmoreiraIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
- ▌ Evaluating Threat Intelligence Platforms · gabrielmoreiraEvaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
- ▌ Scanning Infrastructure With Nessus · gabrielmoreiraTenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.
- ▌ Exploiting Insecure Deserialization · gabrielmoreiraIdentifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.
- ▌ Performing Account Takeover Attacks · gabrielmoreiraSystematically testing authentication, recovery, and identity flows for account takeover (ATO) — including Unicode/normalization email collisions, reusable reset/magic links, pre-account-takeover, response manipulation, email-verification bypass, session/cookie reuse, and QR/device-code login abuse. Activates when assessing login, signup, password reset, email change, SSO/OAuth, or cross-device login flows.
- ▌ Performing Clickjacking Attack Test · gabrielmoreiraTesting web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
- ▌ Testing Ecommerce And Payment Logic · gabrielmoreiraTesting business-logic flaws in e-commerce and payment flows including price/product tampering, quantity abuse, voucher and gift-card manipulation, cart and shipping IDOR, payment-method and amount tampering, currency swaps, refund manipulation, and out-of-stock ordering.
- ▌ Testing For Sensitive Data Exposure · gabrielmoreiraIdentifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
- ▌ Differential Expression Analysis · gabrielmoreiraUse when analyzing bulk RNA-seq or microarray expression data to identify differentially expressed genes between two biological groups (case vs control), with volcano plots and heatmap visualization. NOT for:single-cell RNA-seq, methylation analysis, non-expression data.
- ▌ Unmet Clinical Need Extractor · gabrielmoreiraExtracts concrete unmet clinical needs from guidelines, reviews, real-world studies, and clinical-practice evidence. Use this skill when a user wants to turn broad medical research value into specific clinical pain points such as weak early detection, poor risk stratification, treatment-response heterogeneity, monitoring gaps, diagnostic delay, undertreatment, overtreatment, or implementation failure. Always ground unmet-need claims in retrieved evidence and distinguish true care gaps from generic statements of importance.
- ▌ Bulk Omics Integrative Planner · gabrielmoreiraDesigns complete integrated research plans for bulk transcriptomics, proteomics, metabolomics, and related omics from a user-provided biomedical direction. Always use this skill whenever a user wants to design, scope, or structure a bulk multi-omics or single-omics-plus-clinical study — including disease-focused, mechanism-focused, biomarker-focused, stratification-oriented, or translational projects. It should define the research question, choose the best-fit study pattern, recommend example datasets as reference candidates only, specify the core analysis modules and method choices, propose a validation ladder, and output four workload configurations (Lite / Standard / Advanced / Publication+). Never fabricate datasets, accession numbers, sample counts, metadata completeness, cohort availability, assay coverage, literature references, PMIDs, DOIs, or validation status. Always include the mandatory Dataset Disclaimer immediately before any workflow section that mentions datasets or public resources.
- ▌ Drug Repurposing Study Planner · gabrielmoreiraDesign evidence-discovery and validation workflows for drug repurposing studies by integrating disease mechanisms, drug-target logic, expression reversal, real-world evidence, and validation routes into a closed-loop study blueprint.
- ▌ Oce Load Cost Bases · gabrielmoreiraLoad national and market cost bases into OpenConstructionERP: the 8 national bases (Turkey Birim Fiyat, China Dinge, Brazil SINAPI, Spain BCCA, Italy Prezzario Toscana, Greece GGDE, Vietnam Dinh Muc, Indonesia AHSP), the 30 global markets, and 48 PPP market catalogs per base. Use when importing a cost database, repricing into a market, or troubleshooting a load.
- ▌ Oce MCP Integration · gabrielmoreiraConnect OpenConstructionERP to AI coding assistants via MCP (Model Context Protocol): expose costs, BOQ, BIM and catalog endpoints as MCP tools so Claude Code / Antigravity / OpenCode can drive the platform. Use when wiring an assistant to the ERP.
- ▌ Oce Scheduling 4d5d · gabrielmoreira4D scheduling and 5D cost modelling in OpenConstructionERP: build task schedules, link tasks to BIM elements and BOQ lines, roll up the cost model over time, and export Gantt/sequence views. Use for schedule-cost integration workflows.
- ▌
- ▌ Bootstrap Learning · gabrielmoreiraDomain-agnostic knowledge acquisition — from zero to structured expertise through conversational learning
- ▌
- ▌ Dialog Engineering · gabrielmoreiraCSAR Loop and structured conversation patterns for effective AI dialog -- Clarify, Summarize, Act, Reflect
- ▌ Keep Churn · gabrielmoreiraChurn risk identification and intervention — scans health signals for at-risk accounts, classifies risk level (CRITICAL/HIGH/MEDIUM), and produces an intervention sequence per risk type. Use when asked to "find at-risk accounts", "who might churn", "build a churn prevention plan", "identify churn signals", or "rescue this account".
- ▌ Security Scanning · gabrielmoreiraUse when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets
- ▌ Channel Formats · gabrielmoreiraTransforms one piece of content into each marketing channel's native format — length, structure, hooks, and conventions — across LinkedIn, X threads, newsletters, Instagram, YouTube, short video, and blogs. Use when reformatting content for a specific channel. Trigger with "channel format", "adapt for LinkedIn", or "/multiply".
- ▌ Abridge Core Workflow A · gabrielmoreiraImplement Abridge ambient clinical documentation capture-to-note pipeline. Use when building the primary encounter workflow: audio capture, real-time transcription, AI note generation, and EHR note insertion. Trigger: "abridge clinical workflow", "abridge encounter pipeline", "ambient documentation workflow", "abridge note generation".
- ▌ Abridge Core Workflow B · gabrielmoreiraImplement Abridge patient-facing documentation and after-visit summary generation. Use when building patient portal integration, generating plain-language summaries, multi-language translations, or after-visit instructions from clinical encounters. Trigger: "abridge patient summary", "after-visit summary", "patient portal abridge", "abridge patient-facing", "abridge multilingual".
- ▌ Abridge Security Basics · gabrielmoreiraApply HIPAA-compliant security practices for Abridge clinical AI integrations. Use when securing PHI in transit/at rest, configuring access controls, implementing audit logging, or preparing for HIPAA security audits. Trigger: "abridge security", "abridge HIPAA", "abridge PHI protection", "abridge access control", "abridge audit logging".
- ▌ Abridge Webhooks Events · gabrielmoreiraImplement Abridge webhook handling for clinical documentation events. Use when receiving note completion notifications, encounter status changes, provider enrollment events, or quality alert callbacks from Abridge. Trigger: "abridge webhook", "abridge events", "abridge notifications", "abridge note completed event", "abridge encounter event".
- ▌ Adobe Migration Deep Dive · gabrielmoreiraExecute major Adobe re-architecture: migrating from legacy Adobe APIs to Firefly Services, consolidating Creative Cloud integrations, and strangler-fig migration from competitor document/image APIs to Adobe. Trigger with phrases like "migrate adobe", "adobe migration", "switch to adobe", "adobe replatform", "replace with adobe".
- ▌ Alchemy Core Workflow A · gabrielmoreiraBuild a complete wallet portfolio tracker using Alchemy Enhanced APIs. Use when implementing token balance dashboards, NFT galleries, transaction history views, or wallet analytics applications. Trigger: "alchemy wallet tracker", "alchemy portfolio", "alchemy token dashboard", "alchemy transaction history", "build dApp with alchemy".
- ▌ Alchemy Webhooks Events · gabrielmoreiraImplement Alchemy Notify webhooks for real-time blockchain event notifications. Use when tracking wallet activity, monitoring mined transactions, watching smart contract events, or building real-time dApp features. Trigger: "alchemy webhook", "alchemy notify", "alchemy events", "alchemy address activity", "alchemy real-time notifications".
- ▌ Algolia Core Workflow B · gabrielmoreiraImplement Algolia indexing pipeline: data sync, partial updates, synonyms, and rules. The secondary money-path workflow: keep your index in sync with source data. Trigger: "algolia indexing", "sync data to algolia", "algolia synonyms", "algolia rules", "algolia partial update", "algolia reindex".
- ▌ Algolia Enterprise Rbac · gabrielmoreiraConfigure Algolia enterprise access control: team-scoped API keys, Secured API Keys for multi-tenant RBAC, dashboard team management, and audit logging. Trigger: "algolia RBAC", "algolia enterprise", "algolia roles", "algolia permissions", "algolia team access", "algolia multi-tenant", "algolia SSO".
- ▌ Algolia Multi Env Setup · gabrielmoreiraConfigure Algolia across dev/staging/production: index prefixing, per-environment API keys, settings-as-code, and environment isolation guards. Trigger: "algolia environments", "algolia staging", "algolia dev prod", "algolia environment setup", "algolia config by env".
- ▌ Algolia Webhooks Events · gabrielmoreiraImplement Algolia Insights API for click/conversion tracking, search analytics, and real-time event-driven index updates via database change listeners. Trigger: "algolia events", "algolia analytics", "algolia insights", "algolia click tracking", "algolia conversion", "algolia event tracking".
- ▌ Clay Architecture Variants · gabrielmoreiraChoose and implement Clay integration architecture for different scales and use cases. Use when designing new Clay integrations, comparing direct vs queue-based vs event-driven, or planning architecture for Clay-powered data operations. Trigger with phrases like "clay architecture", "clay blueprint", "how to structure clay", "clay integration design", "clay event-driven".
- ▌ Clickup Enterprise Rbac · gabrielmoreiraImplement ClickUp Enterprise SSO, OAuth 2.0 multi-workspace access, role-based permissions, and organization management via API v2. Trigger: "clickup SSO", "clickup RBAC", "clickup enterprise", "clickup roles", "clickup permissions", "clickup OAuth app", "clickup multi-workspace".
- ▌ Clickup Multi Env Setup · gabrielmoreiraConfigure ClickUp API access across dev, staging, and production environments with per-environment tokens and workspace isolation. Trigger: "clickup environments", "clickup staging", "clickup dev prod", "clickup environment setup", "clickup config by env", "clickup multi-env".
- ▌ Clickup Webhooks Events · gabrielmoreiraCreate and manage ClickUp webhooks for real-time event notifications. Use when setting up webhook listeners for task/list/space events, implementing two-way sync, or handling ClickUp event payloads. Trigger: "clickup webhook", "clickup events", "clickup notifications", "clickup real-time", "clickup event listener", "clickup webhook create".
- ▌ Cohere Upgrade Migration · gabrielmoreiraMigrate from Cohere API v1 to v2 and upgrade SDK versions. Use when upgrading cohere-ai SDK, migrating from CohereClient to CohereClientV2, or handling breaking changes between API versions. Trigger with phrases like "upgrade cohere", "cohere migration", "cohere v1 to v2", "update cohere SDK", "cohere breaking changes".
- ▌ Instantly Rate Limits · gabrielmoreiraImplement Instantly.ai rate limiting, backoff, and request throttling patterns. Use when handling 429 errors, implementing retry logic, or building high-throughput Instantly integrations. Trigger with phrases like "instantly rate limit", "instantly 429", "instantly throttle", "instantly backoff", "instantly retry".
- ▌ Lokalise Observability · gabrielmoreiraSet up comprehensive observability for Lokalise integrations with metrics, traces, and alerts. Use when implementing monitoring for Lokalise operations, setting up dashboards, or configuring alerting for Lokalise integration health. Trigger with phrases like "lokalise monitoring", "lokalise metrics", "lokalise observability", "monitor lokalise", "lokalise alerts", "lokalise tracing".
- ▌ Mistral Core Workflow A · gabrielmoreiraExecute Mistral AI chat completions with streaming, multi-turn, and guardrails. Use when implementing chat interfaces, building conversational AI, or integrating Mistral for text generation. Trigger with phrases like "mistral chat", "mistral completion", "mistral streaming", "mistral conversation", "mistral guardrails".
- ▌ Mistral Security Basics · gabrielmoreiraApply Mistral AI security best practices for secrets, prompt injection, and access control. Use when securing API keys, defending against prompt injection, or auditing Mistral AI security configuration. Trigger with phrases like "mistral security", "mistral secrets", "secure mistral", "mistral prompt injection".
- ▌ Posthog Core Workflow A · gabrielmoreiraImplement PostHog product analytics: event capture, user identification, group analytics, and property management using posthog-js and posthog-node. Trigger: "posthog analytics", "capture events", "track users posthog", "posthog identify", "posthog group analytics", "product analytics".
- ▌ Posthog Core Workflow B · gabrielmoreiraImplement PostHog feature flags, A/B experiments, and cohort management. Use when rolling out features with flags, running A/B tests, creating cohorts, or evaluating multivariate experiments with PostHog. Trigger: "posthog feature flag", "posthog experiment", "posthog A/B test", "posthog cohort", "feature rollout posthog", "posthog multivariate".
- ▌ Posthog Multi Env Setup · gabrielmoreiraConfigure PostHog across development, staging, and production environments. Separate PostHog projects per environment, environment-specific SDK config, feature flag rollout per env, and session recording controls. Trigger: "posthog environments", "posthog staging", "posthog dev prod", "posthog environment setup", "posthog project per env".
- ▌ Replit Policy Guardrails · gabrielmoreiraEnforce security and resource policies for Replit-hosted apps: secrets exposure prevention, resource limits, deployment visibility, and database access controls. Use when hardening a Replit app for production, auditing security posture, or setting up guardrails for team development. Trigger with phrases like "replit policy", "replit guardrails", "replit security audit", "replit hardening", "replit best practices check".
- ▌ Scaffolding Generator · gabrielmoreiraPattern-aware code scaffolding that detects existing conventions and generates new components matching the codebase style. Use when asked to "scaffold a component", "generate boilerplate", "create a new module", "bootstrap a service", "add a new endpoint", "create a new controller", or "add a new feature module". Discovers patterns first, then replicates them.
- ▌ Test Quality Analysis · gabrielmoreiraAnalyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
- ▌ Chart Interpretation · gabrielmoreiraRead any chart (image, HTML, screenshot) and extract insights, patterns, anomalies, bias, and narrative -- the reverse of visualization
- ▌ Boolean String Trap · gabrielmoreiraJavaScript boolean-string coercion trap — "false" is truthy, JSON.parse or strict comparison required
- ▌ Cloud Storage Paths · gabrielmoreiraCross-platform cloud storage path resolution — OneDrive, iCloud, Dropbox path discovery and normalization
- ▌ Line Ending Parsing · gabrielmoreiraLine ending handling across platforms — CRLF vs LF detection, normalization, and git config
- ▌ Guide Cert Rehoming · gabrielmoreiraEnd-to-end process of rehoming (moving or reissuing) certificates so every production Entra app credential lives in the same tenant and cloud as the app itself.
- ▌ Lookup Nsg For Vnet · gabrielmoreiraChecks every subnet in a Virtual Network for an associated Network Security Group, and also inspects each NIC attached to those subnets for NIC-level NSG coverage.
- ▌ Web Crawling · gabrielmoreiraUse when scraping web pages, automating browser interactions, crawling sites for content, or extracting data from rendered JavaScript pages
- ▌ Adobe Known Pitfalls · gabrielmoreiraIdentify and avoid Adobe-specific anti-patterns: using deprecated JWT auth, not caching IMS tokens, ignoring Firefly content policy, missing async job polling, and leaking p8_ secrets. Real code examples with fixes. Trigger with phrases like "adobe mistakes", "adobe anti-patterns", "adobe pitfalls", "adobe what not to do", "adobe code review".
- ▌ Attio CI Integration · gabrielmoreiraConfigure CI/CD pipelines for Attio integrations with GitHub Actions, mock-based unit tests, and live API integration tests. Trigger: "attio CI", "attio GitHub Actions", "attio automated tests", "CI attio", "attio pipeline", "test attio in CI".
- ▌ Attio Local Dev Loop · gabrielmoreiraSet up a fast local development loop for Attio integrations with hot reload, mock server, and integration tests. Trigger: "attio dev setup", "attio local development", "attio dev environment", "develop with attio", "attio project setup".
- ▌ Attio Prod Checklist · gabrielmoreiraProduction readiness checklist for Attio API integrations -- auth, error handling, rate limits, health checks, monitoring, and rollback. Trigger: "attio production", "deploy attio", "attio go-live", "attio launch checklist", "attio production ready".
- ▌ Cohere Sdk Patterns · gabrielmoreiraApply production-ready Cohere SDK patterns for TypeScript and Python. Use when implementing Cohere integrations, refactoring SDK usage, or establishing team coding standards for Cohere API v2. Trigger with phrases like "cohere SDK patterns", "cohere best practices", "cohere code patterns", "idiomatic cohere", "cohere wrapper".
- ▌ Linear Install Auth · gabrielmoreiraInstall and configure Linear SDK/CLI authentication. Use when setting up a new Linear integration, configuring API keys, OAuth2 flows, or initializing LinearClient in your project. Trigger: "install linear", "setup linear", "linear auth", "configure linear API key", "linear SDK setup", "linear OAuth".
- ▌ Miro Incident Runbook · gabrielmoreiraExecute Miro REST API v2 incident response with triage, mitigation, and postmortem. Use when responding to Miro-related outages, investigating API errors, or running post-incident reviews for Miro integration failures. Trigger with phrases like "miro incident", "miro outage", "miro down", "miro on-call", "miro emergency", "miro broken".
- ▌ Replit Install Auth · gabrielmoreiraSet up a Replit project with .replit + replit.nix configuration, Secrets, and Replit Auth. Use when creating a new Replit App, configuring Nix packages, managing secrets, or adding user authentication with Replit Auth. Trigger with phrases like "setup replit", "replit auth", "replit nix config", "replit secrets", "configure replit", "new replit project".
- ▌ Replit Sdk Patterns · gabrielmoreiraApply production-ready patterns for Replit Database, Object Storage, and Auth APIs. Use when implementing Replit integrations, structuring data access layers, or establishing team coding standards for Replit services. Trigger with phrases like "replit patterns", "replit best practices", "replit code patterns", "idiomatic replit", "replit SDK".
- ▌ Engineering Features For Machine Learning · gabrielmoreira bundleExecute create, select, and transform features to improve machine learning model performance. Handles feature scaling, encoding, and importance analysis. Use when asked to "engineer features" or "select features". Trigger with relevant phrases based on skill purpose.
- ▌ Validating Authentication Implementations · gabrielmoreira bundleValidate authentication mechanisms for security weaknesses and compliance. Use when reviewing login systems or auth flows. Trigger with 'validate authentication', 'check auth security', or 'review login'.
- ▌ Csrf Protection Validator · gabrielmoreiraValidate csrf protection validator operations. Auto-activating skill for Security Fundamentals. Triggers on: csrf protection validator, csrf protection validator Part of the Security Fundamentals skill category. Use when working with csrf protection validator functionality. Trigger with phrases like "csrf protection validator", "csrf validator", "csrf".
- ▌ Https Certificate Checker · gabrielmoreiraValidate https certificate checker operations. Auto-activating skill for Security Fundamentals. Triggers on: https certificate checker, https certificate checker Part of the Security Fundamentals skill category. Use when working with https certificate checker functionality. Trigger with phrases like "https certificate checker", "https checker", "https".
- ▌ Xss Vulnerability Scanner · gabrielmoreiraScan xss vulnerability scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: xss vulnerability scanner, xss vulnerability scanner Part of the Security Fundamentals skill category. Use when working with xss vulnerability scanner functionality. Trigger with phrases like "xss vulnerability scanner", "xss scanner", "xss".
- ▌ Certificate Lifecycle Manager · gabrielmoreiraManage certificate lifecycle manager operations. Auto-activating skill for Security Advanced. Triggers on: certificate lifecycle manager, certificate lifecycle manager Part of the Security Advanced skill category. Use when working with certificate lifecycle manager functionality. Trigger with phrases like "certificate lifecycle manager", "certificate manager", "certificate".
- ▌ Mermaid Sequence Diagram Creator · gabrielmoreiraCreate mermaid sequence diagram creator operations. Auto-activating skill for Visual Content. Triggers on: mermaid sequence diagram creator, mermaid sequence diagram creator Part of the Visual Content skill category. Use when working with mermaid sequence diagram creator functionality. Trigger with phrases like "mermaid sequence diagram creator", "mermaid creator", "mermaid".
- ▌ Approval Workflow Generator · gabrielmoreiraGenerate approval workflow generator operations. Auto-activating skill for Business Automation. Triggers on: approval workflow generator, approval workflow generator Part of the Business Automation skill category. Use when working with approval workflow generator functionality. Trigger with phrases like "approval workflow generator", "approval generator", "approval".
- ▌ Backlog Grooming Assistant · gabrielmoreiraExecute backlog grooming assistant operations. Auto-activating skill for Enterprise Workflows. Triggers on: backlog grooming assistant, backlog grooming assistant Part of the Enterprise Workflows skill category. Use when working with backlog grooming assistant functionality. Trigger with phrases like "backlog grooming assistant", "backlog assistant", "backlog".
- ▌ Identify Warehouse Congestion · gabrielmoreira bundleIdentify warehouse congestion from layout, volume, queues, equipment paths, labor activity, delays, and safety boundaries.
- ▌ Research Canadian Dangerous Goods Rules · gabrielmoreiraPrepare Transport Canada dangerous-goods research briefs for Canadian logistics without classifying or certifying dangerous goods.
- ▌ Monitor Cold Chain Temperature · gabrielmoreiraPlan cold-chain temperature monitoring evidence reviews for food storage and transport without approving product release or equipment sufficiency.
- ▌ Plan Cold Chain Transportation · gabrielmoreiraPlan cold-chain food transportation evidence, equipment questions, temperature monitoring handoffs, sanitation needs, and carrier boundaries.
- ▌ Research Us Storage Requirements · gabrielmoreiraPrepare United States storage requirement research briefs for warehouses, yards, hazardous materials, hazardous waste, inventory status, and facility controls.
- ▌ Research Us Transportation Rules · gabrielmoreiraPrepare United States transportation rule research briefs while separating mode, state, federal, carrier, shipper, and consignee scope.
- ▌ Conducting Internal Reconnaissance With Bloodhound Ce · gabrielmoreira bundleConduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold to Domain Admin. Use after an initial AD foothold to identify privilege escalation chains, or to validate that AD hardening closed known attack paths.
- ▌ Implementing Infrastructure As Code Security Scanning · gabrielmoreira bundleImplements automated security scanning for Infrastructure as Code using Checkov, tfsec, and KICS to detect misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts, plus policy-based governance and CI/CD integration. Use when validating cloud infrastructure before deployment or blocking insecure changes (public S3 buckets, open security groups) in pull requests.
- ▌ Implementing Network Segmentation With Firewall Zones · gabrielmoreira bundleDesigns and implements network segmentation using firewall security zones, VLANs, inter-zone ACLs, and workload-level microsegmentation to restrict east-west lateral movement and enforce least-privilege access. Use when architecting security zones, writing inter-zone firewall policies, or meeting PCI DSS/HIPAA/NIST 800-53/zero-trust segmentation requirements for dynamic or traditional network environments.
- ▌ Implementing Threat Intelligence Lifecycle Management · gabrielmoreira bundleBuild out a full CTI program around the six-phase threat intelligence lifecycle (direction, collection, processing, analysis, dissemination, feedback), including defining intelligence requirements, building a collection pipeline, normalizing data, and tracking dissemination feedback. Use when standing up or maturing a threat intelligence program, defining intelligence requirements, or designing collection-to-dissemination workflows for a CTI team.
- ▌ Implementing Web Application Logging With Modsecurity · gabrielmoreira bundleConfigure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia levels to reduce false positives, and writing custom SecRules for application-specific threats. Use when deploying or tuning a ModSecurity WAF, analyzing audit logs for attack detection, or reducing CRS false positives.
- ▌ Performing Adversary In The Middle Phishing Detection · gabrielmoreira bundleDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure AD/Entra sign-in logs, SIEM alerts, and EDR telemetry. Use when investigating suspected MFA-bypass phishing or session token theft, or building detection and response playbooks against reverse-proxy phishing kits.
- ▌ Implementing Usb Device Control Policy · gabrielmoreiraImplements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
- ▌ Analyzing Macos Persistence And Autostart · gabrielmoreiraEnumerating, planting, and hunting macOS persistence and auto-start (ASEP) locations during authorized engagements - LaunchAgents/LaunchDaemons, shell rc files, login items, cron/at/periodic jobs, login/logout hooks, Dock and Terminal/iTerm2 preferences, audio/QuickLook/Spotlight plugins, PAM modules, Authorization plugins, emond, and StartupItems - and mapping each to its trigger, required privilege, and sandbox/TCC implications.
- ▌ Performing Scada Hmi Security Assessment · gabrielmoreiraPerform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.
- ▌ Detecting SQL Injection Via Waf Logs · gabrielmoreiraAnalyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates multi-stage injection attempts, and generates incident reports with OWASP classification.
- ▌ Implementing Siem Use Cases For Detection · gabrielmoreiraImplements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
- ▌ Implementing Soar Automation With Phantom · gabrielmoreiraImplements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.
- ▌ Hunting For Command And Control Beaconing · gabrielmoreiraDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
- ▌ Performing Threat Hunting With Yara Rules · gabrielmoreiraUse YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
- ▌ Exploiting Dependency Confusion · gabrielmoreiraIdentifying and exploiting dependency confusion (substitution) attacks where a package manager resolves an internal dependency name from a public registry instead of the intended private one, leading to attacker-controlled code execution at install time. Activates when testing build pipelines, CI/CD systems, leaked manifests, or any ecosystem (npm, PyPI, NuGet, Maven, Gradle, Go, Cargo, RubyGems) that mixes internal and public package sources.
- ▌ Exploiting Os Command Injection · gabrielmoreiraIdentifying and exploiting OS command injection vulnerabilities in web applications where user input is passed to a system shell, leading to arbitrary command execution. Covers in-band, blind, and out-of-band detection across Linux and Windows, separator and filter-bypass variants, and escalation to full RCE.
- ▌ Detecting Bluetooth Low Energy Attacks · gabrielmoreiraDetects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
- ▌ Claim Strength Calibrator · gabrielmoreiraCalibrates manuscript claim strength so wording matches the actual evidence level, study design, and validation status.
- ▌ Revision Strategy Planner · gabrielmoreiraBuilds prioritized manuscript revision plans for major or minor revisions by separating comments that require experiments, analyses, clarification, restructuring, or wording changes.
- ▌ Hierarchical Clustering Plot · gabrielmoreiraUse when building a sample-level hierarchical clustering dendrogram from a bulk expression matrix and sample annotation table, especially for QC, batch inspection, or sample similarity assessment. Trigger keywords: hierarchical clustering, dendrogram, sample QC, batch inspection, sample similarity. NOT for: differential expression testing, gene clustering heatmaps, single-cell clustering workflows.
- ▌ Pca Dimensionality Reduction · gabrielmoreiraUse when performing PCA principal component dimensionality reduction on tabular numeric data. Supports command-line parameter input, automatic numeric feature selection, parameter validation, result directory creation, and CSV or TXT format result export.