mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Wordlists 2 · mukul975SecLists path map, hashcat rules, CeWL usage, and custom wordlist generation for all attack categories
- ▌ Ad Attacks 2 · mukul975Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist
- ▌ Exploit DB 2 · mukul975Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns
- ▌ Mitre Attack 2 · mukul975MITRE ATT&CK framework reference — tactics, techniques, and tool-to-TTP mappings for pentest documentation and detection rule writing
- ▌ Report Templates 2 · mukul975CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports
- ▌ Wordlists · mukul975SecLists path map, hashcat rules, CeWL usage, and custom wordlist generation for all attack categories
- ▌ Ad Attacks · mukul975Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist
- ▌ Exploit DB · mukul975Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns
- ▌ Mitre Attack · mukul975MITRE ATT&CK framework reference — tactics, techniques, and tool-to-TTP mappings for pentest documentation and detection rule writing
- ▌ Report Templates · mukul975CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports
- ▌ Conducting Gdpr Compliance Assessment · mukul975 bundleConduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
- ▌ Implementing Deception Based Detection With Canarytoken · mukul975 bundleDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
- ▌ Implementing Data Loss Prevention With Microsoft Purview · mukul975 bundleConfigures sensitivity labels, DLP policies, and endpoint data protection rules in Microsoft Purview to safeguard sensitive information across Exchange, SharePoint, OneDrive, Teams, and endpoints.
- ▌ Implementing Epss Score For Vulnerability Prioritization · mukul975 bundleIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
- ▌ Implementing Container Image Minimal Base With Distroless · mukul975 bundleReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
- ▌ Performing Cloud Native Threat Hunting With AWS Detective · mukul975 bundleHunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
- ▌ Performing Windows Artifact Analysis With Eric Zimmerman Too · mukul975 bundleParse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
- ▌ Detecting Dns Exfiltration With Dns Query Analysis · mukul975 bundleDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
- ▌ Implementing Network Access Control With Cisco Ise · mukul975 bundleDeploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
- ▌ Implementing Policy As Code With Open Policy Agent · mukul975 bundleEnforce organizational security policies across Kubernetes clusters and CI/CD pipelines using Open Policy Agent (OPA) and Gatekeeper, including writing Rego policies, deploying admission controllers, and testing policies locally.
- ▌ Implementing Zero Standing Privilege With Cyberark · mukul975 bundleDeploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.
- ▌ Performing Log Analysis For Forensic Investigation · mukul975 bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ Performing Malware Hash Enrichment With Virustotal · mukul975 bundleEnrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
- ▌ Performing Mobile Device Forensics With Cellebrite · mukul975 bundleAcquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
- ▌ Analyzing Memory Forensics With Lime And Volatility · mukul975 bundleAcquires Linux memory using the LiME kernel module and analyzes the image with Volatility 3 to extract processes, network connections, bash history, kernel modules, and injected code for incident response.
- ▌ Implementing API Abuse Detection With Rate Limiting · mukul975 bundleImplement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.
- ▌ Implementing Cloud Vulnerability Posture Management · mukul975 bundleContinuously monitor cloud infrastructure for misconfigurations, compliance violations, and security risks using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite.
- ▌ Implementing Container Network Policies With Calico · mukul975 bundleEnforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.
- ▌ Implementing Passwordless Auth With Microsoft Entra · mukul975 bundleDeploys passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks.
- ▌ Implementing Passwordless Authentication With Fido2 · mukul975 bundleDeploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators, covering WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentication, and migration from password-based systems aligned with NIST SP 800-63B AAL3.
- ▌ Implementing Zero Trust Network Access With Zscaler · mukul975 bundleDeploy Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.
- ▌ Performing AWS Account Enumeration With Scout Suite · mukul975 bundleEnumerate AWS resources and identify misconfigurations using ScoutSuite to generate interactive security reports.
- ▌ Performing Kubernetes Cis Benchmark With Kube Bench · mukul975 bundleAudit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
- ▌ Performing Ot Vulnerability Assessment With Claroty · mukul975 bundleCorrelates OT asset inventory with ICS-CERT advisories and CVE data to identify, prioritize, and track vulnerabilities in operational technology environments using Claroty xDome.
- ▌ Performing Threat Modeling With Owasp Threat Dragon · mukul975 bundleCreate data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review with OWASP Threat Dragon.
- ▌ Performing Wireless Security Assessment With Kismet · mukul975 bundleConduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
- ▌ Analyzing Malware Family Relationships With Malpedia · mukul975 bundleQuery the Malpedia API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
- ▌ Detecting Broken Object Property Level Authorization · mukul975 bundleDetect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
- ▌ Exploiting Vulnerabilities With Metasploit Framework · mukul975 bundleValidate and confirm exploitability of vulnerabilities using the Metasploit Framework for risk-based prioritization and patch verification.
- ▌ Implementing Application Whitelisting With Applocker · mukul975 bundleGuides through implementing application whitelisting on Windows using AppLocker, from inventory and rule creation to audit-mode deployment and enforcement.
- ▌ Implementing Azure Ad Privileged Identity Management · mukul975 bundleConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
- ▌ Implementing Continuous Security Validation With Bas · mukul975 bundleDeploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.
- ▌ Implementing Device Posture Assessment In Zero Trust · mukul975 bundleIntegrates endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies to enforce device compliance before granting resource access.
- ▌ Implementing Next Generation Firewall With Palo Alto · mukul975 bundleConfigure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
- ▌ Implementing Ot Network Traffic Analysis With Nozomi · mukul975 bundleDeploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve asset visibility, threat detection, and vulnerability assessment across industrial control systems.
- ▌ Implementing Security Information Sharing With Stix2 · mukul975 bundleCreate, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library, covering indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
- ▌ Implementing Vulnerability Management With Greenbone · mukul975 bundleDeploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.
- ▌ Implementing Zero Knowledge Proof For Authentication · mukul975 bundleImplements Schnorr identification protocol and zero-knowledge password proof for authentication where the server never learns the user's password.
- ▌ Performing Active Directory Compromise Investigation · mukul975 bundleInvestigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
- ▌ Performing Active Directory Vulnerability Assessment · mukul975 bundleAssess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.
- ▌ Performing Memory Forensics With Volatility3 Plugins · mukul975 bundleAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
- ▌ Performing Thick Client Application Penetration Test · mukul975 bundleConduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
- ▌ Conducting Internal Reconnaissance With Bloodhound Ce · mukul975 bundleMap Active Directory attack paths and identify privilege escalation chains using BloodHound Community Edition for authorized security assessments.
- ▌ Exploiting Active Directory Certificate Services Esc1 · mukul975 bundleExploit misconfigured Active Directory Certificate Services ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
- ▌ Implementing Infrastructure As Code Security Scanning · mukul975 bundleAutomates security scanning for Infrastructure as Code templates using Checkov, tfsec, and KICS to detect misconfigurations before deployment.
- ▌ Implementing Network Segmentation With Firewall Zones · mukul975 bundleDesign and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.
- ▌ Implementing Threat Intelligence Lifecycle Management · mukul975 bundleImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.
- ▌ Implementing Web Application Logging With Modsecurity · mukul975 bundleConfigure ModSecurity WAF with OWASP Core Rule Set for web application logging, tune rules to reduce false positives, and analyze audit logs for attack detection.
- ▌ Performing Adversary In The Middle Phishing Detection · mukul975 bundleDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
- ▌ Implementing Image Provenance Verification With Cosign · mukul975 bundleSign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
- ▌ Implementing Iso 27001 Information Security Management · mukul975 bundleGuides through the complete ISO/IEC 27001:2022 ISMS lifecycle from scoping and risk assessment to certification and continual improvement, including Annex A control selection and Statement of Applicability creation.
- ▌ Performing GCP Penetration Testing With Gcpbucketbrute · mukul975 bundleEnumerate and audit GCP storage buckets and IAM policies using GCPBucketBrute and gcloud CLI to identify privilege escalation paths and overly permissive access.
- ▌ Implementing Github Advanced Security For Code Scanning · mukul975 bundleConfigure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
- ▌ Implementing Network Intrusion Prevention With Suricata · mukul975 bundleDeploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.
- ▌ Implementing Privileged Access Management With Cyberark · mukul975 bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure, covering vault architecture, session isolation, credential rotation policies, and NIST 800-53 integration.
- ▌ Building Vulnerability Dashboard With Defectdojo · mukul975 bundleDeploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.
- ▌ Designing Adversary Engagement With Mitre Engage · mukul975 bundlePlan, run, and measure adversary engagement operations using the MITRE Engage framework, covering the Engage Matrix, 10-Step Operational Process, and mapping Activities to ATT&CK techniques.
- ▌ Detecting Golden Ticket Attacks In Kerberos Logs · mukul975 bundleDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
- ▌ Exploiting Zerologon Vulnerability Cve 2020 1472 · mukul975 bundleExploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
- ▌ Implementing Canary Tokens For Network Intrusion · mukul975 bundleDeploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement, with webhook alerting to Slack, Teams, email, or generic HTTP endpoints.
- ▌ Implementing End To End Encryption For Messaging · mukul975 bundleImplements a simplified version of the Signal Protocol's Double Ratchet algorithm using X25519, HKDF, and AES-256-GCM for end-to-end encrypted messaging.
- ▌ Implementing File Integrity Monitoring With Aide · mukul975 bundleConfigure AIDE for file integrity monitoring, including baseline creation, scheduled integrity checks, change detection, and alerting.
- ▌ Implementing GCP Organization Policy Constraints · mukul975 bundleEnforce security guardrails across GCP resource hierarchy by configuring organization policy constraints to restrict risky configurations and ensure compliance at organization, folder, and project levels.
- ▌ Implementing Mimecast Targeted Attack Protection · mukul975 bundleDeploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
- ▌ Implementing Runtime Application Self Protection · mukul975 bundleDeploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.
- ▌ Performing Cloud Incident Containment Procedures · mukul975 bundleExecute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
- ▌ Performing Entitlement Review With Sailpoint Iiq · mukul975 bundleRuns entitlement review and access certification campaigns using SailPoint IdentityIQ, including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows.
- ▌ Performing Mobile App Certificate Pinning Bypass · mukul975 bundleBypasses SSL/TLS certificate pinning in Android and iOS apps to intercept HTTPS traffic during authorized security assessments using Frida, Objection, and custom scripts.
- ▌ Performing Paste Site Monitoring For Credentials · mukul975 bundleMonitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data using automated scraping and keyword matching to detect breaches early.
- ▌ Performing Threat Emulation With Atomic Red Team · mukul975 bundleExecutes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage.
- ▌ Performing Threat Intelligence Sharing With Misp · mukul975 bundleCreate, enrich, and share threat intelligence events on a MISP platform using PyMISP, including IOC management, feed integration, STIX export, and community sharing workflows.
- ▌ Post Exploiting Microsoft Graph With Graphrunner · mukul975 bundlePerform reconnaissance, persistence, privilege escalation, and data pillaging on Microsoft 365/Entra ID tenants via the Microsoft Graph API using the GraphRunner PowerShell toolset.
- ▌ Analyzing Ethereum Smart Contract Vulnerabilities · mukul975 bundlePerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
- ▌ Building Adversary Infrastructure Tracking System · mukul975 bundleBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
- ▌ Building Threat Intelligence Enrichment In Splunk · mukul975 bundleBuild automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
- ▌ Conducting Cyber Risk Assessment With Nist 800 30 · mukul975 bundleConduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology, from scoping and threat identification to risk determination and communication.
- ▌ Detecting Anomalies In Industrial Control Systems · mukul975 bundleDeploys anomaly detection for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications.
- ▌ Detecting AWS Credential Exposure With Trufflehog · mukul975 bundleScan source code repositories, CI/CD pipelines, and configuration files for exposed AWS credentials using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
- ▌ Detecting Azure Storage Account Misconfigurations · mukul975 bundleAudit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
- ▌ Detecting Privilege Escalation In Kubernetes Pods · mukul975 bundleDetect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
- ▌ Detecting T1548 Abuse Elevation Control Mechanism · mukul975 bundleDetect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.
- ▌ Implementing Aqua Security For Container Scanning · mukul975 bundleDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
- ▌ Implementing Conditional Access Policies Azure Ad · mukul975 bundleConfigure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance, risk-based authentication, named locations, session controls, and NIST SP 1800-35 integration.
- ▌ Implementing Google Workspace Phishing Protection · mukul975 bundleConfigure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
- ▌ Implementing Hardware Security Key Authentication · mukul975 bundleImplements FIDO2/WebAuthn hardware security key authentication with registration, authentication, YubiKey enrollment, and passkey migration using the python-fido2 library.
- ▌ Implementing Identity Verification For Zero Trust · mukul975 bundleImplement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
- ▌ Implementing Network Traffic Analysis With Arkime · mukul975 bundleDeploy and query Arkime for full packet capture network traffic analysis, including session search, PCAP download, beaconing detection, DNS tunneling analysis, and TLS anomaly identification.
- ▌ Performing Android App Static Analysis With Mobsf · mukul975 bundleAutomates static analysis of Android APK/AAB files using MobSF to identify hardcoded secrets, insecure permissions, vulnerable components, and weak cryptography for pre-deployment security assessments or CI/CD integration.
- ▌ Performing Bandwidth Throttling Attack Simulation · mukul975 bundleSimulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks.
- ▌ Performing Cloud Asset Inventory With Cartography · mukul975 bundleMap cloud infrastructure assets and relationships into a Neo4j graph using Cartography to discover attack paths, IAM permission chains, and security gaps across AWS, GCP, and Azure.