mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Performing Container Security Scanning With Trivy · mukul975 bundleScan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
- ▌ Performing Static Malware Analysis With Pe Studio · mukul975 bundlePerforms static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary.
- ▌ Performing Threat Landscape Assessment For Sector · mukul975 bundleConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
- ▌ Reverse Engineering Ransomware Encryption Routine · mukul975 bundleIdentify cryptographic algorithms, key generation flaws, and potential decryption opportunities in ransomware samples using static and dynamic analysis.
- ▌ Testing API For Broken Object Level Authorization · mukul975 bundleTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities by manipulating object identifiers to detect missing per-object authorization checks.
- ▌ Analyzing Email Headers For Phishing Investigation · mukul975 bundleParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
- ▌ Collecting Volatile Evidence From Compromised Host · mukul975 bundleCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
- ▌ Implementing Conduit Security For Ot Remote Access · mukul975 bundleDesign and deploy IEC 62443-compliant conduit architecture for secure OT remote access, including jump servers, MFA gateways, session recording, and approval-based workflows for vendor and engineer access to industrial control systems.
- ▌ Implementing Fuzz Testing In Cicd With Aflplusplus · mukul975 bundleIntegrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.
- ▌ Implementing Kubernetes Network Policy With Calico · mukul975 bundleImplement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.
- ▌ Implementing Opa Gatekeeper For Policy Enforcement · mukul975 bundleEnforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
- ▌ Performing AWS Privilege Escalation Assessment · mukul975 bundleIdentify and test IAM misconfigurations that allow privilege escalation in AWS environments using Pacu, CloudFox, Principal Mapper, and manual analysis.
- ▌ Performing Cloud Forensics With AWS Cloudtrail · mukul975 bundleInvestigate AWS account compromises by querying CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
- ▌ Performing Cloud Penetration Testing With Pacu · mukul975 bundleConduct authorized AWS penetration testing using Pacu to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation.
- ▌ Performing Cve Prioritization With Kev Catalog · mukul975 bundleIntegrate the CISA Known Exploited Vulnerabilities catalog with EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.
- ▌ Performing Kubernetes Etcd Security Assessment · mukul975 bundleAssess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
- ▌ Performing Post Quantum Cryptography Migration · mukul975 bundleAssesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards, performs cryptographic inventory scanning, evaluates hybrid TLS configurations, and validates CRYSTALS-Kyber and CRYSTALS-Dilithium readiness.
- ▌ Performing Power Grid Cybersecurity Assessment · mukul975 bundleConduct cybersecurity assessments of electric power grid infrastructure, including NERC CIP compliance verification, substation automation security, and IEC 61850 protocol analysis.
- ▌ Performing Serverless Function Security Review · mukul975 bundleAudit serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions for overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
- ▌ Performing Service Account Credential Rotation · mukul975 bundleAutomate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
- ▌ Performing Web Application Scanning With Nikto · mukul975 bundleScan web servers and applications for vulnerabilities, misconfigurations, and outdated software using the Nikto open-source scanner.
- ▌ Performing Yara Rule Development For Detection · mukul975 bundleDevelop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
- ▌ Prioritizing Vulnerabilities With Cvss Scoring · mukul975 bundleCalculate CVSS scores, interpret vector strings, and prioritize vulnerabilities using CVSS alongside EPSS and CISA KEV for effective risk-based remediation.
- ▌ Testing For Xss Vulnerabilities With Burpsuite · mukul975 bundleIdentify and validate cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
- ▌ Analyzing Certificate Transparency For Phishing · mukul975 bundleMonitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
- ▌ Analyzing Sbom For Supply Chain Vulnerabilities · mukul975 bundleParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API, building dependency graphs, calculating risk scores, and generating compliance reports.
- ▌ Analyzing Slack Space And File System Artifacts · mukul975 bundleExamine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.
- ▌ Building Identity Federation With Saml Azure Ad · mukul975 bundleEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for cross-domain authentication and SSO to cloud applications.
- ▌ Coercing Authentication With Coercer Petitpotam · mukul975 bundleTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
- ▌ Configuring Windows Event Logging For Detection · mukul975 bundleConfigures Windows Advanced Audit Policy, event log sizes, and Windows Event Forwarding to generate high-fidelity security events for threat detection and SIEM ingestion.
- ▌ Detecting Malicious Scheduled Tasks With Sysmon · mukul975 bundleDetect malicious scheduled task creation and modification using Sysmon Event IDs 1, 11, and Windows Security Event 4698/4702, correlating task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement.
- ▌ Implementing API Security Testing With 42crunch · mukul975 bundlePerform static audit and dynamic conformance scanning of OpenAPI specifications using the 42Crunch platform to identify OWASP API Security Top 10 vulnerabilities.
- ▌ Implementing Attack Path Analysis With Xm Cyber · mukul975 bundleDeploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
- ▌ Implementing Beyondcorp Zero Trust Access Model · mukul975 bundleImplement Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.
- ▌ Implementing Google Workspace Sso Configuration · mukul975 bundleConfigure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
- ▌ Implementing Identity Governance With Sailpoint · mukul975 bundleDeploy SailPoint IdentityNow or IdentityIQ for identity governance and administration, covering identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy enforcement, and compliance reporting.
- ▌ Implementing Soar Playbook With Palo Alto Xsoar · mukul975 bundleAutomate incident response workflows in Cortex XSOAR by building playbooks that orchestrate security tools, enrich indicators, and execute containment actions.
- ▌ Implementing Supply Chain Security With In Toto · mukul975 bundleVerify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations.
- ▌ Implementing Syslog Centralization With Rsyslog · mukul975 bundleConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
- ▌ Implementing Zero Trust With Hashicorp Boundary · mukul975 bundleConfigure and deploy HashiCorp Boundary for identity-aware zero trust infrastructure access with dynamic credential brokering, session recording, and Vault integration.
- ▌ Performing Active Directory Bloodhound Analysis · mukul975 bundleEnumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin using BloodHound and SharpHound.
- ▌ Performing Active Directory Forest Trust Attack · mukul975 bundleEnumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.
- ▌ Performing Automated Malware Analysis With Cape · mukul975 bundleDeploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
- ▌ Performing GCP Security Assessment With Forseti · mukul975 bundleAudit Google Cloud Platform environments for security misconfigurations using Forseti, Security Command Center, and gcloud CLI to evaluate IAM policies, firewall rules, storage permissions, and CIS compliance.
- ▌ Performing Hardware Security Module Integration · mukul975 bundleIntegrate Hardware Security Modules (HSMs) using the PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.
- ▌ Performing Network Traffic Analysis With Tshark · mukul975 bundleAutomates packet capture analysis using tshark and pyshark to extract protocol statistics, detect suspicious flows, identify IOCs, and analyze DNS anomalies from PCAP files.
- ▌ Performing Ssl Certificate Lifecycle Management · mukul975 bundleAutomates the full lifecycle of SSL/TLS certificates—requesting, issuing, deploying, monitoring, renewing, and revoking—using Python and ACME protocol tools.
- ▌ Performing Subdomain Enumeration With Subfinder · mukul975 bundleEnumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
- ▌ Performing Web Application Vulnerability Triage · mukul975 bundleTriage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
- ▌ Performing Wifi Password Cracking With Aircrack · mukul975 bundleCaptures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.
- ▌ Analyzing Threat Actor Ttps With Mitre Navigator · mukul975 bundleMap advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library.
- ▌ Building Attack Pattern Library From Cti Reports · mukul975 bundleExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.
- ▌ Building C2 Infrastructure With Sliver Framework · mukul975 bundleBuild and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.
- ▌ Building Malware Incident Communication Template · mukul975 bundleBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
- ▌ Building Ransomware Playbook With Cisa Framework · mukul975 bundleBuilds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists.
- ▌ Building Vulnerability Exception Tracking System · mukul975 bundleBuild a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.
- ▌ Configuring Identity Aware Proxy With Google Iap · mukul975 bundleConfigure Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
- ▌ Configuring Multi Factor Authentication With Duo · mukul975 bundleDeploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points, covering integration methods, adaptive policies, device trust, and phishing-resistant MFA aligned with NIST 800-63B.
- ▌ Implementing Security Monitoring With Datadog · mukul975 bundleDeploys Datadog Cloud SIEM, CSM, and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure.
- ▌ Implementing Zero Trust For Saas Applications · mukul975 bundleEnforce identity verification, device compliance, and data protection for cloud-hosted services using CASB, SSPM, conditional access policies, OAuth app governance, and session controls.
- ▌ Performing Brand Monitoring For Impersonation · mukul975 bundleDetect brand impersonation attacks across domains, social media, mobile apps, and dark web channels to identify phishing campaigns, fake sites, and unauthorized brand usage.
- ▌ Performing Cloud Storage Forensic Acquisition · mukul975 bundlePerform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
- ▌ Performing Cryptographic Audit Of Application · mukul975 bundleSystematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoded keys, insufficient entropy, and protocol misconfigurations.
- ▌ Performing Endpoint Vulnerability Remediation · mukul975 bundlePrioritizes and remediates endpoint vulnerabilities by importing scan results, applying patches via WSUS/SCCM/Intune, making configuration changes, and validating fixes.
- ▌ Performing Ip Reputation Analysis With Shodan · mukul975 bundleEnrich IP addresses with Shodan API data to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence and incident triage.
- ▌ Performing Network Traffic Analysis With Zeek · mukul975 bundleDeploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
- ▌ Performing Open Source Intelligence Gathering · mukul975 bundleCollects publicly available information about a target organization to identify attack surfaces, social engineering targets, technology stacks, and credential exposures for authorized security testing.
- ▌ Performing Timeline Reconstruction With Plaso · mukul975 bundleBuild comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
- ▌ Performing Vulnerability Scanning With Nessus · mukul975 bundleConduct authenticated and unauthenticated vulnerability scans using Tenable Nessus to identify known vulnerabilities, misconfigurations, and missing patches, with prioritized remediation guidance.
- ▌ Reverse Engineering Android Malware With Jadx · mukul975 bundleReverse engineer malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks.
- ▌ Reverse Engineering Dotnet Malware With Dnspy · mukul975 bundleAnalyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.
- ▌ Testing API For Mass Assignment Vulnerability · mukul975 bundleTests API endpoints for mass assignment vulnerabilities by injecting privileged fields (role, isAdmin, balance) into request bodies and verifying if the server binds them without filtering.
- ▌ Verifying Build Provenance With Slsa Sigstore · mukul975 bundleVerify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
- ▌ Analyzing Malware Behavior With Cuckoo Sandbox · mukul975 bundleExecutes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.
- ▌ Analyzing Prefetch Files For Execution History · mukul975 bundleParse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
- ▌ Auditing Terraform Infrastructure For Security · mukul975 bundleAudit Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
- ▌ Building Automated Malware Submission Pipeline · mukul975 bundleAutomates the collection of suspicious files from endpoints and email gateways, submission to sandbox and multi-engine scanners, and generation of verdicts with IOCs for SIEM integration.
- ▌ Building Identity Governance Lifecycle Process · mukul975 bundleDesigns and automates identity governance lifecycle processes including joiner-mover-leaver workflows, role mining, access requests, periodic recertification, and orphaned account remediation using IGA platforms.
- ▌ Building Red Team C2 Infrastructure With Havoc · mukul975 bundleDeploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
- ▌ Conducting Man In The Middle Attack Simulation · mukul975 bundleSimulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities.
- ▌ Conducting Social Engineering Penetration Test · mukul975 bundleDesign and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
- ▌ Configuring Certificate Authority With Openssl · mukul975 bundleBuild a two-tier PKI hierarchy (Root CA + Intermediate CA) using OpenSSL and Python, including certificate issuance, CRL distribution, OCSP responder configuration, and certificate policy management.
- ▌ Configuring Windows Defender Advanced Settings · mukul975 bundleHardens Windows endpoints by configuring Microsoft Defender for Endpoint advanced settings, including attack surface reduction rules, controlled folder access, network protection, and exploit protection.
- ▌ Deploying Cloud Deception With Decoy Resources · mukul975 bundleDeploy cloud-native deception across AWS, Azure, and GCP using decoy resources that generate high-fidelity alerts when attackers interact with them.
- ▌ Deploying Decoy Files For Ransomware Detection · mukul975 bundleDeploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time using file integrity monitoring or OS-level watchdogs.
- ▌ Detecting Container Runtime Threats With Falco · mukul975 bundleWrite and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
- ▌ Detecting Network Scanning With Ids Signatures · mukul975 bundleDetect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
- ▌ Detecting Qr Code Phishing With Email Security · mukul975 bundleDetect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.
- ▌ Detecting Suspicious OAUTH Application Consent · mukul975 bundleDetect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
- ▌ Exploiting Broken Function Level Authorization · mukul975 bundleTests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them.
- ▌ Exploiting Smb Vulnerabilities With Metasploit · mukul975 bundleIdentifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.
- ▌ Hunting For Lolbins Execution In Endpoint Logs · mukul975 bundleHunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.
- ▌ Implementing API Threat Protection With Apigee · mukul975 bundleConfigure Google Apigee security policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security to defend against OWASP API Top 10 threats.
- ▌ Implementing AWS Macie For Data Classification · mukul975 bundleAutomatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
- ▌ Implementing Cloud Security Posture Management · mukul975 bundleContinuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center.
- ▌ Implementing Dragos Platform For Ot Monitoring · mukul975 bundleDeploy and configure the Dragos Platform for OT network monitoring, leveraging industrial protocol parsers, threat detection analytics, and asset visibility to protect ICS environments.
- ▌ Implementing Honeypot For Ransomware Detection · mukul975 bundleDeploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.
- ▌ Implementing Kubernetes Pod Security Standards · mukul975 bundleEnforce Pod Security Standards (Privileged, Baseline, Restricted) in Kubernetes 1.25+ using the Pod Security Admission controller with namespace labels and compliant pod specs.
- ▌ Implementing Microsegmentation With Guardicore · mukul975 bundleMap application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads using Akamai Guardicore Segmentation.
- ▌ Implementing Pod Security Admission Controller · mukul975 bundleEnforce Kubernetes Pod Security Standards at the namespace level using the built-in admission controller, with support for baseline and restricted profiles.