all publishers

mukul975

@mukul975 source repo

828 published skills · page 3 of 9

  1. ▌
    Implementing Proofpoint Email Security Gateway · mukul975 bundle
    Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
    24.6k repo stars
  2. ▌
    Implementing Purdue Model Network Segmentation · mukul975 bundle
    Design and implement network segmentation for industrial control systems using the Purdue Enterprise Reference Architecture model, separating OT and IT networks into hierarchical security zones with strict traffic control.
    24.6k repo stars
  3. ▌
    Implementing Threat Modeling With Mitre Attack · mukul975 bundle
    Map adversary TTPs against organizational assets using the MITRE ATT&CK framework, assess detection coverage gaps, and prioritize defensive investments.
    24.6k repo stars
  4. ▌
    Implementing Vulnerability Sla Breach Alerting · mukul975 bundle
    Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
    24.6k repo stars
  5. ▌
    Performing Access Recertification With Saviynt · mukul975 bundle
    Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
    24.6k repo stars
  6. ▌
    Performing Asset Criticality Scoring For Vulns · mukul975 bundle
    Build a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
    24.6k repo stars
  7. ▌
    Implementing Network Policies For Kubernetes · mukul975 bundle
    Create and apply Kubernetes NetworkPolicies to enforce pod-level network segmentation, restrict traffic between pods and namespaces, and block access to cloud metadata endpoints.
    24.6k repo stars
  8. ▌
    Implementing Patch Management For Ot Systems · mukul975 bundle
    Establish a structured patch management program for OT/ICS environments, covering vendor compatibility testing, risk-based prioritization, staged deployment, rollback procedures, and compensating controls for unpatchable systems.
    24.6k repo stars
  9. ▌
    Performing Active Directory Penetration Test · mukul975 bundle
    Enumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    24.6k repo stars
  10. ▌
    Performing API Security Testing With Postman · mukul975 bundle
    Builds repeatable API security test suites in Postman covering OWASP API Security Top 10 vulnerabilities, with automated authentication, multi-role testing, and CI/CD integration via Newman.
    24.6k repo stars
  11. ▌
    Performing Cloud Native Forensics With Falco · mukul975 bundle
    Deploys and manages Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Parses Falco alerts for incident response.
    24.6k repo stars
  12. ▌
    Performing Dns Enumeration And Zone Transfer · mukul975 bundle
    Enumerate DNS records, attempt zone transfers, brute-force subdomains, and map DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.
    24.6k repo stars
  13. ▌
    Performing External Network Penetration Test · mukul975 bundle
    Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.
    24.6k repo stars
  14. ▌
    Performing Linux Log Forensics Investigation · mukul975 bundle
    Analyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
    24.6k repo stars
  15. ▌
    Performing Malware Persistence Investigation · mukul975 bundle
    Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
    24.6k repo stars
  16. ▌
    Performing Memory Forensics With Volatility3 · mukul975 bundle
    Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
    24.6k repo stars
  17. ▌
    Performing S7comm Protocol Security Analysis · mukul975 bundle
    Analyze Siemens S7comm and S7CommPlus protocol traffic to identify vulnerabilities such as replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation in SIMATIC S7 PLCs.
    24.6k repo stars
  18. ▌
    Performing Sca Dependency Scanning With Snyk · mukul975 bundle
    Scan open-source dependencies for known vulnerabilities using Snyk, including CI/CD integration, automated fix PRs, license compliance, and continuous monitoring.
    24.6k repo stars
  19. ▌
    Performing Soap Web Service Security Testing · mukul975 bundle
    Analyze WSDL definitions and test SOAP endpoints for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
    24.6k repo stars
  20. ▌
    Performing Wireless Network Penetration Test · mukul975 bundle
    Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
    24.6k repo stars
  21. ▌
    Triaging Vulnerabilities With Ssvc Framework · mukul975 bundle
    Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
    24.6k repo stars
  22. ▌
    Analyzing Office365 Audit Logs For Compromise · mukul975 bundle
    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
    24.6k repo stars
  23. ▌
    Analyzing Threat Actor Ttps With Mitre Attack · mukul975 bundle
    Map threat actor behavior to the MITRE ATT&CK framework, build technique coverage heatmaps, identify detection gaps, and produce actionable intelligence reports.
    24.6k repo stars
  24. ▌
    Analyzing Typosquatting Domains With Dnstwist · mukul975 bundle
    Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
    24.6k repo stars
  25. ▌
    Auditing Azure Active Directory Configuration · mukul975 bundle
    Audit Microsoft Entra ID (Azure Active Directory) configuration for risky authentication policies, over-privileged role assignments, stale accounts, conditional access gaps, and guest user risks using PowerShell, Graph API, and ScoutSuite.
    24.6k repo stars
  26. ▌
    Auditing Kubernetes Rbac Privilege Escalation · mukul975 bundle
    Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
    24.6k repo stars
  27. ▌
    Building Ioc Enrichment Pipeline With Opencti · mukul975 bundle
    Build an automated IOC enrichment pipeline using OpenCTI's connector ecosystem to enrich indicators with context from VirusTotal, Shodan, AbuseIPDB, GreyNoise, and other sources.
    24.6k repo stars
  28. ▌
    Building Threat Intelligence Feed Integration · mukul975 bundle
    Automates ingestion, normalization, deduplication, and distribution of threat intelligence feeds from STIX/TAXII, open-source, and commercial sources into SIEM platforms for real-time IOC matching and alerting.
    24.6k repo stars
  29. ▌
    Building Vulnerability Aging And Sla Tracking · mukul975 bundle
    Track vulnerability aging and SLA compliance with severity-based remediation timelines, automated escalations, and compliance metrics.
    24.6k repo stars
  30. ▌
    Bypassing Authentication With Forced Browsing · mukul975 bundle
    Discover hidden directories, files, APIs, and administrative interfaces by enumerating URLs and testing authentication enforcement during authorized security assessments.
    24.6k repo stars
  31. ▌
    Conducting External Reconnaissance With Osint · mukul975 bundle
    Maps an organization's external attack surface using public sources like DNS records, certificate transparency logs, search engines, social media, and data breach databases, without directly interacting with target systems.
    24.6k repo stars
  32. ▌
    Configuring Snort Ids For Intrusion Detection · mukul975 bundle
    Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments.
    24.6k repo stars
  33. ▌
    Configuring Tls 1 3 For Secure Communications · mukul975 bundle
    Configure TLS 1.3 on nginx, Apache, and Python applications, validate configurations with openssl and testssl.sh, and disable legacy TLS versions.
    24.6k repo stars
  34. ▌
    Detecting Entra Offensive Tools In Graph Logs · mukul975 bundle
    Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
    24.6k repo stars
  35. ▌
    Detecting Evasion Techniques In Endpoint Logs · mukul975 bundle
    Detects defense evasion techniques in endpoint logs, including log tampering, timestomping, process injection, and security tool disabling, using Sysmon, EDR telemetry, and SIEM queries.
    24.6k repo stars
  36. ▌
    Detecting T1055 Process Injection With Sysmon · mukul975 bundle
    Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
    24.6k repo stars
  37. ▌
    Emulating Cloud Attacks With Stratus Red Team · mukul975 bundle
    Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
    24.6k repo stars
  38. ▌
    Exploiting Ms17 010 Eternalblue Vulnerability · mukul975 bundle
    Exploits the MS17-010 (EternalBlue) vulnerability in Microsoft's SMBv1 implementation for authorized security testing, red team exercises, and penetration testing engagements.
    24.6k repo stars
  39. ▌
    Exploiting Template Injection Vulnerabilities · mukul975 bundle
    Detect and exploit Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution during authorized penetration tests.
    24.6k repo stars
  40. ▌
    Hardening Windows Endpoint With Cis Benchmark · mukul975 bundle
    Hardens Windows endpoints using CIS Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.
    24.6k repo stars
  41. ▌
    Hunting For Beaconing With Frequency Analysis · mukul975 bundle
    Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
    24.6k repo stars
  42. ▌
    Hunting For Persistence Mechanisms In Windows · mukul975 bundle
    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
    24.6k repo stars
  43. ▌
    Hunting For Persistence Via Wmi Subscriptions · mukul975 bundle
    Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
    24.6k repo stars
  44. ▌
    Implementing API Rate Limiting And Throttling · mukul975 bundle
    Protect APIs from abuse and resource exhaustion by implementing rate limiting with token bucket, sliding window, and fixed window algorithms using Redis-backed counters, API gateway plugins, or application middleware.
    24.6k repo stars
  45. ▌
    Implementing Browser Isolation For Zero Trust · mukul975 bundle
    Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture, implementing isolation policies with URL categorization, risk-based routing, content disarming and reconstruction (CDR), and data loss prevention controls.
    24.6k repo stars
  46. ▌
    Implementing Email Sandboxing With Proofpoint · mukul975 bundle
    Configure Proofpoint Targeted Attack Protection (TAP) to detonate suspicious attachments and URLs in isolated sandboxes, integrate with email flow, analyze reports, and tune detection policies.
    24.6k repo stars
  47. ▌
    Implementing Envelope Encryption With AWS Kms · mukul975 bundle
    Encrypt large data volumes locally using envelope encryption with AWS KMS, generating data keys and managing encrypted keys alongside ciphertext.
    24.6k repo stars
  48. ▌
    Implementing Gdpr Data Subject Access Request · mukul975 bundle
    Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging.
    24.6k repo stars
  49. ▌
    Implementing Honeytokens For Breach Detection · mukul975 bundle
    Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection.
    24.6k repo stars
  50. ▌
    Implementing Just In Time Access Provisioning · mukul975 bundle
    Eliminate standing privileges by granting temporary, time-bound access only when needed, covering JIT architecture design, approval workflows, automatic expiration, and integration with PAM and IGA platforms.
    24.6k repo stars
  51. ▌
    Implementing Network Deception With Honeypots · mukul975 bundle
    Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
    24.6k repo stars
  52. ▌
    Implementing Ransomware Kill Switch Detection · mukul975 bundle
    Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing.
    24.6k repo stars
  53. ▌
    Integrating Sast Into Github Actions Pipeline · mukul975 bundle
    Integrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
    24.6k repo stars
  54. ▌
    Implementing Disk Encryption With Bitlocker · mukul975 bundle
    Encrypts Windows endpoints using Microsoft BitLocker to protect data at rest, covering TPM configuration, GPO settings, Intune deployment, and recovery key management for compliance requirements.
    24.6k repo stars
  55. ▌
    Implementing Runtime Security With Tetragon · mukul975 bundle
    Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
    24.6k repo stars
  56. ▌
    Implementing Siem Correlation Rules For Apt · mukul975 bundle
    Detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
    24.6k repo stars
  57. ▌
    Implementing Ticketing System For Incidents · mukul975 bundle
    Automates incident ticketing by connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured tracking, SLA management, escalation workflows, and compliance documentation.
    24.6k repo stars
  58. ▌
    Implementing Velociraptor For Ir Collection · mukul975 bundle
    Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
    24.6k repo stars
  59. ▌
    Integrating Dast With Owasp Zap In Pipeline · mukul975 bundle
    Integrates OWASP ZAP for Dynamic Application Security Testing in CI/CD pipelines, configuring baseline, full, and API scans, interpreting findings, tuning policies, and establishing quality gates in GitHub Actions and GitLab CI.
    24.6k repo stars
  60. ▌
    Parsing Artifacts With Eric Zimmerman Tools · mukul975 bundle
    Parse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
    24.6k repo stars
  61. ▌
    Performing Agentless Vulnerability Scanning · mukul975 bundle
    Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
    24.6k repo stars
  62. ▌
    Performing Authenticated Vulnerability Scan · mukul975 bundle
    Run authenticated vulnerability scans using valid credentials to deeply inspect target systems for missing patches, misconfigurations, and security weaknesses.
    24.6k repo stars
  63. ▌
    Performing Dmarc Policy Enforcement Rollout · mukul975 bundle
    Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
    24.6k repo stars
  64. ▌
    Performing Docker Bench Security Assessment · mukul975 bundle
    Audits Docker host and daemon configuration against the CIS Docker Benchmark, generating compliance reports with pass/fail/warn results and remediation steps.
    24.6k repo stars
  65. ▌
    Performing Endpoint Forensics Investigation · mukul975 bundle
    Conducts digital forensics investigations on compromised endpoints, including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction for incident response and evidence collection.
    24.6k repo stars
  66. ▌
    Performing False Positive Reduction In Siem · mukul975 bundle
    Systematically reduce SIEM false positives through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
    24.6k repo stars
  67. ▌
    Performing Firmware Extraction With Binwalk · mukul975 bundle
    Extracts and analyzes firmware images using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis, recursive extraction, filesystem mounting, and string analysis for credential and configuration discovery.
    24.6k repo stars
  68. ▌
    Performing Ics Asset Discovery With Claroty · mukul975 bundle
    Discover and inventory ICS/OT assets using Claroty xDome, including passive monitoring, active queries, and integration with CMDB tools.
    24.6k repo stars
  69. ▌
    Performing Network Forensics With Wireshark · mukul975 bundle
    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
    24.6k repo stars
  70. ▌
    Performing Oil Gas Cybersecurity Assessment · mukul975 bundle
    Conduct cybersecurity assessments for oil and gas facilities, covering upstream, midstream, and downstream operations, including SCADA, DCS, and safety systems, with compliance mapping to API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST CSF.
    24.6k repo stars
  71. ▌
    Performing Ot Vulnerability Scanning Safely · mukul975 bundle
    Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
    24.6k repo stars
  72. ▌
    Performing Phishing Simulation With Gophish · mukul975 bundle
    Deploy GoPhish, create phishing scenarios, and analyze campaign results to measure organizational resilience against phishing attacks.
    24.6k repo stars
  73. ▌
    Performing Privileged Account Access Review · mukul975 bundle
    Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
    24.6k repo stars
  74. ▌
    Performing Ssl Tls Inspection Configuration · mukul975 bundle
    Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
    24.6k repo stars
  75. ▌
    Performing Threat Hunting With Elastic Siem · mukul975 bundle
    Proactively search for threats in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection.
    24.6k repo stars
  76. ▌
    Performing Web Application Penetration Test · mukul975 bundle
    Systematically tests web applications for vulnerabilities following the OWASP Web Security Testing Guide (WSTG) methodology, covering authentication, authorization, input validation, session management, and business logic using Burp Suite and manual techniques.
    24.6k repo stars
  77. ▌
    Securing Historian Server In Ot Environment · mukul975 bundle
    Hardens and secures process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments, covering network placement, access control, data replication through DMZ, SQL injection prevention, and data integrity protection.
    24.6k repo stars
  78. ▌
    Testing Android Intents For Vulnerabilities · mukul975 bundle
    Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage.
    24.6k repo stars
  79. ▌
    Triaging Security Incident With Ir Playbook · mukul975 bundle
    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
    24.6k repo stars
  80. ▌
    Analyzing Cobalt Strike Beacon Configuration · mukul975 bundle
    Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
    24.6k repo stars
  81. ▌
    Analyzing Cobaltstrike Malleable C2 Profiles · mukul975 bundle
    Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
    24.6k repo stars
  82. ▌
    Analyzing Malware Sandbox Evasion Techniques · mukul975 bundle
    Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
    24.6k repo stars
  83. ▌
    Analyzing Network Covert Channels In Malware · mukul975 bundle
    Detect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and protocol abuse for C2 and data exfiltration.
    24.6k repo stars
  84. ▌
    Conducting Internal Network Penetration Test · mukul975 bundle
    Simulate an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within a corporate network.
    24.6k repo stars
  85. ▌
    Conducting Spearphishing Simulation Campaign · mukul975 bundle
    Plan and execute authorized spearphishing simulations for red team engagements, covering pretext development, payload creation, infrastructure setup, campaign execution, and post-campaign analysis.
    24.6k repo stars
  86. ▌
    Conducting Wireless Network Penetration Test · mukul975 bundle
    Assess the security of WiFi infrastructure through authorized penetration testing, including weak encryption detection, handshake capture, evil twin attacks, and network segmentation validation.
    24.6k repo stars
  87. ▌
    Configuring Microsegmentation For Zero Trust · mukul975 bundle
    Design and enforce microsegmentation policies using workload identity and label-based rules to prevent lateral movement in zero trust architectures, with guidance for tools like VMware NSX, Illumio, and Calico.
    24.6k repo stars
  88. ▌
    Deploying Palo Alto Prisma Access Zero Trust · mukul975 bundle
    Deploy Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager.
    24.6k repo stars
  89. ▌
    Detecting Typosquatting Packages In NPM Pypi · mukul975 bundle
    Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity, publish date heuristics, and download count anomalies.
    24.6k repo stars
  90. ▌
    Executing Active Directory Attack Simulation · mukul975 bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
    24.6k repo stars
  91. ▌
    Exploiting Prototype Pollution In Javascript · mukul975 bundle
    Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
    24.6k repo stars
  92. ▌
    Hunting For Data Staging Before Exfiltration · mukul975 bundle
    Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry.
    24.6k repo stars
  93. ▌
    Hunting For Defense Evasion Via Timestomping · mukul975 bundle
    Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT using analyzeMFT and Python.
    24.6k repo stars
  94. ▌
    Implementing Aes Encryption For Data At REST · mukul975 bundle
    Implement AES-256-GCM encryption for files and data at rest, including key derivation, IV management, and authenticated encryption.
    24.6k repo stars
  95. ▌
    Implementing API Security Posture Management · mukul975 bundle
    Continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.
    24.6k repo stars
  96. ▌
    Implementing AWS Config Rules For Compliance · mukul975 bundle
    Deploy AWS Config rules for continuous compliance monitoring, including managed and custom rules aligned to CIS and PCI DSS frameworks, automatic remediation with SSM Automation, and multi-account compliance aggregation.
    24.6k repo stars
  97. ▌
    Implementing Ddos Mitigation With Cloudflare · mukul975 bundle
    Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
    24.6k repo stars
  98. ▌
    Implementing Digital Signatures With Ed25519 · mukul975 bundle
    Implement Ed25519 digital signatures for document signing, code signing, and API authentication using Python.
    24.6k repo stars
  99. ▌
    Implementing Google Workspace Admin Security · mukul975 bundle
    Hardens Google Workspace environments by configuring super admin accounts, phishing-resistant MFA, email authentication (SPF/DKIM/DMARC), DLP policies, OAuth app controls, and external sharing restrictions.
    24.6k repo stars
  100. ▌
    Implementing Hashicorp Vault Dynamic Secrets · mukul975 bundle
    Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation.
    24.6k repo stars