mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Implementing Proofpoint Email Security Gateway · mukul975 bundleDeploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
- ▌ Implementing Purdue Model Network Segmentation · mukul975 bundleDesign and implement network segmentation for industrial control systems using the Purdue Enterprise Reference Architecture model, separating OT and IT networks into hierarchical security zones with strict traffic control.
- ▌ Implementing Threat Modeling With Mitre Attack · mukul975 bundleMap adversary TTPs against organizational assets using the MITRE ATT&CK framework, assess detection coverage gaps, and prioritize defensive investments.
- ▌ Implementing Vulnerability Sla Breach Alerting · mukul975 bundleBuild automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
- ▌ Performing Access Recertification With Saviynt · mukul975 bundleConfigure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
- ▌ Performing Asset Criticality Scoring For Vulns · mukul975 bundleBuild a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
- ▌ Implementing Network Policies For Kubernetes · mukul975 bundleCreate and apply Kubernetes NetworkPolicies to enforce pod-level network segmentation, restrict traffic between pods and namespaces, and block access to cloud metadata endpoints.
- ▌ Implementing Patch Management For Ot Systems · mukul975 bundleEstablish a structured patch management program for OT/ICS environments, covering vendor compatibility testing, risk-based prioritization, staged deployment, rollback procedures, and compensating controls for unpatchable systems.
- ▌ Performing Active Directory Penetration Test · mukul975 bundleEnumerate Active Directory domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
- ▌ Performing API Security Testing With Postman · mukul975 bundleBuilds repeatable API security test suites in Postman covering OWASP API Security Top 10 vulnerabilities, with automated authentication, multi-role testing, and CI/CD integration via Newman.
- ▌ Performing Cloud Native Forensics With Falco · mukul975 bundleDeploys and manages Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Parses Falco alerts for incident response.
- ▌ Performing Dns Enumeration And Zone Transfer · mukul975 bundleEnumerate DNS records, attempt zone transfers, brute-force subdomains, and map DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.
- ▌ Performing External Network Penetration Test · mukul975 bundleConduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.
- ▌ Performing Linux Log Forensics Investigation · mukul975 bundleAnalyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
- ▌ Performing Malware Persistence Investigation · mukul975 bundleSystematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
- ▌ Performing Memory Forensics With Volatility3 · mukul975 bundleAnalyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
- ▌ Performing S7comm Protocol Security Analysis · mukul975 bundleAnalyze Siemens S7comm and S7CommPlus protocol traffic to identify vulnerabilities such as replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation in SIMATIC S7 PLCs.
- ▌ Performing Sca Dependency Scanning With Snyk · mukul975 bundleScan open-source dependencies for known vulnerabilities using Snyk, including CI/CD integration, automated fix PRs, license compliance, and continuous monitoring.
- ▌ Performing Soap Web Service Security Testing · mukul975 bundleAnalyze WSDL definitions and test SOAP endpoints for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
- ▌ Performing Wireless Network Penetration Test · mukul975 bundleExecute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
- ▌ Triaging Vulnerabilities With Ssvc Framework · mukul975 bundleTriage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
- ▌ Analyzing Office365 Audit Logs For Compromise · mukul975 bundleParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ Analyzing Threat Actor Ttps With Mitre Attack · mukul975 bundleMap threat actor behavior to the MITRE ATT&CK framework, build technique coverage heatmaps, identify detection gaps, and produce actionable intelligence reports.
- ▌ Analyzing Typosquatting Domains With Dnstwist · mukul975 bundleDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
- ▌ Auditing Azure Active Directory Configuration · mukul975 bundleAudit Microsoft Entra ID (Azure Active Directory) configuration for risky authentication policies, over-privileged role assignments, stale accounts, conditional access gaps, and guest user risks using PowerShell, Graph API, and ScoutSuite.
- ▌ Auditing Kubernetes Rbac Privilege Escalation · mukul975 bundleFind over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
- ▌ Building Ioc Enrichment Pipeline With Opencti · mukul975 bundleBuild an automated IOC enrichment pipeline using OpenCTI's connector ecosystem to enrich indicators with context from VirusTotal, Shodan, AbuseIPDB, GreyNoise, and other sources.
- ▌ Building Threat Intelligence Feed Integration · mukul975 bundleAutomates ingestion, normalization, deduplication, and distribution of threat intelligence feeds from STIX/TAXII, open-source, and commercial sources into SIEM platforms for real-time IOC matching and alerting.
- ▌ Building Vulnerability Aging And Sla Tracking · mukul975 bundleTrack vulnerability aging and SLA compliance with severity-based remediation timelines, automated escalations, and compliance metrics.
- ▌ Bypassing Authentication With Forced Browsing · mukul975 bundleDiscover hidden directories, files, APIs, and administrative interfaces by enumerating URLs and testing authentication enforcement during authorized security assessments.
- ▌ Conducting External Reconnaissance With Osint · mukul975 bundleMaps an organization's external attack surface using public sources like DNS records, certificate transparency logs, search engines, social media, and data breach databases, without directly interacting with target systems.
- ▌ Configuring Snort Ids For Intrusion Detection · mukul975 bundleInstalls, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments.
- ▌ Configuring Tls 1 3 For Secure Communications · mukul975 bundleConfigure TLS 1.3 on nginx, Apache, and Python applications, validate configurations with openssl and testssl.sh, and disable legacy TLS versions.
- ▌ Detecting Entra Offensive Tools In Graph Logs · mukul975 bundleHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
- ▌ Detecting Evasion Techniques In Endpoint Logs · mukul975 bundleDetects defense evasion techniques in endpoint logs, including log tampering, timestomping, process injection, and security tool disabling, using Sysmon, EDR telemetry, and SIEM queries.
- ▌ Detecting T1055 Process Injection With Sysmon · mukul975 bundleDetect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
- ▌ Emulating Cloud Attacks With Stratus Red Team · mukul975 bundleDetonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
- ▌ Exploiting Ms17 010 Eternalblue Vulnerability · mukul975 bundleExploits the MS17-010 (EternalBlue) vulnerability in Microsoft's SMBv1 implementation for authorized security testing, red team exercises, and penetration testing engagements.
- ▌ Exploiting Template Injection Vulnerabilities · mukul975 bundleDetect and exploit Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution during authorized penetration tests.
- ▌ Hardening Windows Endpoint With Cis Benchmark · mukul975 bundleHardens Windows endpoints using CIS Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.
- ▌ Hunting For Beaconing With Frequency Analysis · mukul975 bundleIdentify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
- ▌ Hunting For Persistence Mechanisms In Windows · mukul975 bundleSystematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
- ▌ Hunting For Persistence Via Wmi Subscriptions · mukul975 bundleHunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
- ▌ Implementing API Rate Limiting And Throttling · mukul975 bundleProtect APIs from abuse and resource exhaustion by implementing rate limiting with token bucket, sliding window, and fixed window algorithms using Redis-backed counters, API gateway plugins, or application middleware.
- ▌ Implementing Browser Isolation For Zero Trust · mukul975 bundleDeploys remote browser isolation (RBI) as a core component of a Zero Trust architecture, implementing isolation policies with URL categorization, risk-based routing, content disarming and reconstruction (CDR), and data loss prevention controls.
- ▌ Implementing Email Sandboxing With Proofpoint · mukul975 bundleConfigure Proofpoint Targeted Attack Protection (TAP) to detonate suspicious attachments and URLs in isolated sandboxes, integrate with email flow, analyze reports, and tune detection policies.
- ▌ Implementing Envelope Encryption With AWS Kms · mukul975 bundleEncrypt large data volumes locally using envelope encryption with AWS KMS, generating data keys and managing encrypted keys alongside ciphertext.
- ▌ Implementing Gdpr Data Subject Access Request · mukul975 bundleAutomates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging.
- ▌ Implementing Honeytokens For Breach Detection · mukul975 bundleDeploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection.
- ▌ Implementing Just In Time Access Provisioning · mukul975 bundleEliminate standing privileges by granting temporary, time-bound access only when needed, covering JIT architecture design, approval workflows, automatic expiration, and integration with PAM and IGA platforms.
- ▌ Implementing Network Deception With Honeypots · mukul975 bundleDeploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
- ▌ Implementing Ransomware Kill Switch Detection · mukul975 bundleDetects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing.
- ▌ Integrating Sast Into Github Actions Pipeline · mukul975 bundleIntegrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
- ▌ Implementing Disk Encryption With Bitlocker · mukul975 bundleEncrypts Windows endpoints using Microsoft BitLocker to protect data at rest, covering TPM configuration, GPO settings, Intune deployment, and recovery key management for compliance requirements.
- ▌ Implementing Runtime Security With Tetragon · mukul975 bundleImplement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
- ▌ Implementing Siem Correlation Rules For Apt · mukul975 bundleDetect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
- ▌ Implementing Ticketing System For Incidents · mukul975 bundleAutomates incident ticketing by connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured tracking, SLA management, escalation workflows, and compliance documentation.
- ▌ Implementing Velociraptor For Ir Collection · mukul975 bundleDeploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
- ▌ Integrating Dast With Owasp Zap In Pipeline · mukul975 bundleIntegrates OWASP ZAP for Dynamic Application Security Testing in CI/CD pipelines, configuring baseline, full, and API scans, interpreting findings, tuning policies, and establishing quality gates in GitHub Actions and GitLab CI.
- ▌ Parsing Artifacts With Eric Zimmerman Tools · mukul975 bundleParse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
- ▌ Performing Agentless Vulnerability Scanning · mukul975 bundleConfigure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
- ▌ Performing Authenticated Vulnerability Scan · mukul975 bundleRun authenticated vulnerability scans using valid credentials to deeply inspect target systems for missing patches, misconfigurations, and security weaknesses.
- ▌ Performing Dmarc Policy Enforcement Rollout · mukul975 bundleExecute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
- ▌ Performing Docker Bench Security Assessment · mukul975 bundleAudits Docker host and daemon configuration against the CIS Docker Benchmark, generating compliance reports with pass/fail/warn results and remediation steps.
- ▌ Performing Endpoint Forensics Investigation · mukul975 bundleConducts digital forensics investigations on compromised endpoints, including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction for incident response and evidence collection.
- ▌ Performing False Positive Reduction In Siem · mukul975 bundleSystematically reduce SIEM false positives through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
- ▌ Performing Firmware Extraction With Binwalk · mukul975 bundleExtracts and analyzes firmware images using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis, recursive extraction, filesystem mounting, and string analysis for credential and configuration discovery.
- ▌ Performing Ics Asset Discovery With Claroty · mukul975 bundleDiscover and inventory ICS/OT assets using Claroty xDome, including passive monitoring, active queries, and integration with CMDB tools.
- ▌ Performing Network Forensics With Wireshark · mukul975 bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
- ▌ Performing Oil Gas Cybersecurity Assessment · mukul975 bundleConduct cybersecurity assessments for oil and gas facilities, covering upstream, midstream, and downstream operations, including SCADA, DCS, and safety systems, with compliance mapping to API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST CSF.
- ▌ Performing Ot Vulnerability Scanning Safely · mukul975 bundlePerform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
- ▌ Performing Phishing Simulation With Gophish · mukul975 bundleDeploy GoPhish, create phishing scenarios, and analyze campaign results to measure organizational resilience against phishing attacks.
- ▌ Performing Privileged Account Access Review · mukul975 bundleConduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
- ▌ Performing Ssl Tls Inspection Configuration · mukul975 bundleConfigure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
- ▌ Performing Threat Hunting With Elastic Siem · mukul975 bundleProactively search for threats in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection.
- ▌ Performing Web Application Penetration Test · mukul975 bundleSystematically tests web applications for vulnerabilities following the OWASP Web Security Testing Guide (WSTG) methodology, covering authentication, authorization, input validation, session management, and business logic using Burp Suite and manual techniques.
- ▌ Securing Historian Server In Ot Environment · mukul975 bundleHardens and secures process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments, covering network placement, access control, data replication through DMZ, SQL injection prevention, and data integrity protection.
- ▌ Testing Android Intents For Vulnerabilities · mukul975 bundleTests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage.
- ▌ Triaging Security Incident With Ir Playbook · mukul975 bundleClassify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
- ▌ Analyzing Cobalt Strike Beacon Configuration · mukul975 bundleExtract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
- ▌ Analyzing Cobaltstrike Malleable C2 Profiles · mukul975 bundleParse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
- ▌ Analyzing Malware Sandbox Evasion Techniques · mukul975 bundleDetect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
- ▌ Analyzing Network Covert Channels In Malware · mukul975 bundleDetect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, and protocol abuse for C2 and data exfiltration.
- ▌ Conducting Internal Network Penetration Test · mukul975 bundleSimulate an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within a corporate network.
- ▌ Conducting Spearphishing Simulation Campaign · mukul975 bundlePlan and execute authorized spearphishing simulations for red team engagements, covering pretext development, payload creation, infrastructure setup, campaign execution, and post-campaign analysis.
- ▌ Conducting Wireless Network Penetration Test · mukul975 bundleAssess the security of WiFi infrastructure through authorized penetration testing, including weak encryption detection, handshake capture, evil twin attacks, and network segmentation validation.
- ▌ Configuring Microsegmentation For Zero Trust · mukul975 bundleDesign and enforce microsegmentation policies using workload identity and label-based rules to prevent lateral movement in zero trust architectures, with guidance for tools like VMware NSX, Illumio, and Calico.
- ▌ Deploying Palo Alto Prisma Access Zero Trust · mukul975 bundleDeploy Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager.
- ▌ Detecting Typosquatting Packages In NPM Pypi · mukul975 bundleDetects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity, publish date heuristics, and download count anomalies.
- ▌ Executing Active Directory Attack Simulation · mukul975 bundleExecutes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise.
- ▌ Exploiting Prototype Pollution In Javascript · mukul975 bundleDetect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
- ▌ Hunting For Data Staging Before Exfiltration · mukul975 bundleDetect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry.
- ▌ Hunting For Defense Evasion Via Timestomping · mukul975 bundleDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT using analyzeMFT and Python.
- ▌ Implementing Aes Encryption For Data At REST · mukul975 bundleImplement AES-256-GCM encryption for files and data at rest, including key derivation, IV management, and authenticated encryption.
- ▌ Implementing API Security Posture Management · mukul975 bundleContinuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.
- ▌ Implementing AWS Config Rules For Compliance · mukul975 bundleDeploy AWS Config rules for continuous compliance monitoring, including managed and custom rules aligned to CIS and PCI DSS frameworks, automatic remediation with SSM Automation, and multi-account compliance aggregation.
- ▌ Implementing Ddos Mitigation With Cloudflare · mukul975 bundleConfigure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
- ▌ Implementing Digital Signatures With Ed25519 · mukul975 bundleImplement Ed25519 digital signatures for document signing, code signing, and API authentication using Python.
- ▌ Implementing Google Workspace Admin Security · mukul975 bundleHardens Google Workspace environments by configuring super admin accounts, phishing-resistant MFA, email authentication (SPF/DKIM/DMARC), DLP policies, OAuth app controls, and external sharing restrictions.
- ▌ Implementing Hashicorp Vault Dynamic Secrets · mukul975 bundleConfigures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation.