mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Implementing Memory Protection With Dep Aslr · mukul975 bundleConfigures memory protection mechanisms including DEP, ASLR, CFG, and Windows Exploit Protection to harden endpoints against buffer overflows, ROP chains, and code injection.
- ▌ Implementing Sigstore For Software Signing · mukul975 bundleSigns and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls.
- ▌ Intercepting Mobile Traffic With Burpsuite · mukul975 bundleIntercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities.
- ▌ Performing Access Review And Certification · mukul975 bundleConduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles, covering review campaign design, reviewer selection, risk-based prioritization, and remediation tracking for compliance with SOX, HIPAA, and PCI DSS.
- ▌ Performing Authenticated Scan With Openvas · mukul975 bundleConfigure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.
- ▌ Performing Cloud Log Forensics With Athena · mukul975 bundleQuery AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
- ▌ Performing Dark Web Monitoring For Threats · mukul975 bundleScan Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked credentials, data breaches, and threat actor discussions.
- ▌ Performing Deception Technology Deployment · mukul975 bundleDeploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates.
- ▌ Performing Dynamic Analysis Of Android App · mukul975 bundlePerforms runtime dynamic analysis of Android applications using Frida, Objection, and ADB to observe behavior, intercept function calls, modify runtime values, and identify vulnerabilities missed by static analysis.
- ▌ Performing HTTP Parameter Pollution Attack · mukul975 bundleExecute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
- ▌ Performing Network Packet Capture Analysis · mukul975 bundleAnalyze network packet captures (PCAP/PCAPNG) using Wireshark, tshark, tcpdump, and Python to reconstruct communications, extract files, and identify malicious traffic.
- ▌ Performing OAUTH Scope Minimization Review · mukul975 bundleAudits OAuth 2.0 permissions across identity providers to identify over-privileged third-party integrations, excessive API scopes, and unused token grants, enforcing least-privilege access.
- ▌ Performing Privilege Escalation Assessment · mukul975 bundlePerforms privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control.
- ▌ Performing Ssrf Vulnerability Exploitation · mukul975 bundleTest for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters.
- ▌ Performing Web Application Firewall Bypass · mukul975 bundleBypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
- ▌ Scanning Kubernetes Manifests With Kubesec · mukul975 bundleScan Kubernetes resource manifests with Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
- ▌ Testing For Business Logic Vulnerabilities · mukul975 bundleIdentify flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what automated scanners can detect.
- ▌ Testing For JSON Web Token Vulnerabilities · mukul975 bundleTest JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
- ▌ Analyzing Command And Control Communication · mukul975 bundleAnalyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure for detection development and threat intelligence.
- ▌ Analyzing Macro Malware In Office Documents · mukul975 bundleExtracts and analyzes malicious VBA macros, XLM macros, DDE, and remote template injections in Microsoft Office documents using olevba, oledump, and deobfuscation techniques to identify download cradles, payload execution, and persistence mechanisms.
- ▌ Analyzing Malware Persistence With Autoruns · mukul975 bundleIdentify and analyze malware persistence mechanisms on Windows systems using Sysinternals Autoruns, covering registry keys, scheduled tasks, services, drivers, and startup locations.
- ▌ Analyzing Ransomware Leak Site Intelligence · mukul975 bundleMonitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
- ▌ Analyzing Tls Certificate Transparency Logs · mukul975 bundleQueries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance.
- ▌ Building Ioc Defanging And Sharing Pipeline · mukul975 bundleBuild an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
- ▌ Building Phishing Reporting Button Workflow · mukul975 bundleDeploy a phishing report button in email clients and build an automated triage workflow that analyzes user-reported suspicious emails, extracts IOCs, and provides feedback to reporters.
- ▌ Conducting Memory Forensics With Volatility · mukul975 bundleAnalyze RAM dumps with Volatility 3 to detect malware, process injection, network connections, and credential theft during incident response.
- ▌ Configuring Network Segmentation With Vlans · mukul975 bundleDesigns and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
- ▌ Configuring Suricata For Network Monitoring · mukul975 bundleDeploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
- ▌ Configuring Zscaler Private Access For Ztna · mukul975 bundleReplace traditional VPNs with zero trust network access by deploying Zscaler Private Access, configuring App Connectors, defining application segments, and setting identity-based access policies.
- ▌ Deobfuscating Powershell Obfuscated Malware · mukul975 bundleSystematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
- ▌ Detecting AI Model Prompt Injection Attacks · mukul975 bundleDetects prompt injection attacks targeting LLM-based applications using regex pattern matching, heuristic scoring, and DeBERTa transformer classification.
- ▌ Detecting Anomalous Authentication Patterns · mukul975 bundleDetects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs.
- ▌ Detecting AWS Guardduty Findings Automation · mukul975 bundleAutomate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
- ▌ Detecting Business Email Compromise With AI · mukul975 bundleDeploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
- ▌ Detecting Container Escape With Falco Rules · mukul975 bundleDetect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
- ▌ Detecting Dcsync Attack In Active Directory · mukul975 bundleDetect DCSync attacks by monitoring Active Directory replication requests from non-domain-controller accounts via Event ID 4662 and associated GUIDs.
- ▌ Detecting Deepfake Audio In Vishing Attacks · mukul975 bundleDetects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features and classifying samples with machine learning models.
- ▌ Detecting Insider Data Exfiltration Via Dlp · mukul975 bundleDetects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs using pandas for behavioral analytics and statistical baselines.
- ▌ Detecting Ntlm Relay With Event Correlation · mukul975 bundleDetect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, and auditing SMB and LDAP signing enforcement.
- ▌ Detecting T1003 Credential Dumping With Edr · mukul975 bundleDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
- ▌ Executing Nist Rmf Authorization To Operate · mukul975 bundleGuide federal systems through the NIST Risk Management Framework (SP 800-37 Rev 2) to achieve an Authorization to Operate (ATO), covering categorization, control selection, assessment, and continuous monitoring.
- ▌ Exploiting Active Directory With Bloodhound · mukul975 bundleGraph-based Active Directory reconnaissance tool that reveals hidden relationships and attack paths from compromised accounts to high-value targets like Domain Admins.
- ▌ Generating Forensic Timelines With Hayabusa · mukul975 bundleGenerate Sigma-based forensic timelines from Windows EVTX files using Hayabusa for incident response triage.
- ▌ Hardening Linux Endpoint With Cis Benchmark · mukul975 bundleHardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.
- ▌ Hunting For Living Off The Cloud Techniques · mukul975 bundleHunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration across Azure, AWS, GCP, and SaaS platforms.
- ▌ Hunting For Registry Persistence Mechanisms · mukul975 bundleHunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
- ▌ Implementing Anti Phishing Training Program · mukul975 bundleDesign, deploy, and measure a comprehensive phishing awareness program using platforms like KnowBe4, Proofpoint, and open-source alternatives.
- ▌ Implementing API Schema Validation Security · mukul975 bundleEnforce API input/output contracts using OpenAPI specifications and JSON Schema to prevent injection, mass assignment, and data leakage attacks.
- ▌ Implementing Cisa Zero Trust Maturity Model · mukul975 bundleAssess and implement the CISA Zero Trust Maturity Model v2.0 across identity, devices, networks, applications, and data pillars to achieve progressive zero trust maturity.
- ▌ Implementing Hipaa Security Rule Safeguards · mukul975 bundleConduct HIPAA Security Rule risk analysis, implement administrative, physical, and technical safeguards, manage Business Associate Agreements, and establish breach-notification readiness for covered entities and business associates.
- ▌ Performing Plc Firmware Security Analysis · mukul975 bundleAnalyze PLC firmware for security vulnerabilities including hardcoded credentials, insecure updates, backdoors, memory corruption, and undocumented debug interfaces using static and dynamic analysis techniques.
- ▌ Performing Supply Chain Attack Simulation · mukul975 bundleSimulate and detect software supply chain attacks including typosquatting via Levenshtein distance, dependency confusion testing, package hash verification, and vulnerability scanning with pip-audit.
- ▌ Performing Threat Hunting With Yara Rules · mukul975 bundleScan files, directories, and memory dumps using YARA rules to identify malware families, suspicious patterns, and IOC matches.
- ▌ Testing For Open Redirect Vulnerabilities · mukul975 bundleIdentify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
- ▌ Testing For XML Injection Vulnerabilities · mukul975 bundleTest web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
- ▌ Testing For Xxe Injection Vulnerabilities · mukul975 bundleDiscover and exploit XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
- ▌ Testing Prompt Injection In RAG Pipelines · mukul975 bundleProbe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
- ▌ Analyzing Browser Forensics With Hindsight · mukul975 bundleExtract and analyze Chromium-based browser artifacts using Hindsight to reconstruct user web activity for forensic investigations.
- ▌ Analyzing Lnk File And Jump List Artifacts · mukul975 bundleAnalyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
- ▌ Analyzing Packed Malware With Upx Unpacker · mukul975 bundleIdentifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis.
- ▌ Analyzing Ransomware Encryption Mechanisms · mukul975 bundleAnalyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts.
- ▌ Auditing Tls Certificate Transparency Logs · mukul975 bundleMonitors Certificate Transparency logs to detect unauthorized certificate issuance, discover subdomains, and alert on suspicious certificate activity for owned domains.
- ▌ Building Devsecops Pipeline With Gitlab CI · mukul975 bundleDesign and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
- ▌ Building Incident Timeline With Timesketch · mukul975 bundleBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
- ▌ Building Role Mining For Rbac Optimization · mukul975 bundleApply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
- ▌ Building Threat Feed Aggregation With Misp · mukul975 bundleDeploy MISP to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
- ▌ Conducting Social Engineering Pretext Call · mukul975 bundlePlan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
- ▌ Configuring Host Based Intrusion Detection · mukul975 bundleDeploys and configures host-based intrusion detection systems (Wazuh, OSSEC, AIDE) to monitor file integrity, system calls, and configuration changes across endpoints. Includes FIM policies, rootkit detection, custom alert rules, active response, and SIEM integration.
- ▌ Deploying Cloudflare Access For Zero Trust · mukul975 bundleDeploy Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
- ▌ Detecting Arp Poisoning In Network Traffic · mukul975 bundleDetect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom Python monitoring scripts to protect against man-in-the-middle interception.
- ▌ Detecting Modbus Command Injection Attacks · mukul975 bundleDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines.
- ▌ Detecting Ransomware Precursors In Network · mukul975 bundleDetects early-stage ransomware indicators in network traffic before encryption begins, using Zeek, Suricata, Arkime, SIEM correlation rules, and threat intelligence feeds to identify Cobalt Strike beacons, Mimikatz signatures, and RDP brute-force attempts.
- ▌ Detecting Spearphishing With Email Gateway · mukul975 bundleConfigure email security gateways like Microsoft Defender, Proofpoint, and Mimecast to detect and block targeted spearphishing attacks using impersonation protection, URL detonation, and attachment sandboxing.
- ▌ Exploiting Insecure Data Storage In Mobile · mukul975 bundleIdentifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications, including unencrypted databases, world-readable files, and plaintext credential storage.
- ▌ Exploiting Nosql Injection Vulnerabilities · mukul975 bundleDetect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
- ▌ Hardening Docker Containers For Production · mukul975 bundleApply CIS Docker Benchmark v1.8.0 security best practices to harden Docker containers for production, covering daemon configuration, image building, runtime controls, and auditing.
- ▌ Hunting For Anomalous Powershell Execution · mukul975 bundleHunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events from Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles.
- ▌ Implementing API Gateway Security Controls · mukul975 bundleConfigures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) as a centralized security enforcement point with authentication, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection.
- ▌ Implementing AWS Iam Permission Boundaries · mukul975 bundleConfigure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.
- ▌ Implementing Cloud Dlp For Data Protection · mukul975 bundleDiscover, classify, and protect sensitive data across cloud storage, databases, and data pipelines using Amazon Macie, Azure Information Protection, and Google Cloud DLP API.
- ▌ Implementing Delinea Secret Server For Pam · mukul975 bundleDeploys and configures Delinea Secret Server for privileged access management, including secret vault setup, role-based access policies, automated password rotation, session recording, and Active Directory integration.
- ▌ Implementing Dmarc Dkim Spf Email Security · mukul975 bundlePrevent domain spoofing and phishing by implementing SPF, DKIM, and DMARC email authentication protocols with DNS configuration and validation.
- ▌ Implementing Endpoint Detection With Wazuh · mukul975 bundleDeploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
- ▌ Implementing Gdpr Data Protection Controls · mukul975 bundleImplement technical and organizational measures required by GDPR, including data mapping, DPIAs, data subject rights management, breach notification, and cross-border transfer mechanisms.
- ▌ Implementing Log Integrity With Blockchain · mukul975 bundleBuild an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes.
- ▌ Implementing Mitre Attack Coverage Mapping · mukul975 bundleMap MITRE ATT&CK coverage to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
- ▌ Implementing Mobile Application Management · mukul975 bundleDeploys Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization.
- ▌ Implementing Ot Incident Response Playbook · mukul975 bundleDevelop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
- ▌ Implementing Privileged Access Workstation · mukul975 bundleDesign and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
- ▌ Implementing Privileged Session Monitoring · mukul975 bundleConfigure privileged session monitoring and recording using CyberArk PSM or open-source alternatives like Teleport, with keystroke logging, real-time alerts, and compliance audit trails.
- ▌ Implementing Rapid7 Insightvm For Scanning · mukul975 bundleDeploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
- ▌ Implementing Rbac Hardening For Kubernetes · mukul975 bundleHarden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
- ▌ Implementing Secret Scanning With Gitleaks · mukul975 bundleDetect and prevent hardcoded secrets in git repositories using Gitleaks, including pre-commit hooks, CI/CD integration, custom rules, baseline management, and remediation workflows.
- ▌ Implementing Secrets Management With Vault · mukul975 bundleCentralize secrets management with HashiCorp Vault, including dynamic secret generation, transit encryption, PKI certificate management, and Kubernetes integration.
- ▌ Implementing Semgrep For Custom Sast Rules · mukul975 bundleWrite custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.
- ▌ Implementing Vulnerability Remediation Sla · mukul975 bundleDefine and enforce vulnerability remediation SLAs based on severity, asset criticality, and exploit availability to drive accountability and track compliance.
- ▌ Performing Dynamic Analysis With Any Run · mukul975 bundlePerforms interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes.
- ▌ Performing Lateral Movement With Wmiexec · mukul975 bundleExecute remote commands on Windows targets using WMI-based lateral movement techniques, including Impacket wmiexec.py, CrackMapExec, and native PowerShell WMI commands for red team engagements.
- ▌ Performing Log Source Onboarding In Siem · mukul975 bundleIntegrate new data sources into SIEM platforms by configuring collectors, parsers, normalization, and validation for security monitoring.
- ▌ Performing Physical Intrusion Assessment · mukul975 bundleConduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.