all publishers

mukul975

@mukul975 source repo

828 published skills · page 4 of 9

  1. ▌
    Implementing Memory Protection With Dep Aslr · mukul975 bundle
    Configures memory protection mechanisms including DEP, ASLR, CFG, and Windows Exploit Protection to harden endpoints against buffer overflows, ROP chains, and code injection.
    24.6k repo stars
  2. ▌
    Implementing Sigstore For Software Signing · mukul975 bundle
    Signs and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls.
    24.6k repo stars
  3. ▌
    Intercepting Mobile Traffic With Burpsuite · mukul975 bundle
    Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities.
    24.6k repo stars
  4. ▌
    Performing Access Review And Certification · mukul975 bundle
    Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles, covering review campaign design, reviewer selection, risk-based prioritization, and remediation tracking for compliance with SOX, HIPAA, and PCI DSS.
    24.6k repo stars
  5. ▌
    Performing Authenticated Scan With Openvas · mukul975 bundle
    Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.
    24.6k repo stars
  6. ▌
    Performing Cloud Log Forensics With Athena · mukul975 bundle
    Query AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
    24.6k repo stars
  7. ▌
    Performing Dark Web Monitoring For Threats · mukul975 bundle
    Scan Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked credentials, data breaches, and threat actor discussions.
    24.6k repo stars
  8. ▌
    Performing Deception Technology Deployment · mukul975 bundle
    Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates.
    24.6k repo stars
  9. ▌
    Performing Dynamic Analysis Of Android App · mukul975 bundle
    Performs runtime dynamic analysis of Android applications using Frida, Objection, and ADB to observe behavior, intercept function calls, modify runtime values, and identify vulnerabilities missed by static analysis.
    24.6k repo stars
  10. ▌
    Performing HTTP Parameter Pollution Attack · mukul975 bundle
    Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
    24.6k repo stars
  11. ▌
    Performing Network Packet Capture Analysis · mukul975 bundle
    Analyze network packet captures (PCAP/PCAPNG) using Wireshark, tshark, tcpdump, and Python to reconstruct communications, extract files, and identify malicious traffic.
    24.6k repo stars
  12. ▌
    Performing OAUTH Scope Minimization Review · mukul975 bundle
    Audits OAuth 2.0 permissions across identity providers to identify over-privileged third-party integrations, excessive API scopes, and unused token grants, enforcing least-privilege access.
    24.6k repo stars
  13. ▌
    Performing Privilege Escalation Assessment · mukul975 bundle
    Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control.
    24.6k repo stars
  14. ▌
    Performing Ssrf Vulnerability Exploitation · mukul975 bundle
    Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters.
    24.6k repo stars
  15. ▌
    Performing Web Application Firewall Bypass · mukul975 bundle
    Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
    24.6k repo stars
  16. ▌
    Scanning Kubernetes Manifests With Kubesec · mukul975 bundle
    Scan Kubernetes resource manifests with Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
    24.6k repo stars
  17. ▌
    Testing For Business Logic Vulnerabilities · mukul975 bundle
    Identify flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what automated scanners can detect.
    24.6k repo stars
  18. ▌
    Testing For JSON Web Token Vulnerabilities · mukul975 bundle
    Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
    24.6k repo stars
  19. ▌
    Analyzing Command And Control Communication · mukul975 bundle
    Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure for detection development and threat intelligence.
    24.6k repo stars
  20. ▌
    Analyzing Macro Malware In Office Documents · mukul975 bundle
    Extracts and analyzes malicious VBA macros, XLM macros, DDE, and remote template injections in Microsoft Office documents using olevba, oledump, and deobfuscation techniques to identify download cradles, payload execution, and persistence mechanisms.
    24.6k repo stars
  21. ▌
    Analyzing Malware Persistence With Autoruns · mukul975 bundle
    Identify and analyze malware persistence mechanisms on Windows systems using Sysinternals Autoruns, covering registry keys, scheduled tasks, services, drivers, and startup locations.
    24.6k repo stars
  22. ▌
    Analyzing Ransomware Leak Site Intelligence · mukul975 bundle
    Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
    24.6k repo stars
  23. ▌
    Analyzing Tls Certificate Transparency Logs · mukul975 bundle
    Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance.
    24.6k repo stars
  24. ▌
    Building Ioc Defanging And Sharing Pipeline · mukul975 bundle
    Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
    24.6k repo stars
  25. ▌
    Building Phishing Reporting Button Workflow · mukul975 bundle
    Deploy a phishing report button in email clients and build an automated triage workflow that analyzes user-reported suspicious emails, extracts IOCs, and provides feedback to reporters.
    24.6k repo stars
  26. ▌
    Conducting Memory Forensics With Volatility · mukul975 bundle
    Analyze RAM dumps with Volatility 3 to detect malware, process injection, network connections, and credential theft during incident response.
    24.6k repo stars
  27. ▌
    Configuring Network Segmentation With Vlans · mukul975 bundle
    Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
    24.6k repo stars
  28. ▌
    Configuring Suricata For Network Monitoring · mukul975 bundle
    Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
    24.6k repo stars
  29. ▌
    Configuring Zscaler Private Access For Ztna · mukul975 bundle
    Replace traditional VPNs with zero trust network access by deploying Zscaler Private Access, configuring App Connectors, defining application segments, and setting identity-based access policies.
    24.6k repo stars
  30. ▌
    Deobfuscating Powershell Obfuscated Malware · mukul975 bundle
    Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
    24.6k repo stars
  31. ▌
    Detecting AI Model Prompt Injection Attacks · mukul975 bundle
    Detects prompt injection attacks targeting LLM-based applications using regex pattern matching, heuristic scoring, and DeBERTa transformer classification.
    24.6k repo stars
  32. ▌
    Detecting Anomalous Authentication Patterns · mukul975 bundle
    Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs.
    24.6k repo stars
  33. ▌
    Detecting AWS Guardduty Findings Automation · mukul975 bundle
    Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
    24.6k repo stars
  34. ▌
    Detecting Business Email Compromise With AI · mukul975 bundle
    Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
    24.6k repo stars
  35. ▌
    Detecting Container Escape With Falco Rules · mukul975 bundle
    Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
    24.6k repo stars
  36. ▌
    Detecting Dcsync Attack In Active Directory · mukul975 bundle
    Detect DCSync attacks by monitoring Active Directory replication requests from non-domain-controller accounts via Event ID 4662 and associated GUIDs.
    24.6k repo stars
  37. ▌
    Detecting Deepfake Audio In Vishing Attacks · mukul975 bundle
    Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features and classifying samples with machine learning models.
    24.6k repo stars
  38. ▌
    Detecting Insider Data Exfiltration Via Dlp · mukul975 bundle
    Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs using pandas for behavioral analytics and statistical baselines.
    24.6k repo stars
  39. ▌
    Detecting Ntlm Relay With Event Correlation · mukul975 bundle
    Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, and auditing SMB and LDAP signing enforcement.
    24.6k repo stars
  40. ▌
    Detecting T1003 Credential Dumping With Edr · mukul975 bundle
    Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
    24.6k repo stars
  41. ▌
    Executing Nist Rmf Authorization To Operate · mukul975 bundle
    Guide federal systems through the NIST Risk Management Framework (SP 800-37 Rev 2) to achieve an Authorization to Operate (ATO), covering categorization, control selection, assessment, and continuous monitoring.
    24.6k repo stars
  42. ▌
    Exploiting Active Directory With Bloodhound · mukul975 bundle
    Graph-based Active Directory reconnaissance tool that reveals hidden relationships and attack paths from compromised accounts to high-value targets like Domain Admins.
    24.6k repo stars
  43. ▌
    Generating Forensic Timelines With Hayabusa · mukul975 bundle
    Generate Sigma-based forensic timelines from Windows EVTX files using Hayabusa for incident response triage.
    24.6k repo stars
  44. ▌
    Hardening Linux Endpoint With Cis Benchmark · mukul975 bundle
    Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.
    24.6k repo stars
  45. ▌
    Hunting For Living Off The Cloud Techniques · mukul975 bundle
    Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration across Azure, AWS, GCP, and SaaS platforms.
    24.6k repo stars
  46. ▌
    Hunting For Registry Persistence Mechanisms · mukul975 bundle
    Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
    24.6k repo stars
  47. ▌
    Implementing Anti Phishing Training Program · mukul975 bundle
    Design, deploy, and measure a comprehensive phishing awareness program using platforms like KnowBe4, Proofpoint, and open-source alternatives.
    24.6k repo stars
  48. ▌
    Implementing API Schema Validation Security · mukul975 bundle
    Enforce API input/output contracts using OpenAPI specifications and JSON Schema to prevent injection, mass assignment, and data leakage attacks.
    24.6k repo stars
  49. ▌
    Implementing Cisa Zero Trust Maturity Model · mukul975 bundle
    Assess and implement the CISA Zero Trust Maturity Model v2.0 across identity, devices, networks, applications, and data pillars to achieve progressive zero trust maturity.
    24.6k repo stars
  50. ▌
    Implementing Hipaa Security Rule Safeguards · mukul975 bundle
    Conduct HIPAA Security Rule risk analysis, implement administrative, physical, and technical safeguards, manage Business Associate Agreements, and establish breach-notification readiness for covered entities and business associates.
    24.6k repo stars
  51. ▌
    Performing Plc Firmware Security Analysis · mukul975 bundle
    Analyze PLC firmware for security vulnerabilities including hardcoded credentials, insecure updates, backdoors, memory corruption, and undocumented debug interfaces using static and dynamic analysis techniques.
    24.6k repo stars
  52. ▌
    Performing Supply Chain Attack Simulation · mukul975 bundle
    Simulate and detect software supply chain attacks including typosquatting via Levenshtein distance, dependency confusion testing, package hash verification, and vulnerability scanning with pip-audit.
    24.6k repo stars
  53. ▌
    Performing Threat Hunting With Yara Rules · mukul975 bundle
    Scan files, directories, and memory dumps using YARA rules to identify malware families, suspicious patterns, and IOC matches.
    24.6k repo stars
  54. ▌
    Testing For Open Redirect Vulnerabilities · mukul975 bundle
    Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
    24.6k repo stars
  55. ▌
    Testing For XML Injection Vulnerabilities · mukul975 bundle
    Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
    24.6k repo stars
  56. ▌
    Testing For Xxe Injection Vulnerabilities · mukul975 bundle
    Discover and exploit XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
    24.6k repo stars
  57. ▌
    Testing Prompt Injection In RAG Pipelines · mukul975 bundle
    Probe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
    24.6k repo stars
  58. ▌
    Analyzing Browser Forensics With Hindsight · mukul975 bundle
    Extract and analyze Chromium-based browser artifacts using Hindsight to reconstruct user web activity for forensic investigations.
    24.6k repo stars
  59. ▌
    Analyzing Lnk File And Jump List Artifacts · mukul975 bundle
    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
    24.6k repo stars
  60. ▌
    Analyzing Packed Malware With Upx Unpacker · mukul975 bundle
    Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis.
    24.6k repo stars
  61. ▌
    Analyzing Ransomware Encryption Mechanisms · mukul975 bundle
    Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts.
    24.6k repo stars
  62. ▌
    Auditing Tls Certificate Transparency Logs · mukul975 bundle
    Monitors Certificate Transparency logs to detect unauthorized certificate issuance, discover subdomains, and alert on suspicious certificate activity for owned domains.
    24.6k repo stars
  63. ▌
    Building Devsecops Pipeline With Gitlab CI · mukul975 bundle
    Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
    24.6k repo stars
  64. ▌
    Building Incident Timeline With Timesketch · mukul975 bundle
    Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
    24.6k repo stars
  65. ▌
    Building Role Mining For Rbac Optimization · mukul975 bundle
    Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
    24.6k repo stars
  66. ▌
    Building Threat Feed Aggregation With Misp · mukul975 bundle
    Deploy MISP to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
    24.6k repo stars
  67. ▌
    Conducting Social Engineering Pretext Call · mukul975 bundle
    Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
    24.6k repo stars
  68. ▌
    Configuring Host Based Intrusion Detection · mukul975 bundle
    Deploys and configures host-based intrusion detection systems (Wazuh, OSSEC, AIDE) to monitor file integrity, system calls, and configuration changes across endpoints. Includes FIM policies, rootkit detection, custom alert rules, active response, and SIEM integration.
    24.6k repo stars
  69. ▌
    Deploying Cloudflare Access For Zero Trust · mukul975 bundle
    Deploy Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
    24.6k repo stars
  70. ▌
    Detecting Arp Poisoning In Network Traffic · mukul975 bundle
    Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom Python monitoring scripts to protect against man-in-the-middle interception.
    24.6k repo stars
  71. ▌
    Detecting Modbus Command Injection Attacks · mukul975 bundle
    Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines.
    24.6k repo stars
  72. ▌
    Detecting Ransomware Precursors In Network · mukul975 bundle
    Detects early-stage ransomware indicators in network traffic before encryption begins, using Zeek, Suricata, Arkime, SIEM correlation rules, and threat intelligence feeds to identify Cobalt Strike beacons, Mimikatz signatures, and RDP brute-force attempts.
    24.6k repo stars
  73. ▌
    Detecting Spearphishing With Email Gateway · mukul975 bundle
    Configure email security gateways like Microsoft Defender, Proofpoint, and Mimecast to detect and block targeted spearphishing attacks using impersonation protection, URL detonation, and attachment sandboxing.
    24.6k repo stars
  74. ▌
    Exploiting Insecure Data Storage In Mobile · mukul975 bundle
    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications, including unencrypted databases, world-readable files, and plaintext credential storage.
    24.6k repo stars
  75. ▌
    Exploiting Nosql Injection Vulnerabilities · mukul975 bundle
    Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
    24.6k repo stars
  76. ▌
    Hardening Docker Containers For Production · mukul975 bundle
    Apply CIS Docker Benchmark v1.8.0 security best practices to harden Docker containers for production, covering daemon configuration, image building, runtime controls, and auditing.
    24.6k repo stars
  77. ▌
    Hunting For Anomalous Powershell Execution · mukul975 bundle
    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events from Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles.
    24.6k repo stars
  78. ▌
    Implementing API Gateway Security Controls · mukul975 bundle
    Configures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) as a centralized security enforcement point with authentication, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection.
    24.6k repo stars
  79. ▌
    Implementing AWS Iam Permission Boundaries · mukul975 bundle
    Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.
    24.6k repo stars
  80. ▌
    Implementing Cloud Dlp For Data Protection · mukul975 bundle
    Discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines using Amazon Macie, Azure Information Protection, and Google Cloud DLP API.
    24.6k repo stars
  81. ▌
    Implementing Delinea Secret Server For Pam · mukul975 bundle
    Deploys and configures Delinea Secret Server for privileged access management, including secret vault setup, role-based access policies, automated password rotation, session recording, and Active Directory integration.
    24.6k repo stars
  82. ▌
    Implementing Dmarc Dkim Spf Email Security · mukul975 bundle
    Prevent domain spoofing and phishing by implementing SPF, DKIM, and DMARC email authentication protocols with DNS configuration and validation.
    24.6k repo stars
  83. ▌
    Implementing Endpoint Detection With Wazuh · mukul975 bundle
    Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    24.6k repo stars
  84. ▌
    Implementing Gdpr Data Protection Controls · mukul975 bundle
    Implement technical and organizational measures required by GDPR, including data mapping, DPIAs, data subject rights management, breach notification, and cross-border transfer mechanisms.
    24.6k repo stars
  85. ▌
    Implementing Log Integrity With Blockchain · mukul975 bundle
    Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes.
    24.6k repo stars
  86. ▌
    Implementing Mitre Attack Coverage Mapping · mukul975 bundle
    Map MITRE ATT&CK coverage to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
    24.6k repo stars
  87. ▌
    Implementing Mobile Application Management · mukul975 bundle
    Deploys Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization.
    24.6k repo stars
  88. ▌
    Implementing Ot Incident Response Playbook · mukul975 bundle
    Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
    24.6k repo stars
  89. ▌
    Implementing Privileged Access Workstation · mukul975 bundle
    Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
    24.6k repo stars
  90. ▌
    Implementing Privileged Session Monitoring · mukul975 bundle
    Configure privileged session monitoring and recording using CyberArk PSM or open-source alternatives like Teleport, with keystroke logging, real-time alerts, and compliance audit trails.
    24.6k repo stars
  91. ▌
    Implementing Rapid7 Insightvm For Scanning · mukul975 bundle
    Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
    24.6k repo stars
  92. ▌
    Implementing Rbac Hardening For Kubernetes · mukul975 bundle
    Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
    24.6k repo stars
  93. ▌
    Implementing Secret Scanning With Gitleaks · mukul975 bundle
    Detect and prevent hardcoded secrets in git repositories using Gitleaks, including pre-commit hooks, CI/CD integration, custom rules, baseline management, and remediation workflows.
    24.6k repo stars
  94. ▌
    Implementing Secrets Management With Vault · mukul975 bundle
    Centralize secrets management with HashiCorp Vault, including dynamic secret generation, transit encryption, PKI certificate management, and Kubernetes integration.
    24.6k repo stars
  95. ▌
    Implementing Semgrep For Custom Sast Rules · mukul975 bundle
    Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.
    24.6k repo stars
  96. ▌
    Implementing Vulnerability Remediation Sla · mukul975 bundle
    Define and enforce vulnerability remediation SLAs based on severity, asset criticality, and exploit availability to drive accountability and track compliance.
    24.6k repo stars
  97. ▌
    Performing Dynamic Analysis With Any Run · mukul975 bundle
    Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes.
    24.6k repo stars
  98. ▌
    Performing Lateral Movement With Wmiexec · mukul975 bundle
    Execute remote commands on Windows targets using WMI-based lateral movement techniques, including Impacket wmiexec.py, CrackMapExec, and native PowerShell WMI commands for red team engagements.
    24.6k repo stars
  99. ▌
    Performing Log Source Onboarding In Siem · mukul975 bundle
    Integrate new data sources into SIEM platforms by configuring collectors, parsers, normalization, and validation for security monitoring.
    24.6k repo stars
  100. ▌
    Performing Physical Intrusion Assessment · mukul975 bundle
    Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
    24.6k repo stars