mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Performing Privilege Escalation On Linux · mukul975 bundleElevate from a low-privilege user account to root access on a compromised Linux system by exploiting misconfigurations, vulnerable services, kernel exploits, and weak permissions.
- ▌ Performing Scada Hmi Security Assessment · mukul975 bundleAssess security of SCADA HMI systems by evaluating authentication, communication, web interfaces, and hardening against IEC 62443 and NIST SP 800-82 guidelines.
- ▌ Securing Remote Access To Ot Environment · mukul975 bundleImplements secure remote access architecture for OT/ICS environments with jump servers, MFA, session recording, and privileged access management.
- ▌ Validating Backup Integrity For Recovery · mukul975 bundleValidate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
- ▌ Validating Tpm Measured Boot Attestation · mukul975 bundleVerify TPM measured boot integrity and remote attestation using tpm2-tools, including PCR reading, event log replay, quote generation and verification, and golden baseline comparison.
- ▌ Analyzing Azure Activity Logs For Threats · mukul975 bundleQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
- ▌ Analyzing IOS App Security With Objection · mukul975 bundlePerform runtime iOS app security assessments using Objection and Frida to inspect keychain, filesystem, and memory, bypass client-side protections, and evaluate data storage, network, and authentication controls during authorized penetration tests.
- ▌ Analyzing Outlook Pst For Email Forensics · mukul975 bundleAnalyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
- ▌ Analyzing Persistence Mechanisms In Linux · mukul975 bundleDetect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring.
- ▌ Analyzing Powershell Script Block Logging · mukul975 bundleParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.
- ▌ Analyzing Windows Lnk Files For Artifacts · mukul975 bundleParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
- ▌ Assessing Vector And Embedding Weaknesses · mukul975 bundleTest vector stores for embedding inversion, cross-tenant leakage, and poisoning.
- ▌ Attacking OAUTH With Device Code Phishing · mukul975 bundleExecute OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services during authorized red-team engagements.
- ▌ Building Threat Hunt Hypothesis Framework · mukul975 bundleTransform threat intelligence and attack patterns into testable hunting hypotheses for proactive threat detection.
- ▌ Conducting Domain Persistence With Dcsync · mukul975 bundleExtract Active Directory credentials via DCSync attacks and establish domain persistence by dumping KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
- ▌ Conducting Full Scope Red Team Engagement · mukul975 bundlePlan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.
- ▌ Configuring Active Directory Tiered Model · mukul975 bundleImplement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations, and credential theft mitigation.
- ▌ Continuous LLM Red Teaming With Promptfoo · mukul975 bundleWire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
- ▌ Deploying Osquery For Endpoint Monitoring · mukul975 bundleDeploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.
- ▌ Detecting Exfiltration Over Dns With Zeek · mukul975 bundleAnalyze Zeek dns.log files to detect DNS-based data exfiltration by computing Shannon entropy, flagging long subdomain labels, and identifying anomalous query patterns.
- ▌ Detecting Living Off The Land With Lolbas · mukul975 bundleDetect abuse of legitimate Windows binaries (LOLBins) like certutil, regsvr32, mshta, and rundll32 using process telemetry, Sigma rules, and parent-child process analysis.
- ▌ Detecting Suspicious Powershell Execution · mukul975 bundleDetect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
- ▌ Eradicating Malware From Infected Systems · mukul975 bundleSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
- ▌ Exploiting Excessive Data Exposure In API · mukul975 bundleTests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. Maps to OWASP API3:2023 Broken Object Property Level Authorization.
- ▌ Exploiting JWT Algorithm Confusion Attack · mukul975 bundleExploit JWT algorithm confusion vulnerabilities by manipulating the alg header to switch from RS256 to HS256, set alg to none, or inject kid/jku/x5u headers to bypass signature verification.
- ▌ Exploiting Race Condition Vulnerabilities · mukul975 bundleDetect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
- ▌ Hunting For Command And Control Beaconing · mukul975 bundleDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
- ▌ Hunting For Unusual Service Installations · mukul975 bundleDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
- ▌ Implementing Anti Ransomware Group Policy · mukul975 bundleHardens Windows Active Directory environments against ransomware by configuring Group Policy Objects with AppLocker rules, Controlled Folder Access, Attack Surface Reduction rules, and lateral movement restrictions.
- ▌ Implementing Immutable Backup With Restic · mukul975 bundleImplements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection, automating backup creation, integrity verification, snapshot retention, and restore testing.
- ▌ Implementing JWT Signing And Verification · mukul975 bundleImplement secure JWT signing and verification with HMAC-SHA256, RSA-PSS, and EdDSA, including token expiration, claims validation, and defense against common JWT attacks.
- ▌ Implementing Mtls For Zero Trust Services · mukul975 bundleGenerates CA and service certificates, then configures mutual TLS authentication between microservices using Python's cryptography and ssl modules.
- ▌ Implementing Nerc Cip Compliance Controls · mukul975 bundleCategorize BES cyber systems and implement NERC CIP compliance controls for high, medium, and low impact assets, including electronic security perimeters, configuration management, and supply chain risk management.
- ▌ Implementing Siem Use Cases For Detection · mukul975 bundleDesign, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
- ▌ Implementing Soar Automation With Phantom · mukul975 bundleAutomates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.
- ▌ Investigating Ransomware Attack Artifacts · mukul975 bundleIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
- ▌ Monitoring Scada Modbus Traffic Anomalies · mukul975 bundleMonitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns using deep packet inspection with pymodbus, Scapy, and Zeek.
- ▌ Performing Alert Triage With Elastic Siem · mukul975 bundlePerform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.
- ▌ Performing Arp Spoofing Attack Simulation · mukul975 bundleSimulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
- ▌ Performing Content Security Policy Bypass · mukul975 bundleAnalyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
- ▌ Performing Credential Access With Lazagne · mukul975 bundleExtract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
- ▌ Performing Indicator Lifecycle Management · mukul975 bundleTracks indicators of compromise from initial discovery through validation, enrichment, deployment, monitoring, and retirement to maintain a high-quality, actionable indicator database.
- ▌ Performing Kubernetes Penetration Testing · mukul975 bundleSystematically evaluates Kubernetes cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets using tools like kube-hunter, Kubescape, and kube-bench.
- ▌ Performing Ot Network Security Assessment · mukul975 bundleConduct comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths, addressing the Purdue Reference Model layers and identifying IT/OT convergence risks.
- ▌ Performing Red Team Phishing With Gophish · mukul975 bundleAutomates GoPhish phishing simulation campaigns using the Python gophish library to create email templates, configure SMTP profiles, import targets, launch campaigns, and analyze results for security awareness assessment.
- ▌ Implementing Soar Playbook For Phishing · mukul975 bundleAutomate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.
- ▌ Mapping Attack Paths With Bloodhound Ce · mukul975 bundleCollect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
- ▌ Performing Binary Exploitation Analysis · mukul975 bundleAnalyze ELF binaries for exploitation vectors using checksec, ROPgadget, and pwntools for buffer overflow and ROP chain development during authorized security testing and CTF challenges.
- ▌ Performing Disk Forensics Investigation · mukul975 bundleConducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases.
- ▌ Performing GRAPHQL Introspection Attack · mukul975 bundleExtracts GraphQL API schemas through introspection attacks, identifies sensitive fields and mutations, and tests for query depth and complexity vulnerabilities.
- ▌ Performing Insider Threat Investigation · mukul975 bundleInvestigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case.
- ▌ Performing Nist Csf Maturity Assessment · mukul975 bundleConduct a maturity assessment against the NIST Cybersecurity Framework (CSF) 2.0, using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
- ▌ Performing Privileged Account Discovery · mukul975 bundleDiscover and inventory privileged accounts across enterprise infrastructure, including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin accounts, with automated scanning, risk classification, and PAM onboarding.
- ▌ Performing Ransomware Tabletop Exercise · mukul975 bundlePlans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures.
- ▌ Performing Soc2 Type2 Audit Preparation · mukul975 bundleAutomates SOC 2 Type II audit preparation including gap assessment, evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring.
- ▌ Reverse Engineering Malware With Ghidra · mukul975 bundleReverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.
- ▌ Securing Container Registry With Harbor · mukul975 bundleConfigure and manage Harbor container registry with security features including vulnerability scanning, image signing, RBAC, content trust, and audit logging.
- ▌ Analyzing Apt Group With Mitre Navigator · mukul975 bundleQuery MITRE ATT&CK data programmatically, map APT group TTPs to Navigator layers, create multi-layer overlays for gap analysis, and generate actionable intelligence reports for detection engineering teams.
- ▌ Analyzing Linux Audit Logs For Intrusion · mukul975 bundleDetect intrusion attempts, unauthorized access, and privilege escalation on Linux hosts using the auditd framework with ausearch and aureport utilities.
- ▌ Analyzing Network Flow Data With Netflow · mukul975 bundleParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns using the Python netflow library.
- ▌ Analyzing Network Traffic With Wireshark · mukul975 bundleCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
- ▌ Analyzing Supply Chain Malware Artifacts · mukul975 bundleInvestigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
- ▌ Analyzing Windows Registry For Artifacts · mukul975 bundleExtract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
- ▌ Auditing Foundry Smart Contract Security · mukul975 bundleRuns a pre-deployment security audit of Solidity smart contracts in a Foundry project, combining static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing to catch reentrancy, access-control, and arithmetic bugs before deploying to an EVM chain.
- ▌ Building Threat Actor Profile From Osint · mukul975 bundleBuild comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
- ▌ Building Vulnerability Scanning Workflow · mukul975 bundleEstablishes recurring vulnerability scanning workflows using Nessus, Qualys, or OpenVAS, prioritizes findings with risk scoring and CISA KEV data, integrates with SIEM for exploitation detection, and tracks remediation via SLA-based dashboards and automated ticketing.
- ▌ Collecting Threat Intelligence With Misp · mukul975 bundleDeploy MISP, configure threat feeds, use the PyMISP API for programmatic access, and build automated collection pipelines that aggregate IOCs from multiple community and commercial sources.
- ▌ Conducting Post Incident Lessons Learned · mukul975 bundleFacilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
- ▌ Configuring AWS Verified Access For Ztna · mukul975 bundleConfigure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.
- ▌ Detecting Ransomware Encryption Behavior · mukul975 bundleDetects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics.
- ▌ Evaluating Threat Intelligence Platforms · mukul975 bundleEvaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership.
- ▌ Exploiting API Injection Vulnerabilities · mukul975 bundleTests APIs for injection vulnerabilities including SQL, NoSQL, OS command, LDAP, and SSRF through parameters, headers, and request bodies.
- ▌ Exploiting Bgp Hijacking Vulnerabilities · mukul975 bundleSimulates BGP hijacking attacks in isolated lab environments to test RPKI deployment, route origin validation, and BGP monitoring defenses against prefix hijacking and route leak attacks.
- ▌ Exploiting SQL Injection Vulnerabilities · mukul975 bundleIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.
- ▌ Exploiting Type Juggling Vulnerabilities · mukul975 bundleExploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
- ▌ Hunting Bootkits In Efi System Partition · mukul975 bundleBaseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
- ▌ Hunting For Data Exfiltration Indicators · mukul975 bundleAnalyze network traffic, logs, and data flows to detect potential data exfiltration via DNS tunneling, cloud storage uploads, encrypted channels, and other indicators of compromise.
- ▌ Hunting For Living Off The Land Binaries · mukul975 bundleProactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
- ▌ Hunting For Process Injection Techniques · mukul975 bundleDetect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry.
- ▌ Hunting For Registry Run Key Persistence · mukul975 bundleDetect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
- ▌ Implementing AWS Security Hub Compliance · mukul975 bundleAggregate security findings across AWS accounts, enable compliance standards like CIS and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
- ▌ Implementing Devsecops Security Scanning · mukul975 bundleIntegrates SAST, DAST, and SCA security scanning into CI/CD pipelines using open-source tools like Semgrep, Trivy, OWASP ZAP, and Gitleaks.
- ▌ Implementing LLM Guardrails For Security · mukul975 bundleBuilds input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs using NeMo Guardrails, Presidio, and Guardrails AI.
- ▌ Implementing Log Forwarding With Fluentd · mukul975 bundleConfigure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure.
- ▌ Implementing Network Segmentation For Ot · mukul975 bundleDesign and implement network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking, following the Purdue Model and IEC 62443 standards.
- ▌ Implementing Pci Dss Compliance Controls · mukul975 bundleImplement PCI DSS 4.0.1 compliance controls across all 12 requirements, including scoping, network security, data protection, access controls, monitoring, and governance.
- ▌ Implementing Scim Provisioning With Okta · mukul975 bundleBuild a SCIM 2.0-compliant API server and integrate it with Okta for automated user provisioning, deprovisioning, profile updates, and group management.
- ▌ Implementing Stix Taxii Feed Integration · mukul975 bundleConsume and produce STIX/TAXII 2.1 cyber threat intelligence feeds using Python, including server discovery, collection polling, object parsing, and SIEM/TIP integration.
- ▌ Implementing Taxii Server With Opentaxii · mukul975 bundleDeploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
- ▌ Implementing Zero Trust Dns With Nextdns · mukul975 bundleConfigure NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
- ▌ Performing Bluetooth Security Assessment · mukul975 bundleScan for Bluetooth Low Energy devices, enumerate GATT services and characteristics, and detect security vulnerabilities such as unencrypted data exposure and known vulnerable device fingerprints.
- ▌ Performing Cloud Forensics Investigation · mukul975 bundleCollect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments.
- ▌ Performing Initial Access With Evilginx3 · mukul975 bundleConduct authorized red team initial access using EvilGinx3 adversary-in-the-middle phishing to capture session tokens and bypass multi-factor authentication.
- ▌ Performing API Inventory And Discovery · mukul975 bundleBuild a comprehensive catalog of API endpoints including documented, undocumented, shadow, zombie, and deprecated APIs using passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory.
- ▌ Performing Directory Traversal Testing · mukul975 bundleTest web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
- ▌ Performing GRAPHQL Security Assessment · mukul975 bundleAssess GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
- ▌ Performing IOS App Security Assessment · mukul975 bundleConduct authorized iOS application security assessments using Frida, Objection, and static analysis to evaluate app security posture against OWASP MASTG standards.
- ▌ Performing Ssl Tls Security Assessment · mukul975 bundleAssess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
- ▌ Recovering Deleted Files With Photorec · mukul975 bundleRecover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine, regardless of file system damage.
- ▌ Remediating S3 Bucket Misconfiguration · mukul975 bundleIdentify and remediate Amazon S3 bucket misconfigurations that expose sensitive data, including enabling Block Public Access, auditing policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation with AWS Config and Lambda.