all publishers

mukul975

@mukul975 source repo

828 published skills · page 5 of 9

  1. ▌
    Performing Privilege Escalation On Linux · mukul975 bundle
    Elevate from a low-privilege user account to root access on a compromised Linux system by exploiting misconfigurations, vulnerable services, kernel exploits, and weak permissions.
    24.6k repo stars
  2. ▌
    Performing Scada Hmi Security Assessment · mukul975 bundle
    Assess security of SCADA HMI systems by evaluating authentication, communication, web interfaces, and hardening against IEC 62443 and NIST SP 800-82 guidelines.
    24.6k repo stars
  3. ▌
    Securing Remote Access To Ot Environment · mukul975 bundle
    Implements secure remote access architecture for OT/ICS environments with jump servers, MFA, session recording, and privileged access management.
    24.6k repo stars
  4. ▌
    Validating Backup Integrity For Recovery · mukul975 bundle
    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    24.6k repo stars
  5. ▌
    Validating Tpm Measured Boot Attestation · mukul975 bundle
    Verify TPM measured boot integrity and remote attestation using tpm2-tools, including PCR reading, event log replay, quote generation and verification, and golden baseline comparison.
    24.6k repo stars
  6. ▌
    Analyzing Azure Activity Logs For Threats · mukul975 bundle
    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
    24.6k repo stars
  7. ▌
    Analyzing IOS App Security With Objection · mukul975 bundle
    Perform runtime iOS app security assessments using Objection and Frida to inspect keychain, filesystem, and memory, bypass client-side protections, and evaluate data storage, network, and authentication controls during authorized penetration tests.
    24.6k repo stars
  8. ▌
    Analyzing Outlook Pst For Email Forensics · mukul975 bundle
    Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
    24.6k repo stars
  9. ▌
    Analyzing Persistence Mechanisms In Linux · mukul975 bundle
    Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring.
    24.6k repo stars
  10. ▌
    Analyzing Powershell Script Block Logging · mukul975 bundle
    Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.
    24.6k repo stars
  11. ▌
    Analyzing Windows Lnk Files For Artifacts · mukul975 bundle
    Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
    24.6k repo stars
  12. ▌
    Assessing Vector And Embedding Weaknesses · mukul975 bundle
    Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
    24.6k repo stars
  13. ▌
    Attacking OAUTH With Device Code Phishing · mukul975 bundle
    Execute OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services during authorized red-team engagements.
    24.6k repo stars
  14. ▌
    Building Threat Hunt Hypothesis Framework · mukul975 bundle
    Transform threat intelligence and attack patterns into testable hunting hypotheses for proactive threat detection.
    24.6k repo stars
  15. ▌
    Conducting Domain Persistence With Dcsync · mukul975 bundle
    Extract Active Directory credentials via DCSync attacks and establish domain persistence by dumping KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
    24.6k repo stars
  16. ▌
    Conducting Full Scope Red Team Engagement · mukul975 bundle
    Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.
    24.6k repo stars
  17. ▌
    Configuring Active Directory Tiered Model · mukul975 bundle
    Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations, and credential theft mitigation.
    24.6k repo stars
  18. ▌
    Continuous LLM Red Teaming With Promptfoo · mukul975 bundle
    Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
    24.6k repo stars
  19. ▌
    Deploying Osquery For Endpoint Monitoring · mukul975 bundle
    Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.
    24.6k repo stars
  20. ▌
    Detecting Exfiltration Over Dns With Zeek · mukul975 bundle
    Analyze Zeek dns.log files to detect DNS-based data exfiltration by computing Shannon entropy, flagging long subdomain labels, and identifying anomalous query patterns.
    24.6k repo stars
  21. ▌
    Detecting Living Off The Land With Lolbas · mukul975 bundle
    Detect abuse of legitimate Windows binaries (LOLBins) like certutil, regsvr32, mshta, and rundll32 using process telemetry, Sigma rules, and parent-child process analysis.
    24.6k repo stars
  22. ▌
    Detecting Suspicious Powershell Execution · mukul975 bundle
    Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
    24.6k repo stars
  23. ▌
    Eradicating Malware From Infected Systems · mukul975 bundle
    Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
    24.6k repo stars
  24. ▌
    Exploiting Excessive Data Exposure In API · mukul975 bundle
    Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. Maps to OWASP API3:2023 Broken Object Property Level Authorization.
    24.6k repo stars
  25. ▌
    Exploiting JWT Algorithm Confusion Attack · mukul975 bundle
    Exploit JWT algorithm confusion vulnerabilities by manipulating the alg header to switch from RS256 to HS256, set alg to none, or inject kid/jku/x5u headers to bypass signature verification.
    24.6k repo stars
  26. ▌
    Exploiting Race Condition Vulnerabilities · mukul975 bundle
    Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
    24.6k repo stars
  27. ▌
    Hunting For Command And Control Beaconing · mukul975 bundle
    Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
    24.6k repo stars
  28. ▌
    Hunting For Unusual Service Installations · mukul975 bundle
    Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
    24.6k repo stars
  29. ▌
    Implementing Anti Ransomware Group Policy · mukul975 bundle
    Hardens Windows Active Directory environments against ransomware by configuring Group Policy Objects with AppLocker rules, Controlled Folder Access, Attack Surface Reduction rules, and lateral movement restrictions.
    24.6k repo stars
  30. ▌
    Implementing Immutable Backup With Restic · mukul975 bundle
    Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection, automating backup creation, integrity verification, snapshot retention, and restore testing.
    24.6k repo stars
  31. ▌
    Implementing JWT Signing And Verification · mukul975 bundle
    Implement secure JWT signing and verification with HMAC-SHA256, RSA-PSS, and EdDSA, including token expiration, claims validation, and defense against common JWT attacks.
    24.6k repo stars
  32. ▌
    Implementing Mtls For Zero Trust Services · mukul975 bundle
    Generates CA and service certificates, then configures mutual TLS authentication between microservices using Python's cryptography and ssl modules.
    24.6k repo stars
  33. ▌
    Implementing Nerc Cip Compliance Controls · mukul975 bundle
    Categorize BES cyber systems and implement NERC CIP compliance controls for high, medium, and low impact assets, including electronic security perimeters, configuration management, and supply chain risk management.
    24.6k repo stars
  34. ▌
    Implementing Siem Use Cases For Detection · mukul975 bundle
    Design, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
    24.6k repo stars
  35. ▌
    Implementing Soar Automation With Phantom · mukul975 bundle
    Automates alert triage, IOC enrichment, containment actions, and incident response playbooks using Splunk SOAR (Phantom) to reduce manual analyst work and standardize response procedures.
    24.6k repo stars
  36. ▌
    Investigating Ransomware Attack Artifacts · mukul975 bundle
    Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
    24.6k repo stars
  37. ▌
    Monitoring Scada Modbus Traffic Anomalies · mukul975 bundle
    Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns using deep packet inspection with pymodbus, Scapy, and Zeek.
    24.6k repo stars
  38. ▌
    Performing Alert Triage With Elastic Siem · mukul975 bundle
    Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.
    24.6k repo stars
  39. ▌
    Performing Arp Spoofing Attack Simulation · mukul975 bundle
    Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
    24.6k repo stars
  40. ▌
    Performing Content Security Policy Bypass · mukul975 bundle
    Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
    24.6k repo stars
  41. ▌
    Performing Credential Access With Lazagne · mukul975 bundle
    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
    24.6k repo stars
  42. ▌
    Performing Indicator Lifecycle Management · mukul975 bundle
    Tracks indicators of compromise from initial discovery through validation, enrichment, deployment, monitoring, and retirement to maintain a high-quality, actionable indicator database.
    24.6k repo stars
  43. ▌
    Performing Kubernetes Penetration Testing · mukul975 bundle
    Systematically evaluates Kubernetes cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets using tools like kube-hunter, Kubescape, and kube-bench.
    24.6k repo stars
  44. ▌
    Performing Ot Network Security Assessment · mukul975 bundle
    Conduct comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths, addressing the Purdue Reference Model layers and identifying IT/OT convergence risks.
    24.6k repo stars
  45. ▌
    Performing Red Team Phishing With Gophish · mukul975 bundle
    Automates GoPhish phishing simulation campaigns using the Python gophish library to create email templates, configure SMTP profiles, import targets, launch campaigns, and analyze results for security awareness assessment.
    24.6k repo stars
  46. ▌
    Implementing Soar Playbook For Phishing · mukul975 bundle
    Automate phishing incident response by creating Splunk SOAR containers, adding artifacts, and triggering investigation playbooks.
    24.6k repo stars
  47. ▌
    Mapping Attack Paths With Bloodhound Ce · mukul975 bundle
    Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
    24.6k repo stars
  48. ▌
    Performing Binary Exploitation Analysis · mukul975 bundle
    Analyze ELF binaries for exploitation vectors using checksec, ROPgadget, and pwntools for buffer overflow and ROP chain development during authorized security testing and CTF challenges.
    24.6k repo stars
  49. ▌
    Performing Disk Forensics Investigation · mukul975 bundle
    Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases.
    24.6k repo stars
  50. ▌
    Performing GRAPHQL Introspection Attack · mukul975 bundle
    Extracts GraphQL API schemas through introspection attacks, identifies sensitive fields and mutations, and tests for query depth and complexity vulnerabilities.
    24.6k repo stars
  51. ▌
    Performing Insider Threat Investigation · mukul975 bundle
    Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case.
    24.6k repo stars
  52. ▌
    Performing Nist Csf Maturity Assessment · mukul975 bundle
    Conduct a maturity assessment against the NIST Cybersecurity Framework (CSF) 2.0, using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
    24.6k repo stars
  53. ▌
    Performing Privileged Account Discovery · mukul975 bundle
    Discover and inventory privileged accounts across enterprise infrastructure, including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin accounts, with automated scanning, risk classification, and PAM onboarding.
    24.6k repo stars
  54. ▌
    Performing Ransomware Tabletop Exercise · mukul975 bundle
    Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures.
    24.6k repo stars
  55. ▌
    Performing Soc2 Type2 Audit Preparation · mukul975 bundle
    Automates SOC 2 Type II audit preparation including gap assessment, evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring.
    24.6k repo stars
  56. ▌
    Reverse Engineering Malware With Ghidra · mukul975 bundle
    Reverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.
    24.6k repo stars
  57. ▌
    Securing Container Registry With Harbor · mukul975 bundle
    Configure and manage Harbor container registry with security features including vulnerability scanning, image signing, RBAC, content trust, and audit logging.
    24.6k repo stars
  58. ▌
    Analyzing Apt Group With Mitre Navigator · mukul975 bundle
    Query MITRE ATT&CK data programmatically, map APT group TTPs to Navigator layers, create multi-layer overlays for gap analysis, and generate actionable intelligence reports for detection engineering teams.
    24.6k repo stars
  59. ▌
    Analyzing Linux Audit Logs For Intrusion · mukul975 bundle
    Detect intrusion attempts, unauthorized access, and privilege escalation on Linux hosts using the auditd framework with ausearch and aureport utilities.
    24.6k repo stars
  60. ▌
    Analyzing Network Flow Data With Netflow · mukul975 bundle
    Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns using the Python netflow library.
    24.6k repo stars
  61. ▌
    Analyzing Network Traffic With Wireshark · mukul975 bundle
    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
    24.6k repo stars
  62. ▌
    Analyzing Supply Chain Malware Artifacts · mukul975 bundle
    Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
    24.6k repo stars
  63. ▌
    Analyzing Windows Registry For Artifacts · mukul975 bundle
    Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
    24.6k repo stars
  64. ▌
    Auditing Foundry Smart Contract Security · mukul975 bundle
    Runs a pre-deployment security audit of Solidity smart contracts in a Foundry project, combining static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing to catch reentrancy, access-control, and arithmetic bugs before deploying to an EVM chain.
    24.6k repo stars
  65. ▌
    Building Threat Actor Profile From Osint · mukul975 bundle
    Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
    24.6k repo stars
  66. ▌
    Building Vulnerability Scanning Workflow · mukul975 bundle
    Establishes recurring vulnerability scanning workflows using Nessus, Qualys, or OpenVAS, prioritizes findings with risk scoring and CISA KEV data, integrates with SIEM for exploitation detection, and tracks remediation via SLA-based dashboards and automated ticketing.
    24.6k repo stars
  67. ▌
    Collecting Threat Intelligence With Misp · mukul975 bundle
    Deploy MISP, configure threat feeds, use the PyMISP API for programmatic access, and build automated collection pipelines that aggregate IOCs from multiple community and commercial sources.
    24.6k repo stars
  68. ▌
    Conducting Post Incident Lessons Learned · mukul975 bundle
    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
    24.6k repo stars
  69. ▌
    Configuring AWS Verified Access For Ztna · mukul975 bundle
    Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.
    24.6k repo stars
  70. ▌
    Detecting Ransomware Encryption Behavior · mukul975 bundle
    Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics.
    24.6k repo stars
  71. ▌
    Evaluating Threat Intelligence Platforms · mukul975 bundle
    Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership.
    24.6k repo stars
  72. ▌
    Exploiting API Injection Vulnerabilities · mukul975 bundle
    Tests APIs for injection vulnerabilities including SQL, NoSQL, OS command, LDAP, and SSRF through parameters, headers, and request bodies.
    24.6k repo stars
  73. ▌
    Exploiting Bgp Hijacking Vulnerabilities · mukul975 bundle
    Simulates BGP hijacking attacks in isolated lab environments to test RPKI deployment, route origin validation, and BGP monitoring defenses against prefix hijacking and route leak attacks.
    24.6k repo stars
  74. ▌
    Exploiting SQL Injection Vulnerabilities · mukul975 bundle
    Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.
    24.6k repo stars
  75. ▌
    Exploiting Type Juggling Vulnerabilities · mukul975 bundle
    Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
    24.6k repo stars
  76. ▌
    Hunting Bootkits In Efi System Partition · mukul975 bundle
    Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
    24.6k repo stars
  77. ▌
    Hunting For Data Exfiltration Indicators · mukul975 bundle
    Analyze network traffic, logs, and data flows to detect potential data exfiltration via DNS tunneling, cloud storage uploads, encrypted channels, and other indicators of compromise.
    24.6k repo stars
  78. ▌
    Hunting For Living Off The Land Binaries · mukul975 bundle
    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
    24.6k repo stars
  79. ▌
    Hunting For Process Injection Techniques · mukul975 bundle
    Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry.
    24.6k repo stars
  80. ▌
    Hunting For Registry Run Key Persistence · mukul975 bundle
    Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
    24.6k repo stars
  81. ▌
    Implementing AWS Security Hub Compliance · mukul975 bundle
    Aggregate security findings across AWS accounts, enable compliance standards like CIS and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
    24.6k repo stars
  82. ▌
    Implementing Devsecops Security Scanning · mukul975 bundle
    Integrates SAST, DAST, and SCA security scanning into CI/CD pipelines using open-source tools like Semgrep, Trivy, OWASP ZAP, and Gitleaks.
    24.6k repo stars
  83. ▌
    Implementing LLM Guardrails For Security · mukul975 bundle
    Builds input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs using NeMo Guardrails, Presidio, and Guardrails AI.
    24.6k repo stars
  84. ▌
    Implementing Log Forwarding With Fluentd · mukul975 bundle
    Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure.
    24.6k repo stars
  85. ▌
    Implementing Network Segmentation For Ot · mukul975 bundle
    Design and implement network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking, following the Purdue Model and IEC 62443 standards.
    24.6k repo stars
  86. ▌
    Implementing Pci Dss Compliance Controls · mukul975 bundle
    Implement PCI DSS 4.0.1 compliance controls across all 12 requirements, including scoping, network security, data protection, access controls, monitoring, and governance.
    24.6k repo stars
  87. ▌
    Implementing Scim Provisioning With Okta · mukul975 bundle
    Build a SCIM 2.0-compliant API server and integrate it with Okta for automated user provisioning, deprovisioning, profile updates, and group management.
    24.6k repo stars
  88. ▌
    Implementing Stix Taxii Feed Integration · mukul975 bundle
    Consume and produce STIX/TAXII 2.1 cyber threat intelligence feeds using Python, including server discovery, collection polling, object parsing, and SIEM/TIP integration.
    24.6k repo stars
  89. ▌
    Implementing Taxii Server With Opentaxii · mukul975 bundle
    Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
    24.6k repo stars
  90. ▌
    Implementing Zero Trust Dns With Nextdns · mukul975 bundle
    Configure NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
    24.6k repo stars
  91. ▌
    Performing Bluetooth Security Assessment · mukul975 bundle
    Scan for Bluetooth Low Energy devices, enumerate GATT services and characteristics, and detect security vulnerabilities such as unencrypted data exposure and known vulnerable device fingerprints.
    24.6k repo stars
  92. ▌
    Performing Cloud Forensics Investigation · mukul975 bundle
    Collect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments.
    24.6k repo stars
  93. ▌
    Performing Initial Access With Evilginx3 · mukul975 bundle
    Conduct authorized red team initial access using EvilGinx3 adversary-in-the-middle phishing to capture session tokens and bypass multi-factor authentication.
    24.6k repo stars
  94. ▌
    Performing API Inventory And Discovery · mukul975 bundle
    Build a comprehensive catalog of API endpoints including documented, undocumented, shadow, zombie, and deprecated APIs using passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory.
    24.6k repo stars
  95. ▌
    Performing Directory Traversal Testing · mukul975 bundle
    Test web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
    24.6k repo stars
  96. ▌
    Performing GRAPHQL Security Assessment · mukul975 bundle
    Assess GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
    24.6k repo stars
  97. ▌
    Performing IOS App Security Assessment · mukul975 bundle
    Conduct authorized iOS application security assessments using Frida, Objection, and static analysis to evaluate app security posture against OWASP MASTG standards.
    24.6k repo stars
  98. ▌
    Performing Ssl Tls Security Assessment · mukul975 bundle
    Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
    24.6k repo stars
  99. ▌
    Recovering Deleted Files With Photorec · mukul975 bundle
    Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine, regardless of file system damage.
    24.6k repo stars
  100. ▌
    Remediating S3 Bucket Misconfiguration · mukul975 bundle
    Identify and remediate Amazon S3 bucket misconfigurations that expose sensitive data, including enabling Block Public Access, auditing policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation with AWS Config and Lambda.
    24.6k repo stars