mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Reverse Engineering IOS App With Frida · mukul975 bundleDynamically instrument iOS apps with Frida to trace methods, extract secrets, and bypass security controls during authorized penetration testing.
- ▌ Scanning Containers With Trivy In Cicd · mukul975 bundleIntegrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates.
- ▌ Securing Azure With Microsoft Defender · mukul975 bundleDeploy Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. Covers enabling Defender plans, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal.
- ▌ Testing API Security With Owasp Top 10 · mukul975 bundleSystematically assess REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
- ▌ Testing Ransomware Recovery Procedures · mukul975 bundleValidate ransomware recovery plans by testing backup restore operations, measuring RTO/RPO targets, verifying data integrity, and documenting recovery gaps in an isolated lab environment.
- ▌ Acquiring Disk Image With Dd And Dcfldd · mukul975 bundleCreate forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
- ▌ Analyzing Campaign Attribution Evidence · mukul975 bundleSystematically evaluates evidence to determine which threat actor is responsible for a cyber operation using the Diamond Model and Analysis of Competing Hypotheses.
- ▌ Analyzing Cloud Storage Access Patterns · mukul975 bundleDetect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls, and potential data exfiltration using statistical baselines.
- ▌ Analyzing Mft For Deleted File Recovery · mukul975 bundleRecover metadata and content of deleted files from NTFS volumes by analyzing the Master File Table, $LogFile, $UsnJrnl, and MFT slack space using forensic tools like MFTECmd and analyzeMFT.
- ▌ Analyzing Network Traffic For Incidents · mukul975 bundleAnalyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts.
- ▌ Analyzing Ransomware Network Indicators · mukul975 bundleAnalyze Zeek conn.log and NetFlow data to detect ransomware network indicators including C2 beaconing, TOR exit node connections, data exfiltration, and suspicious DNS patterns.
- ▌ Analyzing Usb Device Connection History · mukul975 bundleInvestigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
- ▌ Analyzing Web Server Logs For Intrusion · mukul975 bundleParse Apache and Nginx access logs to detect SQL injection, LFI, XSS, scanner fingerprints, and brute-force patterns using regex-based detection, GeoIP enrichment, and statistical anomaly analysis.
- ▌ Auditing MCP Servers For Tool Poisoning · mukul975 bundleScan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
- ▌ Benchmarking Kubernetes With Kube Bench · mukul975 bundleRun CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
- ▌ Building Detection Rule With Splunk Spl · mukul975 bundleBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
- ▌ Building Patch Tuesday Response Process · mukul975 bundleEstablish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
- ▌ Detecting Azure Service Principal Abuse · mukul975 bundleDetect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
- ▌ Detecting Compromised Cloud Credentials · mukul975 bundleDetect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
- ▌ Detecting Credential Dumping Techniques · mukul975 bundleDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules.
- ▌ Detecting Email Forwarding Rules Attack · mukul975 bundleDetect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
- ▌ Detecting Fileless Attacks On Endpoints · mukul975 bundleDetects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Provides detection rules for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware.
- ▌ Detecting Privilege Escalation Attempts · mukul975 bundleDetect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
- ▌ Detecting S3 Data Exfiltration Attempts · mukul975 bundleAnalyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3.
- ▌ Detecting Serverless Function Injection · mukul975 bundleDetects and prevents code injection attacks targeting serverless functions through static analysis, event source poisoning detection, and IAM policy auditing.
- ▌ Detecting Supply Chain Attacks In CI CD · mukul975 bundleScans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.
- ▌ Exploiting Constrained Delegation Abuse · mukul975 bundleExploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
- ▌ Exploiting Mass Assignment In REST Apis · mukul975 bundleDiscover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
- ▌ Extracting Credentials From Memory Dump · mukul975 bundleExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
- ▌ Extracting Memory Artifacts With Rekall · mukul975 bundleAnalyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
- ▌ Extracting Windows Event Logs Artifacts · mukul975 bundleExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
- ▌ Hunting For Unusual Network Connections · mukul975 bundleHunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
- ▌ Implementing AWS Nitro Enclave Security · mukul975 bundleBuilds AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration, and secure vsock communication for processing sensitive data.
- ▌ Implementing Code Signing For Artifacts · mukul975 bundleSign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
- ▌ Implementing Network Traffic Baselining · mukul975 bundleBuild network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling.
- ▌ Implementing Ransomware Backup Strategy · mukul975 bundleDesigns and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology, including asset classification, immutable storage configuration, credential isolation, and automated restore testing.
- ▌ Implementing Security Chaos Engineering · mukul975 bundleDeliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
- ▌ Implementing Zero Trust With Beyondcorp · mukul975 bundleDeploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
- ▌ Investigating Insider Threat Indicators · mukul975 bundleInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation.
- ▌ Implementing Ics Firewall With Tofino · mukul975 bundleDeploy and configure Tofino industrial firewalls to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones.
- ▌ Implementing Iec 62443 Security Zones · mukul975 bundleDesign and implement security zones and conduits for industrial automation and control systems per IEC 62443-3-2, including zone partitioning, firewall configuration, and validation through traffic analysis and penetration testing.
- ▌ Investigating Phishing Email Incident · mukul975 bundleInvestigate phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms.
- ▌ Performing File Carving With Foremost · mukul975 bundleRecover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
- ▌ Performing GRAPHQL Depth Limit Attack · mukul975 bundleTest GraphQL APIs for depth limit vulnerabilities by sending deeply nested recursive queries to identify denial-of-service risks.
- ▌ Performing Hash Cracking With Hashcat · mukul975 bundleCrack password hashes using Hashcat for authorized penetration testing and password policy assessment, supporting dictionary, brute-force, rule-based, and hybrid attacks.
- ▌ Performing Lateral Movement Detection · mukul975 bundleDetects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
- ▌ Performing Purple Team Atomic Testing · mukul975 bundleExecutes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis, and runs detection validation loops to measure blue team visibility.
- ▌ Performing Second Order SQL Injection · mukul975 bundleDetect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
- ▌ Performing Web Cache Deception Attack · mukul975 bundleExploit path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve authenticated content.
- ▌ Performing Web Cache Poisoning Attack · mukul975 bundleExploit web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
- ▌ Testing API Authentication Weaknesses · mukul975 bundleTests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws.
- ▌ Abusing Shadow Credentials For Privesc · mukul975 bundleTake over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
- ▌ Analyzing Android Malware With Apktool · mukul975 bundlePerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
- ▌ Analyzing Memory Dumps With Volatility · mukul975 bundleAnalyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
- ▌ Analyzing Windows Event Logs In Splunk · mukul975 bundleDetect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement by analyzing Windows Security, System, and Sysmon event logs in Splunk using SPL queries mapped to MITRE ATT&CK techniques.
- ▌ Analyzing Windows Prefetch With Python · mukul975 bundleParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
- ▌ Conducting Mobile App Penetration Test · mukul975 bundleConducts penetration testing of iOS and Android mobile applications following the OWASP MASTG to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls.
- ▌ Deploying Active Directory Honeytokens · mukul975 bundleDeploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs.
- ▌ Deploying Honeytokens And Canarytokens · mukul975 bundleDeploy honeytokens and canarytokens as decoy artifacts to detect intrusions with near-zero false positives.
- ▌ Deploying Tailscale For Zero Trust Vpn · mukul975 bundleDeploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
- ▌ Detecting Attacks On Historian Servers · mukul975 bundleDetect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
- ▌ Detecting AWS Iam Privilege Escalation · mukul975 bundleIdentify AWS IAM privilege escalation paths by analyzing policies for dangerous permission combinations and least-privilege violations using boto3 and Cloudsplaining-style analysis.
- ▌ Detecting Beaconing Patterns With Zeek · mukul975 bundleAnalyzes Zeek conn.log connection intervals using statistical methods to detect C2 beaconing patterns, flagging periodic connections with low jitter.
- ▌ Detecting Bluetooth Low Energy Attacks · mukul975 bundleDetects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception using Ubertooth One, nRF52840, bleak, and crackle.
- ▌ Detecting Cloud Threats With Guardduty · mukul975 bundleDeploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads, including enabling protection plans, interpreting findings, and building automated response workflows.
- ▌ Detecting Command And Control Over Dns · mukul975 bundleDetects command-and-control (C2) communications tunneled through DNS protocol, including DNS tunneling tools, domain generation algorithms, and encoded payload delivery via TXT/CNAME records.
- ▌ Detecting Lateral Movement With Splunk · mukul975 bundleDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
- ▌ Detecting Process Injection Techniques · mukul975 bundleDetects and analyzes process injection techniques used by malware, including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading, using memory forensics, API monitoring, and behavioral analysis.
- ▌ Executing Phishing Simulation Campaign · mukul975 bundleExecutes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks, including scenario design, infrastructure setup, and metric tracking.
- ▌ Executing Red Team Engagement Planning · mukul975 bundleDefines scope, objectives, rules of engagement, threat model selection, and operational timelines for red team engagements before any offensive testing begins.
- ▌ Exploiting Kerberoasting With Impacket · mukul975 bundlePerform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
- ▌ Exploiting Server Side Request Forgery · mukul975 bundleIdentify and exploit SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
- ▌ Extracting Config From Agent Tesla Rat · mukul975 bundleExtract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
- ▌ Generating Threat Intelligence Reports · mukul975 bundleGenerates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts.
- ▌ Hunting For Domain Fronting C2 Traffic · mukul975 bundleDetect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection.
- ▌ Hunting For Scheduled Task Persistence · mukul975 bundleHunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
- ▌ Hunting For Startup Folder Persistence · mukul975 bundleDetect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
- ▌ Hunting For Suspicious Scheduled Tasks · mukul975 bundleHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns.
- ▌ Hunting For T1098 Account Manipulation · mukul975 bundleDetect MITRE ATT&CK T1098 account manipulation techniques including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
- ▌ Implementing API Key Security Controls · mukul975 bundleGenerates, stores, validates, rotates, and revokes API keys with secure hashing, scoping, rate limiting, and leak monitoring.
- ▌ Implementing Attack Surface Management · mukul975 bundleBuilds an external attack surface management (EASM) program using Shodan, Censys, and ProjectDiscovery tools for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring.
- ▌ Implementing Cloud Workload Protection · mukul975 bundleMonitors cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies on EC2 and GCE instances.
- ▌ Implementing Patch Management Workflow · mukul975 bundleIdentify, test, deploy, and verify software updates across an organization's IT infrastructure using a structured patch management workflow with phased rollouts and automated assessment.
- ▌ Implementing Secrets Scanning In CI CD · mukul975 bundleIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment.
- ▌ Implementing Usb Device Control Policy · mukul975 bundleRestricts unauthorized removable media access on endpoints by implementing USB device control policies via Group Policy, Intune, or EDR platforms to prevent data exfiltration and malware introduction.
- ▌ Implementing Zero Trust Network Access · mukul975 bundleConfigure identity-aware proxies, micro-segmentation, and continuous verification to replace traditional VPN-based remote access with zero trust network access across AWS, Azure, and GCP.
- ▌ Migrating To Post Quantum Cryptography · mukul975 bundleInventory cryptographic assets, deploy hybrid X25519 and ML-KEM key exchange, and prioritize migration of harvest-now-decrypt-later data.
- ▌ Performing AI Driven Osint Correlation · mukul975 bundleCorrelate findings across OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
- ▌ Building Soc Playbook For Ransomware · mukul975 bundleBuilds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
- ▌ Conducting Cloud Penetration Testing · mukul975 bundlePerform authorized penetration testing against AWS, Azure, and GCP cloud environments using cloud-specific tools and methodologies, with findings mapped to the MITRE ATT&CK Cloud matrix.
- ▌ Deploying Edr Agent With Crowdstrike · mukul975 bundleDeploys and configures CrowdStrike Falcon EDR sensors across Windows, macOS, and Linux endpoints, sets prevention and response policies, validates deployment, and integrates with SIEM platforms.
- ▌ Detecting Container Drift At Runtime · mukul975 bundleDetect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
- ▌ Detecting Lateral Movement With Zeek · mukul975 bundleAnalyze Zeek network logs to detect lateral movement techniques including SMB admin share access, DCE/RPC remote service creation, NTLM account spray, Kerberos anomalies, and large internal data transfers.
- ▌ Detecting SQL Injection Via Waf Logs · mukul975 bundleAnalyze WAF logs from ModSecurity, AWS WAF, or Cloudflare to detect SQL injection attack campaigns, classify injection types, and generate incident reports with OWASP classification.
- ▌ Exploiting SQL Injection With Sqlmap · mukul975 bundleDetect and exploit SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
- ▌ Exploiting Websocket Vulnerabilities · mukul975 bundleTest WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
- ▌ Extracting Browser History Artifacts · mukul975 bundleExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
- ▌ Extracting Iocs From Malware Samples · mukul975 bundleExtracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators, host artifacts, and behavioral patterns for threat intelligence sharing and detection rule creation.
- ▌ Hunting For Lateral Movement Via Wmi · mukul975 bundleDetect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
- ▌ Hunting For Spearphishing Indicators · mukul975 bundleHunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.