all publishers

mukul975

@mukul975 source repo

828 published skills · page 6 of 9

  1. ▌
    Reverse Engineering IOS App With Frida · mukul975 bundle
    Dynamically instrument iOS apps with Frida to trace methods, extract secrets, and bypass security controls during authorized penetration testing.
    24.6k repo stars
  2. ▌
    Scanning Containers With Trivy In Cicd · mukul975 bundle
    Integrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates.
    24.6k repo stars
  3. ▌
    Securing Azure With Microsoft Defender · mukul975 bundle
    Deploy Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. Covers enabling Defender plans, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal.
    24.6k repo stars
  4. ▌
    Testing API Security With Owasp Top 10 · mukul975 bundle
    Systematically assess REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
    24.6k repo stars
  5. ▌
    Testing Ransomware Recovery Procedures · mukul975 bundle
    Validate ransomware recovery plans by testing backup restore operations, measuring RTO/RPO targets, verifying data integrity, and documenting recovery gaps in an isolated lab environment.
    24.6k repo stars
  6. ▌
    Acquiring Disk Image With Dd And Dcfldd · mukul975 bundle
    Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
    24.6k repo stars
  7. ▌
    Analyzing Campaign Attribution Evidence · mukul975 bundle
    Systematically evaluates evidence to determine which threat actor is responsible for a cyber operation using the Diamond Model and Analysis of Competing Hypotheses.
    24.6k repo stars
  8. ▌
    Analyzing Cloud Storage Access Patterns · mukul975 bundle
    Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls, and potential data exfiltration using statistical baselines.
    24.6k repo stars
  9. ▌
    Analyzing Mft For Deleted File Recovery · mukul975 bundle
    Recover metadata and content of deleted files from NTFS volumes by analyzing the Master File Table, $LogFile, $UsnJrnl, and MFT slack space using forensic tools like MFTECmd and analyzeMFT.
    24.6k repo stars
  10. ▌
    Analyzing Network Traffic For Incidents · mukul975 bundle
    Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts.
    24.6k repo stars
  11. ▌
    Analyzing Ransomware Network Indicators · mukul975 bundle
    Analyze Zeek conn.log and NetFlow data to detect ransomware network indicators including C2 beaconing, TOR exit node connections, data exfiltration, and suspicious DNS patterns.
    24.6k repo stars
  12. ▌
    Analyzing Usb Device Connection History · mukul975 bundle
    Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
    24.6k repo stars
  13. ▌
    Analyzing Web Server Logs For Intrusion · mukul975 bundle
    Parse Apache and Nginx access logs to detect SQL injection, LFI, XSS, scanner fingerprints, and brute-force patterns using regex-based detection, GeoIP enrichment, and statistical anomaly analysis.
    24.6k repo stars
  14. ▌
    Auditing MCP Servers For Tool Poisoning · mukul975 bundle
    Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
    24.6k repo stars
  15. ▌
    Benchmarking Kubernetes With Kube Bench · mukul975 bundle
    Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
    24.6k repo stars
  16. ▌
    Building Detection Rule With Splunk Spl · mukul975 bundle
    Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
    24.6k repo stars
  17. ▌
    Building Patch Tuesday Response Process · mukul975 bundle
    Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
    24.6k repo stars
  18. ▌
    Detecting Azure Service Principal Abuse · mukul975 bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    24.6k repo stars
  19. ▌
    Detecting Compromised Cloud Credentials · mukul975 bundle
    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    24.6k repo stars
  20. ▌
    Detecting Credential Dumping Techniques · mukul975 bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules.
    24.6k repo stars
  21. ▌
    Detecting Email Forwarding Rules Attack · mukul975 bundle
    Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
    24.6k repo stars
  22. ▌
    Detecting Fileless Attacks On Endpoints · mukul975 bundle
    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Provides detection rules for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware.
    24.6k repo stars
  23. ▌
    Detecting Privilege Escalation Attempts · mukul975 bundle
    Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
    24.6k repo stars
  24. ▌
    Detecting S3 Data Exfiltration Attempts · mukul975 bundle
    Analyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3.
    24.6k repo stars
  25. ▌
    Detecting Serverless Function Injection · mukul975 bundle
    Detects and prevents code injection attacks targeting serverless functions through static analysis, event source poisoning detection, and IAM policy auditing.
    24.6k repo stars
  26. ▌
    Detecting Supply Chain Attacks In CI CD · mukul975 bundle
    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.
    24.6k repo stars
  27. ▌
    Exploiting Constrained Delegation Abuse · mukul975 bundle
    Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
    24.6k repo stars
  28. ▌
    Exploiting Mass Assignment In REST Apis · mukul975 bundle
    Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
    24.6k repo stars
  29. ▌
    Extracting Credentials From Memory Dump · mukul975 bundle
    Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
    24.6k repo stars
  30. ▌
    Extracting Memory Artifacts With Rekall · mukul975 bundle
    Analyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
    24.6k repo stars
  31. ▌
    Extracting Windows Event Logs Artifacts · mukul975 bundle
    Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
    24.6k repo stars
  32. ▌
    Hunting For Unusual Network Connections · mukul975 bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    24.6k repo stars
  33. ▌
    Implementing AWS Nitro Enclave Security · mukul975 bundle
    Builds AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration, and secure vsock communication for processing sensitive data.
    24.6k repo stars
  34. ▌
    Implementing Code Signing For Artifacts · mukul975 bundle
    Sign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
    24.6k repo stars
  35. ▌
    Implementing Network Traffic Baselining · mukul975 bundle
    Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling.
    24.6k repo stars
  36. ▌
    Implementing Ransomware Backup Strategy · mukul975 bundle
    Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology, including asset classification, immutable storage configuration, credential isolation, and automated restore testing.
    24.6k repo stars
  37. ▌
    Implementing Security Chaos Engineering · mukul975 bundle
    Deliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
    24.6k repo stars
  38. ▌
    Implementing Zero Trust With Beyondcorp · mukul975 bundle
    Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
    24.6k repo stars
  39. ▌
    Investigating Insider Threat Indicators · mukul975 bundle
    Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation.
    24.6k repo stars
  40. ▌
    Implementing Ics Firewall With Tofino · mukul975 bundle
    Deploy and configure Tofino industrial firewalls to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones.
    24.6k repo stars
  41. ▌
    Implementing Iec 62443 Security Zones · mukul975 bundle
    Design and implement security zones and conduits for industrial automation and control systems per IEC 62443-3-2, including zone partitioning, firewall configuration, and validation through traffic analysis and penetration testing.
    24.6k repo stars
  42. ▌
    Investigating Phishing Email Incident · mukul975 bundle
    Investigate phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms.
    24.6k repo stars
  43. ▌
    Performing File Carving With Foremost · mukul975 bundle
    Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
    24.6k repo stars
  44. ▌
    Performing GRAPHQL Depth Limit Attack · mukul975 bundle
    Test GraphQL APIs for depth limit vulnerabilities by sending deeply nested recursive queries to identify denial-of-service risks.
    24.6k repo stars
  45. ▌
    Performing Hash Cracking With Hashcat · mukul975 bundle
    Crack password hashes using Hashcat for authorized penetration testing and password policy assessment, supporting dictionary, brute-force, rule-based, and hybrid attacks.
    24.6k repo stars
  46. ▌
    Performing Lateral Movement Detection · mukul975 bundle
    Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
    24.6k repo stars
  47. ▌
    Performing Purple Team Atomic Testing · mukul975 bundle
    Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis, and runs detection validation loops to measure blue team visibility.
    24.6k repo stars
  48. ▌
    Performing Second Order SQL Injection · mukul975 bundle
    Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
    24.6k repo stars
  49. ▌
    Performing Web Cache Deception Attack · mukul975 bundle
    Exploit path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve authenticated content.
    24.6k repo stars
  50. ▌
    Performing Web Cache Poisoning Attack · mukul975 bundle
    Exploit web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
    24.6k repo stars
  51. ▌
    Testing API Authentication Weaknesses · mukul975 bundle
    Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws.
    24.6k repo stars
  52. ▌
    Abusing Shadow Credentials For Privesc · mukul975 bundle
    Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
    24.6k repo stars
  53. ▌
    Analyzing Android Malware With Apktool · mukul975 bundle
    Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
    24.6k repo stars
  54. ▌
    Analyzing Memory Dumps With Volatility · mukul975 bundle
    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
    24.6k repo stars
  55. ▌
    Analyzing Windows Event Logs In Splunk · mukul975 bundle
    Detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement by analyzing Windows Security, System, and Sysmon event logs in Splunk using SPL queries mapped to MITRE ATT&CK techniques.
    24.6k repo stars
  56. ▌
    Analyzing Windows Prefetch With Python · mukul975 bundle
    Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
    24.6k repo stars
  57. ▌
    Conducting Mobile App Penetration Test · mukul975 bundle
    Conducts penetration testing of iOS and Android mobile applications following the OWASP MASTG to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls.
    24.6k repo stars
  58. ▌
    Deploying Active Directory Honeytokens · mukul975 bundle
    Deploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs.
    24.6k repo stars
  59. ▌
    Deploying Honeytokens And Canarytokens · mukul975 bundle
    Deploy honeytokens and canarytokens as decoy artifacts to detect intrusions with near-zero false positives.
    24.6k repo stars
  60. ▌
    Deploying Tailscale For Zero Trust Vpn · mukul975 bundle
    Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
    24.6k repo stars
  61. ▌
    Detecting Attacks On Historian Servers · mukul975 bundle
    Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
    24.6k repo stars
  62. ▌
    Detecting AWS Iam Privilege Escalation · mukul975 bundle
    Identify AWS IAM privilege escalation paths by analyzing policies for dangerous permission combinations and least-privilege violations using boto3 and Cloudsplaining-style analysis.
    24.6k repo stars
  63. ▌
    Detecting Beaconing Patterns With Zeek · mukul975 bundle
    Analyzes Zeek conn.log connection intervals using statistical methods to detect C2 beaconing patterns, flagging periodic connections with low jitter.
    24.6k repo stars
  64. ▌
    Detecting Bluetooth Low Energy Attacks · mukul975 bundle
    Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception using Ubertooth One, nRF52840, bleak, and crackle.
    24.6k repo stars
  65. ▌
    Detecting Cloud Threats With Guardduty · mukul975 bundle
    Deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads, including enabling protection plans, interpreting findings, and building automated response workflows.
    24.6k repo stars
  66. ▌
    Detecting Command And Control Over Dns · mukul975 bundle
    Detects command-and-control (C2) communications tunneled through DNS protocol, including DNS tunneling tools, domain generation algorithms, and encoded payload delivery via TXT/CNAME records.
    24.6k repo stars
  67. ▌
    Detecting Lateral Movement With Splunk · mukul975 bundle
    Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
    24.6k repo stars
  68. ▌
    Detecting Process Injection Techniques · mukul975 bundle
    Detects and analyzes process injection techniques used by malware, including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading, using memory forensics, API monitoring, and behavioral analysis.
    24.6k repo stars
  69. ▌
    Executing Phishing Simulation Campaign · mukul975 bundle
    Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks, including scenario design, infrastructure setup, and metric tracking.
    24.6k repo stars
  70. ▌
    Executing Red Team Engagement Planning · mukul975 bundle
    Defines scope, objectives, rules of engagement, threat model selection, and operational timelines for red team engagements before any offensive testing begins.
    24.6k repo stars
  71. ▌
    Exploiting Kerberoasting With Impacket · mukul975 bundle
    Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
    24.6k repo stars
  72. ▌
    Exploiting Server Side Request Forgery · mukul975 bundle
    Identify and exploit SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
    24.6k repo stars
  73. ▌
    Extracting Config From Agent Tesla Rat · mukul975 bundle
    Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
    24.6k repo stars
  74. ▌
    Generating Threat Intelligence Reports · mukul975 bundle
    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts.
    24.6k repo stars
  75. ▌
    Hunting For Domain Fronting C2 Traffic · mukul975 bundle
    Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection.
    24.6k repo stars
  76. ▌
    Hunting For Scheduled Task Persistence · mukul975 bundle
    Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
    24.6k repo stars
  77. ▌
    Hunting For Startup Folder Persistence · mukul975 bundle
    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
    24.6k repo stars
  78. ▌
    Hunting For Suspicious Scheduled Tasks · mukul975 bundle
    Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns.
    24.6k repo stars
  79. ▌
    Hunting For T1098 Account Manipulation · mukul975 bundle
    Detect MITRE ATT&CK T1098 account manipulation techniques including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
    24.6k repo stars
  80. ▌
    Implementing API Key Security Controls · mukul975 bundle
    Generates, stores, validates, rotates, and revokes API keys with secure hashing, scoping, rate limiting, and leak monitoring.
    24.6k repo stars
  81. ▌
    Implementing Attack Surface Management · mukul975 bundle
    Builds an external attack surface management (EASM) program using Shodan, Censys, and ProjectDiscovery tools for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring.
    24.6k repo stars
  82. ▌
    Implementing Cloud Workload Protection · mukul975 bundle
    Monitors cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies on EC2 and GCE instances.
    24.6k repo stars
  83. ▌
    Implementing Patch Management Workflow · mukul975 bundle
    Identify, test, deploy, and verify software updates across an organization's IT infrastructure using a structured patch management workflow with phased rollouts and automated assessment.
    24.6k repo stars
  84. ▌
    Implementing Secrets Scanning In CI CD · mukul975 bundle
    Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment.
    24.6k repo stars
  85. ▌
    Implementing Usb Device Control Policy · mukul975 bundle
    Restricts unauthorized removable media access on endpoints by implementing USB device control policies via Group Policy, Intune, or EDR platforms to prevent data exfiltration and malware introduction.
    24.6k repo stars
  86. ▌
    Implementing Zero Trust Network Access · mukul975 bundle
    Configure identity-aware proxies, micro-segmentation, and continuous verification to replace traditional VPN-based remote access with zero trust network access across AWS, Azure, and GCP.
    24.6k repo stars
  87. ▌
    Migrating To Post Quantum Cryptography · mukul975 bundle
    Inventory cryptographic assets, deploy hybrid X25519 and ML-KEM key exchange, and prioritize migration of harvest-now-decrypt-later data.
    24.6k repo stars
  88. ▌
    Performing AI Driven Osint Correlation · mukul975 bundle
    Correlate findings across OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
    24.6k repo stars
  89. ▌
    Building Soc Playbook For Ransomware · mukul975 bundle
    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
    24.6k repo stars
  90. ▌
    Conducting Cloud Penetration Testing · mukul975 bundle
    Perform authorized penetration testing against AWS, Azure, and GCP cloud environments using cloud-specific tools and methodologies, with findings mapped to the MITRE ATT&CK Cloud matrix.
    24.6k repo stars
  91. ▌
    Deploying Edr Agent With Crowdstrike · mukul975 bundle
    Deploys and configures CrowdStrike Falcon EDR sensors across Windows, macOS, and Linux endpoints, sets prevention and response policies, validates deployment, and integrates with SIEM platforms.
    24.6k repo stars
  92. ▌
    Detecting Container Drift At Runtime · mukul975 bundle
    Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
    24.6k repo stars
  93. ▌
    Detecting Lateral Movement With Zeek · mukul975 bundle
    Analyze Zeek network logs to detect lateral movement techniques including SMB admin share access, DCE/RPC remote service creation, NTLM account spray, Kerberos anomalies, and large internal data transfers.
    24.6k repo stars
  94. ▌
    Detecting SQL Injection Via Waf Logs · mukul975 bundle
    Analyze WAF logs from ModSecurity, AWS WAF, or Cloudflare to detect SQL injection attack campaigns, classify injection types, and generate incident reports with OWASP classification.
    24.6k repo stars
  95. ▌
    Exploiting SQL Injection With Sqlmap · mukul975 bundle
    Detect and exploit SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
    24.6k repo stars
  96. ▌
    Exploiting Websocket Vulnerabilities · mukul975 bundle
    Test WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
    24.6k repo stars
  97. ▌
    Extracting Browser History Artifacts · mukul975 bundle
    Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
    24.6k repo stars
  98. ▌
    Extracting Iocs From Malware Samples · mukul975 bundle
    Extracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators, host artifacts, and behavioral patterns for threat intelligence sharing and detection rule creation.
    24.6k repo stars
  99. ▌
    Hunting For Lateral Movement Via Wmi · mukul975 bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    24.6k repo stars
  100. ▌
    Hunting For Spearphishing Indicators · mukul975 bundle
    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
    24.6k repo stars