all publishers

mukul975

@mukul975 source repo

828 published skills · page 7 of 9

  1. ▌
    Implementing Alert Fatigue Reduction · mukul975 bundle
    Reduces SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness.
    24.6k repo stars
  2. ▌
    Implementing Pam For Database Access · mukul975 bundle
    Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles.
    24.6k repo stars
  3. ▌
    Implementing Rsa Key Pair Management · mukul975 bundle
    Generate, store, rotate, and manage RSA key pairs following NIST SP 800-57 guidelines, including key serialization, passphrase protection, and key strength validation.
    24.6k repo stars
  4. ▌
    Orchestrating LLM Attacks With Pyrit · mukul975 bundle
    Automate multi-turn adversarial conversations against LLM agents using Microsoft PyRIT, including Crescendo and Tree-of-Attacks-with-Pruning (TAP) attack chains with scorer feedback loops.
    24.6k repo stars
  5. ▌
    Performing Container Image Hardening · mukul975 bundle
    Harden container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations.
    24.6k repo stars
  6. ▌
    Performing Firmware Malware Analysis · mukul975 bundle
    Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.
    24.6k repo stars
  7. ▌
    Performing Ioc Enrichment Automation · mukul975 bundle
    Automates multi-source enrichment of IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, Shodan, GreyNoise, URLScan.io, and MISP to provide contextual risk scoring and disposition recommendations for SOC analysts.
    24.6k repo stars
  8. ▌
    Performing JWT None Algorithm Attack · mukul975 bundle
    Test JWT signature verification bypass by crafting tokens with the 'none' algorithm.
    24.6k repo stars
  9. ▌
    Performing Privacy Impact Assessment · mukul975 bundle
    Automates privacy impact assessments including data flow mapping, risk scoring, GDPR/CCPA compliance checks, and remediation planning using the NIST Privacy Framework and ICO DPIA guidance.
    24.6k repo stars
  10. ▌
    Performing Sqlite Database Forensics · mukul975 bundle
    Recover deleted records, analyze freelist pages, WAL files, and unallocated space in SQLite databases for digital forensics and incident response.
    24.6k repo stars
  11. ▌
    Scanning Container Images With Grype · mukul975 bundle
    Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
    24.6k repo stars
  12. ▌
    Tracking Threat Actor Infrastructure · mukul975 bundle
    Monitor and map adversary-controlled assets including C2 servers, phishing domains, and exploit kit hosts using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting.
    24.6k repo stars
  13. ▌
    Analyzing Bootkit And Rootkit Samples · mukul975 bundle
    Analyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
    24.6k repo stars
  14. ▌
    Analyzing Powershell Empire Artifacts · mukul975 bundle
    Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
    24.6k repo stars
  15. ▌
    Building C2 Redirector Infrastructure · mukul975 bundle
    Architect C2 redirectors with nginx and Apache, derive filter rules from malleable profiles, and apply OPSEC controls for resilient red-team infrastructure.
    24.6k repo stars
  16. ▌
    Building Soc Metrics And Kpi Tracking · mukul975 bundle
    Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data.
    24.6k repo stars
  17. ▌
    Building Threat Intelligence Platform · mukul975 bundle
    Deploy and integrate open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified threat intelligence platform for collecting, analyzing, enriching, and disseminating threat intelligence.
    24.6k repo stars
  18. ▌
    Conducting Phishing Incident Response · mukul975 bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
    24.6k repo stars
  19. ▌
    Configuring Oauth2 Authorization Flow · mukul975 bundle
    Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
    24.6k repo stars
  20. ▌
    Correlating Security Events In Qradar · mukul975 bundle
    Correlates security events in IBM QRadar SIEM using AQL queries, custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources.
    24.6k repo stars
  21. ▌
    Detecting Fileless Malware Techniques · mukul975 bundle
    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk.
    24.6k repo stars
  22. ▌
    Detecting Lateral Movement In Network · mukul975 bundle
    Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
    24.6k repo stars
  23. ▌
    Detecting Living Off The Land Attacks · mukul975 bundle
    Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks by monitoring process creation, command-line arguments, and parent-child relationships.
    24.6k repo stars
  24. ▌
    Detecting Mimikatz Execution Patterns · mukul975 bundle
    Hunt for Mimikatz execution using command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
    24.6k repo stars
  25. ▌
    Detecting Misconfigured Azure Storage · mukul975 bundle
    Audits Azure Storage accounts for misconfigurations including public blob access, weak network rules, missing encryption, permissive SAS tokens, and disabled logging using Azure CLI, PowerShell, and Defender for Storage.
    24.6k repo stars
  26. ▌
    Detecting Network Anomalies With Zeek · mukul975 bundle
    Deploys and configures Zeek network security monitor to passively analyze traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
    24.6k repo stars
  27. ▌
    Detecting Port Scanning With Fail2ban · mukul975 bundle
    Configures Fail2ban with custom filters and actions to detect port scanning, SSH brute force, and network reconnaissance, automatically banning offending IPs and alerting security teams.
    24.6k repo stars
  28. ▌
    Detecting Process Hollowing Technique · mukul975 bundle
    Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
    24.6k repo stars
  29. ▌
    Exploiting Nopac Cve 2021 42278 42287 · mukul975 bundle
    Escalate from standard domain user to Domain Admin by exploiting the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) in Active Directory environments.
    24.6k repo stars
  30. ▌
    Hardening Docker Daemon Configuration · mukul975 bundle
    Hardens the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
    24.6k repo stars
  31. ▌
    Implementing Azure Defender For Cloud · mukul975 bundle
    Enables comprehensive security monitoring across Azure subscriptions, including cloud security posture management, workload protection, regulatory compliance assessment, and adaptive security controls.
    24.6k repo stars
  32. ▌
    Implementing Cloud Trail Log Analysis · mukul975 bundle
    Analyze AWS CloudTrail logs for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration.
    24.6k repo stars
  33. ▌
    Implementing Ebpf Security Monitoring · mukul975 bundle
    Deploy kernel-level runtime security monitoring on Linux hosts or Kubernetes clusters using eBPF and Cilium Tetragon for process execution tracking, network observability, file access auditing, and runtime enforcement.
    24.6k repo stars
  34. ▌
    Implementing GCP Binary Authorization · mukul975 bundle
    Enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
    24.6k repo stars
  35. ▌
    Performing Container Escape Detection · mukul975 bundle
    Audits Kubernetes pods for container escape vectors by analyzing privileged mode, dangerous capabilities, host namespace sharing, and writable hostPath mounts using the Kubernetes Python client.
    24.6k repo stars
  36. ▌
    Analyzing Threat Intelligence Feeds · mukul975 bundle
    Ingests, normalizes, and enriches structured and unstructured threat intelligence feeds into STIX 2.1 format, evaluating feed quality and deduplicating indicators for distribution to SIEM, firewall, and EDR platforms.
    24.6k repo stars
  37. ▌
    Analyzing Windows Amcache Artifacts · mukul975 bundle
    Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations.
    24.6k repo stars
  38. ▌
    Auditing Entra Id With Aadinternals · mukul975 bundle
    Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
    24.6k repo stars
  39. ▌
    Auditing Uefi Firmware With Chipsec · mukul975 bundle
    Assess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
    24.6k repo stars
  40. ▌
    Building Detection Rules With Sigma · mukul975 bundle
    Creates vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.
    24.6k repo stars
  41. ▌
    Building Incident Response Playbook · mukul975 bundle
    Designs and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.
    24.6k repo stars
  42. ▌
    Building Super Timelines With Plaso · mukul975 bundle
    Build forensic super timelines from disk images using Plaso (log2timeline) and triage them in Timesketch.
    24.6k repo stars
  43. ▌
    Collecting Indicators Of Compromise · mukul975 bundle
    Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.
    24.6k repo stars
  44. ▌
    Collecting Open Source Intelligence · mukul975 bundle
    Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using passive reconnaissance tools and public data sources.
    24.6k repo stars
  45. ▌
    Conducting Network Penetration Test · mukul975 bundle
    Conducts comprehensive network penetration tests against authorized target environments using host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation following PTES methodology.
    24.6k repo stars
  46. ▌
    Configuring Ldap Security Hardening · mukul975 bundle
    Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP signing, access control lists, and monitoring for LDAP-based attacks.
    24.6k repo stars
  47. ▌
    Detecting Business Email Compromise · mukul975 bundle
    Detect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
    24.6k repo stars
  48. ▌
    Detecting Container Escape Attempts · mukul975 bundle
    Detect container escape attempts using runtime security tools like Falco, Sysdig, and custom seccomp/audit rules.
    24.6k repo stars
  49. ▌
    Detecting Indirect Prompt Injection · mukul975 bundle
    Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
    24.6k repo stars
  50. ▌
    Detecting Modbus Protocol Anomalies · mukul975 bundle
    Detects anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems using Zeek, Suricata, and custom Python analysis.
    24.6k repo stars
  51. ▌
    Exploiting Deeplink Vulnerabilities · mukul975 bundle
    Tests and exploits deep link vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation.
    24.6k repo stars
  52. ▌
    Exploiting Insecure Deserialization · mukul975 bundle
    Identify and exploit insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications during authorized penetration tests.
    24.6k repo stars
  53. ▌
    Hunting Advanced Persistent Threats · mukul975 bundle
    Proactively hunts for Advanced Persistent Threat activity using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts.
    24.6k repo stars
  54. ▌
    Hunting Credential Stuffing Attacks · mukul975 bundle
    Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins using statistical analysis on Splunk or raw log data.
    24.6k repo stars
  55. ▌
    Hunting For Dns Tunneling With Zeek · mukul975 bundle
    Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.
    24.6k repo stars
  56. ▌
    Hunting For Supply Chain Compromise · mukul975 bundle
    Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
    24.6k repo stars
  57. ▌
    Implementing Bgp Security With Rpki · mukul975 bundle
    Create Route Origin Authorizations (ROAs) at RIRs, deploy RPKI validator software, and configure Route Origin Validation (ROV) on Cisco and Juniper routers to prevent BGP route hijacking.
    24.6k repo stars
  58. ▌
    Implementing Diamond Model Analysis · mukul975 bundle
    Provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    24.6k repo stars
  59. ▌
    Implementing GCP Vpc Firewall Rules · mukul975 bundle
    Audit, create, and monitor GCP VPC firewall rules to enforce network segmentation and least-privilege access.
    24.6k repo stars
  60. ▌
    Implementing Network Access Control · mukul975 bundle
    Enforces identity-based network access with 802.1X, RADIUS authentication, dynamic VLAN assignment, and endpoint posture assessment using PacketFence.
    24.6k repo stars
  61. ▌
    Performing API Fuzzing With Restler · mukul975 bundle
    Automates stateful REST API fuzzing using Microsoft RESTler to discover security and reliability bugs by compiling OpenAPI specs, configuring authentication, and running test, fuzz-lean, and full fuzzing modes.
    24.6k repo stars
  62. ▌
    Performing API Rate Limiting Bypass · mukul975 bundle
    Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls.
    24.6k repo stars
  63. ▌
    Performing Clickjacking Attack Test · mukul975 bundle
    Test web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
    24.6k repo stars
  64. ▌
    Performing Fuzzing With Aflplusplus · mukul975 bundle
    Perform coverage-guided fuzzing of compiled binaries using AFL++ to discover memory corruption, crashes, and security vulnerabilities.
    24.6k repo stars
  65. ▌
    Performing Malware Triage With Yara · mukul975 bundle
    Rapidly classify malware samples against known family signatures using YARA rules, covering rule writing, scanning, and integration with analysis pipelines.
    24.6k repo stars
  66. ▌
    Scanning Infrastructure With Nessus · mukul975 bundle
    Configure and run Nessus vulnerability scans, analyze results, and integrate scanning into continuous vulnerability management workflows.
    24.6k repo stars
  67. ▌
    Scanning Network With Nmap Advanced · mukul975 bundle
    Performs advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
    24.6k repo stars
  68. ▌
    Securing Agentic AI Tool Invocation · mukul975 bundle
    Apply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
    24.6k repo stars
  69. ▌
    Securing AWS Lambda Execution Roles · mukul975 bundle
    Audit and harden AWS Lambda execution roles by implementing least-privilege IAM policies, permission boundaries, and SCP enforcement.
    24.6k repo stars
  70. ▌
    Testing For Sensitive Data Exposure · mukul975 bundle
    Identify sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
    24.6k repo stars
  71. ▌
    Testing Oauth2 Implementation Flaws · mukul975 bundle
    Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass.
    24.6k repo stars
  72. ▌
    Analyzing Active Directory Acl Abuse · mukul975 bundle
    Detect dangerous ACL misconfigurations in Active Directory by querying and parsing nTSecurityDescriptor attributes to identify GenericAll, WriteDACL, WriteOwner, and GenericWrite abuse paths.
    24.6k repo stars
  73. ▌
    Analyzing Docker Container Forensics · mukul975 bundle
    Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
    24.6k repo stars
  74. ▌
    Analyzing Golang Malware With Ghidra · mukul975 bundle
    Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
    24.6k repo stars
  75. ▌
    Analyzing Malicious Url With Urlscan · mukul975 bundle
    Investigate phishing URLs, credential harvesting pages, and malicious redirects using URLScan.io's safe browsing environment and API.
    24.6k repo stars
  76. ▌
    Analyzing Network Packets With Scapy · mukul975 bundle
    Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing.
    24.6k repo stars
  77. ▌
    Analyzing Network Traffic Of Malware · mukul975 bundle
    Analyzes malware-generated network traffic from PCAP files to identify C2 protocols, data exfiltration, DNS tunneling, and beaconing patterns using Wireshark, Zeek, Suricata, and Python.
    24.6k repo stars
  78. ▌
    Analyzing Ransomware Payment Wallets · mukul975 bundle
    Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution.
    24.6k repo stars
  79. ▌
    Analyzing Threat Landscape With Misp · mukul975 bundle
    Query MISP event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time to generate threat landscape reports.
    24.6k repo stars
  80. ▌
    Analyzing Windows Shellbag Artifacts · mukul975 bundle
    Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
    24.6k repo stars
  81. ▌
    Building Incident Response Dashboard · mukul975 bundle
    Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline.
    24.6k repo stars
  82. ▌
    Conducting Malware Incident Response · mukul975 bundle
    Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.
    24.6k repo stars
  83. ▌
    Deploying Software Defined Perimeter · mukul975 bundle
    Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
    24.6k repo stars
  84. ▌
    Detecting Dnp3 Protocol Anomalies · mukul975 bundle
    Detect anomalies in DNP3 protocol communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
    24.6k repo stars
  85. ▌
    Hunting For Cobalt Strike Beacons · mukul975 bundle
    Detect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP C2 profile matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
    24.6k repo stars
  86. ▌
    Hunting For Dcom Lateral Movement · mukul975 bundle
    Detect DCOM-based lateral movement by correlating Sysmon process creation and network connection events, WMI event analysis, and RPC endpoint mapper traffic to identify abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects.
    24.6k repo stars
  87. ▌
    Hunting For Dns Based Persistence · mukul975 bundle
    Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
    24.6k repo stars
  88. ▌
    Implementing Siem Use Case Tuning · mukul975 bundle
    Reduce SIEM alert fatigue by systematically tuning detection rules in Splunk and Elastic, using statistical baselines, whitelists, and precision/recall metrics.
    24.6k repo stars
  89. ▌
    Managing Cloud Identity With Okta · mukul975 bundle
    Implement Okta as a centralized identity provider for cloud environments, configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA, automate user lifecycle management, and enforce adaptive access policies.
    24.6k repo stars
  90. ▌
    Performing Csrf Attack Simulation · mukul975 bundle
    Test web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
    24.6k repo stars
  91. ▌
    Performing Malware Ioc Extraction · mukul975 bundle
    Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
    24.6k repo stars
  92. ▌
    Performing Red Team With Covenant · mukul975 bundle
    Automate red team operations using the Covenant C2 framework's REST API for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
    24.6k repo stars
  93. ▌
    Performing Security Headers Audit · mukul975 bundle
    Audits HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
    24.6k repo stars
  94. ▌
    Recovering From Ransomware Attack · mukul975 bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection.
    24.6k repo stars
  95. ▌
    Scanning Docker Images With Trivy · mukul975 bundle
    Scan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
    24.6k repo stars
  96. ▌
    Securing API Gateway With AWS Waf · mukul975 bundle
    Protect API Gateway endpoints with AWS WAF by configuring managed rule groups, rate limiting, bot control, IP reputation filtering, and monitoring.
    24.6k repo stars
  97. ▌
    Securing Github Actions Workflows · mukul975 bundle
    Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
    24.6k repo stars
  98. ▌
    Testing For Broken Access Control · mukul975 bundle
    Systematically test web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
    24.6k repo stars
  99. ▌
    Testing For Host Header Injection · mukul975 bundle
    Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
    24.6k repo stars
  100. ▌
    Testing For System Prompt Leakage · mukul975 bundle
    Test LLM applications for system prompt leakage using manual payloads, garak, and Promptfoo to extract embedded secrets and routing logic.
    24.6k repo stars