mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Implementing Alert Fatigue Reduction · mukul975 bundleReduces SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness.
- ▌ Implementing Pam For Database Access · mukul975 bundleDeploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles.
- ▌ Implementing Rsa Key Pair Management · mukul975 bundleGenerate, store, rotate, and manage RSA key pairs following NIST SP 800-57 guidelines, including key serialization, passphrase protection, and key strength validation.
- ▌ Orchestrating LLM Attacks With Pyrit · mukul975 bundleAutomate multi-turn adversarial conversations against LLM agents using Microsoft PyRIT, including Crescendo and Tree-of-Attacks-with-Pruning (TAP) attack chains with scorer feedback loops.
- ▌ Performing Container Image Hardening · mukul975 bundleHarden container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations.
- ▌ Performing Firmware Malware Analysis · mukul975 bundleAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.
- ▌ Performing Ioc Enrichment Automation · mukul975 bundleAutomates multi-source enrichment of IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, Shodan, GreyNoise, URLScan.io, and MISP to provide contextual risk scoring and disposition recommendations for SOC analysts.
- ▌ Performing JWT None Algorithm Attack · mukul975 bundleTest JWT signature verification bypass by crafting tokens with the 'none' algorithm.
- ▌ Performing Privacy Impact Assessment · mukul975 bundleAutomates privacy impact assessments including data flow mapping, risk scoring, GDPR/CCPA compliance checks, and remediation planning using the NIST Privacy Framework and ICO DPIA guidance.
- ▌ Performing Sqlite Database Forensics · mukul975 bundleRecover deleted records, analyze freelist pages, WAL files, and unallocated space in SQLite databases for digital forensics and incident response.
- ▌ Scanning Container Images With Grype · mukul975 bundleScan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
- ▌ Tracking Threat Actor Infrastructure · mukul975 bundleMonitor and map adversary-controlled assets including C2 servers, phishing domains, and exploit kit hosts using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting.
- ▌ Analyzing Bootkit And Rootkit Samples · mukul975 bundleAnalyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
- ▌ Analyzing Powershell Empire Artifacts · mukul975 bundleDetect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
- ▌ Building C2 Redirector Infrastructure · mukul975 bundleArchitect C2 redirectors with nginx and Apache, derive filter rules from malleable profiles, and apply OPSEC controls for resilient red-team infrastructure.
- ▌ Building Soc Metrics And Kpi Tracking · mukul975 bundleBuilds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data.
- ▌ Building Threat Intelligence Platform · mukul975 bundleDeploy and integrate open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified threat intelligence platform for collecting, analyzing, enriching, and disseminating threat intelligence.
- ▌ Conducting Phishing Incident Response · mukul975 bundleResponds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
- ▌ Configuring Oauth2 Authorization Flow · mukul975 bundleConfigure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token lifecycle management, scope design, and alignment with OAuth 2.1 security requirements.
- ▌ Correlating Security Events In Qradar · mukul975 bundleCorrelates security events in IBM QRadar SIEM using AQL queries, custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources.
- ▌ Detecting Fileless Malware Techniques · mukul975 bundleDetects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk.
- ▌ Detecting Lateral Movement In Network · mukul975 bundleIdentifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
- ▌ Detecting Living Off The Land Attacks · mukul975 bundleDetect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks by monitoring process creation, command-line arguments, and parent-child relationships.
- ▌ Detecting Mimikatz Execution Patterns · mukul975 bundleHunt for Mimikatz execution using command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
- ▌ Detecting Misconfigured Azure Storage · mukul975 bundleAudits Azure Storage accounts for misconfigurations including public blob access, weak network rules, missing encryption, permissive SAS tokens, and disabled logging using Azure CLI, PowerShell, and Defender for Storage.
- ▌ Detecting Network Anomalies With Zeek · mukul975 bundleDeploys and configures Zeek network security monitor to passively analyze traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
- ▌ Detecting Port Scanning With Fail2ban · mukul975 bundleConfigures Fail2ban with custom filters and actions to detect port scanning, SSH brute force, and network reconnaissance, automatically banning offending IPs and alerting security teams.
- ▌ Detecting Process Hollowing Technique · mukul975 bundleDetect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
- ▌ Exploiting Nopac Cve 2021 42278 42287 · mukul975 bundleEscalate from standard domain user to Domain Admin by exploiting the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) in Active Directory environments.
- ▌ Hardening Docker Daemon Configuration · mukul975 bundleHardens the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
- ▌ Implementing Azure Defender For Cloud · mukul975 bundleEnables comprehensive security monitoring across Azure subscriptions, including cloud security posture management, workload protection, regulatory compliance assessment, and adaptive security controls.
- ▌ Implementing Cloud Trail Log Analysis · mukul975 bundleAnalyze AWS CloudTrail logs for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration.
- ▌ Implementing Ebpf Security Monitoring · mukul975 bundleDeploy kernel-level runtime security monitoring on Linux hosts or Kubernetes clusters using eBPF and Cilium Tetragon for process execution tracking, network observability, file access auditing, and runtime enforcement.
- ▌ Implementing GCP Binary Authorization · mukul975 bundleEnforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
- ▌ Performing Container Escape Detection · mukul975 bundleAudits Kubernetes pods for container escape vectors by analyzing privileged mode, dangerous capabilities, host namespace sharing, and writable hostPath mounts using the Kubernetes Python client.
- ▌ Analyzing Threat Intelligence Feeds · mukul975 bundleIngests, normalizes, and enriches structured and unstructured threat intelligence feeds into STIX 2.1 format, evaluating feed quality and deduplicating indicators for distribution to SIEM, firewall, and EDR platforms.
- ▌ Analyzing Windows Amcache Artifacts · mukul975 bundleParses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations.
- ▌ Auditing Entra Id With Aadinternals · mukul975 bundleRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
- ▌ Auditing Uefi Firmware With Chipsec · mukul975 bundleAssess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
- ▌ Building Detection Rules With Sigma · mukul975 bundleCreates vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.
- ▌ Building Incident Response Playbook · mukul975 bundleDesigns and documents structured incident response playbooks aligned with NIST SP 800-61r3 and SANS PICERL frameworks, covering playbook structure, decision trees, escalation criteria, RACI matrices, and SOAR integration.
- ▌ Building Super Timelines With Plaso · mukul975 bundleBuild forensic super timelines from disk images using Plaso (log2timeline) and triage them in Timesketch.
- ▌ Collecting Indicators Of Compromise · mukul975 bundleSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.
- ▌ Collecting Open Source Intelligence · mukul975 bundleCollects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using passive reconnaissance tools and public data sources.
- ▌ Conducting Network Penetration Test · mukul975 bundleConducts comprehensive network penetration tests against authorized target environments using host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation following PTES methodology.
- ▌ Configuring Ldap Security Hardening · mukul975 bundleHarden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP signing, access control lists, and monitoring for LDAP-based attacks.
- ▌ Detecting Business Email Compromise · mukul975 bundleDetect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
- ▌ Detecting Container Escape Attempts · mukul975 bundleDetect container escape attempts using runtime security tools like Falco, Sysdig, and custom seccomp/audit rules.
- ▌ Detecting Indirect Prompt Injection · mukul975 bundleDetect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
- ▌ Detecting Modbus Protocol Anomalies · mukul975 bundleDetects anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems using Zeek, Suricata, and custom Python analysis.
- ▌ Exploiting Deeplink Vulnerabilities · mukul975 bundleTests and exploits deep link vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation.
- ▌ Exploiting Insecure Deserialization · mukul975 bundleIdentify and exploit insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications during authorized penetration tests.
- ▌ Hunting Advanced Persistent Threats · mukul975 bundleProactively hunts for Advanced Persistent Threat activity using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts.
- ▌ Hunting Credential Stuffing Attacks · mukul975 bundleDetects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins using statistical analysis on Splunk or raw log data.
- ▌ Hunting For Dns Tunneling With Zeek · mukul975 bundleDetect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.
- ▌ Hunting For Supply Chain Compromise · mukul975 bundleHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
- ▌ Implementing Bgp Security With Rpki · mukul975 bundleCreate Route Origin Authorizations (ROAs) at RIRs, deploy RPKI validator software, and configure Route Origin Validation (ROV) on Cisco and Juniper routers to prevent BGP route hijacking.
- ▌ Implementing Diamond Model Analysis · mukul975 bundleProvides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
- ▌ Implementing GCP Vpc Firewall Rules · mukul975 bundleAudit, create, and monitor GCP VPC firewall rules to enforce network segmentation and least-privilege access.
- ▌ Implementing Network Access Control · mukul975 bundleEnforces identity-based network access with 802.1X, RADIUS authentication, dynamic VLAN assignment, and endpoint posture assessment using PacketFence.
- ▌ Performing API Fuzzing With Restler · mukul975 bundleAutomates stateful REST API fuzzing using Microsoft RESTler to discover security and reliability bugs by compiling OpenAPI specs, configuring authentication, and running test, fuzz-lean, and full fuzzing modes.
- ▌ Performing API Rate Limiting Bypass · mukul975 bundleTests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls.
- ▌ Performing Clickjacking Attack Test · mukul975 bundleTest web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
- ▌ Performing Fuzzing With Aflplusplus · mukul975 bundlePerform coverage-guided fuzzing of compiled binaries using AFL++ to discover memory corruption, crashes, and security vulnerabilities.
- ▌ Performing Malware Triage With Yara · mukul975 bundleRapidly classify malware samples against known family signatures using YARA rules, covering rule writing, scanning, and integration with analysis pipelines.
- ▌ Scanning Infrastructure With Nessus · mukul975 bundleConfigure and run Nessus vulnerability scans, analyze results, and integrate scanning into continuous vulnerability management workflows.
- ▌ Scanning Network With Nmap Advanced · mukul975 bundlePerforms advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
- ▌ Securing Agentic AI Tool Invocation · mukul975 bundleApply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
- ▌ Securing AWS Lambda Execution Roles · mukul975 bundleAudit and harden AWS Lambda execution roles by implementing least-privilege IAM policies, permission boundaries, and SCP enforcement.
- ▌ Testing For Sensitive Data Exposure · mukul975 bundleIdentify sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
- ▌ Testing Oauth2 Implementation Flaws · mukul975 bundleTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass.
- ▌ Analyzing Active Directory Acl Abuse · mukul975 bundleDetect dangerous ACL misconfigurations in Active Directory by querying and parsing nTSecurityDescriptor attributes to identify GenericAll, WriteDACL, WriteOwner, and GenericWrite abuse paths.
- ▌ Analyzing Docker Container Forensics · mukul975 bundleInvestigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
- ▌ Analyzing Golang Malware With Ghidra · mukul975 bundleReverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
- ▌ Analyzing Malicious Url With Urlscan · mukul975 bundleInvestigate phishing URLs, credential harvesting pages, and malicious redirects using URLScan.io's safe browsing environment and API.
- ▌ Analyzing Network Packets With Scapy · mukul975 bundleCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing.
- ▌ Analyzing Network Traffic Of Malware · mukul975 bundleAnalyzes malware-generated network traffic from PCAP files to identify C2 protocols, data exfiltration, DNS tunneling, and beaconing patterns using Wireshark, Zeek, Suricata, and Python.
- ▌ Analyzing Ransomware Payment Wallets · mukul975 bundleTraces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution.
- ▌ Analyzing Threat Landscape With Misp · mukul975 bundleQuery MISP event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time to generate threat landscape reports.
- ▌ Analyzing Windows Shellbag Artifacts · mukul975 bundleAnalyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
- ▌ Building Incident Response Dashboard · mukul975 bundleBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline.
- ▌ Conducting Malware Incident Response · mukul975 bundleResponds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.
- ▌ Deploying Software Defined Perimeter · mukul975 bundleDeploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
- ▌ Detecting Dnp3 Protocol Anomalies · mukul975 bundleDetect anomalies in DNP3 protocol communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
- ▌ Hunting For Cobalt Strike Beacons · mukul975 bundleDetect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP C2 profile matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
- ▌ Hunting For Dcom Lateral Movement · mukul975 bundleDetect DCOM-based lateral movement by correlating Sysmon process creation and network connection events, WMI event analysis, and RPC endpoint mapper traffic to identify abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects.
- ▌ Hunting For Dns Based Persistence · mukul975 bundleHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
- ▌ Implementing Siem Use Case Tuning · mukul975 bundleReduce SIEM alert fatigue by systematically tuning detection rules in Splunk and Elastic, using statistical baselines, whitelists, and precision/recall metrics.
- ▌ Managing Cloud Identity With Okta · mukul975 bundleImplement Okta as a centralized identity provider for cloud environments, configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA, automate user lifecycle management, and enforce adaptive access policies.
- ▌ Performing Csrf Attack Simulation · mukul975 bundleTest web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
- ▌ Performing Malware Ioc Extraction · mukul975 bundleAnalyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
- ▌ Performing Red Team With Covenant · mukul975 bundleAutomate red team operations using the Covenant C2 framework's REST API for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
- ▌ Performing Security Headers Audit · mukul975 bundleAudits HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
- ▌ Recovering From Ransomware Attack · mukul975 bundleExecutes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection.
- ▌ Scanning Docker Images With Trivy · mukul975 bundleScan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
- ▌ Securing API Gateway With AWS Waf · mukul975 bundleProtect API Gateway endpoints with AWS WAF by configuring managed rule groups, rate limiting, bot control, IP reputation filtering, and monitoring.
- ▌ Securing Github Actions Workflows · mukul975 bundleHardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
- ▌ Testing For Broken Access Control · mukul975 bundleSystematically test web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
- ▌ Testing For Host Header Injection · mukul975 bundleTest web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
- ▌ Testing For System Prompt Leakage · mukul975 bundleTest LLM applications for system prompt leakage using manual payloads, garak, and Promptfoo to extract embedded secrets and routing logic.