all publishers

mukul975

@mukul975 source repo

828 published skills · page 8 of 9

  1. ▌
    Testing Mobile API Authentication · mukul975 bundle
    Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities.
    24.6k repo stars
  2. ▌
    Analyzing Indicators Of Compromise · mukul975 bundle
    Triages and enriches indicators of compromise (IPs, domains, file hashes, URLs, email artifacts) from phishing emails, security alerts, or threat feeds, assigning confidence scores and dispositions using VirusTotal, AbuseIPDB, MalwareBazaar, and MISP.
    24.6k repo stars
  3. ▌
    Analyzing Uefi Bootkit Persistence · mukul975 bundle
    Analyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.
    24.6k repo stars
  4. ▌
    Auditing AWS S3 Bucket Permissions · mukul975 bundle
    Audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, Prowler, and IAM Access Analyzer.
    24.6k repo stars
  5. ▌
    Auditing Cloud With Cis Benchmarks · mukul975 bundle
    Conduct cloud security audits using CIS benchmarks for AWS, Azure, and GCP, including automated assessments, remediation, and continuous compliance monitoring.
    24.6k repo stars
  6. ▌
    Conducting Cloud Incident Response · mukul975 bundle
    Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
    24.6k repo stars
  7. ▌
    Configuring Pfsense Firewall Rules · mukul975 bundle
    Guides the configuration of pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation and protect network zones.
    24.6k repo stars
  8. ▌
    Detecting Attacks On Scada Systems · mukul975 bundle
    Detects cyber attacks targeting SCADA systems, including man-in-the-middle, command injection, HMI compromise, historian manipulation, and DoS, using OT-specific intrusion detection and protocol anomaly analysis.
    24.6k repo stars
  9. ▌
    Detecting AWS Cloudtrail Anomalies · mukul975 bundle
    Query AWS CloudTrail events with boto3, build statistical baselines of normal API activity, and detect anomalies such as unusual event sources, geographic anomalies, high-frequency API calls, and first-time API usage patterns.
    24.6k repo stars
  10. ▌
    Detecting Data And Model Poisoning · mukul975 bundle
    Detect poisoned training data and backdoored models across the ML pipeline using statistical analysis, activation clustering, and spectral signatures.
    24.6k repo stars
  11. ▌
    Detecting Email Account Compromise · mukul975 bundle
    Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
    24.6k repo stars
  12. ▌
    Detecting Insider Threat Behaviors · mukul975 bundle
    Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
    24.6k repo stars
  13. ▌
    Detecting Insider Threat With Ueba · mukul975 bundle
    Detect insider threats by modeling normal user and entity behavior with Elasticsearch, computing anomaly scores, and correlating low-confidence indicators into high-confidence alerts.
    24.6k repo stars
  14. ▌
    Detecting Model Extraction Attacks · mukul975 bundle
    Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
    24.6k repo stars
  15. ▌
    Implementing Endpoint Dlp Controls · mukul975 bundle
    Deploys endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing using Microsoft Purview or Symantec DLP.
    24.6k repo stars
  16. ▌
    Operationalizing Misp Threat Feeds · mukul975 bundle
    Run MISP, curate threat feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
    24.6k repo stars
  17. ▌
    Performing Blind Ssrf Exploitation · mukul975 bundle
    Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
    24.6k repo stars
  18. ▌
    Performing Dns Tunneling Detection · mukul975 bundle
    Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality using scapy for packet capture analysis.
    24.6k repo stars
  19. ▌
    Performing Iot Security Assessment · mukul975 bundle
    Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications.
    24.6k repo stars
  20. ▌
    Performing Packet Injection Attack · mukul975 bundle
    Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
    24.6k repo stars
  21. ▌
    Performing Steganography Detection · mukul975 bundle
    Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
    24.6k repo stars
  22. ▌
    Performing User Behavior Analytics · mukul975 bundle
    Detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis.
    24.6k repo stars
  23. ▌
    Scanning Iac And Images With Trivy · mukul975 bundle
    Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
    24.6k repo stars
  24. ▌
    Securing Container Registry Images · mukul975 bundle
    Scan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
    24.6k repo stars
  25. ▌
    Testing For Email Header Injection · mukul975 bundle
    Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
    24.6k repo stars
  26. ▌
    Triaging Security Alerts In Splunk · mukul975 bundle
    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard.
    24.6k repo stars
  27. ▌
    Abusing Dpapi For Credential Access · mukul975 bundle
    Extract DPAPI-protected secrets such as credentials and browser data from Windows systems during authorized penetration tests.
    24.6k repo stars
  28. ▌
    Analyzing Dns Logs For Exfiltration · mukul975 bundle
    Detects DNS-based data exfiltration, tunneling, and DGA communication by analyzing query logs with entropy analysis, volume anomalies, and subdomain length detection in SIEM platforms.
    24.6k repo stars
  29. ▌
    Analyzing Malicious PDF With Peepdf · mukul975 bundle
    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
    24.6k repo stars
  30. ▌
    Analyzing Security Logs With Splunk · mukul975 bundle
    Investigate security incidents by correlating Windows event logs, firewall, proxy, and authentication data using Splunk SPL queries and Enterprise Security.
    24.6k repo stars
  31. ▌
    Detecting Cryptomining In Cloud · mukul975 bundle
    Detect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
    24.6k repo stars
  32. ▌
    Detecting Kerberoasting Attacks · mukul975 bundle
    Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
    24.6k repo stars
  33. ▌
    Detecting Pass The Hash Attacks · mukul975 bundle
    Hunt for Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons where Kerberos is expected, and correlating with credential dumping indicators.
    24.6k repo stars
  34. ▌
    Detecting Service Account Abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k repo stars
  35. ▌
    Detecting Shadow It Cloud Usage · mukul975 bundle
    Analyze proxy logs, DNS query logs, and netflow data to detect unauthorized SaaS and cloud service usage, classify domains, and flag high-risk services.
    24.6k repo stars
  36. ▌
    Detecting Stuxnet Style Attacks · mukul975 bundle
    Detect sophisticated cyber-physical attacks that modify PLC logic while spoofing sensor readings, covering PLC integrity monitoring, process anomaly detection, and multi-stage attack chain detection.
    24.6k repo stars
  37. ▌
    Enumerating Cloud With Cloudfox · mukul975 bundle
    Map AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
    24.6k repo stars
  38. ▌
    Exploiting Idor Vulnerabilities · mukul975 bundle
    Identify and exploit Insecure Direct Object Reference vulnerabilities during authorized penetration tests by manipulating object identifiers in API requests and URLs.
    24.6k repo stars
  39. ▌
    Exploiting Ipv6 Vulnerabilities · mukul975 bundle
    Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
    24.6k repo stars
  40. ▌
    Fleet Hunting With Velociraptor · mukul975 bundle
    Deploy a Velociraptor server and agents, then write and execute VQL hunts across a fleet of endpoints for threat hunting and incident response.
    24.6k repo stars
  41. ▌
    Implementing Saml Sso With Okta · mukul975 bundle
    Configure Okta as a SAML 2.0 Identity Provider and implement SP-initiated and IdP-initiated SSO flows with attribute mapping, assertion encryption, and security hardening.
    24.6k repo stars
  42. ▌
    Managing Intelligence Lifecycle · mukul975 bundle
    Guides the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to establish or mature a CTI program.
    24.6k repo stars
  43. ▌
    Mapping Mitre Attack Techniques · mukul975 bundle
    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.
    24.6k repo stars
  44. ▌
    Performing Kerberoasting Attack · mukul975 bundle
    Enumerate Active Directory service accounts, request Kerberos TGS tickets, and crack them offline to assess password strength and privilege escalation paths.
    24.6k repo stars
  45. ▌
    Performing Purple Team Exercise · mukul975 bundle
    Coordinates purple team exercises by running MITRE ATT&CK-mapped attack scenarios with real-time detection testing and collaborative gap remediation.
    24.6k repo stars
  46. ▌
    Performing Ssl Stripping Attack · mukul975 bundle
    Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms.
    24.6k repo stars
  47. ▌
    Securing Helm Chart Deployments · mukul975 bundle
    Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
    24.6k repo stars
  48. ▌
    Testing For Xss Vulnerabilities · mukul975 bundle
    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
    24.6k repo stars
  49. ▌
    Analyzing Linux System Artifacts · mukul975 bundle
    Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
    24.6k repo stars
  50. ▌
    Analyzing PDF Malware With Pdfid · mukul975 bundle
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis.
    24.6k repo stars
  51. ▌
    Auditing Kubernetes Cluster Rbac · mukul975 bundle
    Audit Kubernetes RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous bindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
    24.6k repo stars
  52. ▌
    Deobfuscating Javascript Malware · mukul975 bundle
    Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic.
    24.6k repo stars
  53. ▌
    Detecting Azure Lateral Movement · mukul975 bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    24.6k repo stars
  54. ▌
    Detecting Malicious NPM Packages · mukul975 bundle
    Triage npm packages for install-script malware, exfiltration, and worming behavior using GuardDog, manual inspection, and safe detonation.
    24.6k repo stars
  55. ▌
    Detecting Typosquatting Packages · mukul975 bundle
    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
    24.6k repo stars
  56. ▌
    Exploiting Broken Link Hijacking · mukul975 bundle
    Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.
    24.6k repo stars
  57. ▌
    Hunting For Shadow Copy Deletion · mukul975 bundle
    Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
    24.6k repo stars
  58. ▌
    Implementing Zero Trust In Cloud · mukul975 bundle
    Guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles, covering identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy in AWS, Azure, and GCP.
    24.6k repo stars
  59. ▌
    Managing Third Party Vendor Risk · mukul975 bundle
    Build and run a third-party/vendor risk management program aligned to NIST SP 800-161 and NIST CSF 2.0: inventory, tier, assess, contract, monitor, and offboard vendors.
    24.6k repo stars
  60. ▌
    Performing Osint With Spiderfoot · mukul975 bundle
    Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources.
    24.6k repo stars
  61. ▌
    Performing Service Account Audit · mukul975 bundle
    Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts, covering Active Directory, cloud platforms, databases, and applications.
    24.6k repo stars
  62. ▌
    Performing Soc Tabletop Exercise · mukul975 bundle
    Facilitates discussion-based tabletop exercises for SOC teams to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems.
    24.6k repo stars
  63. ▌
    Reverse Engineering Rust Malware · mukul975 bundle
    Analyze Rust-compiled malware binaries using IDA Pro and Ghidra, with techniques for extracting crate dependencies, non-null-terminated strings, and Rust-specific control flow patterns.
    24.6k repo stars
  64. ▌
    Achieving Cmmc Level 2 Compliance · mukul975 bundle
    Prepare a defense-contractor environment for CMMC Level 2 certification by scoping CUI and FCI, implementing NIST SP 800-171 Rev 2 requirements, computing SPRS scores, managing POA&Ms, and readying for C3PAO assessment.
    24.6k repo stars
  65. ▌
    Analyzing API Gateway Access Logs · mukul975 bundle
    Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts using pandas for statistical analysis and anomaly detection.
    24.6k repo stars
  66. ▌
    Analyzing Disk Image With Autopsy · mukul975 bundle
    Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
    24.6k repo stars
  67. ▌
    Analyzing Heap Spray Exploitation · mukul975 bundle
    Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
    24.6k repo stars
  68. ▌
    Attacking Entra Id With Roadtools · mukul975 bundle
    Enumerate Microsoft Entra ID tenants using ROADrecon and acquire/exchange tokens with roadtx for authorized red-team operations.
    24.6k repo stars
  69. ▌
    Building Cloud Siem With Sentinel · mukul975 bundle
    Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.
    24.6k repo stars
  70. ▌
    Conducting Pass The Ticket Attack · mukul975 bundle
    Extract Kerberos tickets from LSASS memory, inject them into an attacker session, and perform lateral movement to access remote systems as the impersonated user.
    24.6k repo stars
  71. ▌
    Deploying Ransomware Canary Files · mukul975 bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection, triggering alerts via email, Slack, or syslog when decoy files are accessed.
    24.6k repo stars
  72. ▌
    Detecting API Enumeration Attacks · mukul975 bundle
    Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
    24.6k repo stars
  73. ▌
    Detecting Dll Sideloading Attacks · mukul975 bundle
    Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
    24.6k repo stars
  74. ▌
    Detecting Mobile Malware Behavior · mukul975 bundle
    Analyzes mobile applications for malicious behavior through static analysis, runtime monitoring, and network traffic inspection to identify malware indicators.
    24.6k repo stars
  75. ▌
    Detecting Pass The Ticket Attacks · mukul975 bundle
    Detect Kerberos Pass-the-Ticket attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM.
    24.6k repo stars
  76. ▌
    Detecting Rdp Brute Force Attacks · mukul975 bundle
    Analyze Windows Security Event Logs to detect RDP brute force attacks by parsing Event ID 4625 and 4624 entries, identifying source IP frequency, and generating detection reports.
    24.6k repo stars
  77. ▌
    Exploiting HTTP Request Smuggling · mukul975 bundle
    Detect and exploit HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
    24.6k repo stars
  78. ▌
    Exploiting OAUTH Misconfiguration · mukul975 bundle
    Identify and exploit OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during authorized security assessments.
    24.6k repo stars
  79. ▌
    Containing Active Breach · mukul975 bundle
    Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach, using network segmentation, endpoint isolation, credential revocation, and access control modifications.
    24.6k repo stars
  80. ▌
    Exploiting AWS With Pacu · mukul975 bundle
    Use Pacu modules for AWS privilege escalation, persistence, and backdooring during authorized penetration tests.
    24.6k repo stars
  81. ▌
    Automating Ioc Enrichment · mukul975 bundle
    Automates enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs.
    24.6k repo stars
  82. ▌
    Detecting Wmi Persistence · mukul975 bundle
    Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
    24.6k repo stars
  83. ▌
    Analyzing Cyber Kill Chain · mukul975 bundle
    Maps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention.
    24.6k repo stars
  84. ▌
    Detecting Rootkit Activity · mukul975 bundle
    Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.
    24.6k repo stars
  85. ▌
    Hunting Evtx With Chainsaw · mukul975 bundle
    Hunt for threats in Windows Event Logs using Chainsaw, a fast Rust-based forensic tool that runs Sigma rules, keyword searches, and artifact analysis offline.
    24.6k repo stars
  86. ▌
    Hunting For Dcsync Attacks · mukul975 bundle
    Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
    24.6k repo stars
  87. ▌
    Monitoring Darkweb Sources · mukul975 bundle
    Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence.
    24.6k repo stars
  88. ▌
    Testing JWT Token Security · mukul975 bundle
    Assess JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
    24.6k repo stars
  89. ▌
    Triaging Security Incident · mukul975 bundle
    Triages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
    24.6k repo stars
  90. ▌
    Triaging Windows With Kape · mukul975 bundle
    Collect and parse forensic artifacts from Windows systems using KAPE for rapid DFIR triage.
    24.6k repo stars
  91. ▌
    Analyzing Linux Elf Malware · mukul975 bundle
    Analyzes malicious Linux ELF binaries including botnets, cryptominers, ransomware, and rootkits targeting servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples.
    24.6k repo stars
  92. ▌
    Detecting OAUTH Token Theft · mukul975 bundle
    Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
    24.6k repo stars
  93. ▌
    Escaping Containers To Host · mukul975 bundle
    Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
    24.6k repo stars
  94. ▌
    Executing Red Team Exercise · mukul975 bundle
    Simulates real-world adversary operations to test an organization's detection and response capabilities through the full attack lifecycle, from reconnaissance to objective completion.
    24.6k repo stars
  95. ▌
    Processing Stix Taxii Feeds · mukul975 bundle
    Processes STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
    24.6k repo stars
  96. ▌
    Red Teaming Llms With Garak · mukul975 bundle
    Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
    24.6k repo stars
  97. ▌
    Relaying Ntlm For Adcs Esc8 · mukul975 bundle
    Coerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync.
    24.6k repo stars
  98. ▌
    Auditing GCP Iam Permissions · mukul975 bundle
    Audits Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
    24.6k repo stars
  99. ▌
    Correlating Threat Campaigns · mukul975 bundle
    Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
    24.6k repo stars
  100. ▌
    Detecting Secure Boot Bypass · mukul975 bundle
    Detect bootkits such as BlackLotus and Bootkitty and verify Secure Boot bypass via DBX and binary checks.
    24.6k repo stars