mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Testing Mobile API Authentication · mukul975 bundleTests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities.
- ▌ Analyzing Indicators Of Compromise · mukul975 bundleTriages and enriches indicators of compromise (IPs, domains, file hashes, URLs, email artifacts) from phishing emails, security alerts, or threat feeds, assigning confidence scores and dispositions using VirusTotal, AbuseIPDB, MalwareBazaar, and MISP.
- ▌ Analyzing Uefi Bootkit Persistence · mukul975 bundleAnalyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.
- ▌ Auditing AWS S3 Bucket Permissions · mukul975 bundleAudit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, Prowler, and IAM Access Analyzer.
- ▌ Auditing Cloud With Cis Benchmarks · mukul975 bundleConduct cloud security audits using CIS benchmarks for AWS, Azure, and GCP, including automated assessments, remediation, and continuous compliance monitoring.
- ▌ Conducting Cloud Incident Response · mukul975 bundleResponds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
- ▌ Configuring Pfsense Firewall Rules · mukul975 bundleGuides the configuration of pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation and protect network zones.
- ▌ Detecting Attacks On Scada Systems · mukul975 bundleDetects cyber attacks targeting SCADA systems, including man-in-the-middle, command injection, HMI compromise, historian manipulation, and DoS, using OT-specific intrusion detection and protocol anomaly analysis.
- ▌ Detecting AWS Cloudtrail Anomalies · mukul975 bundleQuery AWS CloudTrail events with boto3, build statistical baselines of normal API activity, and detect anomalies such as unusual event sources, geographic anomalies, high-frequency API calls, and first-time API usage patterns.
- ▌ Detecting Data And Model Poisoning · mukul975 bundleDetect poisoned training data and backdoored models across the ML pipeline using statistical analysis, activation clustering, and spectral signatures.
- ▌ Detecting Email Account Compromise · mukul975 bundleDetect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
- ▌ Detecting Insider Threat Behaviors · mukul975 bundleDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
- ▌ Detecting Insider Threat With Ueba · mukul975 bundleDetect insider threats by modeling normal user and entity behavior with Elasticsearch, computing anomaly scores, and correlating low-confidence indicators into high-confidence alerts.
- ▌ Detecting Model Extraction Attacks · mukul975 bundleDetect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
- ▌ Implementing Endpoint Dlp Controls · mukul975 bundleDeploys endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing using Microsoft Purview or Symantec DLP.
- ▌ Operationalizing Misp Threat Feeds · mukul975 bundleRun MISP, curate threat feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
- ▌ Performing Blind Ssrf Exploitation · mukul975 bundleDetect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
- ▌ Performing Dns Tunneling Detection · mukul975 bundleDetects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality using scapy for packet capture analysis.
- ▌ Performing Iot Security Assessment · mukul975 bundlePerforms comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications.
- ▌ Performing Packet Injection Attack · mukul975 bundleCrafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
- ▌ Performing Steganography Detection · mukul975 bundleDetect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
- ▌ Performing User Behavior Analytics · mukul975 bundleDetect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis.
- ▌ Scanning Iac And Images With Trivy · mukul975 bundleScan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
- ▌ Securing Container Registry Images · mukul975 bundleScan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
- ▌ Testing For Email Header Injection · mukul975 bundleTest web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
- ▌ Triaging Security Alerts In Splunk · mukul975 bundleTriages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard.
- ▌ Abusing Dpapi For Credential Access · mukul975 bundleExtract DPAPI-protected secrets such as credentials and browser data from Windows systems during authorized penetration tests.
- ▌ Analyzing Dns Logs For Exfiltration · mukul975 bundleDetects DNS-based data exfiltration, tunneling, and DGA communication by analyzing query logs with entropy analysis, volume anomalies, and subdomain length detection in SIEM platforms.
- ▌ Analyzing Malicious PDF With Peepdf · mukul975 bundlePerform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
- ▌ Analyzing Security Logs With Splunk · mukul975 bundleInvestigate security incidents by correlating Windows event logs, firewall, proxy, and authentication data using Splunk SPL queries and Enterprise Security.
- ▌ Detecting Cryptomining In Cloud · mukul975 bundleDetect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
- ▌ Detecting Kerberoasting Attacks · mukul975 bundleDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
- ▌ Detecting Pass The Hash Attacks · mukul975 bundleHunt for Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons where Kerberos is expected, and correlating with credential dumping indicators.
- ▌ Detecting Service Account Abuse · mukul975 bundleDetect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
- ▌ Detecting Shadow It Cloud Usage · mukul975 bundleAnalyze proxy logs, DNS query logs, and netflow data to detect unauthorized SaaS and cloud service usage, classify domains, and flag high-risk services.
- ▌ Detecting Stuxnet Style Attacks · mukul975 bundleDetect sophisticated cyber-physical attacks that modify PLC logic while spoofing sensor readings, covering PLC integrity monitoring, process anomaly detection, and multi-stage attack chain detection.
- ▌ Enumerating Cloud With Cloudfox · mukul975 bundleMap AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
- ▌ Exploiting Idor Vulnerabilities · mukul975 bundleIdentify and exploit Insecure Direct Object Reference vulnerabilities during authorized penetration tests by manipulating object identifiers in API requests and URLs.
- ▌ Exploiting Ipv6 Vulnerabilities · mukul975 bundleIdentifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
- ▌ Fleet Hunting With Velociraptor · mukul975 bundleDeploy a Velociraptor server and agents, then write and execute VQL hunts across a fleet of endpoints for threat hunting and incident response.
- ▌ Implementing Saml Sso With Okta · mukul975 bundleConfigure Okta as a SAML 2.0 Identity Provider and implement SP-initiated and IdP-initiated SSO flows with attribute mapping, assertion encryption, and security hardening.
- ▌ Managing Intelligence Lifecycle · mukul975 bundleGuides the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to establish or mature a CTI program.
- ▌ Mapping Mitre Attack Techniques · mukul975 bundleMaps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.
- ▌ Performing Kerberoasting Attack · mukul975 bundleEnumerate Active Directory service accounts, request Kerberos TGS tickets, and crack them offline to assess password strength and privilege escalation paths.
- ▌ Performing Purple Team Exercise · mukul975 bundleCoordinates purple team exercises by running MITRE ATT&CK-mapped attack scenarios with real-time detection testing and collaborative gap remediation.
- ▌ Performing Ssl Stripping Attack · mukul975 bundleSimulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms.
- ▌ Securing Helm Chart Deployments · mukul975 bundleSecure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
- ▌ Testing For Xss Vulnerabilities · mukul975 bundleTests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
- ▌ Analyzing Linux System Artifacts · mukul975 bundleExamine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
- ▌ Analyzing PDF Malware With Pdfid · mukul975 bundleAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis.
- ▌ Auditing Kubernetes Cluster Rbac · mukul975 bundleAudit Kubernetes RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous bindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
- ▌ Deobfuscating Javascript Malware · mukul975 bundleDeobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic.
- ▌ Detecting Azure Lateral Movement · mukul975 bundleDetect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
- ▌ Detecting Malicious NPM Packages · mukul975 bundleTriage npm packages for install-script malware, exfiltration, and worming behavior using GuardDog, manual inspection, and safe detonation.
- ▌ Detecting Typosquatting Packages · mukul975 bundleFlag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
- ▌ Exploiting Broken Link Hijacking · mukul975 bundleDiscover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.
- ▌ Hunting For Shadow Copy Deletion · mukul975 bundleHunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
- ▌ Implementing Zero Trust In Cloud · mukul975 bundleGuides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles, covering identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy in AWS, Azure, and GCP.
- ▌ Managing Third Party Vendor Risk · mukul975 bundleBuild and run a third-party/vendor risk management program aligned to NIST SP 800-161 and NIST CSF 2.0: inventory, tier, assess, contract, monitor, and offboard vendors.
- ▌ Performing Osint With Spiderfoot · mukul975 bundleAutomate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources.
- ▌ Performing Service Account Audit · mukul975 bundleAudit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts, covering Active Directory, cloud platforms, databases, and applications.
- ▌ Performing Soc Tabletop Exercise · mukul975 bundleFacilitates discussion-based tabletop exercises for SOC teams to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems.
- ▌ Reverse Engineering Rust Malware · mukul975 bundleAnalyze Rust-compiled malware binaries using IDA Pro and Ghidra, with techniques for extracting crate dependencies, non-null-terminated strings, and Rust-specific control flow patterns.
- ▌ Achieving Cmmc Level 2 Compliance · mukul975 bundlePrepare a defense-contractor environment for CMMC Level 2 certification by scoping CUI and FCI, implementing NIST SP 800-171 Rev 2 requirements, computing SPRS scores, managing POA&Ms, and readying for C3PAO assessment.
- ▌ Analyzing API Gateway Access Logs · mukul975 bundleParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts using pandas for statistical analysis and anomaly detection.
- ▌ Analyzing Disk Image With Autopsy · mukul975 bundlePerform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
- ▌ Analyzing Heap Spray Exploitation · mukul975 bundleDetect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
- ▌ Attacking Entra Id With Roadtools · mukul975 bundleEnumerate Microsoft Entra ID tenants using ROADrecon and acquire/exchange tokens with roadtx for authorized red-team operations.
- ▌ Building Cloud Siem With Sentinel · mukul975 bundleDeploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.
- ▌ Conducting Pass The Ticket Attack · mukul975 bundleExtract Kerberos tickets from LSASS memory, inject them into an attacker session, and perform lateral movement to access remote systems as the impersonated user.
- ▌ Deploying Ransomware Canary Files · mukul975 bundleDeploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection, triggering alerts via email, Slack, or syslog when decoy files are accessed.
- ▌ Detecting API Enumeration Attacks · mukul975 bundleDetect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
- ▌ Detecting Dll Sideloading Attacks · mukul975 bundleDetect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
- ▌ Detecting Mobile Malware Behavior · mukul975 bundleAnalyzes mobile applications for malicious behavior through static analysis, runtime monitoring, and network traffic inspection to identify malware indicators.
- ▌ Detecting Pass The Ticket Attacks · mukul975 bundleDetect Kerberos Pass-the-Ticket attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM.
- ▌ Detecting Rdp Brute Force Attacks · mukul975 bundleAnalyze Windows Security Event Logs to detect RDP brute force attacks by parsing Event ID 4625 and 4624 entries, identifying source IP frequency, and generating detection reports.
- ▌ Exploiting HTTP Request Smuggling · mukul975 bundleDetect and exploit HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
- ▌ Exploiting OAUTH Misconfiguration · mukul975 bundleIdentify and exploit OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during authorized security assessments.
- ▌ Containing Active Breach · mukul975 bundleExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach, using network segmentation, endpoint isolation, credential revocation, and access control modifications.
- ▌ Exploiting AWS With Pacu · mukul975 bundleUse Pacu modules for AWS privilege escalation, persistence, and backdooring during authorized penetration tests.
- ▌ Automating Ioc Enrichment · mukul975 bundleAutomates enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs.
- ▌ Detecting Wmi Persistence · mukul975 bundleDetect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
- ▌ Analyzing Cyber Kill Chain · mukul975 bundleMaps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention.
- ▌ Detecting Rootkit Activity · mukul975 bundleDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.
- ▌ Hunting Evtx With Chainsaw · mukul975 bundleHunt for threats in Windows Event Logs using Chainsaw, a fast Rust-based forensic tool that runs Sigma rules, keyword searches, and artifact analysis offline.
- ▌ Hunting For Dcsync Attacks · mukul975 bundleDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
- ▌ Monitoring Darkweb Sources · mukul975 bundleMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence.
- ▌ Testing JWT Token Security · mukul975 bundleAssess JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
- ▌ Triaging Security Incident · mukul975 bundleTriages security incidents by classifying type, assigning severity based on business impact, enriching with threat intelligence, and routing to appropriate response teams using NIST SP 800-61r3 and SANS PICERL frameworks.
- ▌ Triaging Windows With Kape · mukul975 bundleCollect and parse forensic artifacts from Windows systems using KAPE for rapid DFIR triage.
- ▌ Analyzing Linux Elf Malware · mukul975 bundleAnalyzes malicious Linux ELF binaries including botnets, cryptominers, ransomware, and rootkits targeting servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples.
- ▌ Detecting OAUTH Token Theft · mukul975 bundleDetects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
- ▌ Escaping Containers To Host · mukul975 bundleExploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
- ▌ Executing Red Team Exercise · mukul975 bundleSimulates real-world adversary operations to test an organization's detection and response capabilities through the full attack lifecycle, from reconnaissance to objective completion.
- ▌ Processing Stix Taxii Feeds · mukul975 bundleProcesses STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
- ▌ Red Teaming Llms With Garak · mukul975 bundleRun NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
- ▌ Relaying Ntlm For Adcs Esc8 · mukul975 bundleCoerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync.
- ▌ Auditing GCP Iam Permissions · mukul975 bundleAudits Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
- ▌ Correlating Threat Campaigns · mukul975 bundleCorrelates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns and attribute them to common threat actors.
- ▌ Detecting Secure Boot Bypass · mukul975 bundleDetect bootkits such as BlackLotus and Bootkitty and verify Secure Boot bypass via DBX and binary checks.