all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 1 of 13

  1. ▌
    Clients 2 · oyi77 bundle
    Use when model Context Protocol client hub — connect AI agents to any MCP server for tool discovery, invocation, and ecosystem management. Use when working with MCP clients, discovering MCP servers, or building MCP-based toolchains.
    10 repo stars
  2. ▌
    Marketing Ops 2 · oyi77
    Use when > Complete AI-powered marketing & sales operating system for solo founders. Covers the full revenue lifecycle: customer research, content creation, SEO/GEO/SMO optimization, paid ads, email sequences, sales enablement, CRO, pricing, retention, analytics, automation, and global expansion. Includes stage-based playbooks ($0→$100K MRR), AI agent orchestration, PLG frameworks, Indonesia e-commerce, and decision-making infrastructure.
    10 repo stars
  3. ▌
    Design · oyi77 bundle
    Design
    10 repo stars
  4. ▌
    Sales Pipeline 2 · oyi77
    Use when aI-powered sales pipeline inside 1ai-social. Track leads, qualify with BANT, generate proposals, schedule follow-ups, and get daily sales analytics. Use when managing B2B sales pipelines.
    10 repo stars
  5. ▌
    Ponytail 2 · oyi77 bundle
    Use when lazy senior dev mode. Four disciplined mindsets — audit, debt, help, review — that cut complexity, track deferrals, surface reference, and catch over-engineering. Forces YAGNI, stdlib first, no unrequested abstractions. Use when working with ponytail.
    10 repo stars
  6. ▌
    Slack 2 · oyi77
    Use when slack Automation Hub — Bot, Notifier, and Slash Commands for team communication, DevOps alerts, and workflow automation. Monetize through integration-as-a-service.
    10 repo stars
  7. ▌
    Trading Strategist 2 · oyi77
    Use when design and backtest trading strategies using technical indicators, fundamental analysis, and statistical models. Use when designing and backtesting trading strategies.
    10 repo stars
  8. ▌
    UI UX Pro Max · oyi77 bundle
    UI/UX Pro Max - Design Intelligence
    10 repo stars
  9. ▌
    Reverse Engineering Ransomware Encryption Routine · oyi77
    Use when reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis. Use when reverseing engineer ransomware encryption routines to identify cryptographic algorithms, key.
    10 repo stars
  10. ▌
    Testing API For Broken Object Level Authorization · oyi77
    Use when tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to determine if the server enforces per-object authorization.
    10 repo stars
  11. ▌
    Analyzing Windows Prefetch With Python · oyi77
    Use when parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns. Use when working with analyzing windows prefetch with python.
    10 repo stars
  12. ▌
    Analyzing Email Headers For Phishing Investigation · oyi77
    Use when parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation. Use when working with analyzing email headers for phishing investigation.
    10 repo stars
  13. ▌
    Collecting Volatile Evidence From Compromised Host · oyi77
    Use when collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost. Use when working with collecting volatile evidence from compromised host.
    10 repo stars
  14. ▌
    Detecting Dns Exfiltration With Dns Query Analysis · oyi77
    Use when detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring. Use when detecting data exfiltration through dns tunneling by analyzing query entropy,.
    10 repo stars
  15. ▌
    Implementing Conduit Security For Ot Remote Access · oyi77
    Use when implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly. . Use when working with implementing conduit security for ot remote access.
    10 repo stars
  16. ▌
    Implementing Fuzz Testing In Cicd With Aflplusplus · oyi77
    Use when integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications. Use when integrateing afl++ coverage-guided fuzz testing into ci/cd pipelines to discover.
    10 repo stars
  17. ▌
    Implementing Kubernetes Network Policy With Calico · oyi77
    Use when implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication. Use when implementing kubernetes network segmentation using calico networkpolicy and globalnetworkpolicy for.
    10 repo stars
  18. ▌
    Implementing Network Access Control With Cisco Ise · oyi77
    Use when deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control. Use when deploying cisco identity services engine for 802.1x wired and wireless.
    10 repo stars
  19. ▌
    Implementing Opa Gatekeeper For Policy Enforcement · oyi77
    Use when enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library. Use when working with implementing opa gatekeeper for policy enforcement.
    10 repo stars
  20. ▌
    Implementing Policy As Code With Open Policy Agent · oyi77
    Use when this skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.
    10 repo stars
  21. ▌
    Implementing Zero Standing Privilege With Cyberark · oyi77
    Use when deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls. Use when deploying cyberark secure cloud access to eliminate standing privileges in.
    10 repo stars
  22. ▌
    Performing Log Analysis For Forensic Investigation · oyi77
    Use when collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations. Use when working with performing log analysis for forensic investigation.
    10 repo stars
  23. ▌
    Performing Malware Hash Enrichment With Virustotal · oyi77
    Use when enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation. Use when working with performing malware hash enrichment with virustotal.
    10 repo stars
  24. ▌
    Performing Mobile Device Forensics With Cellebrite · oyi77
    Use when acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts. Use when working with performing mobile device forensics with cellebrite.
    10 repo stars
  25. ▌
    Detecting Fileless Attacks On Endpoints · oyi77
    Use when detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
    10 repo stars
  26. ▌
    Implementing Zero Trust With Beyondcorp · oyi77
    Use when deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications. Use when deploying google beyondcorp enterprise zero trust access controls using identity-aware.
    10 repo stars
  27. ▌
    Analyzing Memory Forensics With Lime And Volatility · oyi77
    Use when performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
    10 repo stars
  28. ▌
    Implementing API Abuse Detection With Rate Limiting · oyi77
    Use when implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks. Use when implementing api abuse detection using token bucket, sliding window, and.
    10 repo stars
  29. ▌
    Implementing Cloud Vulnerability Posture Management · oyi77
    Use when implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection. Use when implementing cloud security posture management using aws security hub, azure.
    10 repo stars
  30. ▌
    Implementing Container Network Policies With Calico · oyi77
    Use when enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation. Use when working with implementing container network policies with calico.
    10 repo stars
  31. ▌
    Implementing Passwordless Auth With Microsoft Entra · oyi77
    Use when implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies. . Use when working with implementing passwordless auth with microsoft entra.
    10 repo stars
  32. ▌
    Implementing Passwordless Authentication With Fido2 · oyi77
    Use when deploying FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica
    10 repo stars
  33. ▌
    Performing AWS Account Enumeration With Scout Suite · oyi77
    Use when performing comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.
    10 repo stars
  34. ▌
    Performing Kubernetes Cis Benchmark With Kube Bench · oyi77
    Use when auditing Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
    10 repo stars
  35. ▌
    Performing Ot Vulnerability Assessment With Claroty · oyi77
    Use when this skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
    10 repo stars
  36. ▌
    Performing Threat Modeling With Owasp Threat Dragon · oyi77
    Use when using OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
    10 repo stars
  37. ▌
    Performing Wireless Security Assessment With Kismet · oyi77
    Use when conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring. Use when conducting wireless network security assessments using kismet to detect rogue.
    10 repo stars
  38. ▌
    Hunting For Living Off The Land Binaries · oyi77
    Use when proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection. Use when working with hunting for living off the land binaries.
    10 repo stars
  39. ▌
    Hunting For Process Injection Techniques · oyi77
    Use when detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry. Use when detecting process injection techniques (t1055) including createremotethread, process hollowing, and.
    10 repo stars
  40. ▌
    Hunting For Registry Run Key Persistence · oyi77
    Use when detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries. Use when detecting mitre att&ck t1547.001 registry run key persistence by analyzing.
    10 repo stars
  41. ▌
    Analyzing Malware Family Relationships With Malpedia · oyi77
    Use when use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages. Use when working with analyzing malware family relationships with malpedia.
    10 repo stars
  42. ▌
    Detecting Broken Object Property Level Authorization · oyi77
    Use when detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks. Use when detecting and test for owasp api3:2023 broken object property level.
    10 repo stars
  43. ▌
    Exploiting Vulnerabilities With Metasploit Framework · oyi77
    Use when the Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules. Use when working with exploiting vulnerabilities with metasploit framework.
    10 repo stars
  44. ▌
    Implementing Application Whitelisting With Applocker · oyi77
    Use when implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.
    10 repo stars
  45. ▌
    Implementing Azure Ad Privileged Identity Management · oyi77
    Use when configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles. Use when configureing microsoft entra privileged identity management to enforce just-in-time role.
    10 repo stars
  46. ▌
    Implementing Continuous Security Validation With Bas · oyi77
    Use when deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain. Use when deploying breach and attack simulation tools to continuously validate security.
    10 repo stars
  47. ▌
    Implementing Device Posture Assessment In Zero Trust · oyi77
    Use when implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access. . Use when working with implementing device posture assessment in zero trust.
    10 repo stars
  48. ▌
    Implementing Next Generation Firewall With Palo Alto · oyi77
    Use when configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security. Use when configureing and deploy palo alto networks next-generation firewalls with app-id,.
    10 repo stars
  49. ▌
    Implementing Ot Network Traffic Analysis With Nozomi · oyi77
    Use when deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring. . Use when working with implementing ot network traffic analysis with nozomi.
    10 repo stars
  50. ▌
    Implementing Security Information Sharing With Stix2 · oyi77
    Use when creating, validating, and sharing STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
    10 repo stars
  51. ▌
    Implementing Vulnerability Management With Greenbone · oyi77
    Use when deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol. Use when deploying and operate greenbone/openvas vulnerability management using the python-gvm library.
    10 repo stars
  52. ▌
    Implementing Zero Knowledge Proof For Authentication · oyi77
    Use when zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati. Use when working with implementing zero knowledge proof for authentication.
    10 repo stars
  53. ▌
    Performing Active Directory Compromise Investigation · oyi77
    Use when investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths. Use when working with performing active directory compromise investigation.
    10 repo stars
  54. ▌
    Performing Active Directory Vulnerability Assessment · oyi77
    Use when assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors. Use when working with performing active directory vulnerability assessment.
    10 repo stars
  55. ▌
    Performing Memory Forensics With Volatility3 Plugins · oyi77
    Use when analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. Use when analyzeing memory dumps using volatility3 plugins to detect injected code,.
    10 repo stars
  56. ▌
    Performing Thick Client Application Penetration Test · oyi77
    Use when conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite. Use when conducting a thick client application penetration test to identify insecure.
    10 repo stars
  57. ▌
    Analyzing Windows Lnk Files For Artifacts · oyi77
    Use when parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction. Use when working with analyzing windows lnk files for artifacts.
    10 repo stars
  58. ▌
    Detecting Exfiltration Over Dns With Zeek · oyi77
    Use when detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns. Use when detecting dns-based data exfiltration by analyzing zeek dns.log for high-entropy.
    10 repo stars
  59. ▌
    Detecting Living Off The Land With Lolbas · oyi77
    Use when detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis. Use when detecting living off the land binaries (lolbins/lolbas) abuse including certutil,.
    10 repo stars
  60. ▌
    Conducting Internal Reconnaissance With Bloodhound Ce · oyi77
    Use when conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments. Use when conducting internal active directory reconnaissance using bloodhound community edition to.
    10 repo stars
  61. ▌
    Exploiting Active Directory Certificate Services Esc1 · oyi77
    Use when exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments. Use when exploiting misconfigured active directory certificate services (ad cs) esc1 vulnerability.
    10 repo stars
  62. ▌
    Implementing Infrastructure As Code Security Scanning · oyi77
    Use when this skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.
    10 repo stars
  63. ▌
    Implementing Network Segmentation With Firewall Zones · oyi77
    Use when design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access. Use when designing and implement network segmentation using firewall security zones, vlans,.
    10 repo stars
  64. ▌
    Implementing Threat Intelligence Lifecycle Management · oyi77
    Use when implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making. Use when implementing a structured threat intelligence lifecycle encompassing planning, collection, processing,.
    10 repo stars
  65. ▌
    Implementing Web Application Logging With Modsecurity · oyi77
    Use when configuring ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tuning rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability.
    10 repo stars
  66. ▌
    Performing Adversary In The Middle Phishing Detection · oyi77
    Use when detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens. Use when detecting and respond to adversary-in-the-middle (aitm) phishing attacks that use.
    10 repo stars
  67. ▌
    Implementing Image Provenance Verification With Cosign · oyi77
    Use when sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement. Use when working with implementing image provenance verification with cosign.
    10 repo stars
  68. ▌
    Implementing Iso 27001 Information Security Management · oyi77
    Use when ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
    10 repo stars
  69. ▌
    Performing GCP Penetration Testing With Gcpbucketbrute · oyi77
    Use when perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing. Use when performing gcp security testing using gcpbucketbrute for storage bucket enumeration,.
    10 repo stars
  70. ▌
    Conducting Memory Forensics With Volatility · oyi77
    Use when performing memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
    10 repo stars
  71. ▌
    Implementing Deception Based Detection With Canarytoken · oyi77
    Use when deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens. Use when deploying and monitor canary tokens via the thinkst canary api.
    10 repo stars
  72. ▌
    Implementing Github Advanced Security For Code Scanning · oyi77
    Use when configuring GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
    10 repo stars
  73. ▌
    Implementing Network Intrusion Prevention With Suricata · oyi77
    Use when deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking. Use when deploying and configure suricata as a network intrusion prevention system.
    10 repo stars
  74. ▌
    Implementing Privileged Access Management With Cyberark · oyi77
    Use when deploying CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
    10 repo stars
  75. ▌
    Analyzing Cobaltstrike Malleable C2 Profiles · oyi77
    Use when parsing and analyzing Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
    10 repo stars
  76. ▌
    Performing Memory Forensics With Volatility3 · oyi77
    Use when analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity. Use when analyzeing volatile memory dumps using volatility 3 to extract running.
    10 repo stars
  77. ▌
    Implementing Data Loss Prevention With Microsoft Purview · oyi77
    Use when implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Acti...
    10 repo stars
  78. ▌
    Implementing Epss Score For Vulnerability Prioritization · oyi77
    Use when integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days. Use when integrateing first's exploit prediction scoring system (epss) api to prioritize.
    10 repo stars
  79. ▌
    Implementing Container Image Minimal Base With Distroless · oyi77
    Use when reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities. Use when working with implementing container image minimal base with distroless.
    10 repo stars
  80. ▌
    Performing Cloud Native Threat Hunting With AWS Detective · oyi77
    Use when hunting for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
    10 repo stars
  81. ▌
    Analyzing Threat Actor Ttps With Mitre Navigator · oyi77
    Use when mapping advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles.
    10 repo stars
  82. ▌
    Performing Windows Artifact Analysis With Eric Zimmerman Too · oyi77
    Use when perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata. Use when performing comprehensive windows forensic artifact analysis using eric zimmerman's open-source.
    10 repo stars
  83. ▌
    Implementing Zero Trust Network Access With Zscaler · oyi77
    Use when implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange. Use when implementing zero trust network access using zscaler private access (zpa).
    10 repo stars
  84. ▌
    Triaging Security Incident With Ir Playbook · oyi77
    Use when classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures. Use when working with triaging security incident with ir playbook.
    10 repo stars
  85. ▌
    Analyzing Cobalt Strike Beacon Configuration · oyi77
    Use when extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft. Use when working with analyzing cobalt strike beacon configuration.
    10 repo stars
  86. ▌
    Analyzing Malware Sandbox Evasion Techniques · oyi77
    Use when detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports. Use when detecting sandbox evasion techniques in malware samples by analyzing timing.
    10 repo stars
  87. ▌
    Analyzing Network Covert Channels In Malware · oyi77
    Use when detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration. Use when detecting and analyze covert communication channels used by malware including.
    10 repo stars
  88. ▌
    Conducting Internal Network Penetration Test · oyi77
    Use when execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network. Use when working with conducting internal network penetration test.
    10 repo stars
  89. ▌
    Conducting Spearphishing Simulation Campaign · oyi77
    Use when spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf. Use when working with conducting spearphishing simulation campaign.
    10 repo stars
  90. ▌
    Conducting Wireless Network Penetration Test · oyi77
    Use when conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Use when working with conducting wireless network penetration test.
    10 repo stars
  91. ▌
    Configuring Microsegmentation For Zero Trust · oyi77
    Use when configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures. Use when configureing microsegmentation policies to enforce least-privilege workload-to-workload access using tools.
    10 repo stars
  92. ▌
    Deploying Palo Alto Prisma Access Zero Trust · oyi77
    Use when deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management. . Use when working with deploying palo alto prisma access zero trust.
    10 repo stars
  93. ▌
    Detecting Typosquatting Packages In NPM Pypi · oyi77
    Use when detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. Use when working with detecting typosquatting packages in npm pypi.
    10 repo stars
  94. ▌
    Executing Active Directory Attack Simulation · oyi77
    Use when executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, and delegation abuse. Use when working with executing active directory attack simulation.
    10 repo stars
  95. ▌
    Exploiting Prototype Pollution In Javascript · oyi77
    Use when detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection. Use when detecting and exploit javascript prototype pollution vulnerabilities on both client-side.
    10 repo stars
  96. ▌
    Hunting For Data Staging Before Exfiltration · oyi77
    Use when detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry. Use when detecting data staging activity before exfiltration by monitoring for archive.
    10 repo stars
  97. ▌
    Hunting For Defense Evasion Via Timestomping · oyi77
    Use when detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity. . Use when working with hunting for defense evasion via timestomping.
    10 repo stars
  98. ▌
    Implementing Aes Encryption For Data At REST · oyi77
    Use when AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m
    10 repo stars
  99. ▌
    Implementing API Security Posture Management · oyi77
    Use when implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle. Use when implementing api security posture management to continuously discover, classify, and.
    10 repo stars
  100. ▌
    Implementing AWS Config Rules For Compliance · oyi77
    Use when implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts. . Use when working with implementing aws config rules for compliance.
    10 repo stars