oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Clients 2 · oyi77 bundleUse when model Context Protocol client hub — connect AI agents to any MCP server for tool discovery, invocation, and ecosystem management. Use when working with MCP clients, discovering MCP servers, or building MCP-based toolchains.
- ▌ Marketing Ops 2 · oyi77Use when > Complete AI-powered marketing & sales operating system for solo founders. Covers the full revenue lifecycle: customer research, content creation, SEO/GEO/SMO optimization, paid ads, email sequences, sales enablement, CRO, pricing, retention, analytics, automation, and global expansion. Includes stage-based playbooks ($0→$100K MRR), AI agent orchestration, PLG frameworks, Indonesia e-commerce, and decision-making infrastructure.
- ▌
- ▌ Sales Pipeline 2 · oyi77Use when aI-powered sales pipeline inside 1ai-social. Track leads, qualify with BANT, generate proposals, schedule follow-ups, and get daily sales analytics. Use when managing B2B sales pipelines.
- ▌ Ponytail 2 · oyi77 bundleUse when lazy senior dev mode. Four disciplined mindsets — audit, debt, help, review — that cut complexity, track deferrals, surface reference, and catch over-engineering. Forces YAGNI, stdlib first, no unrequested abstractions. Use when working with ponytail.
- ▌ Slack 2 · oyi77Use when slack Automation Hub — Bot, Notifier, and Slash Commands for team communication, DevOps alerts, and workflow automation. Monetize through integration-as-a-service.
- ▌ Trading Strategist 2 · oyi77Use when design and backtest trading strategies using technical indicators, fundamental analysis, and statistical models. Use when designing and backtesting trading strategies.
- ▌
- ▌ Reverse Engineering Ransomware Encryption Routine · oyi77Use when reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis. Use when reverseing engineer ransomware encryption routines to identify cryptographic algorithms, key.
- ▌ Testing API For Broken Object Level Authorization · oyi77Use when tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to determine if the server enforces per-object authorization.
- ▌ Analyzing Windows Prefetch With Python · oyi77Use when parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns. Use when working with analyzing windows prefetch with python.
- ▌ Analyzing Email Headers For Phishing Investigation · oyi77Use when parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation. Use when working with analyzing email headers for phishing investigation.
- ▌ Collecting Volatile Evidence From Compromised Host · oyi77Use when collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost. Use when working with collecting volatile evidence from compromised host.
- ▌ Detecting Dns Exfiltration With Dns Query Analysis · oyi77Use when detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring. Use when detecting data exfiltration through dns tunneling by analyzing query entropy,.
- ▌ Implementing Conduit Security For Ot Remote Access · oyi77Use when implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly. . Use when working with implementing conduit security for ot remote access.
- ▌ Implementing Fuzz Testing In Cicd With Aflplusplus · oyi77Use when integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications. Use when integrateing afl++ coverage-guided fuzz testing into ci/cd pipelines to discover.
- ▌ Implementing Kubernetes Network Policy With Calico · oyi77Use when implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication. Use when implementing kubernetes network segmentation using calico networkpolicy and globalnetworkpolicy for.
- ▌ Implementing Network Access Control With Cisco Ise · oyi77Use when deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control. Use when deploying cisco identity services engine for 802.1x wired and wireless.
- ▌ Implementing Opa Gatekeeper For Policy Enforcement · oyi77Use when enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library. Use when working with implementing opa gatekeeper for policy enforcement.
- ▌ Implementing Policy As Code With Open Policy Agent · oyi77Use when this skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.
- ▌ Implementing Zero Standing Privilege With Cyberark · oyi77Use when deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls. Use when deploying cyberark secure cloud access to eliminate standing privileges in.
- ▌ Performing Log Analysis For Forensic Investigation · oyi77Use when collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations. Use when working with performing log analysis for forensic investigation.
- ▌ Performing Malware Hash Enrichment With Virustotal · oyi77Use when enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation. Use when working with performing malware hash enrichment with virustotal.
- ▌ Performing Mobile Device Forensics With Cellebrite · oyi77Use when acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts. Use when working with performing mobile device forensics with cellebrite.
- ▌ Detecting Fileless Attacks On Endpoints · oyi77Use when detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
- ▌ Implementing Zero Trust With Beyondcorp · oyi77Use when deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications. Use when deploying google beyondcorp enterprise zero trust access controls using identity-aware.
- ▌ Analyzing Memory Forensics With Lime And Volatility · oyi77Use when performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
- ▌ Implementing API Abuse Detection With Rate Limiting · oyi77Use when implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks. Use when implementing api abuse detection using token bucket, sliding window, and.
- ▌ Implementing Cloud Vulnerability Posture Management · oyi77Use when implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection. Use when implementing cloud security posture management using aws security hub, azure.
- ▌ Implementing Container Network Policies With Calico · oyi77Use when enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation. Use when working with implementing container network policies with calico.
- ▌ Implementing Passwordless Auth With Microsoft Entra · oyi77Use when implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies. . Use when working with implementing passwordless auth with microsoft entra.
- ▌ Implementing Passwordless Authentication With Fido2 · oyi77Use when deploying FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica
- ▌ Performing AWS Account Enumeration With Scout Suite · oyi77Use when performing comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.
- ▌ Performing Kubernetes Cis Benchmark With Kube Bench · oyi77Use when auditing Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
- ▌ Performing Ot Vulnerability Assessment With Claroty · oyi77Use when this skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
- ▌ Performing Threat Modeling With Owasp Threat Dragon · oyi77Use when using OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
- ▌ Performing Wireless Security Assessment With Kismet · oyi77Use when conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring. Use when conducting wireless network security assessments using kismet to detect rogue.
- ▌ Hunting For Living Off The Land Binaries · oyi77Use when proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection. Use when working with hunting for living off the land binaries.
- ▌ Hunting For Process Injection Techniques · oyi77Use when detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry. Use when detecting process injection techniques (t1055) including createremotethread, process hollowing, and.
- ▌ Hunting For Registry Run Key Persistence · oyi77Use when detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries. Use when detecting mitre att&ck t1547.001 registry run key persistence by analyzing.
- ▌ Analyzing Malware Family Relationships With Malpedia · oyi77Use when use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages. Use when working with analyzing malware family relationships with malpedia.
- ▌ Detecting Broken Object Property Level Authorization · oyi77Use when detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks. Use when detecting and test for owasp api3:2023 broken object property level.
- ▌ Exploiting Vulnerabilities With Metasploit Framework · oyi77Use when the Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules. Use when working with exploiting vulnerabilities with metasploit framework.
- ▌ Implementing Application Whitelisting With Applocker · oyi77Use when implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.
- ▌ Implementing Azure Ad Privileged Identity Management · oyi77Use when configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles. Use when configureing microsoft entra privileged identity management to enforce just-in-time role.
- ▌ Implementing Continuous Security Validation With Bas · oyi77Use when deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain. Use when deploying breach and attack simulation tools to continuously validate security.
- ▌ Implementing Device Posture Assessment In Zero Trust · oyi77Use when implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access. . Use when working with implementing device posture assessment in zero trust.
- ▌ Implementing Next Generation Firewall With Palo Alto · oyi77Use when configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security. Use when configureing and deploy palo alto networks next-generation firewalls with app-id,.
- ▌ Implementing Ot Network Traffic Analysis With Nozomi · oyi77Use when deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring. . Use when working with implementing ot network traffic analysis with nozomi.
- ▌ Implementing Security Information Sharing With Stix2 · oyi77Use when creating, validating, and sharing STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
- ▌ Implementing Vulnerability Management With Greenbone · oyi77Use when deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol. Use when deploying and operate greenbone/openvas vulnerability management using the python-gvm library.
- ▌ Implementing Zero Knowledge Proof For Authentication · oyi77Use when zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati. Use when working with implementing zero knowledge proof for authentication.
- ▌ Performing Active Directory Compromise Investigation · oyi77Use when investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths. Use when working with performing active directory compromise investigation.
- ▌ Performing Active Directory Vulnerability Assessment · oyi77Use when assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors. Use when working with performing active directory vulnerability assessment.
- ▌ Performing Memory Forensics With Volatility3 Plugins · oyi77Use when analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. Use when analyzeing memory dumps using volatility3 plugins to detect injected code,.
- ▌ Performing Thick Client Application Penetration Test · oyi77Use when conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite. Use when conducting a thick client application penetration test to identify insecure.
- ▌ Analyzing Windows Lnk Files For Artifacts · oyi77Use when parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction. Use when working with analyzing windows lnk files for artifacts.
- ▌ Detecting Exfiltration Over Dns With Zeek · oyi77Use when detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns. Use when detecting dns-based data exfiltration by analyzing zeek dns.log for high-entropy.
- ▌ Detecting Living Off The Land With Lolbas · oyi77Use when detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis. Use when detecting living off the land binaries (lolbins/lolbas) abuse including certutil,.
- ▌ Conducting Internal Reconnaissance With Bloodhound Ce · oyi77Use when conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments. Use when conducting internal active directory reconnaissance using bloodhound community edition to.
- ▌ Exploiting Active Directory Certificate Services Esc1 · oyi77Use when exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments. Use when exploiting misconfigured active directory certificate services (ad cs) esc1 vulnerability.
- ▌ Implementing Infrastructure As Code Security Scanning · oyi77Use when this skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.
- ▌ Implementing Network Segmentation With Firewall Zones · oyi77Use when design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access. Use when designing and implement network segmentation using firewall security zones, vlans,.
- ▌ Implementing Threat Intelligence Lifecycle Management · oyi77Use when implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making. Use when implementing a structured threat intelligence lifecycle encompassing planning, collection, processing,.
- ▌ Implementing Web Application Logging With Modsecurity · oyi77Use when configuring ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tuning rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability.
- ▌ Performing Adversary In The Middle Phishing Detection · oyi77Use when detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens. Use when detecting and respond to adversary-in-the-middle (aitm) phishing attacks that use.
- ▌ Implementing Image Provenance Verification With Cosign · oyi77Use when sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement. Use when working with implementing image provenance verification with cosign.
- ▌ Implementing Iso 27001 Information Security Management · oyi77Use when ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
- ▌ Performing GCP Penetration Testing With Gcpbucketbrute · oyi77Use when perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing. Use when performing gcp security testing using gcpbucketbrute for storage bucket enumeration,.
- ▌ Conducting Memory Forensics With Volatility · oyi77Use when performing memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
- ▌ Implementing Deception Based Detection With Canarytoken · oyi77Use when deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens. Use when deploying and monitor canary tokens via the thinkst canary api.
- ▌ Implementing Github Advanced Security For Code Scanning · oyi77Use when configuring GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
- ▌ Implementing Network Intrusion Prevention With Suricata · oyi77Use when deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking. Use when deploying and configure suricata as a network intrusion prevention system.
- ▌ Implementing Privileged Access Management With Cyberark · oyi77Use when deploying CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
- ▌ Analyzing Cobaltstrike Malleable C2 Profiles · oyi77Use when parsing and analyzing Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
- ▌ Performing Memory Forensics With Volatility3 · oyi77Use when analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity. Use when analyzeing volatile memory dumps using volatility 3 to extract running.
- ▌ Implementing Data Loss Prevention With Microsoft Purview · oyi77Use when implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Acti...
- ▌ Implementing Epss Score For Vulnerability Prioritization · oyi77Use when integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days. Use when integrateing first's exploit prediction scoring system (epss) api to prioritize.
- ▌ Implementing Container Image Minimal Base With Distroless · oyi77Use when reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities. Use when working with implementing container image minimal base with distroless.
- ▌ Performing Cloud Native Threat Hunting With AWS Detective · oyi77Use when hunting for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
- ▌ Analyzing Threat Actor Ttps With Mitre Navigator · oyi77Use when mapping advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles.
- ▌ Performing Windows Artifact Analysis With Eric Zimmerman Too · oyi77Use when perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata. Use when performing comprehensive windows forensic artifact analysis using eric zimmerman's open-source.
- ▌ Implementing Zero Trust Network Access With Zscaler · oyi77Use when implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange. Use when implementing zero trust network access using zscaler private access (zpa).
- ▌ Triaging Security Incident With Ir Playbook · oyi77Use when classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures. Use when working with triaging security incident with ir playbook.
- ▌ Analyzing Cobalt Strike Beacon Configuration · oyi77Use when extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft. Use when working with analyzing cobalt strike beacon configuration.
- ▌ Analyzing Malware Sandbox Evasion Techniques · oyi77Use when detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports. Use when detecting sandbox evasion techniques in malware samples by analyzing timing.
- ▌ Analyzing Network Covert Channels In Malware · oyi77Use when detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration. Use when detecting and analyze covert communication channels used by malware including.
- ▌ Conducting Internal Network Penetration Test · oyi77Use when execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network. Use when working with conducting internal network penetration test.
- ▌ Conducting Spearphishing Simulation Campaign · oyi77Use when spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf. Use when working with conducting spearphishing simulation campaign.
- ▌ Conducting Wireless Network Penetration Test · oyi77Use when conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Use when working with conducting wireless network penetration test.
- ▌ Configuring Microsegmentation For Zero Trust · oyi77Use when configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures. Use when configureing microsegmentation policies to enforce least-privilege workload-to-workload access using tools.
- ▌ Deploying Palo Alto Prisma Access Zero Trust · oyi77Use when deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management. . Use when working with deploying palo alto prisma access zero trust.
- ▌ Detecting Typosquatting Packages In NPM Pypi · oyi77Use when detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. Use when working with detecting typosquatting packages in npm pypi.
- ▌ Executing Active Directory Attack Simulation · oyi77Use when executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, and delegation abuse. Use when working with executing active directory attack simulation.
- ▌ Exploiting Prototype Pollution In Javascript · oyi77Use when detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection. Use when detecting and exploit javascript prototype pollution vulnerabilities on both client-side.
- ▌ Hunting For Data Staging Before Exfiltration · oyi77Use when detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry. Use when detecting data staging activity before exfiltration by monitoring for archive.
- ▌ Hunting For Defense Evasion Via Timestomping · oyi77Use when detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity. . Use when working with hunting for defense evasion via timestomping.
- ▌ Implementing Aes Encryption For Data At REST · oyi77Use when AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m
- ▌ Implementing API Security Posture Management · oyi77Use when implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle. Use when implementing api security posture management to continuously discover, classify, and.
- ▌ Implementing AWS Config Rules For Compliance · oyi77Use when implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts. . Use when working with implementing aws config rules for compliance.