all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 2 of 13

  1. ▌
    Implementing Ddos Mitigation With Cloudflare · oyi77
    Use when configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks. Use when configureing cloudflare ddos protection with managed rulesets, rate limiting, waf.
    10 repo stars
  2. ▌
    Implementing Digital Signatures With Ed25519 · oyi77
    Use when ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove. Use when working with implementing digital signatures with ed25519.
    10 repo stars
  3. ▌
    Implementing Google Workspace Admin Security · oyi77
    Use when implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration. . Use when working with implementing google workspace admin security.
    10 repo stars
  4. ▌
    Implementing Hashicorp Vault Dynamic Secrets · oyi77
    Use when implementing HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation.
    10 repo stars
  5. ▌
    Implementing Memory Protection With Dep Aslr · oyi77
    Use when implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks. Use when hardening endpoints against buffer overflow exploits, ROP chains, and code injection. Activates for requests involving memory protection, exploit mitigation, DEP, ASLR, or CFG configuration.
    10 repo stars
  6. ▌
    Implementing Network Policies For Kubernetes · oyi77
    Use when kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu. Use when working with implementing network policies for kubernetes.
    10 repo stars
  7. ▌
    Implementing Patch Management For Ot Systems · oyi77
    Use when this skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization, staged deployment through test environments, maintenance window coordination, rollback procedures, and compensating controls when patches cannot be applied due to operational constraints or vendor restrictions.
    10 repo stars
  8. ▌
    Performing Active Directory Penetration Test · oyi77
    Use when conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise. Use when conducting a focused active directory penetration test to enumerate domain.
    10 repo stars
  9. ▌
    Performing API Security Testing With Postman · oyi77
    Use when using Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writing test scripts for automated security validation, and integrating Postman with OWASP ZAP and Newman for CI/CD security testing.
    10 repo stars
  10. ▌
    Performing Cloud Native Forensics With Falco · oyi77
    Use when uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
    10 repo stars
  11. ▌
    Performing Dns Enumeration And Zone Transfer · oyi77
    Use when enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains. . Use when working with performing dns enumeration and zone transfer.
    10 repo stars
  12. ▌
    Performing External Network Penetration Test · oyi77
    Use when conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting. Use when conducting a comprehensive external network penetration test to identify vulnerabilities.
    10 repo stars
  13. ▌
    Performing Linux Log Forensics Investigation · oyi77
    Use when perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised Linux systems. Use when performing forensic investigation of linux system logs including syslog, auth.log,.
    10 repo stars
  14. ▌
    Performing Malware Persistence Investigation · oyi77
    Use when systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access. Use when working with performing malware persistence investigation.
    10 repo stars
  15. ▌
    Performing S7comm Protocol Security Analysis · oyi77
    Use when perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers. . Use when working with performing s7comm protocol security analysis.
    10 repo stars
  16. ▌
    Performing Sca Dependency Scanning With Snyk · oyi77
    Use when this skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
    10 repo stars
  17. ▌
    Performing Soap Web Service Security Testing · oyi77
    Use when perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing. Use when performing security testing of soap web services by analyzing wsdl.
    10 repo stars
  18. ▌
    Performing Wireless Network Penetration Test · oyi77
    Use when execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools. Use when working with performing wireless network penetration test.
    10 repo stars
  19. ▌
    Triaging Vulnerabilities With Ssvc Framework · oyi77
    Use when triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities. Use when working with triaging vulnerabilities with ssvc framework.
    10 repo stars
  20. ▌
    Hunting For Cobalt Strike Beacons · oyi77
    Use when detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis. Use when detecting cobalt strike beacon network activity using default tls certificate.
    10 repo stars
  21. ▌
    Analyzing Office365 Audit Logs For Compromise · oyi77
    Use when parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise. Use when working with analyzing office365 audit logs for compromise.
    10 repo stars
  22. ▌
    Analyzing Threat Actor Ttps With Mitre Attack · oyi77
    Use when MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
    10 repo stars
  23. ▌
    Analyzing Typosquatting Domains With Dnstwist · oyi77
    Use when detecting typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
    10 repo stars
  24. ▌
    Auditing Azure Active Directory Configuration · oyi77
    Use when auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite. . Use when working with auditing azure active directory configuration.
    10 repo stars
  25. ▌
    Building Ioc Enrichment Pipeline With Opencti · oyi77
    Use when openCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O
    10 repo stars
  26. ▌
    Building Threat Intelligence Feed Integration · oyi77
    Use when builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
    10 repo stars
  27. ▌
    Building Vulnerability Aging And Sla Tracking · oyi77
    Use when implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability. Use when implementing a vulnerability aging dashboard and sla tracking system to.
    10 repo stars
  28. ▌
    Bypassing Authentication With Forced Browsing · oyi77
    Use when discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments. Use when working with bypassing authentication with forced browsing.
    10 repo stars
  29. ▌
    Conducting External Reconnaissance With Osint · oyi77
    Use when conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization's external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records, certificate transparency logs, search engines, social media, code repositories, and data breach databases to build a comprehensive target profile. Use when working with conducting external reconnaissance with osint.
    10 repo stars
  30. ▌
    Configuring Snort Ids For Intrusion Detection · oyi77
    Use when installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments. . Use when working with configuring snort ids for intrusion detection.
    10 repo stars
  31. ▌
    Configuring Tls 1 3 For Secure Communications · oyi77
    Use when tLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R. Use when working with configuring tls 1 3 for secure communications.
    10 repo stars
  32. ▌
    Detecting Evasion Techniques In Endpoint Logs · oyi77
    Use when detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
    10 repo stars
  33. ▌
    Detecting T1055 Process Injection With Sysmon · oyi77
    Use when detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns. Use when detecting process injection techniques (t1055) including classic dll injection, process.
    10 repo stars
  34. ▌
    Exploiting Ms17 010 Eternalblue Vulnerability · oyi77
    Use when mS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it. Use when working with exploiting ms17 010 eternalblue vulnerability.
    10 repo stars
  35. ▌
    Exploiting Template Injection Vulnerabilities · oyi77
    Use when detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. Use when working with exploiting template injection vulnerabilities.
    10 repo stars
  36. ▌
    Hardening Windows Endpoint With Cis Benchmark · oyi77
    Use when hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.
    10 repo stars
  37. ▌
    Hunting For Beaconing With Frequency Analysis · oyi77
    Use when identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints. Use when working with hunting for beaconing with frequency analysis.
    10 repo stars
  38. ▌
    Hunting For Persistence Mechanisms In Windows · oyi77
    Use when systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions. Use when working with hunting for persistence mechanisms in windows.
    10 repo stars
  39. ▌
    Hunting For Persistence Via Wmi Subscriptions · oyi77
    Use when hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events. Use when hunting for adversary persistence through windows management instrumentation event subscriptions.
    10 repo stars
  40. ▌
    Implementing API Rate Limiting And Throttling · oyi77
    Use when implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers.
    10 repo stars
  41. ▌
    Implementing Browser Isolation For Zero Trust · oyi77
    Use when deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention controls within isolated sessions, and integration with Secure Web Gateway and ZTNA platforms. Based on Cloudflare Browser Isolation, Menlo Security, and Zscaler RBI approaches.
    10 repo stars
  42. ▌
    Implementing Email Sandboxing With Proofpoint · oyi77
    Use when email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is an industry. Use when working with implementing email sandboxing with proofpoint.
    10 repo stars
  43. ▌
    Implementing Envelope Encryption With AWS Kms · oyi77
    Use when envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting. Use when working with implementing envelope encryption with aws kms.
    10 repo stars
  44. ▌
    Implementing Gdpr Data Subject Access Request · oyi77
    Use when automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
    10 repo stars
  45. ▌
    Implementing Honeytokens For Breach Detection · oyi77
    Use when deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection.
    10 repo stars
  46. ▌
    Implementing Just In Time Access Provisioning · oyi77
    Use when implementing Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access only when needed. This skill covers JIT architecture design, approval workflo
    10 repo stars
  47. ▌
    Implementing Network Deception With Honeypots · oyi77
    Use when deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance. Use when deploying and manage network honeypots using opencanary, t-pot, or cowrie.
    10 repo stars
  48. ▌
    Implementing Ransomware Kill Switch Detection · oyi77
    Use when detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection. '.
    10 repo stars
  49. ▌
    Implementing Security Monitoring With Datadog · oyi77
    Use when implementing security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring das...
    10 repo stars
  50. ▌
    Implementing Zero Trust For Saas Applications · oyi77
    Use when implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services. . Use when working with implementing zero trust for saas applications.
    10 repo stars
  51. ▌
    Integrating Sast Into Github Actions Pipeline · oyi77
    Use when this skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.
    10 repo stars
  52. ▌
    Performing Brand Monitoring For Impersonation · oyi77
    Use when monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization. Use when monitoring for brand impersonation attacks across domains, social media, mobile.
    10 repo stars
  53. ▌
    Performing Cloud Storage Forensic Acquisition · oyi77
    Use when perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices. Use when performing forensic acquisition and analysis of cloud storage services including.
    10 repo stars
  54. ▌
    Performing Cryptographic Audit Of Application · oyi77
    Use when a cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco. Use when working with performing cryptographic audit of application.
    10 repo stars
  55. ▌
    Performing Endpoint Vulnerability Remediation · oyi77
    Use when performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.
    10 repo stars
  56. ▌
    Performing Ip Reputation Analysis With Shodan · oyi77
    Use when analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage. Use when analyzeing ip address reputation using the shodan api to identify.
    10 repo stars
  57. ▌
    Performing Network Traffic Analysis With Zeek · oyi77
    Use when deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation. Use when deploying zeek network security monitor to capture, parse, and analyze.
    10 repo stars
  58. ▌
    Performing Open Source Intelligence Gathering · oyi77
    Use when open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s. Use when working with performing open source intelligence gathering.
    10 repo stars
  59. ▌
    Performing Timeline Reconstruction With Plaso · oyi77
    Use when build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view. Use when building comprehensive forensic super-timelines using plaso (log2timeline) to correlate events.
    10 repo stars
  60. ▌
    Performing Vulnerability Scanning With Nessus · oyi77
    Use when performing authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability dete...
    10 repo stars
  61. ▌
    Reverse Engineering Android Malware With Jadx · oyi77
    Use when reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis. '.
    10 repo stars
  62. ▌
    Reverse Engineering Dotnet Malware With Dnspy · oyi77
    Use when reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis. . Use when working with reverse engineering dotnet malware with dnspy.
    10 repo stars
  63. ▌
    Testing API For Mass Assignment Vulnerability · oyi77
    Use when tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization.
    10 repo stars
  64. ▌
    Analyzing Malware Behavior With Cuckoo Sandbox · oyi77
    Use when executing malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.
    10 repo stars
  65. ▌
    Analyzing Prefetch Files For Execution History · oyi77
    Use when parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation. Use when working with analyzing prefetch files for execution history.
    10 repo stars
  66. ▌
    Auditing Terraform Infrastructure For Security · oyi77
    Use when auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment. . Use when working with auditing terraform infrastructure for security.
    10 repo stars
  67. ▌
    Building Automated Malware Submission Pipeline · oyi77
    Use when builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.
    10 repo stars
  68. ▌
    Building Identity Governance Lifecycle Process · oyi77
    Use when builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design. . Use when working with building identity governance lifecycle process.
    10 repo stars
  69. ▌
    Building Red Team C2 Infrastructure With Havoc · oyi77
    Use when deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations. Use when deploying and configure the havoc c2 framework with teamserver, https.
    10 repo stars
  70. ▌
    Conducting Man In The Middle Attack Simulation · oyi77
    Use when simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities. . Use when working with conducting man in the middle attack simulation.
    10 repo stars
  71. ▌
    Conducting Social Engineering Penetration Test · oyi77
    Use when design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps. Use when designing and execute a social engineering penetration test including phishing,.
    10 repo stars
  72. ▌
    Configuring Certificate Authority With Openssl · oyi77
    Use when a Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
    10 repo stars
  73. ▌
    Configuring Windows Defender Advanced Settings · oyi77
    Use when configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint securit.
    10 repo stars
  74. ▌
    Deploying Decoy Files For Ransomware Detection · oyi77
    Use when deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption. '.
    10 repo stars
  75. ▌
    Detecting Network Scanning With Ids Signatures · oyi77
    Use when detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity. Use when detecting network reconnaissance and port scanning using suricata and snort.
    10 repo stars
  76. ▌
    Detecting Qr Code Phishing With Email Security · oyi77
    Use when detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails. Use when detecting and prevent qr code phishing (quishing) attacks that bypass.
    10 repo stars
  77. ▌
    Detecting Suspicious OAUTH Application Consent · oyi77
    Use when detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks. Use when detecting risky oauth application consent grants in azure ad /.
    10 repo stars
  78. ▌
    Exploiting Broken Function Level Authorization · oyi77
    Use when tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken Function Level Authorization.
    10 repo stars
  79. ▌
    Exploiting Smb Vulnerabilities With Metasploit · oyi77
    Use when identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks. . Use when working with exploiting smb vulnerabilities with metasploit.
    10 repo stars
  80. ▌
    Hunting For Lolbins Execution In Endpoint Logs · oyi77
    Use when hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when hunting for adversary abuse of living off the land binaries.
    10 repo stars
  81. ▌
    Implementing API Threat Protection With Apigee · oyi77
    Use when implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense. Use when implementing api threat protection using google apigee policies including json/xml.
    10 repo stars
  82. ▌
    Implementing AWS Macie For Data Classification · oyi77
    Use when implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection. Use when implementing amazon macie to automatically discover, classify, and protect sensitive.
    10 repo stars
  83. ▌
    Implementing Cloud Security Posture Management · oyi77
    Use when implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center. . Use when working with implementing cloud security posture management.
    10 repo stars
  84. ▌
    Implementing Dragos Platform For Ot Monitoring · oyi77
    Use when deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE. . Use when working with implementing dragos platform for ot monitoring.
    10 repo stars
  85. ▌
    Implementing Honeypot For Ransomware Detection · oyi77
    Use when deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Use when working with implementing honeypot for ransomware detection.
    10 repo stars
  86. ▌
    Implementing Kubernetes Pod Security Standards · oyi77
    Use when pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS. Use when working with implementing kubernetes pod security standards.
    10 repo stars
  87. ▌
    Implementing Microsegmentation With Guardicore · oyi77
    Use when implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud. . Use when working with implementing microsegmentation with guardicore.
    10 repo stars
  88. ▌
    Implementing Pod Security Admission Controller · oyi77
    Use when implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller. Use when implementing kubernetes pod security admission to enforce baseline and restricted.
    10 repo stars
  89. ▌
    Implementing Proofpoint Email Security Gateway · oyi77
    Use when deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes. Use when deploying and configure proofpoint email protection as a secure email.
    10 repo stars
  90. ▌
    Implementing Purdue Model Network Segmentation · oyi77
    Use when implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains. . Use when working with implementing purdue model network segmentation.
    10 repo stars
  91. ▌
    Implementing Threat Modeling With Mitre Attack · oyi77
    Use when implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.
    10 repo stars
  92. ▌
    Implementing Vulnerability Sla Breach Alerting · oyi77
    Use when building automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
    10 repo stars
  93. ▌
    Performing Access Recertification With Saviynt · oyi77
    Use when configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA. Use when configureing and execute access recertification campaigns in saviynt enterprise identity.
    10 repo stars
  94. ▌
    Performing Asset Criticality Scoring For Vulns · oyi77
    Use when develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance. Use when developing and apply a multi-factor asset criticality scoring model to.
    10 repo stars
  95. ▌
    Performing AWS Privilege Escalation Assessment · oyi77
    Use when performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques. . Use when working with performing aws privilege escalation assessment.
    10 repo stars
  96. ▌
    Performing Cloud Forensics With AWS Cloudtrail · oyi77
    Use when perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns. Use when performing forensic investigation of aws environments using cloudtrail logs to.
    10 repo stars
  97. ▌
    Performing Cloud Penetration Testing With Pacu · oyi77
    Use when performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation. . Use when working with performing cloud penetration testing with pacu.
    10 repo stars
  98. ▌
    Performing Cve Prioritization With Kev Catalog · oyi77
    Use when leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence. Use when working with performing cve prioritization with kev catalog.
    10 repo stars
  99. ▌
    Performing Kubernetes Etcd Security Assessment · oyi77
    Use when assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation. Use when working with performing kubernetes etcd security assessment.
    10 repo stars
  100. ▌
    Performing Post Quantum Cryptography Migration · oyi77
    Use when assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when working with performing post quantum cryptography migration.
    10 repo stars