oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Implementing Ddos Mitigation With Cloudflare · oyi77Use when configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks. Use when configureing cloudflare ddos protection with managed rulesets, rate limiting, waf.
- ▌ Implementing Digital Signatures With Ed25519 · oyi77Use when ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove. Use when working with implementing digital signatures with ed25519.
- ▌ Implementing Google Workspace Admin Security · oyi77Use when implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration. . Use when working with implementing google workspace admin security.
- ▌ Implementing Hashicorp Vault Dynamic Secrets · oyi77Use when implementing HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation.
- ▌ Implementing Memory Protection With Dep Aslr · oyi77Use when implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks. Use when hardening endpoints against buffer overflow exploits, ROP chains, and code injection. Activates for requests involving memory protection, exploit mitigation, DEP, ASLR, or CFG configuration.
- ▌ Implementing Network Policies For Kubernetes · oyi77Use when kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu. Use when working with implementing network policies for kubernetes.
- ▌ Implementing Patch Management For Ot Systems · oyi77Use when this skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization, staged deployment through test environments, maintenance window coordination, rollback procedures, and compensating controls when patches cannot be applied due to operational constraints or vendor restrictions.
- ▌ Performing Active Directory Penetration Test · oyi77Use when conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise. Use when conducting a focused active directory penetration test to enumerate domain.
- ▌ Performing API Security Testing With Postman · oyi77Use when using Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writing test scripts for automated security validation, and integrating Postman with OWASP ZAP and Newman for CI/CD security testing.
- ▌ Performing Cloud Native Forensics With Falco · oyi77Use when uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
- ▌ Performing Dns Enumeration And Zone Transfer · oyi77Use when enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains. . Use when working with performing dns enumeration and zone transfer.
- ▌ Performing External Network Penetration Test · oyi77Use when conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting. Use when conducting a comprehensive external network penetration test to identify vulnerabilities.
- ▌ Performing Linux Log Forensics Investigation · oyi77Use when perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised Linux systems. Use when performing forensic investigation of linux system logs including syslog, auth.log,.
- ▌ Performing Malware Persistence Investigation · oyi77Use when systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access. Use when working with performing malware persistence investigation.
- ▌ Performing S7comm Protocol Security Analysis · oyi77Use when perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers. . Use when working with performing s7comm protocol security analysis.
- ▌ Performing Sca Dependency Scanning With Snyk · oyi77Use when this skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
- ▌ Performing Soap Web Service Security Testing · oyi77Use when perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing. Use when performing security testing of soap web services by analyzing wsdl.
- ▌ Performing Wireless Network Penetration Test · oyi77Use when execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools. Use when working with performing wireless network penetration test.
- ▌ Triaging Vulnerabilities With Ssvc Framework · oyi77Use when triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities. Use when working with triaging vulnerabilities with ssvc framework.
- ▌ Hunting For Cobalt Strike Beacons · oyi77Use when detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis. Use when detecting cobalt strike beacon network activity using default tls certificate.
- ▌ Analyzing Office365 Audit Logs For Compromise · oyi77Use when parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise. Use when working with analyzing office365 audit logs for compromise.
- ▌ Analyzing Threat Actor Ttps With Mitre Attack · oyi77Use when MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
- ▌ Analyzing Typosquatting Domains With Dnstwist · oyi77Use when detecting typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
- ▌ Auditing Azure Active Directory Configuration · oyi77Use when auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite. . Use when working with auditing azure active directory configuration.
- ▌ Building Ioc Enrichment Pipeline With Opencti · oyi77Use when openCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O
- ▌ Building Threat Intelligence Feed Integration · oyi77Use when builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
- ▌ Building Vulnerability Aging And Sla Tracking · oyi77Use when implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability. Use when implementing a vulnerability aging dashboard and sla tracking system to.
- ▌ Bypassing Authentication With Forced Browsing · oyi77Use when discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments. Use when working with bypassing authentication with forced browsing.
- ▌ Conducting External Reconnaissance With Osint · oyi77Use when conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization's external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records, certificate transparency logs, search engines, social media, code repositories, and data breach databases to build a comprehensive target profile. Use when working with conducting external reconnaissance with osint.
- ▌ Configuring Snort Ids For Intrusion Detection · oyi77Use when installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments. . Use when working with configuring snort ids for intrusion detection.
- ▌ Configuring Tls 1 3 For Secure Communications · oyi77Use when tLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R. Use when working with configuring tls 1 3 for secure communications.
- ▌ Detecting Evasion Techniques In Endpoint Logs · oyi77Use when detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
- ▌ Detecting T1055 Process Injection With Sysmon · oyi77Use when detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns. Use when detecting process injection techniques (t1055) including classic dll injection, process.
- ▌ Exploiting Ms17 010 Eternalblue Vulnerability · oyi77Use when mS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it. Use when working with exploiting ms17 010 eternalblue vulnerability.
- ▌ Exploiting Template Injection Vulnerabilities · oyi77Use when detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. Use when working with exploiting template injection vulnerabilities.
- ▌ Hardening Windows Endpoint With Cis Benchmark · oyi77Use when hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.
- ▌ Hunting For Beaconing With Frequency Analysis · oyi77Use when identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints. Use when working with hunting for beaconing with frequency analysis.
- ▌ Hunting For Persistence Mechanisms In Windows · oyi77Use when systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions. Use when working with hunting for persistence mechanisms in windows.
- ▌ Hunting For Persistence Via Wmi Subscriptions · oyi77Use when hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events. Use when hunting for adversary persistence through windows management instrumentation event subscriptions.
- ▌ Implementing API Rate Limiting And Throttling · oyi77Use when implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers.
- ▌ Implementing Browser Isolation For Zero Trust · oyi77Use when deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention controls within isolated sessions, and integration with Secure Web Gateway and ZTNA platforms. Based on Cloudflare Browser Isolation, Menlo Security, and Zscaler RBI approaches.
- ▌ Implementing Email Sandboxing With Proofpoint · oyi77Use when email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is an industry. Use when working with implementing email sandboxing with proofpoint.
- ▌ Implementing Envelope Encryption With AWS Kms · oyi77Use when envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting. Use when working with implementing envelope encryption with aws kms.
- ▌ Implementing Gdpr Data Subject Access Request · oyi77Use when automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
- ▌ Implementing Honeytokens For Breach Detection · oyi77Use when deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection.
- ▌ Implementing Just In Time Access Provisioning · oyi77Use when implementing Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access only when needed. This skill covers JIT architecture design, approval workflo
- ▌ Implementing Network Deception With Honeypots · oyi77Use when deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance. Use when deploying and manage network honeypots using opencanary, t-pot, or cowrie.
- ▌ Implementing Ransomware Kill Switch Detection · oyi77Use when detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection. '.
- ▌ Implementing Security Monitoring With Datadog · oyi77Use when implementing security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring das...
- ▌ Implementing Zero Trust For Saas Applications · oyi77Use when implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services. . Use when working with implementing zero trust for saas applications.
- ▌ Integrating Sast Into Github Actions Pipeline · oyi77Use when this skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.
- ▌ Performing Brand Monitoring For Impersonation · oyi77Use when monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization. Use when monitoring for brand impersonation attacks across domains, social media, mobile.
- ▌ Performing Cloud Storage Forensic Acquisition · oyi77Use when perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices. Use when performing forensic acquisition and analysis of cloud storage services including.
- ▌ Performing Cryptographic Audit Of Application · oyi77Use when a cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco. Use when working with performing cryptographic audit of application.
- ▌ Performing Endpoint Vulnerability Remediation · oyi77Use when performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.
- ▌ Performing Ip Reputation Analysis With Shodan · oyi77Use when analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage. Use when analyzeing ip address reputation using the shodan api to identify.
- ▌ Performing Network Traffic Analysis With Zeek · oyi77Use when deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation. Use when deploying zeek network security monitor to capture, parse, and analyze.
- ▌ Performing Open Source Intelligence Gathering · oyi77Use when open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s. Use when working with performing open source intelligence gathering.
- ▌ Performing Timeline Reconstruction With Plaso · oyi77Use when build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view. Use when building comprehensive forensic super-timelines using plaso (log2timeline) to correlate events.
- ▌ Performing Vulnerability Scanning With Nessus · oyi77Use when performing authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability dete...
- ▌ Reverse Engineering Android Malware With Jadx · oyi77Use when reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis. '.
- ▌ Reverse Engineering Dotnet Malware With Dnspy · oyi77Use when reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis. . Use when working with reverse engineering dotnet malware with dnspy.
- ▌ Testing API For Mass Assignment Vulnerability · oyi77Use when tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization.
- ▌ Analyzing Malware Behavior With Cuckoo Sandbox · oyi77Use when executing malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.
- ▌ Analyzing Prefetch Files For Execution History · oyi77Use when parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation. Use when working with analyzing prefetch files for execution history.
- ▌ Auditing Terraform Infrastructure For Security · oyi77Use when auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment. . Use when working with auditing terraform infrastructure for security.
- ▌ Building Automated Malware Submission Pipeline · oyi77Use when builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.
- ▌ Building Identity Governance Lifecycle Process · oyi77Use when builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design. . Use when working with building identity governance lifecycle process.
- ▌ Building Red Team C2 Infrastructure With Havoc · oyi77Use when deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations. Use when deploying and configure the havoc c2 framework with teamserver, https.
- ▌ Conducting Man In The Middle Attack Simulation · oyi77Use when simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities. . Use when working with conducting man in the middle attack simulation.
- ▌ Conducting Social Engineering Penetration Test · oyi77Use when design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps. Use when designing and execute a social engineering penetration test including phishing,.
- ▌ Configuring Certificate Authority With Openssl · oyi77Use when a Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
- ▌ Configuring Windows Defender Advanced Settings · oyi77Use when configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint securit.
- ▌ Deploying Decoy Files For Ransomware Detection · oyi77Use when deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption. '.
- ▌ Detecting Network Scanning With Ids Signatures · oyi77Use when detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity. Use when detecting network reconnaissance and port scanning using suricata and snort.
- ▌ Detecting Qr Code Phishing With Email Security · oyi77Use when detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails. Use when detecting and prevent qr code phishing (quishing) attacks that bypass.
- ▌ Detecting Suspicious OAUTH Application Consent · oyi77Use when detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks. Use when detecting risky oauth application consent grants in azure ad /.
- ▌ Exploiting Broken Function Level Authorization · oyi77Use when tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken Function Level Authorization.
- ▌ Exploiting Smb Vulnerabilities With Metasploit · oyi77Use when identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks. . Use when working with exploiting smb vulnerabilities with metasploit.
- ▌ Hunting For Lolbins Execution In Endpoint Logs · oyi77Use when hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when hunting for adversary abuse of living off the land binaries.
- ▌ Implementing API Threat Protection With Apigee · oyi77Use when implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense. Use when implementing api threat protection using google apigee policies including json/xml.
- ▌ Implementing AWS Macie For Data Classification · oyi77Use when implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection. Use when implementing amazon macie to automatically discover, classify, and protect sensitive.
- ▌ Implementing Cloud Security Posture Management · oyi77Use when implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center. . Use when working with implementing cloud security posture management.
- ▌ Implementing Dragos Platform For Ot Monitoring · oyi77Use when deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE. . Use when working with implementing dragos platform for ot monitoring.
- ▌ Implementing Honeypot For Ransomware Detection · oyi77Use when deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Use when working with implementing honeypot for ransomware detection.
- ▌ Implementing Kubernetes Pod Security Standards · oyi77Use when pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS. Use when working with implementing kubernetes pod security standards.
- ▌ Implementing Microsegmentation With Guardicore · oyi77Use when implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud. . Use when working with implementing microsegmentation with guardicore.
- ▌ Implementing Pod Security Admission Controller · oyi77Use when implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller. Use when implementing kubernetes pod security admission to enforce baseline and restricted.
- ▌ Implementing Proofpoint Email Security Gateway · oyi77Use when deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes. Use when deploying and configure proofpoint email protection as a secure email.
- ▌ Implementing Purdue Model Network Segmentation · oyi77Use when implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains. . Use when working with implementing purdue model network segmentation.
- ▌ Implementing Threat Modeling With Mitre Attack · oyi77Use when implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.
- ▌ Implementing Vulnerability Sla Breach Alerting · oyi77Use when building automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
- ▌ Performing Access Recertification With Saviynt · oyi77Use when configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA. Use when configureing and execute access recertification campaigns in saviynt enterprise identity.
- ▌ Performing Asset Criticality Scoring For Vulns · oyi77Use when develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance. Use when developing and apply a multi-factor asset criticality scoring model to.
- ▌ Performing AWS Privilege Escalation Assessment · oyi77Use when performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques. . Use when working with performing aws privilege escalation assessment.
- ▌ Performing Cloud Forensics With AWS Cloudtrail · oyi77Use when perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns. Use when performing forensic investigation of aws environments using cloudtrail logs to.
- ▌ Performing Cloud Penetration Testing With Pacu · oyi77Use when performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation. . Use when working with performing cloud penetration testing with pacu.
- ▌ Performing Cve Prioritization With Kev Catalog · oyi77Use when leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence. Use when working with performing cve prioritization with kev catalog.
- ▌ Performing Kubernetes Etcd Security Assessment · oyi77Use when assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation. Use when working with performing kubernetes etcd security assessment.
- ▌ Performing Post Quantum Cryptography Migration · oyi77Use when assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when working with performing post quantum cryptography migration.