oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Performing Power Grid Cybersecurity Assessment · oyi77Use when this skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and rel...
- ▌ Performing Serverless Function Security Review · oyi77Use when performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections. . Use when working with performing serverless function security review.
- ▌ Performing Service Account Credential Rotation · oyi77Use when automating credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
- ▌ Performing Web Application Scanning With Nikto · oyi77Use when nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve. Use when working with performing web application scanning with nikto.
- ▌ Performing Yara Rule Development For Detection · oyi77Use when develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives. Use when developing precise yara rules for malware detection by identifying unique.
- ▌ Prioritizing Vulnerabilities With Cvss Scoring · oyi77Use when the Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r. Use when working with prioritizing vulnerabilities with cvss scoring.
- ▌ Testing For Xss Vulnerabilities With Burpsuite · oyi77Use when identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments. Use when working with testing for xss vulnerabilities with burpsuite.
- ▌ Analyzing Certificate Transparency For Phishing · oyi77Use when monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization. Use when monitoring certificate transparency logs using crt.sh and certstream to detect.
- ▌ Analyzing Sbom For Supply Chain Vulnerabilities · oyi77Use when parsing Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculating risk scores, identifying transitive vulnerability paths, and generating compliance reports.
- ▌ Analyzing Slack Space And File System Artifacts · oyi77Use when examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes. Use when working with analyzing slack space and file system artifacts.
- ▌ Building Identity Federation With Saml Azure Ad · oyi77Use when establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications. Use when working with building identity federation with saml azure ad.
- ▌ Configuring Windows Event Logging For Detection · oyi77Use when configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
- ▌ Detecting Malicious Scheduled Tasks With Sysmon · oyi77Use when detecting malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.
- ▌ Implementing API Security Testing With 42crunch · oyi77Use when implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications. Use when implementing comprehensive api security testing using the 42crunch platform to.
- ▌ Implementing Attack Path Analysis With Xm Cyber · oyi77Use when deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets. Use when deploying xm cyber's continuous exposure management platform to map attack.
- ▌ Implementing Beyondcorp Zero Trust Access Model · oyi77Use when implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access. . Use when working with implementing beyondcorp zero trust access model.
- ▌ Implementing Google Workspace Sso Configuration · oyi77Use when configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies. Use when configureing saml 2.0 single sign-on for google workspace with a.
- ▌ Implementing Identity Governance With Sailpoint · oyi77Use when deploying SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
- ▌ Implementing Soar Playbook With Palo Alto Xsoar · oyi77Use when implementing automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
- ▌ Implementing Supply Chain Security With In Toto · oyi77Use when implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps. Use when implementing software supply chain integrity verification for container builds using.
- ▌ Implementing Syslog Centralization With Rsyslog · oyi77Use when configuring rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
- ▌ Implementing Zero Trust With Hashicorp Boundary · oyi77Use when implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration. Use when implementing hashicorp boundary for identity-aware zero trust infrastructure access management.
- ▌ Performing Active Directory Bloodhound Analysis · oyi77Use when use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin. Use when working with performing active directory bloodhound analysis.
- ▌ Performing Active Directory Forest Trust Attack · oyi77Use when enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment. Use when working with performing active directory forest trust attack.
- ▌ Performing Automated Malware Analysis With Cape · oyi77Use when deploying and operating CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
- ▌ Performing GCP Security Assessment With Forseti · oyi77Use when performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark. . Use when working with performing gcp security assessment with forseti.
- ▌ Performing Hardware Security Module Integration · oyi77Use when integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2. Use when integrateing hardware security modules (hsms) using pkcs#11 interface for cryptographic.
- ▌ Performing Network Traffic Analysis With Tshark · oyi77Use when automating network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
- ▌ Performing Ssl Certificate Lifecycle Management · oyi77Use when sSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading. Use when working with performing ssl certificate lifecycle management.
- ▌ Performing Subdomain Enumeration With Subfinder · oyi77Use when enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments. Use when working with performing subdomain enumeration with subfinder.
- ▌ Performing Web Application Vulnerability Triage · oyi77Use when triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation. Use when working with performing web application vulnerability triage.
- ▌ Performing Wifi Password Cracking With Aircrack · oyi77Use when captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture. . Use when working with performing wifi password cracking with aircrack.
- ▌ Building Attack Pattern Library From Cti Reports · oyi77Use when extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense. Use when working with building attack pattern library from cti reports.
- ▌ Building C2 Infrastructure With Sliver Framework · oyi77Use when build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements. Use when building and configure a resilient command-and-control infrastructure using bishopfox's sliver.
- ▌ Building Malware Incident Communication Template · oyi77Use when build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures. Use when building structured communication templates for malware incidents including stakeholder notifications,.
- ▌ Building Ransomware Playbook With Cisa Framework · oyi77Use when building a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
- ▌ Building Vulnerability Dashboard With Defectdojo · oyi77Use when deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows. Use when deploying defectdojo as a centralized vulnerability management dashboard with scanner.
- ▌ Building Vulnerability Exception Tracking System · oyi77Use when build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management. Use when building a vulnerability exception and risk acceptance tracking system with.
- ▌ Configuring Identity Aware Proxy With Google Iap · oyi77Use when configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts. . Use when working with configuring identity aware proxy with google iap.
- ▌ Configuring Multi Factor Authentication With Duo · oyi77Use when deploying Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
- ▌ Detecting Golden Ticket Attacks In Kerberos Logs · oyi77Use when detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs. Use when detecting golden ticket attacks in active directory by analyzing kerberos.
- ▌ Exploiting Zerologon Vulnerability Cve 2020 1472 · oyi77Use when exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty. Use when exploiting the zerologon vulnerability (cve-2020-1472) in the netlogon remote protocol.
- ▌ Implementing Canary Tokens For Network Intrusion · oyi77Use when deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.
- ▌ Implementing End To End Encryption For Messaging · oyi77Use when end-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version. Use when working with implementing end to end encryption for messaging.
- ▌ Implementing File Integrity Monitoring With Aide · oyi77Use when configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting. Use when configureing aide (advanced intrusion detection environment) for file integrity monitoring.
- ▌ Implementing GCP Organization Policy Constraints · oyi77Use when implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across.
- ▌ Implementing Mimecast Targeted Attack Protection · oyi77Use when deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks. Use when deploying mimecast targeted threat protection including url protect, attachment protect,.
- ▌ Implementing Runtime Application Self Protection · oyi77Use when deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications. Use when deploying runtime application self-protection (rasp) agents to detect and block.
- ▌ Performing Cloud Incident Containment Procedures · oyi77Use when execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement. Use when working with performing cloud incident containment procedures.
- ▌ Performing Entitlement Review With Sailpoint Iiq · oyi77Use when performing entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates for requests involving access reviews, entitlement certifications, SailPoint IIQ governance, or periodic user access recertification.
- ▌ Performing Mobile App Certificate Pinning Bypass · oyi77Use when bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.
- ▌ Performing Paste Site Monitoring For Credentials · oyi77Use when monitoring paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
- ▌ Performing Threat Emulation With Atomic Red Team · oyi77Use when executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises.
- ▌ Performing Threat Intelligence Sharing With Misp · oyi77Use when use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows. Use when working with performing threat intelligence sharing with misp.
- ▌ Analyzing Ethereum Smart Contract Vulnerabilities · oyi77Use when perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet. Use when performing static and symbolic analysis of solidity smart contracts using.
- ▌ Building Adversary Infrastructure Tracking System · oyi77Use when building an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
- ▌ Building Threat Intelligence Enrichment In Splunk · oyi77Use when building automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
- ▌ Detecting Anomalies In Industrial Control Systems · oyi77Use when this skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
- ▌ Detecting AWS Credential Exposure With Trufflehog · oyi77Use when detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access. . Use when working with detecting aws credential exposure with trufflehog.
- ▌ Detecting Azure Storage Account Misconfigurations · oyi77Use when audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK. Use when auditing azure blob and adls storage accounts for public access.
- ▌ Detecting Privilege Escalation In Kubernetes Pods · oyi77Use when detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies. Use when detecting and prevent privilege escalation in kubernetes pods by monitoring.
- ▌ Detecting T1548 Abuse Elevation Control Mechanism · oyi77Use when detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships. Use when detecting abuse of elevation control mechanisms including uac bypass, sudo.
- ▌ Implementing Aqua Security For Container Scanning · oyi77Use when deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries. Use when deploying aqua security's trivy scanner to detect vulnerabilities, misconfigurations, secrets,.
- ▌ Implementing Conditional Access Policies Azure Ad · oyi77Use when configuring Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l
- ▌ Implementing Google Workspace Phishing Protection · oyi77Use when configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing. Use when configureing google workspace advanced phishing and malware protection settings including.
- ▌ Implementing Hardware Security Key Authentication · oyi77Use when implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Use when working with implementing hardware security key authentication.
- ▌ Implementing Identity Verification For Zero Trust · oyi77Use when implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model. Use when implementing continuous identity verification for zero trust using phishing-resistant mfa.
- ▌ Implementing Network Traffic Analysis With Arkime · oyi77Use when deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across captured traffic. Use when deploying and query arkime (formerly moloch) for full packet capture.
- ▌ Performing Android App Static Analysis With Mobsf · oyi77Use when performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application. Use when assessing Android APK/AAB files for security vulnerabilities before deployment, during penetration testing, or as part of CI/CD security gates.
- ▌ Performing Bandwidth Throttling Attack Simulation · oyi77Use when simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks. . Use when working with performing bandwidth throttling attack simulation.
- ▌ Performing Cloud Asset Inventory With Cartography · oyi77Use when perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure. Use when performing comprehensive cloud asset inventory and relationship mapping using cartography.
- ▌ Performing Container Security Scanning With Trivy · oyi77Use when scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration. Use when scaning container images, filesystems, and kubernetes manifests for vulnerabilities, misconfigurations,.
- ▌ Performing Static Malware Analysis With Pe Studio · oyi77Use when performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage. '.
- ▌ Performing Threat Landscape Assessment For Sector · oyi77Use when conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management. Use when conducting a sector-specific threat landscape assessment by analyzing threat actor.
- ▌ Evaluating Threat Intelligence Platforms · oyi77Use when evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
- ▌ Exploiting API Injection Vulnerabilities · oyi77Use when tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:2023 Security Misconfiguration and API7:2023 SSRF.
- ▌ Exploiting Bgp Hijacking Vulnerabilities · oyi77Use when analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure. . Use when working with exploiting bgp hijacking vulnerabilities.
- ▌ Exploiting SQL Injection Vulnerabilities · oyi77Use when identifying and exploiting SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution.
- ▌ Exploiting Type Juggling Vulnerabilities · oyi77Use when exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks. Use when exploiting php type juggling vulnerabilities caused by loose comparison operators.
- ▌ Hunting For Data Exfiltration Indicators · oyi77Use when hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse. Use when hunting for data exfiltration through network traffic analysis, detecting unusual.
- ▌ Implementing AWS Security Hub Compliance · oyi77Use when implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
- ▌ Implementing Devsecops Security Scanning · oyi77Use when integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation.
- ▌ Implementing LLM Guardrails For Security · oyi77Use when implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang definitions, custom Python validators for PII detection and content policy enforcement, and the Guardrails AI framework for structured output validation. Use when working with implementing llm guardrails for security.
- ▌ Implementing Log Forwarding With Fluentd · oyi77Use when configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure. Use when configureing fluentd and fluent bit for centralized log aggregation, routing,.
- ▌ Implementing Network Segmentation For Ot · oyi77Use when this skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentation strategy, migration from flat networks to segmented architectures without disrupting operations, configuring OT-aware firewalls with industrial protocol deep packet inspection, and validating segmentation effectiveness through traffic analysis.
- ▌ Implementing Pci Dss Compliance Controls · oyi77Use when pCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements. Use when working with implementing pci dss compliance controls.
- ▌ Implementing Scim Provisioning With Okta · oyi77Use when implementing automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
- ▌ Implementing Stix Taxii Feed Integration · oyi77Use when STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.
- ▌ Implementing Taxii Server With Opentaxii · oyi77Use when deploying and configuring an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
- ▌ Implementing Zero Trust Dns With Nextdns · oyi77Use when implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints. Use when implementing nextdns as a zero trust dns filtering layer with.
- ▌ Performing Bluetooth Security Assessment · oyi77Use when assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities. Use when working with performing bluetooth security assessment.
- ▌ Performing Cloud Forensics Investigation · oyi77Use when conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services. Use when conducting forensic investigations in cloud environments by collecting and analyzing.
- ▌ Performing Dynamic Analysis With Any Run · oyi77Use when performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage. . Use when working with performing dynamic analysis with any run.
- ▌ Performing Initial Access With Evilginx3 · oyi77Use when perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements. Use when performing authorized initial access using evilginx3 adversary-in-the-middle phishing framework to.
- ▌ Performing Lateral Movement With Wmiexec · oyi77Use when perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements. Use when performing lateral movement across windows networks using wmi-based remote execution.
- ▌ Performing Log Source Onboarding In Siem · oyi77Use when perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility. Use when performing structured log source onboarding into siem platforms by configuring.
- ▌ Performing Physical Intrusion Assessment · oyi77Use when conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls. Use when conducting authorized physical penetration testing using tailgating, badge cloning, lock.
- ▌ Performing Privilege Escalation On Linux · oyi77Use when linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised system. Red teams exploit misconfigurations, vulnerable services, kernel exploits, and w. Use when working with performing privilege escalation on linux.
- ▌ Performing Scada Hmi Security Assessment · oyi77Use when perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines. . Use when working with performing scada hmi security assessment.
- ▌ Securing Remote Access To Ot Environment · oyi77Use when this skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements.