all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 3 of 13

  1. ▌
    Performing Power Grid Cybersecurity Assessment · oyi77
    Use when this skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and rel...
    10 repo stars
  2. ▌
    Performing Serverless Function Security Review · oyi77
    Use when performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections. . Use when working with performing serverless function security review.
    10 repo stars
  3. ▌
    Performing Service Account Credential Rotation · oyi77
    Use when automating credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
    10 repo stars
  4. ▌
    Performing Web Application Scanning With Nikto · oyi77
    Use when nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve. Use when working with performing web application scanning with nikto.
    10 repo stars
  5. ▌
    Performing Yara Rule Development For Detection · oyi77
    Use when develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives. Use when developing precise yara rules for malware detection by identifying unique.
    10 repo stars
  6. ▌
    Prioritizing Vulnerabilities With Cvss Scoring · oyi77
    Use when the Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r. Use when working with prioritizing vulnerabilities with cvss scoring.
    10 repo stars
  7. ▌
    Testing For Xss Vulnerabilities With Burpsuite · oyi77
    Use when identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments. Use when working with testing for xss vulnerabilities with burpsuite.
    10 repo stars
  8. ▌
    Analyzing Certificate Transparency For Phishing · oyi77
    Use when monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization. Use when monitoring certificate transparency logs using crt.sh and certstream to detect.
    10 repo stars
  9. ▌
    Analyzing Sbom For Supply Chain Vulnerabilities · oyi77
    Use when parsing Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculating risk scores, identifying transitive vulnerability paths, and generating compliance reports.
    10 repo stars
  10. ▌
    Analyzing Slack Space And File System Artifacts · oyi77
    Use when examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes. Use when working with analyzing slack space and file system artifacts.
    10 repo stars
  11. ▌
    Building Identity Federation With Saml Azure Ad · oyi77
    Use when establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications. Use when working with building identity federation with saml azure ad.
    10 repo stars
  12. ▌
    Configuring Windows Event Logging For Detection · oyi77
    Use when configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
    10 repo stars
  13. ▌
    Detecting Malicious Scheduled Tasks With Sysmon · oyi77
    Use when detecting malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.
    10 repo stars
  14. ▌
    Implementing API Security Testing With 42crunch · oyi77
    Use when implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications. Use when implementing comprehensive api security testing using the 42crunch platform to.
    10 repo stars
  15. ▌
    Implementing Attack Path Analysis With Xm Cyber · oyi77
    Use when deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets. Use when deploying xm cyber's continuous exposure management platform to map attack.
    10 repo stars
  16. ▌
    Implementing Beyondcorp Zero Trust Access Model · oyi77
    Use when implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access. . Use when working with implementing beyondcorp zero trust access model.
    10 repo stars
  17. ▌
    Implementing Google Workspace Sso Configuration · oyi77
    Use when configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies. Use when configureing saml 2.0 single sign-on for google workspace with a.
    10 repo stars
  18. ▌
    Implementing Identity Governance With Sailpoint · oyi77
    Use when deploying SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
    10 repo stars
  19. ▌
    Implementing Soar Playbook With Palo Alto Xsoar · oyi77
    Use when implementing automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
    10 repo stars
  20. ▌
    Implementing Supply Chain Security With In Toto · oyi77
    Use when implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps. Use when implementing software supply chain integrity verification for container builds using.
    10 repo stars
  21. ▌
    Implementing Syslog Centralization With Rsyslog · oyi77
    Use when configuring rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
    10 repo stars
  22. ▌
    Implementing Zero Trust With Hashicorp Boundary · oyi77
    Use when implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration. Use when implementing hashicorp boundary for identity-aware zero trust infrastructure access management.
    10 repo stars
  23. ▌
    Performing Active Directory Bloodhound Analysis · oyi77
    Use when use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin. Use when working with performing active directory bloodhound analysis.
    10 repo stars
  24. ▌
    Performing Active Directory Forest Trust Attack · oyi77
    Use when enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment. Use when working with performing active directory forest trust attack.
    10 repo stars
  25. ▌
    Performing Automated Malware Analysis With Cape · oyi77
    Use when deploying and operating CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
    10 repo stars
  26. ▌
    Performing GCP Security Assessment With Forseti · oyi77
    Use when performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark. . Use when working with performing gcp security assessment with forseti.
    10 repo stars
  27. ▌
    Performing Hardware Security Module Integration · oyi77
    Use when integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2. Use when integrateing hardware security modules (hsms) using pkcs#11 interface for cryptographic.
    10 repo stars
  28. ▌
    Performing Network Traffic Analysis With Tshark · oyi77
    Use when automating network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
    10 repo stars
  29. ▌
    Performing Ssl Certificate Lifecycle Management · oyi77
    Use when sSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading. Use when working with performing ssl certificate lifecycle management.
    10 repo stars
  30. ▌
    Performing Subdomain Enumeration With Subfinder · oyi77
    Use when enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments. Use when working with performing subdomain enumeration with subfinder.
    10 repo stars
  31. ▌
    Performing Web Application Vulnerability Triage · oyi77
    Use when triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation. Use when working with performing web application vulnerability triage.
    10 repo stars
  32. ▌
    Performing Wifi Password Cracking With Aircrack · oyi77
    Use when captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture. . Use when working with performing wifi password cracking with aircrack.
    10 repo stars
  33. ▌
    Building Attack Pattern Library From Cti Reports · oyi77
    Use when extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense. Use when working with building attack pattern library from cti reports.
    10 repo stars
  34. ▌
    Building C2 Infrastructure With Sliver Framework · oyi77
    Use when build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements. Use when building and configure a resilient command-and-control infrastructure using bishopfox's sliver.
    10 repo stars
  35. ▌
    Building Malware Incident Communication Template · oyi77
    Use when build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures. Use when building structured communication templates for malware incidents including stakeholder notifications,.
    10 repo stars
  36. ▌
    Building Ransomware Playbook With Cisa Framework · oyi77
    Use when building a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
    10 repo stars
  37. ▌
    Building Vulnerability Dashboard With Defectdojo · oyi77
    Use when deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows. Use when deploying defectdojo as a centralized vulnerability management dashboard with scanner.
    10 repo stars
  38. ▌
    Building Vulnerability Exception Tracking System · oyi77
    Use when build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management. Use when building a vulnerability exception and risk acceptance tracking system with.
    10 repo stars
  39. ▌
    Configuring Identity Aware Proxy With Google Iap · oyi77
    Use when configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts. . Use when working with configuring identity aware proxy with google iap.
    10 repo stars
  40. ▌
    Configuring Multi Factor Authentication With Duo · oyi77
    Use when deploying Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
    10 repo stars
  41. ▌
    Detecting Golden Ticket Attacks In Kerberos Logs · oyi77
    Use when detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs. Use when detecting golden ticket attacks in active directory by analyzing kerberos.
    10 repo stars
  42. ▌
    Exploiting Zerologon Vulnerability Cve 2020 1472 · oyi77
    Use when exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty. Use when exploiting the zerologon vulnerability (cve-2020-1472) in the netlogon remote protocol.
    10 repo stars
  43. ▌
    Implementing Canary Tokens For Network Intrusion · oyi77
    Use when deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.
    10 repo stars
  44. ▌
    Implementing End To End Encryption For Messaging · oyi77
    Use when end-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version. Use when working with implementing end to end encryption for messaging.
    10 repo stars
  45. ▌
    Implementing File Integrity Monitoring With Aide · oyi77
    Use when configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting. Use when configureing aide (advanced intrusion detection environment) for file integrity monitoring.
    10 repo stars
  46. ▌
    Implementing GCP Organization Policy Constraints · oyi77
    Use when implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across.
    10 repo stars
  47. ▌
    Implementing Mimecast Targeted Attack Protection · oyi77
    Use when deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks. Use when deploying mimecast targeted threat protection including url protect, attachment protect,.
    10 repo stars
  48. ▌
    Implementing Runtime Application Self Protection · oyi77
    Use when deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications. Use when deploying runtime application self-protection (rasp) agents to detect and block.
    10 repo stars
  49. ▌
    Performing Cloud Incident Containment Procedures · oyi77
    Use when execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement. Use when working with performing cloud incident containment procedures.
    10 repo stars
  50. ▌
    Performing Entitlement Review With Sailpoint Iiq · oyi77
    Use when performing entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates for requests involving access reviews, entitlement certifications, SailPoint IIQ governance, or periodic user access recertification.
    10 repo stars
  51. ▌
    Performing Mobile App Certificate Pinning Bypass · oyi77
    Use when bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.
    10 repo stars
  52. ▌
    Performing Paste Site Monitoring For Credentials · oyi77
    Use when monitoring paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
    10 repo stars
  53. ▌
    Performing Threat Emulation With Atomic Red Team · oyi77
    Use when executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises.
    10 repo stars
  54. ▌
    Performing Threat Intelligence Sharing With Misp · oyi77
    Use when use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows. Use when working with performing threat intelligence sharing with misp.
    10 repo stars
  55. ▌
    Analyzing Ethereum Smart Contract Vulnerabilities · oyi77
    Use when perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet. Use when performing static and symbolic analysis of solidity smart contracts using.
    10 repo stars
  56. ▌
    Building Adversary Infrastructure Tracking System · oyi77
    Use when building an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
    10 repo stars
  57. ▌
    Building Threat Intelligence Enrichment In Splunk · oyi77
    Use when building automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
    10 repo stars
  58. ▌
    Detecting Anomalies In Industrial Control Systems · oyi77
    Use when this skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
    10 repo stars
  59. ▌
    Detecting AWS Credential Exposure With Trufflehog · oyi77
    Use when detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access. . Use when working with detecting aws credential exposure with trufflehog.
    10 repo stars
  60. ▌
    Detecting Azure Storage Account Misconfigurations · oyi77
    Use when audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK. Use when auditing azure blob and adls storage accounts for public access.
    10 repo stars
  61. ▌
    Detecting Privilege Escalation In Kubernetes Pods · oyi77
    Use when detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies. Use when detecting and prevent privilege escalation in kubernetes pods by monitoring.
    10 repo stars
  62. ▌
    Detecting T1548 Abuse Elevation Control Mechanism · oyi77
    Use when detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships. Use when detecting abuse of elevation control mechanisms including uac bypass, sudo.
    10 repo stars
  63. ▌
    Implementing Aqua Security For Container Scanning · oyi77
    Use when deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries. Use when deploying aqua security's trivy scanner to detect vulnerabilities, misconfigurations, secrets,.
    10 repo stars
  64. ▌
    Implementing Conditional Access Policies Azure Ad · oyi77
    Use when configuring Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l
    10 repo stars
  65. ▌
    Implementing Google Workspace Phishing Protection · oyi77
    Use when configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing. Use when configureing google workspace advanced phishing and malware protection settings including.
    10 repo stars
  66. ▌
    Implementing Hardware Security Key Authentication · oyi77
    Use when implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Use when working with implementing hardware security key authentication.
    10 repo stars
  67. ▌
    Implementing Identity Verification For Zero Trust · oyi77
    Use when implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model. Use when implementing continuous identity verification for zero trust using phishing-resistant mfa.
    10 repo stars
  68. ▌
    Implementing Network Traffic Analysis With Arkime · oyi77
    Use when deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across captured traffic. Use when deploying and query arkime (formerly moloch) for full packet capture.
    10 repo stars
  69. ▌
    Performing Android App Static Analysis With Mobsf · oyi77
    Use when performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application. Use when assessing Android APK/AAB files for security vulnerabilities before deployment, during penetration testing, or as part of CI/CD security gates.
    10 repo stars
  70. ▌
    Performing Bandwidth Throttling Attack Simulation · oyi77
    Use when simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks. . Use when working with performing bandwidth throttling attack simulation.
    10 repo stars
  71. ▌
    Performing Cloud Asset Inventory With Cartography · oyi77
    Use when perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure. Use when performing comprehensive cloud asset inventory and relationship mapping using cartography.
    10 repo stars
  72. ▌
    Performing Container Security Scanning With Trivy · oyi77
    Use when scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration. Use when scaning container images, filesystems, and kubernetes manifests for vulnerabilities, misconfigurations,.
    10 repo stars
  73. ▌
    Performing Static Malware Analysis With Pe Studio · oyi77
    Use when performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage. '.
    10 repo stars
  74. ▌
    Performing Threat Landscape Assessment For Sector · oyi77
    Use when conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management. Use when conducting a sector-specific threat landscape assessment by analyzing threat actor.
    10 repo stars
  75. ▌
    Evaluating Threat Intelligence Platforms · oyi77
    Use when evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
    10 repo stars
  76. ▌
    Exploiting API Injection Vulnerabilities · oyi77
    Use when tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:2023 Security Misconfiguration and API7:2023 SSRF.
    10 repo stars
  77. ▌
    Exploiting Bgp Hijacking Vulnerabilities · oyi77
    Use when analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure. . Use when working with exploiting bgp hijacking vulnerabilities.
    10 repo stars
  78. ▌
    Exploiting SQL Injection Vulnerabilities · oyi77
    Use when identifying and exploiting SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution.
    10 repo stars
  79. ▌
    Exploiting Type Juggling Vulnerabilities · oyi77
    Use when exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks. Use when exploiting php type juggling vulnerabilities caused by loose comparison operators.
    10 repo stars
  80. ▌
    Hunting For Data Exfiltration Indicators · oyi77
    Use when hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse. Use when hunting for data exfiltration through network traffic analysis, detecting unusual.
    10 repo stars
  81. ▌
    Implementing AWS Security Hub Compliance · oyi77
    Use when implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
    10 repo stars
  82. ▌
    Implementing Devsecops Security Scanning · oyi77
    Use when integrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation.
    10 repo stars
  83. ▌
    Implementing LLM Guardrails For Security · oyi77
    Use when implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang definitions, custom Python validators for PII detection and content policy enforcement, and the Guardrails AI framework for structured output validation. Use when working with implementing llm guardrails for security.
    10 repo stars
  84. ▌
    Implementing Log Forwarding With Fluentd · oyi77
    Use when configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure. Use when configureing fluentd and fluent bit for centralized log aggregation, routing,.
    10 repo stars
  85. ▌
    Implementing Network Segmentation For Ot · oyi77
    Use when this skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentation strategy, migration from flat networks to segmented architectures without disrupting operations, configuring OT-aware firewalls with industrial protocol deep packet inspection, and validating segmentation effectiveness through traffic analysis.
    10 repo stars
  86. ▌
    Implementing Pci Dss Compliance Controls · oyi77
    Use when pCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements. Use when working with implementing pci dss compliance controls.
    10 repo stars
  87. ▌
    Implementing Scim Provisioning With Okta · oyi77
    Use when implementing automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
    10 repo stars
  88. ▌
    Implementing Stix Taxii Feed Integration · oyi77
    Use when STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.
    10 repo stars
  89. ▌
    Implementing Taxii Server With Opentaxii · oyi77
    Use when deploying and configuring an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
    10 repo stars
  90. ▌
    Implementing Zero Trust Dns With Nextdns · oyi77
    Use when implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints. Use when implementing nextdns as a zero trust dns filtering layer with.
    10 repo stars
  91. ▌
    Performing Bluetooth Security Assessment · oyi77
    Use when assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities. Use when working with performing bluetooth security assessment.
    10 repo stars
  92. ▌
    Performing Cloud Forensics Investigation · oyi77
    Use when conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services. Use when conducting forensic investigations in cloud environments by collecting and analyzing.
    10 repo stars
  93. ▌
    Performing Dynamic Analysis With Any Run · oyi77
    Use when performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage. . Use when working with performing dynamic analysis with any run.
    10 repo stars
  94. ▌
    Performing Initial Access With Evilginx3 · oyi77
    Use when perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements. Use when performing authorized initial access using evilginx3 adversary-in-the-middle phishing framework to.
    10 repo stars
  95. ▌
    Performing Lateral Movement With Wmiexec · oyi77
    Use when perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements. Use when performing lateral movement across windows networks using wmi-based remote execution.
    10 repo stars
  96. ▌
    Performing Log Source Onboarding In Siem · oyi77
    Use when perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility. Use when performing structured log source onboarding into siem platforms by configuring.
    10 repo stars
  97. ▌
    Performing Physical Intrusion Assessment · oyi77
    Use when conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls. Use when conducting authorized physical penetration testing using tailgating, badge cloning, lock.
    10 repo stars
  98. ▌
    Performing Privilege Escalation On Linux · oyi77
    Use when linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised system. Red teams exploit misconfigurations, vulnerable services, kernel exploits, and w. Use when working with performing privilege escalation on linux.
    10 repo stars
  99. ▌
    Performing Scada Hmi Security Assessment · oyi77
    Use when perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines. . Use when working with performing scada hmi security assessment.
    10 repo stars
  100. ▌
    Securing Remote Access To Ot Environment · oyi77
    Use when this skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements.
    10 repo stars