all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 4 of 13

  1. ▌
    Validating Backup Integrity For Recovery · oyi77
    Use when validating backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    10 repo stars
  2. ▌
    Analyzing Azure Activity Logs For Threats · oyi77
    Use when queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
    10 repo stars
  3. ▌
    Analyzing IOS App Security With Objection · oyi77
    Use when performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app security posture, bypassing client-side protections, dumping keychain items, inspecting filesystem storage, and evaluating runtime behavior. Activates for requests involving iOS security testing, Objection runtime analysis, Frida-based iOS assessment, or mobile runtime explo.
    10 repo stars
  4. ▌
    Analyzing Outlook Pst For Email Forensics · oyi77
    Use when analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response. Use when analyzeing microsoft outlook pst and ost files for email forensic.
    10 repo stars
  5. ▌
    Analyzing Persistence Mechanisms In Linux · oyi77
    Use when detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring. Use when detecting and analyze linux persistence mechanisms including crontab entries, systemd.
    10 repo stars
  6. ▌
    Building Threat Hunt Hypothesis Framework · oyi77
    Use when build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses. Use when building a systematic threat hunt hypothesis framework that transforms threat.
    10 repo stars
  7. ▌
    Conducting Domain Persistence With Dcsync · oyi77
    Use when perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation. Use when performing dcsync attacks to replicate active directory credentials and establish.
    10 repo stars
  8. ▌
    Conducting Full Scope Red Team Engagement · oyi77 bundle
    Use when plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities. Use when working with conducting full scope red team engagement.
    10 repo stars
  9. ▌
    Configuring Active Directory Tiered Model · oyi77
    Use when implementing Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative f
    10 repo stars
  10. ▌
    Deploying Osquery For Endpoint Monitoring · oyi77
    Use when deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
    10 repo stars
  11. ▌
    Detecting Suspicious Powershell Execution · oyi77
    Use when detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion. Use when detecting suspicious powershell execution patterns including encoded commands, download cradles,.
    10 repo stars
  12. ▌
    Eradicating Malware From Infected Systems · oyi77
    Use when systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection. Use when working with eradicating malware from infected systems.
    10 repo stars
  13. ▌
    Exploiting Excessive Data Exposure In API · oyi77
    Use when tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization. Use when working with exploiting excessive data exposure in api.
    10 repo stars
  14. ▌
    Exploiting JWT Algorithm Confusion Attack · oyi77
    Use when exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to supply attacker-controlled keys. Use when working with exploiting jwt algorithm confusion attack.
    10 repo stars
  15. ▌
    Exploiting Race Condition Vulnerabilities · oyi77
    Use when detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws. Use when detecting and exploit race condition vulnerabilities in web applications using.
    10 repo stars
  16. ▌
    Hunting For Command And Control Beaconing · oyi77
    Use when detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure. Use when detecting c2 beaconing patterns in network traffic using frequency analysis,.
    10 repo stars
  17. ▌
    Hunting For Unusual Service Installations · oyi77
    Use when detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms. Use when detecting suspicious windows service installations (mitre att&ck t1543.003) by parsing.
    10 repo stars
  18. ▌
    Implementing Anti Ransomware Group Policy · oyi77
    Use when configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy. . Use when working with implementing anti ransomware group policy.
    10 repo stars
  19. ▌
    Implementing Immutable Backup With Restic · oyi77
    Use when implementing immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection. Automates backup creation, integrity verification via restic check --read-data, snapshot retention policy enforcement, and restore testing. Integrates with AWS S3 Object Lock, MinIO, and Backblaze B2 for WORM (Write Once Read Many) storage that prevents backup deletion or encryption by ransomware actors.
    10 repo stars
  20. ▌
    Implementing JWT Signing And Verification · oyi77
    Use when JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization in web applications. This skill covers implementing secure JWT signing with HMAC-SHA256
    10 repo stars
  21. ▌
    Implementing Mtls For Zero Trust Services · oyi77
    Use when configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains, checks expiration, and audits mTLS deployment status. Use when implementing zero-trust service-to-service authentication.
    10 repo stars
  22. ▌
    Implementing Nerc Cip Compliance Controls · oyi77
    Use when this skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset req...
    10 repo stars
  23. ▌
    Implementing Siem Use Cases For Detection · oyi77
    Use when implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
    10 repo stars
  24. ▌
    Implementing Soar Automation With Phantom · oyi77
    Use when implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.
    10 repo stars
  25. ▌
    Investigating Ransomware Attack Artifacts · oyi77
    Use when identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options. Use when working with investigating ransomware attack artifacts.
    10 repo stars
  26. ▌
    Monitoring Scada Modbus Traffic Anomalies · oyi77
    Use when monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502.
    10 repo stars
  27. ▌
    Performing Alert Triage With Elastic Siem · oyi77
    Use when perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations. Use when performing systematic alert triage in elastic security siem to rapidly.
    10 repo stars
  28. ▌
    Performing Arp Spoofing Attack Simulation · oyi77
    Use when simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures. . Use when working with performing arp spoofing attack simulation.
    10 repo stars
  29. ▌
    Performing Content Security Policy Bypass · oyi77
    Use when analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques. Use when analyzeing and bypass content security policy implementations to achieve cross-site.
    10 repo stars
  30. ▌
    Performing Credential Access With Lazagne · oyi77
    Use when extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations. Use when working with performing credential access with lazagne.
    10 repo stars
  31. ▌
    Performing Indicator Lifecycle Management · oyi77
    Use when indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
    10 repo stars
  32. ▌
    Performing Kubernetes Penetration Testing · oyi77
    Use when kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools. Use when working with performing kubernetes penetration testing.
    10 repo stars
  33. ▌
    Performing Ot Network Security Assessment · oyi77
    Use when this skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infra...
    10 repo stars
  34. ▌
    Performing Plc Firmware Security Analysis · oyi77
    Use when this skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampe...
    10 repo stars
  35. ▌
    Performing Supply Chain Attack Simulation · oyi77
    Use when simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit. Use when working with performing supply chain attack simulation.
    10 repo stars
  36. ▌
    Performing Threat Hunting With Yara Rules · oyi77
    Use when using YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
    10 repo stars
  37. ▌
    Testing For Open Redirect Vulnerabilities · oyi77
    Use when identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft. Use when working with testing for open redirect vulnerabilities.
    10 repo stars
  38. ▌
    Testing For XML Injection Vulnerabilities · oyi77
    Use when test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks. Use when testing web applications for xml injection vulnerabilities including xxe, xpath.
    10 repo stars
  39. ▌
    Testing For Xxe Injection Vulnerabilities · oyi77
    Use when discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests. Use when working with testing for xxe injection vulnerabilities.
    10 repo stars
  40. ▌
    Oh My Opencode Installation · oyi77
    Use when smart installation and configuration for OpenCode with oh-my-opencode harness - detects existing installation and only installs if needed. Use when working with oh my opencode installation.
    10 repo stars
  41. ▌
    Hunting For Ntlm Relay Attacks · oyi77
    Use when detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain. Use when detecting ntlm relay attacks by analyzing windows event 4624 logon.
    10 repo stars
  42. ▌
    Analyzing Browser Forensics With Hindsight · oyi77
    Use when analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation. Use when analyzeing chromium-based browser artifacts using hindsight to extract browsing history,.
    10 repo stars
  43. ▌
    Analyzing Lnk File And Jump List Artifacts · oyi77
    Use when analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format. Use when analyzeing windows lnk shortcut files and jump list artifacts to.
    10 repo stars
  44. ▌
    Analyzing Packed Malware With Upx Unpacker · oyi77
    Use when identifying and unpacking UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
    10 repo stars
  45. ▌
    Analyzing Ransomware Encryption Mechanisms · oyi77
    Use when analyzing encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
    10 repo stars
  46. ▌
    Auditing Tls Certificate Transparency Logs · oyi77
    Use when monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Use when working with auditing tls certificate transparency logs.
    10 repo stars
  47. ▌
    Building Devsecops Pipeline With Gitlab CI · oyi77
    Use when design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection. Use when designing and implement a comprehensive devsecops pipeline in gitlab ci/cd.
    10 repo stars
  48. ▌
    Building Incident Timeline With Timesketch · oyi77
    Use when build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation. Use when building collaborative forensic incident timelines using timesketch to ingest, normalize,.
    10 repo stars
  49. ▌
    Building Role Mining For Rbac Optimization · oyi77
    Use when apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege. Use when working with building role mining for rbac optimization.
    10 repo stars
  50. ▌
    Building Threat Feed Aggregation With Misp · oyi77
    Use when deploying MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
    10 repo stars
  51. ▌
    Conducting Social Engineering Pretext Call · oyi77
    Use when plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls. Use when working with conducting social engineering pretext call.
    10 repo stars
  52. ▌
    Configuring Host Based Intrusion Detection · oyi77
    Use when configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitoring, building file integrity monitoring (FIM) policies, or meeting compliance requirements for change detection. Activates for requests involving HIDS configuration, file integrity monitoring, OSSEC/Wazuh deployment, or host-based detection.
    10 repo stars
  53. ▌
    Deploying Cloudflare Access For Zero Trust · oyi77
    Use when deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement. . Use when working with deploying cloudflare access for zero trust.
    10 repo stars
  54. ▌
    Detecting Arp Poisoning In Network Traffic · oyi77
    Use when detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception. Use when detecting and prevent arp spoofing attacks using arpwatch, dynamic arp.
    10 repo stars
  55. ▌
    Detecting Modbus Command Injection Attacks · oyi77
    Use when detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and protocol deep packet inspection. . Use when working with detecting modbus command injection attacks.
    10 repo stars
  56. ▌
    Detecting Ransomware Precursors In Network · oyi77
    Use when detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts.
    10 repo stars
  57. ▌
    Detecting Spearphishing With Email Gateway · oyi77
    Use when spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,. Use when working with detecting spearphishing with email gateway.
    10 repo stars
  58. ▌
    Exploiting Insecure Data Storage In Mobile · oyi77
    Use when identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements.
    10 repo stars
  59. ▌
    Exploiting Nosql Injection Vulnerabilities · oyi77
    Use when detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks. Use when detecting and exploit nosql injection vulnerabilities in mongodb, couchdb, and.
    10 repo stars
  60. ▌
    Hardening Docker Containers For Production · oyi77
    Use when hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce leas. Use when working with hardening docker containers for production.
    10 repo stars
  61. ▌
    Hunting For Anomalous Powershell Execution · oyi77
    Use when hunting for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification. '.
    10 repo stars
  62. ▌
    Implementing API Gateway Security Controls · oyi77
    Use when implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) to act as a centralized security enforcement point that validates, throttles, and monitors all API traffic before it reaches backend services. Use when working with implementing api gateway security controls.
    10 repo stars
  63. ▌
    Implementing AWS Iam Permission Boundaries · oyi77
    Use when configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team. Use when configureing iam permission boundaries in aws to delegate role creation.
    10 repo stars
  64. ▌
    Implementing Cloud Dlp For Data Protection · oyi77
    Use when implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines. . Use when working with implementing cloud dlp for data protection.
    10 repo stars
  65. ▌
    Implementing Delinea Secret Server For Pam · oyi77
    Use when implementing Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.
    10 repo stars
  66. ▌
    Implementing Dmarc Dkim Spf Email Security · oyi77
    Use when sPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im. Use when working with implementing dmarc dkim spf email security.
    10 repo stars
  67. ▌
    Implementing Endpoint Detection With Wazuh · oyi77
    Use when deploying and configuring Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    10 repo stars
  68. ▌
    Implementing Gdpr Data Protection Controls · oyi77
    Use when the General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover
    10 repo stars
  69. ▌
    Implementing Log Integrity With Blockchain · oyi77
    Use when build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services. Use when building an append-only log integrity chain using sha-256 hash chaining.
    10 repo stars
  70. ▌
    Implementing Mitre Attack Coverage Mapping · oyi77
    Use when implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques. Use when implementing mitre att&ck coverage mapping to identify detection gaps, prioritize.
    10 repo stars
  71. ▌
    Implementing Mobile Application Management · oyi77
    Use when implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps.
    10 repo stars
  72. ▌
    Implementing Ot Incident Response Playbook · oyi77
    Use when develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams. . Use when working with implementing ot incident response playbook.
    10 repo stars
  73. ▌
    Implementing Privileged Access Workstation · oyi77
    Use when design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations. Use when designing and implement privileged access workstations (paws) with device hardening,.
    10 repo stars
  74. ▌
    Implementing Privileged Session Monitoring · oyi77
    Use when implementing privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke logging, real-time monitoring, risk-based session analysis, and compliance audit trail generation.
    10 repo stars
  75. ▌
    Implementing Rapid7 Insightvm For Scanning · oyi77
    Use when deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments. Use when deploying and configure rapid7 insightvm security console and scan engines.
    10 repo stars
  76. ▌
    Implementing Rbac Hardening For Kubernetes · oyi77
    Use when harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers. Use when working with implementing rbac hardening for kubernetes.
    10 repo stars
  77. ▌
    Implementing Secret Scanning With Gitleaks · oyi77
    Use when this skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
    10 repo stars
  78. ▌
    Implementing Secrets Management With Vault · oyi77
    Use when this skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It addresses eliminating hardcoded credentials from application code and CI/CD pipelines by implementing short-lived, automatically rotated secrets.
    10 repo stars
  79. ▌
    Implementing Sigstore For Software Signing · oyi77
    Use when implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines.
    10 repo stars
  80. ▌
    Implementing Vulnerability Remediation Sla · oyi77
    Use when vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs. Use when working with implementing vulnerability remediation sla.
    10 repo stars
  81. ▌
    Intercepting Mobile Traffic With Burpsuite · oyi77
    Use when intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.
    10 repo stars
  82. ▌
    Performing Access Review And Certification · oyi77
    Use when conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles. This skill covers review campaign design, reviewer selection, risk-based p
    10 repo stars
  83. ▌
    Performing Authenticated Scan With Openvas · oyi77
    Use when configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment. Use when configureing and execute authenticated vulnerability scans using openvas/greenbone vulnerability management.
    10 repo stars
  84. ▌
    Performing Cloud Log Forensics With Athena · oyi77
    Use when uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and privilege escalation. Use when investigating AWS security incidents or building cloud-native forensic workflows at scale.
    10 repo stars
  85. ▌
    Performing Dark Web Monitoring For Threats · oyi77
    Use when dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre. Use when working with performing dark web monitoring for threats.
    10 repo stars
  86. ▌
    Performing Deception Technology Deployment · oyi77
    Use when deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.
    10 repo stars
  87. ▌
    Performing Dynamic Analysis Of Android App · oyi77
    Use when performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications.
    10 repo stars
  88. ▌
    Performing HTTP Parameter Pollution Attack · oyi77
    Use when execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems. Use when working with performing http parameter pollution attack.
    10 repo stars
  89. ▌
    Performing Network Packet Capture Analysis · oyi77
    Use when perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity. Use when performing forensic analysis of network packet captures (pcap/pcapng) using wireshark,.
    10 repo stars
  90. ▌
    Performing OAUTH Scope Minimization Review · oyi77
    Use when performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization. . Use when working with performing oauth scope minimization review.
    10 repo stars
  91. ▌
    Performing Privilege Escalation Assessment · oyi77
    Use when performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Use when working with performing privilege escalation assessment.
    10 repo stars
  92. ▌
    Performing Web Application Firewall Bypass · oyi77
    Use when bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules. Use when working with performing web application firewall bypass.
    10 repo stars
  93. ▌
    Scanning Kubernetes Manifests With Kubesec · oyi77
    Use when perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices. Use when performing security risk analysis on kubernetes resource manifests using kubesec.
    10 repo stars
  94. ▌
    Testing For Business Logic Vulnerabilities · oyi77
    Use when identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect. Use when working with testing for business logic vulnerabilities.
    10 repo stars
  95. ▌
    Testing For JSON Web Token Vulnerabilities · oyi77
    Use when test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation. Use when testing jwt implementations for critical vulnerabilities including algorithm confusion, none.
    10 repo stars
  96. ▌
    Oh My Opencode Configuration · oyi77
    Use when comprehensive configuration guide for oh-my-opencode including agent settings, MCP servers, hooks, categories, and advanced options. Use when working with oh my opencode configuration.
    10 repo stars
  97. ▌
    Detecting Golden Ticket Forgery · oyi77
    Use when detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM. Use when detecting kerberos golden ticket forgery by analyzing windows event id.
    10 repo stars
  98. ▌
    Analyzing Command And Control Communication · oyi77
    Use when analyzing malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.
    10 repo stars
  99. ▌
    Analyzing Macro Malware In Office Documents · oyi77
    Use when analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination. . Use when working with analyzing macro malware in office documents.
    10 repo stars
  100. ▌
    Analyzing Malware Persistence With Autoruns · oyi77
    Use when use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows systems. Use when working with analyzing malware persistence with autoruns.
    10 repo stars