all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 5 of 13

  1. ▌
    Analyzing Ransomware Leak Site Intelligence · oyi77
    Use when monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense. Use when monitoring and analyze ransomware group data leak sites (dls) to.
    10 repo stars
  2. ▌
    Building Ioc Defanging And Sharing Pipeline · oyi77
    Use when building an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
    10 repo stars
  3. ▌
    Building Phishing Reporting Button Workflow · oyi77
    Use when implementing a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.
    10 repo stars
  4. ▌
    Configuring Network Segmentation With Vlans · oyi77
    Use when designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments. . Use when working with configuring network segmentation with vlans.
    10 repo stars
  5. ▌
    Configuring Suricata For Network Monitoring · oyi77
    Use when deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms for centralized security monitoring. . Use when working with configuring suricata for network monitoring.
    10 repo stars
  6. ▌
    Configuring Zscaler Private Access For Ztna · oyi77
    Use when configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and device posture, and integrating with IdPs. . Use when working with configuring zscaler private access for ztna.
    10 repo stars
  7. ▌
    Deobfuscating Powershell Obfuscated Malware · oyi77
    Use when systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. Use when working with deobfuscating powershell obfuscated malware.
    10 repo stars
  8. ▌
    Detecting AI Model Prompt Injection Attacks · oyi77
    Use when detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models. The detector analyzes user inputs before they reach the LLM, flagging direct injections (system prompt overrides, role-play escapes, instruction hijacking) and indirect injections (encoded payloads, multi-language obfuscation, d...
    10 repo stars
  9. ▌
    Detecting Anomalous Authentication Patterns · oyi77
    Use when detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs. Activates for requests involving authentication anomaly detection, login behavior analysis, UEBA implementation, or suspicious sign-in investigation. . Use when working with detecting anomalous authentication patterns.
    10 repo stars
  10. ▌
    Detecting AWS Guardduty Findings Automation · oyi77
    Use when automating AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
    10 repo stars
  11. ▌
    Detecting Container Escape With Falco Rules · oyi77
    Use when detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation. Use when detecting container escape attempts in real-time using falco runtime security.
    10 repo stars
  12. ▌
    Detecting Dcsync Attack In Active Directory · oyi77
    Use when detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges. Use when detecting dcsync attacks where adversaries abuse active directory replication privileges.
    10 repo stars
  13. ▌
    Detecting Deepfake Audio In Vishing Attacks · oyi77
    Use when detecting AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generating confidence scores, and produces forensic reports.
    10 repo stars
  14. ▌
    Detecting Ntlm Relay With Event Correlation · oyi77
    Use when detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis. . Use when working with detecting ntlm relay with event correlation.
    10 repo stars
  15. ▌
    Detecting T1003 Credential Dumping With Edr · oyi77
    Use when detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation. Use when detecting os credential dumping techniques targeting lsass memory, sam database,.
    10 repo stars
  16. ▌
    Exploiting Active Directory With Bloodhound · oyi77
    Use when bloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac. Use when working with exploiting active directory with bloodhound.
    10 repo stars
  17. ▌
    Hardening Linux Endpoint With Cis Benchmark · oyi77
    Use when hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit findings, or establishing security baselines for Linux infrastructure. Activates for requests involving Linux hardening, CIS benchmarks for Linux, server security baselines, or Linux configuration compliance.
    10 repo stars
  18. ▌
    Hunting For Living Off The Cloud Techniques · oyi77
    Use when hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse of Azure, AWS, GCP services, and SaaS platforms. Use when hunting for adversary abuse of legitimate cloud services for c2,.
    10 repo stars
  19. ▌
    Hunting For Registry Persistence Mechanisms · oyi77
    Use when hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments. Use when hunting for registry-based persistence mechanisms including run keys, winlogon modifications,.
    10 repo stars
  20. ▌
    Implementing Anti Phishing Training Program · oyi77
    Use when security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv. Use when working with implementing anti phishing training program.
    10 repo stars
  21. ▌
    Implementing API Schema Validation Security · oyi77
    Use when implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks. Use when implementing api schema validation using openapi specifications and json schema.
    10 repo stars
  22. ▌
    Implementing Cisa Zero Trust Maturity Model · oyi77
    Use when implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity. Use when implementing the cisa zero trust maturity model v2.0 across the.
    10 repo stars
  23. ▌
    Implementing Disk Encryption With Bitlocker · oyi77
    Use when implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.
    10 repo stars
  24. ▌
    Implementing Runtime Security With Tetragon · oyi77
    Use when implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement. Use when implementing ebpf-based runtime security observability and enforcement in kubernetes clusters.
    10 repo stars
  25. ▌
    Implementing Siem Correlation Rules For Apt · oyi77
    Use when write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections. Use when writeing multi-event correlation rules that detect apt lateral movement by.
    10 repo stars
  26. ▌
    Implementing Ticketing System For Incidents · oyi77
    Use when implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.
    10 repo stars
  27. ▌
    Implementing Velociraptor For Ir Collection · oyi77
    Use when deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments. Use when deploying and configure velociraptor for scalable endpoint forensic artifact collection.
    10 repo stars
  28. ▌
    Integrating Dast With Owasp Zap In Pipeline · oyi77
    Use when this skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and establishing DAST quality gates in GitHub Actions and GitLab CI.
    10 repo stars
  29. ▌
    Performing Agentless Vulnerability Scanning · oyi77
    Use when configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents. Use when configureing and execute agentless vulnerability scanning using network protocols, cloud.
    10 repo stars
  30. ▌
    Performing Authenticated Vulnerability Scan · oyi77
    Use when authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security sett. Use when working with performing authenticated vulnerability scan.
    10 repo stars
  31. ▌
    Performing Dmarc Policy Enforcement Rollout · oyi77
    Use when execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders. Use when working with performing dmarc policy enforcement rollout.
    10 repo stars
  32. ▌
    Performing Docker Bench Security Assessment · oyi77
    Use when docker Bench for Security is an open-source script that checks dozens of common best practices around deploying Docker containers in production. Based on the CIS Docker Benchmark, it audits host confi. Use when working with performing docker bench security assessment.
    10 repo stars
  33. ▌
    Performing Endpoint Forensics Investigation · oyi77
    Use when performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.
    10 repo stars
  34. ▌
    Performing False Positive Reduction In Siem · oyi77
    Use when perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue. Use when performing systematic siem false positive reduction through rule tuning, threshold.
    10 repo stars
  35. ▌
    Performing Firmware Extraction With Binwalk · oyi77
    Use when performing firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery.
    10 repo stars
  36. ▌
    Performing Ics Asset Discovery With Claroty · oyi77
    Use when perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels. . Use when working with performing ics asset discovery with claroty.
    10 repo stars
  37. ▌
    Performing Network Forensics With Wireshark · oyi77
    Use when capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications. Use when working with performing network forensics with wireshark.
    10 repo stars
  38. ▌
    Performing Oil Gas Cybersecurity Assessment · oyi77
    Use when this skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443...
    10 repo stars
  39. ▌
    Performing Ot Vulnerability Scanning Safely · oyi77
    Use when perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers. . Use when working with performing ot vulnerability scanning safely.
    10 repo stars
  40. ▌
    Performing Phishing Simulation With Gophish · oyi77
    Use when goPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag. Use when working with performing phishing simulation with gophish.
    10 repo stars
  41. ▌
    Performing Privileged Account Access Review · oyi77
    Use when conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure. Use when conducting systematic reviews of privileged accounts to validate access rights,.
    10 repo stars
  42. ▌
    Performing Ssl Tls Inspection Configuration · oyi77
    Use when configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance. Use when configureing ssl/tls inspection on network security devices to decrypt, inspect,.
    10 repo stars
  43. ▌
    Performing Threat Hunting With Elastic Siem · oyi77
    Use when performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.
    10 repo stars
  44. ▌
    Securing Historian Server In Ot Environment · oyi77
    Use when this skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for historian interfaces, data replication through DMZ using data diodes or PI-to-PI connectors, SQL injection prevention in historian queries, and integrity protection of process data used for safety analysis, regulatory reporting, and process optimization.
    10 repo stars
  45. ▌
    Testing Android Intents For Vulnerabilities · oyi77
    Use when tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.
    10 repo stars
  46. ▌
    Performing Iot Security Assessment · oyi77
    Use when performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware debugging via UART and JTAG, network protocol analysis, and runtime exploitation to identify vulnerabilities across all layers of the IoT stack. Use when working with performing iot security assessment.
    10 repo stars
  47. ▌
    Performing Packet Injection Attack · oyi77
    Use when crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic. . Use when working with performing packet injection attack.
    10 repo stars
  48. ▌
    Performing Steganography Detection · oyi77
    Use when detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels. Use when detecting and extract hidden data embedded in images, audio, and.
    10 repo stars
  49. ▌
    Performing User Behavior Analytics · oyi77
    Use when performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.
    10 repo stars
  50. ▌
    Securing Container Registry Images · oyi77
    Use when securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned images. . Use when working with securing container registry images.
    10 repo stars
  51. ▌
    Testing For Email Header Injection · oyi77
    Use when test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay. Use when testing web application email functionality for smtp header injection vulnerabilities.
    10 repo stars
  52. ▌
    Triaging Security Alerts In Splunk · oyi77
    Use when triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.
    10 repo stars
  53. ▌
    Oh My Opencode Usage · oyi77
    Use when daily usage patterns for oh-my-opencode including workflow commands, session management, agent invocation, and productivity tips. Use when working with oh my opencode usage.
    10 repo stars
  54. ▌
    Analyzing Dns Logs For Exfiltration · oyi77
    Use when analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
    10 repo stars
  55. ▌
    Analyzing Malicious PDF With Peepdf · oyi77
    Use when perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. Use when performing static analysis of malicious pdf documents using peepdf, pdfid,.
    10 repo stars
  56. ▌
    Analyzing Security Logs With Splunk · oyi77
    Use when leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
    10 repo stars
  57. ▌
    Analyzing Threat Intelligence Feeds · oyi77
    Use when analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.
    10 repo stars
  58. ▌
    Analyzing Windows Amcache Artifacts · oyi77
    Use when parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investig...
    10 repo stars
  59. ▌
    Building Detection Rules With Sigma · oyi77
    Use when builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.
    10 repo stars
  60. ▌
    Building Incident Response Playbook · oyi77
    Use when designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design.
    10 repo stars
  61. ▌
    Collecting Indicators Of Compromise · oyi77
    Use when systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
    10 repo stars
  62. ▌
    Configuring Ldap Security Hardening · oyi77
    Use when hardening LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
    10 repo stars
  63. ▌
    Detecting Business Email Compromise · oyi77
    Use when business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,. Use when working with detecting business email compromise.
    10 repo stars
  64. ▌
    Detecting Container Escape Attempts · oyi77
    Use when container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators. Use when working with detecting container escape attempts.
    10 repo stars
  65. ▌
    Detecting Modbus Protocol Anomalies · oyi77
    Use when this skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for malformed Modbus frames. The skill leverages Zeek with Modbus protocol analyzers, Suricata IDS with OT rules, and custom Python-based detection using Markov chain models for normal Modbus transaction sequences.
    10 repo stars
  66. ▌
    Exploiting Deeplink Vulnerabilities · oyi77
    Use when tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based navigation. Activates for requests involving deep link security testing, URL scheme exploitation, mobile intent abuse, or link hijacking.
    10 repo stars
  67. ▌
    Exploiting Insecure Deserialization · oyi77
    Use when identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests. Use when working with exploiting insecure deserialization.
    10 repo stars
  68. ▌
    Hunting Advanced Persistent Threats · oyi77
    Use when proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.
    10 repo stars
  69. ▌
    Hunting For Dns Tunneling With Zeek · oyi77
    Use when detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication. Use when detecting dns tunneling and data exfiltration by analyzing zeek dns.log.
    10 repo stars
  70. ▌
    Hunting For Supply Chain Compromise · oyi77
    Use when hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts. Use when hunting for supply chain compromise indicators including trojanized software updates,.
    10 repo stars
  71. ▌
    Implementing Bgp Security With Rpki · oyi77
    Use when implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking. Use when implementing bgp route origin validation using rpki with route origin.
    10 repo stars
  72. ▌
    Implementing Diamond Model Analysis · oyi77
    Use when the Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    10 repo stars
  73. ▌
    Implementing GCP Vpc Firewall Rules · oyi77
    Use when implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs. . Use when working with implementing gcp vpc firewall rules.
    10 repo stars
  74. ▌
    Implementing Network Access Control · oyi77
    Use when implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices. . Use when working with implementing network access control.
    10 repo stars
  75. ▌
    Performing API Fuzzing With Restler · oyi77
    Use when uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability bugs. The tester compiles an OpenAPI specification into a RESTler fuzzing grammar, configures authentication, runs test/fuzz-lean/fuzz modes, and analyzes results for 500 errors, authentication bypasses, resource leaks, and payload injection vulnerab...
    10 repo stars
  76. ▌
    Performing API Rate Limiting Bypass · oyi77
    Use when tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines enforcement mechanisms, and attempts bypasses including X-Forwarded-For spoofing, parameter pollution, case variation, and endpoint path manipulation. Maps to OWASP API4:2023 Unrestricted Resource Consumption.
    10 repo stars
  77. ▌
    Performing Clickjacking Attack Test · oyi77
    Use when testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments. Use when working with performing clickjacking attack test.
    10 repo stars
  78. ▌
    Performing Fuzzing With Aflplusplus · oyi77
    Use when performing coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with afl-fuzz, and triages crashes using CASR or GDB scripts.
    10 repo stars
  79. ▌
    Performing Malware Triage With Yara · oyi77
    Use when performing rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.
    10 repo stars
  80. ▌
    Scanning Infrastructure With Nessus · oyi77
    Use when tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems. Use when working with scanning infrastructure with nessus.
    10 repo stars
  81. ▌
    Scanning Network With Nmap Advanced · oyi77
    Use when performs advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks. . Use when working with scanning network with nmap advanced.
    10 repo stars
  82. ▌
    Securing AWS Lambda Execution Roles · oyi77
    Use when securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate permissions, and enforcing role scoping through SCPs. . Use when working with securing aws lambda execution roles.
    10 repo stars
  83. ▌
    Testing For Sensitive Data Exposure · oyi77
    Use when identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments. Use when working with testing for sensitive data exposure.
    10 repo stars
  84. ▌
    Testing Oauth2 Implementation Flaws · oyi77
    Use when tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server, client application, and token handling for common misconfigurations that enable account takeover or unauthorized access. Use when working with testing oauth2 implementation flaws.
    10 repo stars
  85. ▌
    Oh My Opencode Agents · oyi77
    Use when deep dive into each oh-my-opencode agent - Sisyphus, Hephaestus, Oracle, Librarian, Explore - their characteristics, use cases, and when to use each. Use when working with oh my opencode agents.
    10 repo stars
  86. ▌
    Analyzing Active Directory Acl Abuse · oyi77
    Use when detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths. Use when detecting dangerous acl misconfigurations in active directory using ldap3 to.
    10 repo stars
  87. ▌
    Analyzing Docker Container Forensics · oyi77
    Use when investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence. Use when working with analyzing docker container forensics.
    10 repo stars
  88. ▌
    Analyzing Golang Malware With Ghidra · oyi77
    Use when reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries. Use when reverseing engineer go-compiled malware using ghidra with specialized scripts for.
    10 repo stars
  89. ▌
    Analyzing Malicious Url With Urlscan · oyi77
    Use when uRLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat. Use when working with analyzing malicious url with urlscan.
    10 repo stars
  90. ▌
    Analyzing Network Packets With Scapy · oyi77
    Use when craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing. Use when working with analyzing network packets with scapy.
    10 repo stars
  91. ▌
    Analyzing Network Traffic Of Malware · oyi77
    Use when analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection. . Use when working with analyzing network traffic of malware.
    10 repo stars
  92. ▌
    Analyzing Ransomware Payment Wallets · oyi77
    Use when traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering. . Use when working with analyzing ransomware payment wallets.
    10 repo stars
  93. ▌
    Analyzing Windows Shellbag Artifacts · oyi77
    Use when analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer. Use when analyzeing windows shellbag registry artifacts to reconstruct folder browsing activity,.
    10 repo stars
  94. ▌
    Building Incident Response Dashboard · oyi77
    Use when builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
    10 repo stars
  95. ▌
    Building Soc Playbook For Ransomware · oyi77
    Use when builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.
    10 repo stars
  96. ▌
    Conducting Cloud Penetration Testing · oyi77
    Use when this skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK Cloud matrix.
    10 repo stars
  97. ▌
    Conducting Malware Incident Response · oyi77
    Use when responding to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment, analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal, worm containment, malware triage, or infected endpoint remediation.
    10 repo stars
  98. ▌
    Deploying Edr Agent With Crowdstrike · oyi77
    Use when deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
    10 repo stars
  99. ▌
    Deploying Software Defined Perimeter · oyi77
    Use when deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access. Use when deploying a software-defined perimeter using the csa v2.0 specification with.
    10 repo stars
  100. ▌
    Detecting Container Drift At Runtime · oyi77
    Use when detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image. Use when detecting unauthorized modifications to running containers by monitoring for binary.
    10 repo stars