all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 6 of 13

  1. ▌
    Detecting Lateral Movement With Zeek · oyi77
    Use when detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections. . Use when working with detecting lateral movement with zeek.
    10 repo stars
  2. ▌
    Exploiting SQL Injection With Sqlmap · oyi77
    Use when detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. Use when working with exploiting sql injection with sqlmap.
    10 repo stars
  3. ▌
    Exploiting Websocket Vulnerabilities · oyi77
    Use when testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments. Use when working with exploiting websocket vulnerabilities.
    10 repo stars
  4. ▌
    Extracting Browser History Artifacts · oyi77
    Use when extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity. Use when working with extracting browser history artifacts.
    10 repo stars
  5. ▌
    Extracting Iocs From Malware Samples · oyi77
    Use when extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples. . Use when working with extracting iocs from malware samples.
    10 repo stars
  6. ▌
    Hunting For Lateral Movement Via Wmi · oyi77
    Use when detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence. Use when detecting wmi-based lateral movement by analyzing windows event id 4688.
    10 repo stars
  7. ▌
    Hunting For Spearphishing Indicators · oyi77
    Use when hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks. Use when hunting for spearphishing campaign indicators across email logs, endpoint telemetry,.
    10 repo stars
  8. ▌
    Implementing Alert Fatigue Reduction · oyi77
    Use when implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.
    10 repo stars
  9. ▌
    Implementing Pam For Database Access · oyi77
    Use when deploying privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
    10 repo stars
  10. ▌
    Implementing Rsa Key Pair Management · oyi77
    Use when RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,
    10 repo stars
  11. ▌
    Performing Container Image Hardening · oyi77
    Use when this skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.
    10 repo stars
  12. ▌
    Performing Firmware Malware Analysis · oyi77
    Use when analyzing firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
    10 repo stars
  13. ▌
    Performing Ioc Enrichment Automation · oyi77
    Use when automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source enrichment of IPs, domains, URLs, and file hashes during alert triage or incident investigation.
    10 repo stars
  14. ▌
    Performing JWT None Algorithm Attack · oyi77
    Use when execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens. Use when working with performing jwt none algorithm attack.
    10 repo stars
  15. ▌
    Performing Privacy Impact Assessment · oyi77
    Use when automating the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework PRAM methodology and ICO DPIA guidance for systematic identification and mitigation of privacy risks across processing activities.
    10 repo stars
  16. ▌
    Performing Sqlite Database Forensics · oyi77
    Use when perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases. Use when performing forensic analysis of sqlite databases to recover deleted records.
    10 repo stars
  17. ▌
    Scanning Container Images With Grype · oyi77
    Use when scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds. Use when scaning container images for known vulnerabilities using anchore grype with.
    10 repo stars
  18. ▌
    Tracking Threat Actor Infrastructure · oyi77
    Use when threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a. Use when working with tracking threat actor infrastructure.
    10 repo stars
  19. ▌
    Analyzing Bootkit And Rootkit Samples · oyi77
    Use when analyzing bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.
    10 repo stars
  20. ▌
    Analyzing Powershell Empire Artifacts · oyi77
    Use when detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events. Use when detecting powershell empire framework artifacts in windows event logs by.
    10 repo stars
  21. ▌
    Building Soc Metrics And Kpi Tracking · oyi77
    Use when builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
    10 repo stars
  22. ▌
    Building Threat Intelligence Platform · oyi77
    Use when building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T. Use when working with building threat intelligence platform.
    10 repo stars
  23. ▌
    Conducting Phishing Incident Response · oyi77
    Use when responding to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email incident, credential phishing, spear phishing investigation, or phishing remediation.
    10 repo stars
  24. ▌
    Configuring Oauth2 Authorization Flow · oyi77
    Use when configuring secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token
    10 repo stars
  25. ▌
    Correlating Security Events In Qradar · oyi77
    Use when correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
    10 repo stars
  26. ▌
    Detecting Fileless Malware Techniques · oyi77
    Use when detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination. . Use when working with detecting fileless malware techniques.
    10 repo stars
  27. ▌
    Detecting Lateral Movement In Network · oyi77
    Use when identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems. . Use when working with detecting lateral movement in network.
    10 repo stars
  28. ▌
    Detecting Living Off The Land Attacks · oyi77
    Use when detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns. . Use when working with detecting living off the land attacks.
    10 repo stars
  29. ▌
    Detecting Mimikatz Execution Patterns · oyi77
    Use when detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules. Use when detecting mimikatz execution through command-line patterns, lsass access signatures, binary.
    10 repo stars
  30. ▌
    Detecting Misconfigured Azure Storage · oyi77
    Use when detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage. . Use when working with detecting misconfigured azure storage.
    10 repo stars
  31. ▌
    Detecting Network Anomalies With Zeek · oyi77
    Use when deploying and configuring Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
    10 repo stars
  32. ▌
    Detecting Port Scanning With Fail2ban · oyi77
    Use when configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. . Use when working with detecting port scanning with fail2ban.
    10 repo stars
  33. ▌
    Detecting Process Hollowing Technique · oyi77
    Use when detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry. Use when detecting process hollowing (t1055.012) by analyzing memory-mapped sections, hollowed process.
    10 repo stars
  34. ▌
    Exploiting Nopac Cve 2021 42278 42287 · oyi77
    Use when exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments. Use when exploiting the nopac vulnerability chain (cve-2021-42278 samaccountname spoofing and cve-2021-42287.
    10 repo stars
  35. ▌
    Hardening Docker Daemon Configuration · oyi77
    Use when harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls. Use when working with hardening docker daemon configuration.
    10 repo stars
  36. ▌
    Implementing Azure Defender For Cloud · oyi77
    Use when implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.
    10 repo stars
  37. ▌
    Implementing Cloud Trail Log Analysis · oyi77
    Use when implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity. . Use when working with implementing cloud trail log analysis.
    10 repo stars
  38. ▌
    Implementing Ebpf Security Monitoring · oyi77
    Use when implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
    10 repo stars
  39. ▌
    Implementing GCP Binary Authorization · oyi77
    Use when implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run. Use when implementing gcp binary authorization to enforce deploy-time security controls that.
    10 repo stars
  40. ▌
    Implementing Ics Firewall With Tofino · oyi77
    Use when deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones. . Use when working with implementing ics firewall with tofino.
    10 repo stars
  41. ▌
    Implementing Iec 62443 Security Zones · oyi77
    Use when this skill covers designing and implementing security zones and conduits for industrial automation and control systems (IACS) per IEC 62443-3-2. It addresses zone partitioning based on risk assessment, assigning Security Level targets (SL-T), designing conduit security controls, implementing microsegmentation with industrial firewalls, and validating zone architecture through traffic analysis and penetration testing against the Purdue Reference Model.
    10 repo stars
  42. ▌
    Investigating Phishing Email Incident · oyi77
    Use when investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
    10 repo stars
  43. ▌
    Performing File Carving With Foremost · oyi77
    Use when recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state. Use when working with performing file carving with foremost.
    10 repo stars
  44. ▌
    Performing GRAPHQL Depth Limit Attack · oyi77
    Use when execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs. Use when working with performing graphql depth limit attack.
    10 repo stars
  45. ▌
    Performing Hash Cracking With Hashcat · oyi77
    Use when hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w. Use when working with performing hash cracking with hashcat.
    10 repo stars
  46. ▌
    Performing Lateral Movement Detection · oyi77
    Use when detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques. . Use when working with performing lateral movement detection.
    10 repo stars
  47. ▌
    Performing Purple Team Atomic Testing · oyi77
    Use when executing Atomic Red Team tests mapped to MITRE ATT&CK techniques, performing coverage gap analysis across the ATT&CK matrix, and running detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines.
    10 repo stars
  48. ▌
    Performing Second Order SQL Injection · oyi77
    Use when detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. Use when detecting and exploit second-order sql injection vulnerabilities where malicious input.
    10 repo stars
  49. ▌
    Performing Web Cache Deception Attack · oyi77
    Use when execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content. Use when working with performing web cache deception attack.
    10 repo stars
  50. ▌
    Performing Web Cache Poisoning Attack · oyi77
    Use when exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests. Use when working with performing web cache poisoning attack.
    10 repo stars
  51. ▌
    Testing API Authentication Weaknesses · oyi77
    Use when tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Use when working with testing api authentication weaknesses.
    10 repo stars
  52. ▌
    Oh My Opencode Features · oyi77
    Use when complete reference of all oh-my-opencode features including agents, tools, MCPs, hooks, workflow automation, and productivity enhancements. Use when working with oh my opencode features.
    10 repo stars
  53. ▌
    Analyzing Android Malware With Apktool · oyi77
    Use when perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection. Use when performing static analysis of android apk malware samples using apktool.
    10 repo stars
  54. ▌
    Analyzing Memory Dumps With Volatility · oyi77
    Use when analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation. . Use when working with analyzing memory dumps with volatility.
    10 repo stars
  55. ▌
    Analyzing Windows Event Logs In Splunk · oyi77
    Use when analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.
    10 repo stars
  56. ▌
    Conducting Mobile App Penetration Test · oyi77
    Use when conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface.
    10 repo stars
  57. ▌
    Deploying Active Directory Honeytokens · oyi77
    Use when deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
    10 repo stars
  58. ▌
    Deploying Tailscale For Zero Trust Vpn · oyi77
    Use when deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity. Use when deploying and configure tailscale as a wireguard-based zero trust mesh.
    10 repo stars
  59. ▌
    Detecting Attacks On Historian Servers · oyi77
    Use when detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities. . Use when working with detecting attacks on historian servers.
    10 repo stars
  60. ▌
    Detecting AWS Iam Privilege Escalation · oyi77
    Use when detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations. Use when detecting aws iam privilege escalation paths using boto3 and cloudsplaining.
    10 repo stars
  61. ▌
    Detecting Bluetooth Low Energy Attacks · oyi77
    Use when detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing.
    10 repo stars
  62. ▌
    Detecting Cloud Threats With Guardduty · oyi77
    Use when this skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda.
    10 repo stars
  63. ▌
    Detecting Command And Control Over Dns · oyi77
    Use when detecting command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development.
    10 repo stars
  64. ▌
    Detecting Lateral Movement With Splunk · oyi77
    Use when detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse. Use when detecting adversary lateral movement across networks using splunk spl queries.
    10 repo stars
  65. ▌
    Detecting Process Injection Techniques · oyi77
    Use when detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection. . Use when working with detecting process injection techniques.
    10 repo stars
  66. ▌
    Executing Phishing Simulation Campaign · oyi77
    Use when executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Use when working with executing phishing simulation campaign.
    10 repo stars
  67. ▌
    Executing Red Team Engagement Planning · oyi77
    Use when red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins. Use when working with executing red team engagement planning.
    10 repo stars
  68. ▌
    Exploiting Kerberoasting With Impacket · oyi77
    Use when perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts. Use when performing kerberoasting attacks using impacket's getuserspns to extract and crack.
    10 repo stars
  69. ▌
    Exploiting Server Side Request Forgery · oyi77
    Use when identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests. Use when working with exploiting server side request forgery.
    10 repo stars
  70. ▌
    Extracting Config From Agent Tesla Rat · oyi77
    Use when extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis. Use when working with extracting config from agent tesla rat.
    10 repo stars
  71. ▌
    Generating Threat Intelligence Reports · oyi77
    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments.
    10 repo stars
  72. ▌
    Hunting For Domain Fronting C2 Traffic · oyi77
    Use when detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection. Use when detecting domain fronting c2 traffic by analyzing sni vs http.
    10 repo stars
  73. ▌
    Hunting For Scheduled Task Persistence · oyi77
    Use when hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns. Use when hunting for adversary persistence via windows scheduled tasks by analyzing.
    10 repo stars
  74. ▌
    Hunting For Startup Folder Persistence · oyi77
    Use when detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring. Use when detecting t1547.001 startup folder persistence by monitoring windows startup directories.
    10 repo stars
  75. ▌
    Hunting For Suspicious Scheduled Tasks · oyi77
    Use when hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse. Use when hunting for adversary persistence and execution via windows scheduled tasks.
    10 repo stars
  76. ▌
    Hunting For T1098 Account Manipulation · oyi77
    Use when hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs. Use when hunting for mitre att&ck t1098 account manipulation including shadow admin.
    10 repo stars
  77. ▌
    Implementing API Key Security Controls · oyi77
    Use when implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Use when working with implementing api key security controls.
    10 repo stars
  78. ▌
    Implementing Attack Surface Management · oyi77
    Use when implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.
    10 repo stars
  79. ▌
    Implementing Patch Management Workflow · oyi77
    Use when patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc. Use when working with implementing patch management workflow.
    10 repo stars
  80. ▌
    Implementing Secrets Scanning In CI CD · oyi77
    Use when integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment. Use when integrateing gitleaks and trufflehog into ci/cd pipelines to detect leaked.
    10 repo stars
  81. ▌
    Implementing Usb Device Control Policy · oyi77
    Use when implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
    10 repo stars
  82. ▌
    Implementing Zero Trust Network Access · oyi77
    Use when implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP. . Use when working with implementing zero trust network access.
    10 repo stars
  83. ▌
    Performing AI Driven Osint Correlation · oyi77
    Use when use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis. Use when working with performing ai driven osint correlation.
    10 repo stars
  84. ▌
    Performing API Inventory And Discovery · oyi77
    Use when performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Use when working with performing api inventory and discovery.
    10 repo stars
  85. ▌
    Performing Directory Traversal Testing · oyi77
    Use when testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters. Use when working with performing directory traversal testing.
    10 repo stars
  86. ▌
    Performing GRAPHQL Security Assessment · oyi77
    Use when assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests. Use when working with performing graphql security assessment.
    10 repo stars
  87. ▌
    Performing IOS App Security Assessment · oyi77
    Use when performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls.
    10 repo stars
  88. ▌
    Recovering Deleted Files With Photorec · oyi77
    Use when recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage. Use when working with recovering deleted files with photorec.
    10 repo stars
  89. ▌
    Remediating S3 Bucket Misconfiguration · oyi77
    Use when this skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.
    10 repo stars
  90. ▌
    Reverse Engineering IOS App With Frida · oyi77
    Use when reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries.
    10 repo stars
  91. ▌
    Scanning Containers With Trivy In Cicd · oyi77
    Use when this skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images.
    10 repo stars
  92. ▌
    Securing Azure With Microsoft Defender · oyi77
    Use when this skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and databases, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal for centralized threat management.
    10 repo stars
  93. ▌
    Testing API Security With Owasp Top 10 · oyi77
    Use when systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
    10 repo stars
  94. ▌
    Testing Ransomware Recovery Procedures · oyi77
    Use when test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks. Use when testing and validate ransomware recovery procedures including backup restore operations,.
    10 repo stars
  95. ▌
    Acquiring Disk Image With Dd And Dcfldd · oyi77
    Use when create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification. Use when createing forensically sound bit-for-bit disk images using dd and dcfldd.
    10 repo stars
  96. ▌
    Analyzing Campaign Attribution Evidence · oyi77
    Use when campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr
    10 repo stars
  97. ▌
    Analyzing Mft For Deleted File Recovery · oyi77
    Use when analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics. Use when analyzeing the ntfs master file table ($mft) to recover metadata.
    10 repo stars
  98. ▌
    Analyzing Network Traffic For Incidents · oyi77
    Use when analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. '.
    10 repo stars
  99. ▌
    Analyzing Ransomware Network Indicators · oyi77
    Use when identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis. Use when working with analyzing ransomware network indicators.
    10 repo stars
  100. ▌
    Analyzing Usb Device Connection History · oyi77
    Use when investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration. Use when working with analyzing usb device connection history.
    10 repo stars