oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Detecting Lateral Movement With Zeek · oyi77Use when detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections. . Use when working with detecting lateral movement with zeek.
- ▌ Exploiting SQL Injection With Sqlmap · oyi77Use when detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. Use when working with exploiting sql injection with sqlmap.
- ▌ Exploiting Websocket Vulnerabilities · oyi77Use when testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments. Use when working with exploiting websocket vulnerabilities.
- ▌ Extracting Browser History Artifacts · oyi77Use when extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity. Use when working with extracting browser history artifacts.
- ▌ Extracting Iocs From Malware Samples · oyi77Use when extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples. . Use when working with extracting iocs from malware samples.
- ▌ Hunting For Lateral Movement Via Wmi · oyi77Use when detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence. Use when detecting wmi-based lateral movement by analyzing windows event id 4688.
- ▌ Hunting For Spearphishing Indicators · oyi77Use when hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks. Use when hunting for spearphishing campaign indicators across email logs, endpoint telemetry,.
- ▌ Implementing Alert Fatigue Reduction · oyi77Use when implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.
- ▌ Implementing Pam For Database Access · oyi77Use when deploying privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
- ▌ Implementing Rsa Key Pair Management · oyi77Use when RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,
- ▌ Performing Container Image Hardening · oyi77Use when this skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.
- ▌ Performing Firmware Malware Analysis · oyi77Use when analyzing firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
- ▌ Performing Ioc Enrichment Automation · oyi77Use when automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source enrichment of IPs, domains, URLs, and file hashes during alert triage or incident investigation.
- ▌ Performing JWT None Algorithm Attack · oyi77Use when execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens. Use when working with performing jwt none algorithm attack.
- ▌ Performing Privacy Impact Assessment · oyi77Use when automating the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework PRAM methodology and ICO DPIA guidance for systematic identification and mitigation of privacy risks across processing activities.
- ▌ Performing Sqlite Database Forensics · oyi77Use when perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases. Use when performing forensic analysis of sqlite databases to recover deleted records.
- ▌ Scanning Container Images With Grype · oyi77Use when scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds. Use when scaning container images for known vulnerabilities using anchore grype with.
- ▌ Tracking Threat Actor Infrastructure · oyi77Use when threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a. Use when working with tracking threat actor infrastructure.
- ▌ Analyzing Bootkit And Rootkit Samples · oyi77Use when analyzing bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.
- ▌ Analyzing Powershell Empire Artifacts · oyi77Use when detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events. Use when detecting powershell empire framework artifacts in windows event logs by.
- ▌ Building Soc Metrics And Kpi Tracking · oyi77Use when builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
- ▌ Building Threat Intelligence Platform · oyi77Use when building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T. Use when working with building threat intelligence platform.
- ▌ Conducting Phishing Incident Response · oyi77Use when responding to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email incident, credential phishing, spear phishing investigation, or phishing remediation.
- ▌ Configuring Oauth2 Authorization Flow · oyi77Use when configuring secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token
- ▌ Correlating Security Events In Qradar · oyi77Use when correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
- ▌ Detecting Fileless Malware Techniques · oyi77Use when detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination. . Use when working with detecting fileless malware techniques.
- ▌ Detecting Lateral Movement In Network · oyi77Use when identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems. . Use when working with detecting lateral movement in network.
- ▌ Detecting Living Off The Land Attacks · oyi77Use when detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns. . Use when working with detecting living off the land attacks.
- ▌ Detecting Mimikatz Execution Patterns · oyi77Use when detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules. Use when detecting mimikatz execution through command-line patterns, lsass access signatures, binary.
- ▌ Detecting Misconfigured Azure Storage · oyi77Use when detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage. . Use when working with detecting misconfigured azure storage.
- ▌ Detecting Network Anomalies With Zeek · oyi77Use when deploying and configuring Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
- ▌ Detecting Port Scanning With Fail2ban · oyi77Use when configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. . Use when working with detecting port scanning with fail2ban.
- ▌ Detecting Process Hollowing Technique · oyi77Use when detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry. Use when detecting process hollowing (t1055.012) by analyzing memory-mapped sections, hollowed process.
- ▌ Exploiting Nopac Cve 2021 42278 42287 · oyi77Use when exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments. Use when exploiting the nopac vulnerability chain (cve-2021-42278 samaccountname spoofing and cve-2021-42287.
- ▌ Hardening Docker Daemon Configuration · oyi77Use when harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls. Use when working with hardening docker daemon configuration.
- ▌ Implementing Azure Defender For Cloud · oyi77Use when implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.
- ▌ Implementing Cloud Trail Log Analysis · oyi77Use when implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity. . Use when working with implementing cloud trail log analysis.
- ▌ Implementing Ebpf Security Monitoring · oyi77Use when implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
- ▌ Implementing GCP Binary Authorization · oyi77Use when implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run. Use when implementing gcp binary authorization to enforce deploy-time security controls that.
- ▌ Implementing Ics Firewall With Tofino · oyi77Use when deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones. . Use when working with implementing ics firewall with tofino.
- ▌ Implementing Iec 62443 Security Zones · oyi77Use when this skill covers designing and implementing security zones and conduits for industrial automation and control systems (IACS) per IEC 62443-3-2. It addresses zone partitioning based on risk assessment, assigning Security Level targets (SL-T), designing conduit security controls, implementing microsegmentation with industrial firewalls, and validating zone architecture through traffic analysis and penetration testing against the Purdue Reference Model.
- ▌ Investigating Phishing Email Incident · oyi77Use when investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
- ▌ Performing File Carving With Foremost · oyi77Use when recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state. Use when working with performing file carving with foremost.
- ▌ Performing GRAPHQL Depth Limit Attack · oyi77Use when execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs. Use when working with performing graphql depth limit attack.
- ▌ Performing Hash Cracking With Hashcat · oyi77Use when hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w. Use when working with performing hash cracking with hashcat.
- ▌ Performing Lateral Movement Detection · oyi77Use when detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques. . Use when working with performing lateral movement detection.
- ▌ Performing Purple Team Atomic Testing · oyi77Use when executing Atomic Red Team tests mapped to MITRE ATT&CK techniques, performing coverage gap analysis across the ATT&CK matrix, and running detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines.
- ▌ Performing Second Order SQL Injection · oyi77Use when detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. Use when detecting and exploit second-order sql injection vulnerabilities where malicious input.
- ▌ Performing Web Cache Deception Attack · oyi77Use when execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content. Use when working with performing web cache deception attack.
- ▌ Performing Web Cache Poisoning Attack · oyi77Use when exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests. Use when working with performing web cache poisoning attack.
- ▌ Testing API Authentication Weaknesses · oyi77Use when tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Use when working with testing api authentication weaknesses.
- ▌ Oh My Opencode Features · oyi77Use when complete reference of all oh-my-opencode features including agents, tools, MCPs, hooks, workflow automation, and productivity enhancements. Use when working with oh my opencode features.
- ▌ Analyzing Android Malware With Apktool · oyi77Use when perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection. Use when performing static analysis of android apk malware samples using apktool.
- ▌ Analyzing Memory Dumps With Volatility · oyi77Use when analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation. . Use when working with analyzing memory dumps with volatility.
- ▌ Analyzing Windows Event Logs In Splunk · oyi77Use when analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.
- ▌ Conducting Mobile App Penetration Test · oyi77Use when conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface.
- ▌ Deploying Active Directory Honeytokens · oyi77Use when deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
- ▌ Deploying Tailscale For Zero Trust Vpn · oyi77Use when deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity. Use when deploying and configure tailscale as a wireguard-based zero trust mesh.
- ▌ Detecting Attacks On Historian Servers · oyi77Use when detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities. . Use when working with detecting attacks on historian servers.
- ▌ Detecting AWS Iam Privilege Escalation · oyi77Use when detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations. Use when detecting aws iam privilege escalation paths using boto3 and cloudsplaining.
- ▌ Detecting Bluetooth Low Energy Attacks · oyi77Use when detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing.
- ▌ Detecting Cloud Threats With Guardduty · oyi77Use when this skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda.
- ▌ Detecting Command And Control Over Dns · oyi77Use when detecting command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development.
- ▌ Detecting Lateral Movement With Splunk · oyi77Use when detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse. Use when detecting adversary lateral movement across networks using splunk spl queries.
- ▌ Detecting Process Injection Techniques · oyi77Use when detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection. . Use when working with detecting process injection techniques.
- ▌ Executing Phishing Simulation Campaign · oyi77Use when executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Use when working with executing phishing simulation campaign.
- ▌ Executing Red Team Engagement Planning · oyi77Use when red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins. Use when working with executing red team engagement planning.
- ▌ Exploiting Kerberoasting With Impacket · oyi77Use when perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts. Use when performing kerberoasting attacks using impacket's getuserspns to extract and crack.
- ▌ Exploiting Server Side Request Forgery · oyi77Use when identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests. Use when working with exploiting server side request forgery.
- ▌ Extracting Config From Agent Tesla Rat · oyi77Use when extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis. Use when working with extracting config from agent tesla rat.
- ▌ Generating Threat Intelligence Reports · oyi77Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments.
- ▌ Hunting For Domain Fronting C2 Traffic · oyi77Use when detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection. Use when detecting domain fronting c2 traffic by analyzing sni vs http.
- ▌ Hunting For Scheduled Task Persistence · oyi77Use when hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns. Use when hunting for adversary persistence via windows scheduled tasks by analyzing.
- ▌ Hunting For Startup Folder Persistence · oyi77Use when detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring. Use when detecting t1547.001 startup folder persistence by monitoring windows startup directories.
- ▌ Hunting For Suspicious Scheduled Tasks · oyi77Use when hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse. Use when hunting for adversary persistence and execution via windows scheduled tasks.
- ▌ Hunting For T1098 Account Manipulation · oyi77Use when hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs. Use when hunting for mitre att&ck t1098 account manipulation including shadow admin.
- ▌ Implementing API Key Security Controls · oyi77Use when implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Use when working with implementing api key security controls.
- ▌ Implementing Attack Surface Management · oyi77Use when implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.
- ▌ Implementing Patch Management Workflow · oyi77Use when patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc. Use when working with implementing patch management workflow.
- ▌ Implementing Secrets Scanning In CI CD · oyi77Use when integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment. Use when integrateing gitleaks and trufflehog into ci/cd pipelines to detect leaked.
- ▌ Implementing Usb Device Control Policy · oyi77Use when implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
- ▌ Implementing Zero Trust Network Access · oyi77Use when implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP. . Use when working with implementing zero trust network access.
- ▌ Performing AI Driven Osint Correlation · oyi77Use when use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis. Use when working with performing ai driven osint correlation.
- ▌ Performing API Inventory And Discovery · oyi77Use when performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Use when working with performing api inventory and discovery.
- ▌ Performing Directory Traversal Testing · oyi77Use when testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters. Use when working with performing directory traversal testing.
- ▌ Performing GRAPHQL Security Assessment · oyi77Use when assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests. Use when working with performing graphql security assessment.
- ▌ Performing IOS App Security Assessment · oyi77Use when performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls.
- ▌ Recovering Deleted Files With Photorec · oyi77Use when recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage. Use when working with recovering deleted files with photorec.
- ▌ Remediating S3 Bucket Misconfiguration · oyi77Use when this skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.
- ▌ Reverse Engineering IOS App With Frida · oyi77Use when reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries.
- ▌ Scanning Containers With Trivy In Cicd · oyi77Use when this skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images.
- ▌ Securing Azure With Microsoft Defender · oyi77Use when this skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and databases, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal for centralized threat management.
- ▌ Testing API Security With Owasp Top 10 · oyi77Use when systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
- ▌ Testing Ransomware Recovery Procedures · oyi77Use when test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks. Use when testing and validate ransomware recovery procedures including backup restore operations,.
- ▌ Acquiring Disk Image With Dd And Dcfldd · oyi77Use when create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification. Use when createing forensically sound bit-for-bit disk images using dd and dcfldd.
- ▌ Analyzing Campaign Attribution Evidence · oyi77Use when campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr
- ▌ Analyzing Mft For Deleted File Recovery · oyi77Use when analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics. Use when analyzeing the ntfs master file table ($mft) to recover metadata.
- ▌ Analyzing Network Traffic For Incidents · oyi77Use when analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. '.
- ▌ Analyzing Ransomware Network Indicators · oyi77Use when identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis. Use when working with analyzing ransomware network indicators.
- ▌ Analyzing Usb Device Connection History · oyi77Use when investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration. Use when working with analyzing usb device connection history.