oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Subagent Driven Development · oyi77Use when executing implementation plans with independent tasks in the current session
- ▌ Agent Reach Channels · oyi77 bundleUse when multi-platform e-commerce and messaging channel extraction (Shopee, TikTok Shop, WeChat)
- ▌ Analyzing Cyber Kill Chain · oyi77Use when analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases.
- ▌ Detecting Rootkit Activity · oyi77Use when detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis. . Use when working with detecting rootkit activity.
- ▌ Hunting For Dcsync Attacks · oyi77Use when detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts. Use when detecting dcsync attacks by analyzing windows event id 4662 for.
- ▌ Monitoring Darkweb Sources · oyi77Use when monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Use when working with monitoring darkweb sources.
- ▌ Pentest Agent Orchestrator · oyi77Use when orchestrate 35 specialized Claude Code subagents for offensive security. Use when planning a pentest, routing tasks to specialist agents, or conducting multi-phase security assessments.
- ▌ Testing JWT Token Security · oyi77Use when assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements. Use when working with testing jwt token security.
- ▌ Triaging Security Incident · oyi77Use when performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis. . Use when working with triaging security incident.
- ▌ Kalodata Storyboard Extract · oyi77Use when extracting AI-generated storyboards from viral TikTok Shop videos, including scene breakdowns, visual descriptions, camera work analysis, and auto-generating content ideas for replication.
- ▌ Analyzing Linux Elf Malware · oyi77Use when analyzing malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
- ▌ Detecting OAUTH Token Theft · oyi77Use when detecting and responding to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investiga...
- ▌ Executing Red Team Exercise · oyi77Use when executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification.
- ▌ Processing Stix Taxii Feeds · oyi77Use when processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.
- ▌ Wallet Address Intelligence · oyi77Use when profile and cluster blockchain wallet addresses to identify entity associations, assess risk levels, and build address reputation intelligence across multiple chains. Use when analyzing wallet behavior, clustering related addresses, assessing counterparty risk, or building address intelligence reports.
- ▌ Kalodata Research Automation · oyi77Use when end-to-end competitive analysis automation that combines product research, video analysis, and storyboard extraction into a single workflow. Accepts product search criteria and returns complete competitive analysis with viral product insights, video breakdowns, and content replication guides. Use when working with kalodata research automation.
- ▌ Auditing GCP Iam Permissions · oyi77Use when auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender. . Use when working with auditing gcp iam permissions.
- ▌ Correlating Threat Campaigns · oyi77Use when correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract shared indicators for improved detection. Use when multiple incidents exhibit overlapping indicators, when sector-wide attack campaigns require cross-organizational analysis, or when building campaign-level intelligence products.
- ▌ Implementing Cloud Waf Rules · oyi77Use when this skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic protection, implementing rate limiting, deploying bot management, and reducing false positives through rule tuning and logging analysis.
- ▌ Securing AWS Iam Permissions · oyi77Use when this skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential rotation strategies to reduce the blast radius of compromised identities.
- ▌ Securing Kubernetes On Cloud · oyi77Use when this skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses cloud-specific security features including IRSA for EKS, Workload Identity for GKE, and Managed Identities for AKS.
- ▌ Token Nft Scam Investigation · oyi77Use when investigate token and NFT scams including rug pulls, honeypot tokens, pump-and-dump schemes, wash trading, and NFT floor manipulation to identify fraudulent patterns and trace perpetrator wallets. Use when analyzing suspicious token launches, investigating NFT fraud, or detecting market manipulation.
- ▌ Finishing A Development Branch · oyi77Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
- ▌ Verification Before Completion · oyi77Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always
- ▌ Hunting For Webshell Activity · oyi77Use when hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns. Use when hunting for web shell deployments on internet-facing servers by analyzing.
- ▌ Implementing AWS Security Hub · oyi77Use when this skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations Benchmark, configuring automated remediation, and building executive dashboards for compliance tracking across multi-account AWS organizations.
- ▌ Onchain Transaction Forensics · oyi77Use when trace and analyze blockchain transactions to investigate illicit fund flows, identify wallet clusters, and map transaction graphs across multiple blockchains. Use when investigating stolen funds, following money trails on-chain, analyzing suspicious addresses, or tracing cross-chain transactions.
- ▌ Profiling Threat Actor Groups · oyi77Use when develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries.
- ▌ Securing Serverless Functions · oyi77Use when this skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input validation, function URL authentication, and runtime monitoring to protect against injection attacks, credential theft, and supply chain compromises.
- ▌ Testing Cors Misconfiguration · oyi77Use when identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments. Use when working with testing cors misconfiguration.
- ▌ Building Soc Escalation Matrix · oyi77Use when build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents. Use when building a structured soc escalation matrix defining severity tiers, response.
- ▌ Detecting Shadow API Endpoints · oyi77Use when discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms. Use when working with detecting shadow api endpoints.
- ▌ Performing Ransomware Response · oyi77Use when executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment. '.
- ▌ Performing Vlan Hopping Attack · oyi77Use when simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks. . Use when working with performing vlan hopping attack.
- ▌ Testing Websocket API Security · oyi77Use when tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels.
- ▌ Analyzing Kubernetes Audit Logs · oyi77Use when parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.
- ▌ Analyzing Linux Kernel Rootkits · oyi77Use when detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures. Use when detecting kernel-level rootkits in linux memory dumps using volatility3 linux.
- ▌ Conducting API Security Testing · oyi77Use when conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Use when working with conducting api security testing.
- ▌ Configuring Hsm For Key Storage · oyi77Use when hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea. Use when working with configuring hsm for key storage.
- ▌ Detecting Cryptomining In Cloud · oyi77Use when this skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
- ▌ Detecting Kerberoasting Attacks · oyi77Use when detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking. Use when detecting kerberoasting attacks by monitoring for anomalous kerberos tgs requests.
- ▌ Detecting Pass The Hash Attacks · oyi77Use when detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping. Use when detecting pass-the-hash attacks by analyzing ntlm authentication patterns, identifying type.
- ▌ Detecting Service Account Abuse · oyi77Use when detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns. Use when detecting abuse of service accounts through anomalous interactive logons, privilege.
- ▌ Detecting Shadow It Cloud Usage · oyi77Use when detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification. Use when detecting unauthorized saas and cloud service usage (shadow it) by.
- ▌ Detecting Stuxnet Style Attacks · oyi77Use when this skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation from operators. It addresses PLC logic integrity monitoring, physics-based process anomaly detection, engineering workstation compromise indicators, USB-borne attack vectors, and multi-stage attack chain detection spanning IT-to-OT lateral movement through to process manipulation.
- ▌ Exploiting Idor Vulnerabilities · oyi77Use when identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs. Use when working with exploiting idor vulnerabilities.
- ▌ Exploiting Ipv6 Vulnerabilities · oyi77Use when identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses. . Use when working with exploiting ipv6 vulnerabilities.
- ▌ Implementing Saml Sso With Okta · oyi77Use when implementing SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
- ▌ Managing Intelligence Lifecycle · oyi77Use when manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers.
- ▌ Mapping Mitre Attack Techniques · oyi77Use when maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
- ▌ Performing Kerberoasting Attack · oyi77Use when kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names. Use when working with performing kerberoasting attack.
- ▌ Performing Purple Team Exercise · oyi77Use when performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
- ▌ Performing Ssl Stripping Attack · oyi77Use when simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections. . Use when working with performing ssl stripping attack.
- ▌ Securing Helm Chart Deployments · oyi77Use when secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases. Use when working with securing helm chart deployments.
- ▌ Testing For Xss Vulnerabilities · oyi77Use when tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies all injection points and output contexts, crafts context-appropriate payloads, and bypasses sanitization and CSP protections. Use when working with testing for xss vulnerabilities.
- ▌ Analyzing Linux System Artifacts · oyi77Use when examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity. Use when working with analyzing linux system artifacts.
- ▌ Analyzing PDF Malware With Pdfid · oyi77Use when analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage. . Use when working with analyzing pdf malware with pdfid.
- ▌ Auditing Kubernetes Cluster Rbac · oyi77Use when auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit. . Use when working with auditing kubernetes cluster rbac.
- ▌ Deobfuscating Javascript Malware · oyi77Use when deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic. Activates for requests involving JavaScript malware analysis, script deobfuscation, web skimmer analysis, or obfuscated dropper investigation. . Use when working with deobfuscating javascript malware.
- ▌ Detecting Azure Lateral Movement · oyi77Use when detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting. Use when detecting lateral movement in azure ad/entra id environments using microsoft.
- ▌ Exploiting Broken Link Hijacking · oyi77Use when discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker. Use when working with exploiting broken link hijacking.
- ▌ Hunting For Shadow Copy Deletion · oyi77Use when hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands. Use when hunting for volume shadow copy deletion activity that indicates ransomware.
- ▌ Implementing Zero Trust In Cloud · oyi77Use when this skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.
- ▌ Performing Osint With Spiderfoot · oyi77Use when automating OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources
- ▌ Performing Service Account Audit · oyi77Use when auditing service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
- ▌ Performing Soc Tabletop Exercise · oyi77Use when performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
- ▌ Reverse Engineering Rust Malware · oyi77Use when reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis. Use when reverseing engineer rust-compiled malware using ida pro and ghidra with.
- ▌ Analyzing Disk Image With Autopsy · oyi77Use when perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines. Use when performing comprehensive forensic analysis of disk images using autopsy to.
- ▌ Analyzing Heap Spray Exploitation · oyi77Use when detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space. Use when detecting and analyze heap spray attacks in memory dumps using.
- ▌ Building Cloud Siem With Sentinel · oyi77Use when this skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.
- ▌ Conducting Pass The Ticket Attack · oyi77Use when pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro. Use when working with conducting pass the ticket attack.
- ▌ Deploying Ransomware Canary Files · oyi77Use when deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Use when working with deploying ransomware canary files.
- ▌ Detecting API Enumeration Attacks · oyi77Use when detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures. Use when detecting and prevent api enumeration attacks including bola and idor.
- ▌ Detecting Dll Sideloading Attacks · oyi77Use when detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion. Use when detecting dll side-loading attacks where adversaries place malicious dlls alongside.
- ▌ Detecting Dnp3 Protocol Anomalies · oyi77Use when detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches. . Use when working with detecting dnp3 protocol anomalies.
- ▌ Detecting Mobile Malware Behavior · oyi77Use when detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
- ▌ Detecting Pass The Ticket Attacks · oyi77Use when detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM. Use when detecting kerberos pass-the-ticket (ptt) attacks by analyzing windows event ids.
- ▌ Detecting Rdp Brute Force Attacks · oyi77Use when detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis. Use when detecting rdp brute force attacks by analyzing windows security event.
- ▌ Exploiting HTTP Request Smuggling · oyi77Use when detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers. Use when working with exploiting http request smuggling.
- ▌ Exploiting OAUTH Misconfiguration · oyi77Use when identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments. Use when working with exploiting oauth misconfiguration.
- ▌ Hunting For Dcom Lateral Movement · oyi77Use when hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation, WMI event analysis, RPC endpoint mapper traffic on port 135, and DCOM-specific parent-child process relationships. . Use when working with hunting for dcom lateral movement.
- ▌ Hunting For Dns Based Persistence · oyi77Use when hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis. Use when hunting for dns-based persistence mechanisms including dns hijacking, dangling cname.
- ▌ Implementing Siem Use Case Tuning · oyi77Use when tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic. Use when working with implementing siem use case tuning.
- ▌ Managing Cloud Identity With Okta · oyi77Use when this skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
- ▌ Performing Csrf Attack Simulation · oyi77Use when testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments. Use when working with performing csrf attack simulation.
- ▌ Performing Malware Ioc Extraction · oyi77Use when malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist. Use when working with performing malware ioc extraction.
- ▌ Performing Security Headers Audit · oyi77Use when auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections. Use when working with performing security headers audit.
- ▌ Recovering From Ransomware Attack · oyi77Use when executing structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order.
- ▌ Scanning Docker Images With Trivy · oyi77Use when trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati. Use when working with scanning docker images with trivy.
- ▌ Securing API Gateway With AWS Waf · oyi77Use when securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness. . Use when working with securing api gateway with aws waf.
- ▌ Securing Github Actions Workflows · oyi77Use when this skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
- ▌ Testing For Broken Access Control · oyi77Use when systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references. Use when working with testing for broken access control.
- ▌ Testing For Host Header Injection · oyi77Use when test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks. Use when testing web applications for http host header injection vulnerabilities to.
- ▌ Testing Mobile API Authentication · oyi77Use when tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management.
- ▌ Analyzing Indicators Of Compromise · oyi77Use when analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.
- ▌ Analyzing Uefi Bootkit Persistence · oyi77Use when analyzing UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing.
- ▌ Auditing AWS S3 Bucket Permissions · oyi77Use when systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls. . Use when working with auditing aws s3 bucket permissions.
- ▌ Auditing Cloud With Cis Benchmarks · oyi77Use when this skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP.
- ▌ Conducting Cloud Incident Response · oyi77Use when responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Activates for requests involving cloud incident response, AWS security incident, Azure compromise, GCP breach, cloud forensics, or cloud identity compromise. . Use when working with conducting cloud incident response.
- ▌ Configuring Pfsense Firewall Rules · oyi77Use when configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments. . Use when working with configuring pfsense firewall rules.