all publishers

oyi77

@oyi77 source repo

1,298 published skills · page 9 of 13

  1. ▌
    Subagent Driven Development · oyi77
    Use when executing implementation plans with independent tasks in the current session
    10 repo stars
  2. ▌
    Agent Reach Channels · oyi77 bundle
    Use when multi-platform e-commerce and messaging channel extraction (Shopee, TikTok Shop, WeChat)
    10 repo stars
  3. ▌
    Analyzing Cyber Kill Chain · oyi77
    Use when analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases.
    10 repo stars
  4. ▌
    Detecting Rootkit Activity · oyi77
    Use when detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis. . Use when working with detecting rootkit activity.
    10 repo stars
  5. ▌
    Hunting For Dcsync Attacks · oyi77
    Use when detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts. Use when detecting dcsync attacks by analyzing windows event id 4662 for.
    10 repo stars
  6. ▌
    Monitoring Darkweb Sources · oyi77
    Use when monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Use when working with monitoring darkweb sources.
    10 repo stars
  7. ▌
    Pentest Agent Orchestrator · oyi77
    Use when orchestrate 35 specialized Claude Code subagents for offensive security. Use when planning a pentest, routing tasks to specialist agents, or conducting multi-phase security assessments.
    10 repo stars
  8. ▌
    Testing JWT Token Security · oyi77
    Use when assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements. Use when working with testing jwt token security.
    10 repo stars
  9. ▌
    Triaging Security Incident · oyi77
    Use when performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis. . Use when working with triaging security incident.
    10 repo stars
  10. ▌
    Kalodata Storyboard Extract · oyi77
    Use when extracting AI-generated storyboards from viral TikTok Shop videos, including scene breakdowns, visual descriptions, camera work analysis, and auto-generating content ideas for replication.
    10 repo stars
  11. ▌
    Analyzing Linux Elf Malware · oyi77
    Use when analyzing malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
    10 repo stars
  12. ▌
    Detecting OAUTH Token Theft · oyi77
    Use when detecting and responding to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investiga...
    10 repo stars
  13. ▌
    Executing Red Team Exercise · oyi77
    Use when executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification.
    10 repo stars
  14. ▌
    Processing Stix Taxii Feeds · oyi77
    Use when processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.
    10 repo stars
  15. ▌
    Wallet Address Intelligence · oyi77
    Use when profile and cluster blockchain wallet addresses to identify entity associations, assess risk levels, and build address reputation intelligence across multiple chains. Use when analyzing wallet behavior, clustering related addresses, assessing counterparty risk, or building address intelligence reports.
    10 repo stars
  16. ▌
    Kalodata Research Automation · oyi77
    Use when end-to-end competitive analysis automation that combines product research, video analysis, and storyboard extraction into a single workflow. Accepts product search criteria and returns complete competitive analysis with viral product insights, video breakdowns, and content replication guides. Use when working with kalodata research automation.
    10 repo stars
  17. ▌
    Auditing GCP Iam Permissions · oyi77
    Use when auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender. . Use when working with auditing gcp iam permissions.
    10 repo stars
  18. ▌
    Correlating Threat Campaigns · oyi77
    Use when correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract shared indicators for improved detection. Use when multiple incidents exhibit overlapping indicators, when sector-wide attack campaigns require cross-organizational analysis, or when building campaign-level intelligence products.
    10 repo stars
  19. ▌
    Implementing Cloud Waf Rules · oyi77
    Use when this skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic protection, implementing rate limiting, deploying bot management, and reducing false positives through rule tuning and logging analysis.
    10 repo stars
  20. ▌
    Securing AWS Iam Permissions · oyi77
    Use when this skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential rotation strategies to reduce the blast radius of compromised identities.
    10 repo stars
  21. ▌
    Securing Kubernetes On Cloud · oyi77
    Use when this skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses cloud-specific security features including IRSA for EKS, Workload Identity for GKE, and Managed Identities for AKS.
    10 repo stars
  22. ▌
    Token Nft Scam Investigation · oyi77
    Use when investigate token and NFT scams including rug pulls, honeypot tokens, pump-and-dump schemes, wash trading, and NFT floor manipulation to identify fraudulent patterns and trace perpetrator wallets. Use when analyzing suspicious token launches, investigating NFT fraud, or detecting market manipulation.
    10 repo stars
  23. ▌
    Finishing A Development Branch · oyi77
    Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
    10 repo stars
  24. ▌
    Verification Before Completion · oyi77
    Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always
    10 repo stars
  25. ▌
    Hunting For Webshell Activity · oyi77
    Use when hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns. Use when hunting for web shell deployments on internet-facing servers by analyzing.
    10 repo stars
  26. ▌
    Implementing AWS Security Hub · oyi77
    Use when this skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations Benchmark, configuring automated remediation, and building executive dashboards for compliance tracking across multi-account AWS organizations.
    10 repo stars
  27. ▌
    Onchain Transaction Forensics · oyi77
    Use when trace and analyze blockchain transactions to investigate illicit fund flows, identify wallet clusters, and map transaction graphs across multiple blockchains. Use when investigating stolen funds, following money trails on-chain, analyzing suspicious addresses, or tracing cross-chain transactions.
    10 repo stars
  28. ▌
    Profiling Threat Actor Groups · oyi77
    Use when develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries.
    10 repo stars
  29. ▌
    Securing Serverless Functions · oyi77
    Use when this skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input validation, function URL authentication, and runtime monitoring to protect against injection attacks, credential theft, and supply chain compromises.
    10 repo stars
  30. ▌
    Testing Cors Misconfiguration · oyi77
    Use when identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments. Use when working with testing cors misconfiguration.
    10 repo stars
  31. ▌
    Building Soc Escalation Matrix · oyi77
    Use when build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents. Use when building a structured soc escalation matrix defining severity tiers, response.
    10 repo stars
  32. ▌
    Detecting Shadow API Endpoints · oyi77
    Use when discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms. Use when working with detecting shadow api endpoints.
    10 repo stars
  33. ▌
    Performing Ransomware Response · oyi77
    Use when executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment. '.
    10 repo stars
  34. ▌
    Performing Vlan Hopping Attack · oyi77
    Use when simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks. . Use when working with performing vlan hopping attack.
    10 repo stars
  35. ▌
    Testing Websocket API Security · oyi77
    Use when tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels.
    10 repo stars
  36. ▌
    Analyzing Kubernetes Audit Logs · oyi77
    Use when parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.
    10 repo stars
  37. ▌
    Analyzing Linux Kernel Rootkits · oyi77
    Use when detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures. Use when detecting kernel-level rootkits in linux memory dumps using volatility3 linux.
    10 repo stars
  38. ▌
    Conducting API Security Testing · oyi77
    Use when conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Use when working with conducting api security testing.
    10 repo stars
  39. ▌
    Configuring Hsm For Key Storage · oyi77
    Use when hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea. Use when working with configuring hsm for key storage.
    10 repo stars
  40. ▌
    Detecting Cryptomining In Cloud · oyi77
    Use when this skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
    10 repo stars
  41. ▌
    Detecting Kerberoasting Attacks · oyi77
    Use when detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking. Use when detecting kerberoasting attacks by monitoring for anomalous kerberos tgs requests.
    10 repo stars
  42. ▌
    Detecting Pass The Hash Attacks · oyi77
    Use when detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping. Use when detecting pass-the-hash attacks by analyzing ntlm authentication patterns, identifying type.
    10 repo stars
  43. ▌
    Detecting Service Account Abuse · oyi77
    Use when detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns. Use when detecting abuse of service accounts through anomalous interactive logons, privilege.
    10 repo stars
  44. ▌
    Detecting Shadow It Cloud Usage · oyi77
    Use when detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification. Use when detecting unauthorized saas and cloud service usage (shadow it) by.
    10 repo stars
  45. ▌
    Detecting Stuxnet Style Attacks · oyi77
    Use when this skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation from operators. It addresses PLC logic integrity monitoring, physics-based process anomaly detection, engineering workstation compromise indicators, USB-borne attack vectors, and multi-stage attack chain detection spanning IT-to-OT lateral movement through to process manipulation.
    10 repo stars
  46. ▌
    Exploiting Idor Vulnerabilities · oyi77
    Use when identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs. Use when working with exploiting idor vulnerabilities.
    10 repo stars
  47. ▌
    Exploiting Ipv6 Vulnerabilities · oyi77
    Use when identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses. . Use when working with exploiting ipv6 vulnerabilities.
    10 repo stars
  48. ▌
    Implementing Saml Sso With Okta · oyi77
    Use when implementing SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
    10 repo stars
  49. ▌
    Managing Intelligence Lifecycle · oyi77
    Use when manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers.
    10 repo stars
  50. ▌
    Mapping Mitre Attack Techniques · oyi77
    Use when maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
    10 repo stars
  51. ▌
    Performing Kerberoasting Attack · oyi77
    Use when kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names. Use when working with performing kerberoasting attack.
    10 repo stars
  52. ▌
    Performing Purple Team Exercise · oyi77
    Use when performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
    10 repo stars
  53. ▌
    Performing Ssl Stripping Attack · oyi77
    Use when simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections. . Use when working with performing ssl stripping attack.
    10 repo stars
  54. ▌
    Securing Helm Chart Deployments · oyi77
    Use when secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases. Use when working with securing helm chart deployments.
    10 repo stars
  55. ▌
    Testing For Xss Vulnerabilities · oyi77
    Use when tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies all injection points and output contexts, crafts context-appropriate payloads, and bypasses sanitization and CSP protections. Use when working with testing for xss vulnerabilities.
    10 repo stars
  56. ▌
    Analyzing Linux System Artifacts · oyi77
    Use when examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity. Use when working with analyzing linux system artifacts.
    10 repo stars
  57. ▌
    Analyzing PDF Malware With Pdfid · oyi77
    Use when analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage. . Use when working with analyzing pdf malware with pdfid.
    10 repo stars
  58. ▌
    Auditing Kubernetes Cluster Rbac · oyi77
    Use when auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit. . Use when working with auditing kubernetes cluster rbac.
    10 repo stars
  59. ▌
    Deobfuscating Javascript Malware · oyi77
    Use when deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic. Activates for requests involving JavaScript malware analysis, script deobfuscation, web skimmer analysis, or obfuscated dropper investigation. . Use when working with deobfuscating javascript malware.
    10 repo stars
  60. ▌
    Detecting Azure Lateral Movement · oyi77
    Use when detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting. Use when detecting lateral movement in azure ad/entra id environments using microsoft.
    10 repo stars
  61. ▌
    Exploiting Broken Link Hijacking · oyi77
    Use when discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker. Use when working with exploiting broken link hijacking.
    10 repo stars
  62. ▌
    Hunting For Shadow Copy Deletion · oyi77
    Use when hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands. Use when hunting for volume shadow copy deletion activity that indicates ransomware.
    10 repo stars
  63. ▌
    Implementing Zero Trust In Cloud · oyi77
    Use when this skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.
    10 repo stars
  64. ▌
    Performing Osint With Spiderfoot · oyi77
    Use when automating OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources
    10 repo stars
  65. ▌
    Performing Service Account Audit · oyi77
    Use when auditing service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
    10 repo stars
  66. ▌
    Performing Soc Tabletop Exercise · oyi77
    Use when performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
    10 repo stars
  67. ▌
    Reverse Engineering Rust Malware · oyi77
    Use when reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis. Use when reverseing engineer rust-compiled malware using ida pro and ghidra with.
    10 repo stars
  68. ▌
    Analyzing Disk Image With Autopsy · oyi77
    Use when perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines. Use when performing comprehensive forensic analysis of disk images using autopsy to.
    10 repo stars
  69. ▌
    Analyzing Heap Spray Exploitation · oyi77
    Use when detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space. Use when detecting and analyze heap spray attacks in memory dumps using.
    10 repo stars
  70. ▌
    Building Cloud Siem With Sentinel · oyi77
    Use when this skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.
    10 repo stars
  71. ▌
    Conducting Pass The Ticket Attack · oyi77
    Use when pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro. Use when working with conducting pass the ticket attack.
    10 repo stars
  72. ▌
    Deploying Ransomware Canary Files · oyi77
    Use when deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Use when working with deploying ransomware canary files.
    10 repo stars
  73. ▌
    Detecting API Enumeration Attacks · oyi77
    Use when detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures. Use when detecting and prevent api enumeration attacks including bola and idor.
    10 repo stars
  74. ▌
    Detecting Dll Sideloading Attacks · oyi77
    Use when detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion. Use when detecting dll side-loading attacks where adversaries place malicious dlls alongside.
    10 repo stars
  75. ▌
    Detecting Dnp3 Protocol Anomalies · oyi77
    Use when detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches. . Use when working with detecting dnp3 protocol anomalies.
    10 repo stars
  76. ▌
    Detecting Mobile Malware Behavior · oyi77
    Use when detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
    10 repo stars
  77. ▌
    Detecting Pass The Ticket Attacks · oyi77
    Use when detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM. Use when detecting kerberos pass-the-ticket (ptt) attacks by analyzing windows event ids.
    10 repo stars
  78. ▌
    Detecting Rdp Brute Force Attacks · oyi77
    Use when detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis. Use when detecting rdp brute force attacks by analyzing windows security event.
    10 repo stars
  79. ▌
    Exploiting HTTP Request Smuggling · oyi77
    Use when detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers. Use when working with exploiting http request smuggling.
    10 repo stars
  80. ▌
    Exploiting OAUTH Misconfiguration · oyi77
    Use when identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments. Use when working with exploiting oauth misconfiguration.
    10 repo stars
  81. ▌
    Hunting For Dcom Lateral Movement · oyi77
    Use when hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation, WMI event analysis, RPC endpoint mapper traffic on port 135, and DCOM-specific parent-child process relationships. . Use when working with hunting for dcom lateral movement.
    10 repo stars
  82. ▌
    Hunting For Dns Based Persistence · oyi77
    Use when hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis. Use when hunting for dns-based persistence mechanisms including dns hijacking, dangling cname.
    10 repo stars
  83. ▌
    Implementing Siem Use Case Tuning · oyi77
    Use when tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic. Use when working with implementing siem use case tuning.
    10 repo stars
  84. ▌
    Managing Cloud Identity With Okta · oyi77
    Use when this skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
    10 repo stars
  85. ▌
    Performing Csrf Attack Simulation · oyi77
    Use when testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments. Use when working with performing csrf attack simulation.
    10 repo stars
  86. ▌
    Performing Malware Ioc Extraction · oyi77
    Use when malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist. Use when working with performing malware ioc extraction.
    10 repo stars
  87. ▌
    Performing Security Headers Audit · oyi77
    Use when auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections. Use when working with performing security headers audit.
    10 repo stars
  88. ▌
    Recovering From Ransomware Attack · oyi77
    Use when executing structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order.
    10 repo stars
  89. ▌
    Scanning Docker Images With Trivy · oyi77
    Use when trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati. Use when working with scanning docker images with trivy.
    10 repo stars
  90. ▌
    Securing API Gateway With AWS Waf · oyi77
    Use when securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness. . Use when working with securing api gateway with aws waf.
    10 repo stars
  91. ▌
    Securing Github Actions Workflows · oyi77
    Use when this skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
    10 repo stars
  92. ▌
    Testing For Broken Access Control · oyi77
    Use when systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references. Use when working with testing for broken access control.
    10 repo stars
  93. ▌
    Testing For Host Header Injection · oyi77
    Use when test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks. Use when testing web applications for http host header injection vulnerabilities to.
    10 repo stars
  94. ▌
    Testing Mobile API Authentication · oyi77
    Use when tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management.
    10 repo stars
  95. ▌
    Analyzing Indicators Of Compromise · oyi77
    Use when analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.
    10 repo stars
  96. ▌
    Analyzing Uefi Bootkit Persistence · oyi77
    Use when analyzing UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing.
    10 repo stars
  97. ▌
    Auditing AWS S3 Bucket Permissions · oyi77
    Use when systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls. . Use when working with auditing aws s3 bucket permissions.
    10 repo stars
  98. ▌
    Auditing Cloud With Cis Benchmarks · oyi77
    Use when this skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP.
    10 repo stars
  99. ▌
    Conducting Cloud Incident Response · oyi77
    Use when responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Activates for requests involving cloud incident response, AWS security incident, Azure compromise, GCP breach, cloud forensics, or cloud identity compromise. . Use when working with conducting cloud incident response.
    10 repo stars
  100. ▌
    Configuring Pfsense Firewall Rules · oyi77
    Use when configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments. . Use when working with configuring pfsense firewall rules.
    10 repo stars