all publishers

peteedoo

@peteedoo source repo

420 published skills · page 1 of 5

  1. ▌
    Operating Havoc C2 2 · peteedoo bundle
    Deploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary emulation.
    0 repo stars
  2. ▌
    Operating Sliver C2 2 · peteedoo bundle
    Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
    0 repo stars
  3. ▌
    Exploiting AWS With Pacu 2 · peteedoo bundle
    Use Pacu modules for AWS privilege escalation, persistence, and backdooring.
    0 repo stars
  4. ▌
    Hunting Evtx With Chainsaw 2 · peteedoo bundle
    Perform rapid Sigma and keyword hunting across Windows event logs with Chainsaw.
    0 repo stars
  5. ▌
    Triaging Windows With Kape 2 · peteedoo bundle
    Run targeted forensic artifact collection and module parsing with KAPE.
    0 repo stars
  6. ▌
    Analyzing Linux Elf Malware 2 · peteedoo bundle
    Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
    0 repo stars
  7. ▌
    Detecting OAUTH Token Theft 2 · peteedoo bundle
    Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
    0 repo stars
  8. ▌
    Escaping Containers To Host 2 · peteedoo bundle
    Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
    0 repo stars
  9. ▌
    Red Teaming Llms With Garak 2 · peteedoo bundle
    Run NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
    0 repo stars
  10. ▌
    Relaying Ntlm For Adcs Esc8 2 · peteedoo bundle
    Run ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
    0 repo stars
  11. ▌
    Detecting Secure Boot Bypass 2 · peteedoo bundle
    Detect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.
    0 repo stars
  12. ▌
    Exploiting Adcs With Certipy 2 · peteedoo bundle
    Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
    0 repo stars
  13. ▌
    Hunting Saas Sso Token Abuse 2 · peteedoo bundle
    Detect SSO and OAuth token replay and SaaS lateral movement.
    0 repo stars
  14. ▌
    Securing AWS Iam Permissions 2 · peteedoo bundle
    This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential rotation strategies to reduce the blast radius of compromised identities.
    0 repo stars
  15. ▌
    Modeling Threats With Opencti 2 · peteedoo bundle
    Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
    0 repo stars
  16. ▌
    Moving Laterally With Netexec 2 · peteedoo bundle
    Use NetExec for SMB, WinRM, LDAP, and MSSQL enumeration, password spraying, and execution.
    0 repo stars
  17. ▌
    Defending Llms With Guardrails 2 · peteedoo bundle
    Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
    0 repo stars
  18. ▌
    Detecting Dependency Confusion 2 · peteedoo bundle
    Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.
    0 repo stars
  19. ▌
    Generating And Analyzing Sboms 2 · peteedoo bundle
    Produce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.
    0 repo stars
  20. ▌
    Performing Ransomware Response 2 · peteedoo bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.
    0 repo stars
  21. ▌
    Enumerating Cloud With Cloudfox 2 · peteedoo bundle
    Map AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
    0 repo stars
  22. ▌
    Fleet Hunting With Velociraptor 2 · peteedoo bundle
    Deploy a Velociraptor server and agents and write VQL hunts across a fleet.
    0 repo stars
  23. ▌
    Implementing Saml Sso With Okta 2 · peteedoo bundle
    Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
    0 repo stars
  24. ▌
    Detecting Malicious NPM Packages 2 · peteedoo bundle
    Triage npm packages for install-script malware, exfiltration, and worming behavior.
    0 repo stars
  25. ▌
    Detecting Typosquatting Packages 2 · peteedoo bundle
    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
    0 repo stars
  26. ▌
    Managing Third Party Vendor Risk 2 · peteedoo bundle
    Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, and offboard securely. Use when an organization needs to assess a new vendor before onboarding, when standing up or maturing a vendor-risk program, when tiering a vendor portfolio, when reviewing a SOC 2 or CAIQ, when writing security requirements into a contract or DPA, when a vendor suffers a breach, or when managing supply-chain / software supply-chain risk. Keywords: third-party risk, vendor risk management, TPRM, supply chain risk, C-SCRM, NIST 800-161, vendor tiering, SIG questionnaire, CAIQ, SOC 2, ISO 27001, right to audit, continuous monitoring, security ratings, fourth-party risk, Nth-party, vendor offboarding, d
    0 repo stars
  27. ▌
    Attacking Entra Id With Roadtools 2 · peteedoo bundle
    Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.
    0 repo stars
  28. ▌
    Deploying Ransomware Canary Files 2 · peteedoo bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.
    0 repo stars
  29. ▌
    Managing Cloud Identity With Okta 2 · peteedoo bundle
    This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
    0 repo stars
  30. ▌
    Recovering From Ransomware Attack 2 · peteedoo bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
    0 repo stars
  31. ▌
    Testing For System Prompt Leakage 2 · peteedoo bundle
    Extract and defend system prompts plus embedded secrets and routing logic.
    0 repo stars
  32. ▌
    Detecting Data And Model Poisoning 2 · peteedoo bundle
    Identify poisoned training data and backdoored models across the ML pipeline.
    0 repo stars
  33. ▌
    Detecting Model Extraction Attacks 2 · peteedoo bundle
    Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
    0 repo stars
  34. ▌
    Operationalizing Misp Threat Feeds 2 · peteedoo bundle
    Run MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
    0 repo stars
  35. ▌
    Scanning Iac And Images With Trivy 2 · peteedoo bundle
    Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
    0 repo stars
  36. ▌
    Abusing Dpapi For Credential Access 2 · peteedoo bundle
    Extract DPAPI-protected secrets such as credentials and browser data offline and online.
    0 repo stars
  37. ▌
    Auditing Entra Id With Aadinternals 2 · peteedoo bundle
    Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
    0 repo stars
  38. ▌
    Building Super Timelines With Plaso 2 · peteedoo bundle
    Generate log2timeline and Plaso super-timelines and triage them in Timesketch.
    0 repo stars
  39. ▌
    Configuring Ldap Security Hardening 2 · peteedoo bundle
    Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
    0 repo stars
  40. ▌
    Detecting Business Email Compromise 2 · peteedoo bundle
    Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
    0 repo stars
  41. ▌
    Detecting Indirect Prompt Injection 2 · peteedoo bundle
    Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
    0 repo stars
  42. ▌
    Securing Agentic AI Tool Invocation 2 · peteedoo bundle
    Apply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
    0 repo stars
  43. ▌
    Analyzing Ransomware Payment Wallets 2 · peteedoo bundle
    Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering.
    0 repo stars
  44. ▌
    Implementing Pam For Database Access 2 · peteedoo bundle
    Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
    0 repo stars
  45. ▌
    Orchestrating LLM Attacks With Pyrit 2 · peteedoo bundle
    Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and scorer feedback loops.
    0 repo stars
  46. ▌
    Tracking Threat Actor Infrastructure 2 · peteedoo bundle
    Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
    0 repo stars
  47. ▌
    Building C2 Redirector Infrastructure 2 · peteedoo bundle
    Architect redirectors with nginx and Apache, malleable profiles, and OPSEC for resilient C2.
    0 repo stars
  48. ▌
    Conducting Phishing Incident Response 2 · peteedoo bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email incident, credential phishing, spear phishing investigation, or phishing remediation.
    0 repo stars
  49. ▌
    Configuring Oauth2 Authorization Flow 2 · peteedoo bundle
    Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token
    0 repo stars
  50. ▌
    Abusing Shadow Credentials For Privesc 2 · peteedoo bundle
    Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
    0 repo stars
  51. ▌
    Deploying Honeytokens And Canarytokens 2 · peteedoo bundle
    Plant canarytokens and honey credentials and alert on breach.
    0 repo stars
  52. ▌
    Migrating To Post Quantum Cryptography 2 · peteedoo bundle
    Inventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
    0 repo stars
  53. ▌
    Testing Ransomware Recovery Procedures 2 · peteedoo bundle
    Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.
    0 repo stars
  54. ▌
    Analyzing Ransomware Network Indicators 2 · peteedoo bundle
    Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis
    0 repo stars
  55. ▌
    Auditing MCP Servers For Tool Poisoning 2 · peteedoo bundle
    Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
    0 repo stars
  56. ▌
    Benchmarking Kubernetes With Kube Bench 2 · peteedoo bundle
    Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
    0 repo stars
  57. ▌
    Detecting Compromised Cloud Credentials 2 · peteedoo bundle
    Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    0 repo stars
  58. ▌
    Detecting Credential Dumping Techniques 2 · peteedoo bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
    0 repo stars
  59. ▌
    Extracting Credentials From Memory Dump 2 · peteedoo bundle
    Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
    0 repo stars
  60. ▌
    Implementing Ransomware Backup Strategy 2 · peteedoo bundle
    Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.
    0 repo stars
  61. ▌
    Implementing Soar Playbook For Phishing 2 · peteedoo bundle
    Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
    0 repo stars
  62. ▌
    Mapping Attack Paths With Bloodhound Ce 2 · peteedoo bundle
    Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
    0 repo stars
  63. ▌
    Performing Ransomware Tabletop Exercise 2 · peteedoo bundle
    Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
    0 repo stars
  64. ▌
    Detecting Ransomware Encryption Behavior 2 · peteedoo bundle
    Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting.
    0 repo stars
  65. ▌
    Hunting Bootkits In Efi System Partition 2 · peteedoo bundle
    Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
    0 repo stars
  66. ▌
    Implementing Scim Provisioning With Okta 2 · peteedoo bundle
    Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
    0 repo stars
  67. ▌
    Validating Backup Integrity For Recovery 2 · peteedoo bundle
    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    0 repo stars
  68. ▌
    Validating Tpm Measured Boot Attestation 2 · peteedoo bundle
    Verify TPM PCRs and measured-boot and remote-attestation integrity.
    0 repo stars
  69. ▌
    Assessing Vector And Embedding Weaknesses 2 · peteedoo bundle
    Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
    0 repo stars
  70. ▌
    Attacking OAUTH With Device Code Phishing 2 · peteedoo bundle
    Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
    0 repo stars
  71. ▌
    Continuous LLM Red Teaming With Promptfoo 2 · peteedoo bundle
    Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
    0 repo stars
  72. ▌
    Implementing Anti Ransomware Group Policy 2 · peteedoo bundle
    Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy.
    0 repo stars
  73. ▌
    Investigating Ransomware Attack Artifacts 2 · peteedoo bundle
    Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
    0 repo stars
  74. ▌
    Performing Red Team Phishing With Gophish 2 · peteedoo bundle
    Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.
    0 repo stars
  75. ▌
    Testing Prompt Injection In RAG Pipelines 2 · peteedoo bundle
    Probe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
    0 repo stars
  76. ▌
    Detecting Spearphishing With Email Gateway 2 · peteedoo bundle
    Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
    0 repo stars
  77. ▌
    Implementing Delinea Secret Server For Pam 2 · peteedoo bundle
    Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.
    0 repo stars
  78. ▌
    Implementing Sigstore For Software Signing 2 · peteedoo bundle
    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.
    0 repo stars
  79. ▌
    Analyzing Ransomware Leak Site Intelligence 2 · peteedoo bundle
    Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
    0 repo stars
  80. ▌
    Building Phishing Reporting Button Workflow 2 · peteedoo bundle
    Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.
    0 repo stars
  81. ▌
    Detecting Deepfake Audio In Vishing Attacks 2 · peteedoo bundle
    Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generates confidence scores, and produces forensic reports. Activates for requests involving deepfake voice detection, vishing investigation, AI-generated speech analysis, voice cloning detection, or audio authenticity verification.
    0 repo stars
  82. ▌
    Detecting T1003 Credential Dumping With Edr 2 · peteedoo bundle
    Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
    0 repo stars
  83. ▌
    Generating Forensic Timelines With Hayabusa 2 · peteedoo bundle
    Produce Sigma-based EVTX timelines and summaries with Hayabusa.
    0 repo stars
  84. ▌
    Implementing Anti Phishing Training Program 2 · peteedoo bundle
    Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv
    0 repo stars
  85. ▌
    Parsing Artifacts With Eric Zimmerman Tools 2 · peteedoo bundle
    Parse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.
    0 repo stars
  86. ▌
    Performing Phishing Simulation With Gophish 2 · peteedoo bundle
    GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag
    0 repo stars
  87. ▌
    Conducting Spearphishing Simulation Campaign 2 · peteedoo bundle
    Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf
    0 repo stars
  88. ▌
    Implementing Google Workspace Admin Security 2 · peteedoo bundle
    Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration.
    0 repo stars
  89. ▌
    Implementing Hashicorp Vault Dynamic Secrets 2 · peteedoo bundle
    Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation.
    0 repo stars
  90. ▌
    Analyzing Typosquatting Domains With Dnstwist 2 · peteedoo bundle
    Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
    0 repo stars
  91. ▌
    Auditing Kubernetes Rbac Privilege Escalation 2 · peteedoo bundle
    Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
    0 repo stars
  92. ▌
    Detecting Entra Offensive Tools In Graph Logs 2 · peteedoo bundle
    Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
    0 repo stars
  93. ▌
    Emulating Cloud Attacks With Stratus Red Team 2 · peteedoo bundle
    Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
    0 repo stars
  94. ▌
    Implementing Ransomware Kill Switch Detection 2 · peteedoo bundle
    Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection.
    0 repo stars
  95. ▌
    Verifying Build Provenance With Slsa Sigstore 2 · peteedoo bundle
    Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
    0 repo stars
  96. ▌
    Building Identity Governance Lifecycle Process 2 · peteedoo bundle
    Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design.
    0 repo stars
  97. ▌
    Conducting Social Engineering Penetration Test 2 · peteedoo bundle
    Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
    0 repo stars
  98. ▌
    Detecting Container Runtime Threats With Falco 2 · peteedoo bundle
    Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
    0 repo stars
  99. ▌
    Detecting Qr Code Phishing With Email Security 2 · peteedoo bundle
    Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.
    0 repo stars
  100. ▌
    Performing Access Recertification With Saviynt 2 · peteedoo bundle
    Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
    0 repo stars