peteedoo
- 420 skills
- 0 followers
- 2 weeks ago last updated
- ▌ Performing Service Account Credential Rotation 2 · peteedoo bundleAutomate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
- ▌ Building Identity Federation With Saml Azure Ad 2 · peteedoo bundleEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.
- ▌ Coercing Authentication With Coercer Petitpotam 2 · peteedoo bundleTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
- ▌ Implementing Google Workspace Sso Configuration 2 · peteedoo bundleConfigure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
- ▌ Implementing Identity Governance With Sailpoint 2 · peteedoo bundleDeploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
- ▌ Implementing Zero Trust With Hashicorp Boundary 2 · peteedoo bundleImplement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
- ▌ Building Ransomware Playbook With Cisa Framework 2 · peteedoo bundleBuilds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
- ▌ Configuring Identity Aware Proxy With Google Iap 2 · peteedoo bundleConfiguring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
- ▌ Implementing Mimecast Targeted Attack Protection 2 · peteedoo bundleDeploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
- ▌ Performing Entitlement Review With Sailpoint Iiq 2 · peteedoo bundlePerforms entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates for requests involving access reviews, entitlement certifications, SailPoint IIQ governance, or periodic user access recertification.
- ▌ Post Exploiting Microsoft Graph With Graphrunner 2 · peteedoo bundlePerform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
- ▌ Detecting AWS Credential Exposure With Trufflehog 2 · peteedoo bundleDetecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
- ▌ Implementing Google Workspace Phishing Protection 2 · peteedoo bundleConfigure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
- ▌ Implementing Identity Verification For Zero Trust 2 · peteedoo bundleImplement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
- ▌ Implementing Passwordless Auth With Microsoft Entra 2 · peteedoo bundleImplements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.
- ▌ Implementing Azure Ad Privileged Identity Management 2 · peteedoo bundleConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
- ▌ Performing Adversary In The Middle Phishing Detection 2 · peteedoo bundleDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
- ▌ Implementing Privileged Access Management With Cyberark 2 · peteedoo bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
- ▌ Operating Havoc C2 · peteedoo bundleDeploy a Havoc team server with Yaotl profiles, generate evasive Demon agents with indirect syscalls and sleep obfuscation, and run post-exploitation and pivoting for adversary emulation.
- ▌ Operating Sliver C2 · peteedoo bundleStand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
- ▌ Exploiting AWS With Pacu · peteedoo bundleUse Pacu modules for AWS privilege escalation, persistence, and backdooring.
- ▌ Hunting Evtx With Chainsaw · peteedoo bundlePerform rapid Sigma and keyword hunting across Windows event logs with Chainsaw.
- ▌ Triaging Windows With Kape · peteedoo bundleRun targeted forensic artifact collection and module parsing with KAPE.
- ▌ Analyzing Linux Elf Malware · peteedoo bundleAnalyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
- ▌ Detecting OAUTH Token Theft · peteedoo bundleDetects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
- ▌ Escaping Containers To Host · peteedoo bundleExploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
- ▌ Red Teaming Llms With Garak · peteedoo bundleRun NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
- ▌ Relaying Ntlm For Adcs Esc8 · peteedoo bundleRun ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
- ▌ Detecting Secure Boot Bypass · peteedoo bundleDetect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.
- ▌ Exploiting Adcs With Certipy · peteedoo bundleEnumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
- ▌ Hunting Saas Sso Token Abuse · peteedoo bundleDetect SSO and OAuth token replay and SaaS lateral movement.
- ▌ Securing AWS Iam Permissions · peteedoo bundleThis skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential rotation strategies to reduce the blast radius of compromised identities.
- ▌ Modeling Threats With Opencti · peteedoo bundleModel threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI (Filigran) using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
- ▌ Moving Laterally With Netexec · peteedoo bundleUse NetExec for SMB, WinRM, LDAP, and MSSQL enumeration, password spraying, and execution.
- ▌ Defending Llms With Guardrails · peteedoo bundleDeploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
- ▌ Detecting Dependency Confusion · peteedoo bundleDetect and prevent public-over-private name resolution in npm, PyPI, and Maven.
- ▌ Generating And Analyzing Sboms · peteedoo bundleProduce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.
- ▌ Performing Ransomware Response · peteedoo bundleExecutes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.
- ▌ Enumerating Cloud With Cloudfox · peteedoo bundleMap AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
- ▌ Fleet Hunting With Velociraptor · peteedoo bundleDeploy a Velociraptor server and agents and write VQL hunts across a fleet.
- ▌ Implementing Saml Sso With Okta · peteedoo bundleImplement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
- ▌ Detecting Malicious NPM Packages · peteedoo bundleTriage npm packages for install-script malware, exfiltration, and worming behavior.
- ▌ Detecting Typosquatting Packages · peteedoo bundleFlag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
- ▌ Managing Third Party Vendor Risk · peteedoo bundleBuild and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, and offboard securely. Use when an organization needs to assess a new vendor before onboarding, when standing up or maturing a vendor-risk program, when tiering a vendor portfolio, when reviewing a SOC 2 or CAIQ, when writing security requirements into a contract or DPA, when a vendor suffers a breach, or when managing supply-chain / software supply-chain risk. Keywords: third-party risk, vendor risk management, TPRM, supply chain risk, C-SCRM, NIST 800-161, vendor tiering, SIG questionnaire, CAIQ, SOC 2, ISO 27001, right to audit, continuous monitoring, security ratings, fourth-party risk, Nth-party, vendor offboarding, d
- ▌ Attacking Entra Id With Roadtools · peteedoo bundleEnumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.
- ▌ Deploying Ransomware Canary Files · peteedoo bundleDeploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.
- ▌ Managing Cloud Identity With Okta · peteedoo bundleThis skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
- ▌ Recovering From Ransomware Attack · peteedoo bundleExecutes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
- ▌ Testing For System Prompt Leakage · peteedoo bundleExtract and defend system prompts plus embedded secrets and routing logic.
- ▌ Detecting Data And Model Poisoning · peteedoo bundleIdentify poisoned training data and backdoored models across the ML pipeline.
- ▌ Detecting Model Extraction Attacks · peteedoo bundleDetect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
- ▌ Operationalizing Misp Threat Feeds · peteedoo bundleRun MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
- ▌ Scanning Iac And Images With Trivy · peteedoo bundleScan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
- ▌ Abusing Dpapi For Credential Access · peteedoo bundleExtract DPAPI-protected secrets such as credentials and browser data offline and online.
- ▌ Auditing Entra Id With Aadinternals · peteedoo bundleRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
- ▌ Building Super Timelines With Plaso · peteedoo bundleGenerate log2timeline and Plaso super-timelines and triage them in Timesketch.
- ▌ Configuring Ldap Security Hardening · peteedoo bundleHarden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
- ▌ Detecting Business Email Compromise · peteedoo bundleBusiness Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
- ▌ Detecting Indirect Prompt Injection · peteedoo bundleDetect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
- ▌ Securing Agentic AI Tool Invocation · peteedoo bundleApply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.
- ▌ Analyzing Ransomware Payment Wallets · peteedoo bundleTraces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering.
- ▌ Implementing Pam For Database Access · peteedoo bundleDeploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
- ▌ Orchestrating LLM Attacks With Pyrit · peteedoo bundleBuild multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and scorer feedback loops.
- ▌ Tracking Threat Actor Infrastructure · peteedoo bundleThreat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
- ▌ Building C2 Redirector Infrastructure · peteedoo bundleArchitect redirectors with nginx and Apache, malleable profiles, and OPSEC for resilient C2.
- ▌ Conducting Phishing Incident Response · peteedoo bundleResponds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email incident, credential phishing, spear phishing investigation, or phishing remediation.
- ▌ Configuring Oauth2 Authorization Flow · peteedoo bundleConfigure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token
- ▌ Abusing Shadow Credentials For Privesc · peteedoo bundleTake over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
- ▌ Deploying Honeytokens And Canarytokens · peteedoo bundlePlant canarytokens and honey credentials and alert on breach.
- ▌ Migrating To Post Quantum Cryptography · peteedoo bundleInventory cryptography, deploy hybrid X25519 and ML-KEM, and prioritize harvest-now-decrypt-later data.
- ▌ Testing Ransomware Recovery Procedures · peteedoo bundleTest and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.
- ▌ Analyzing Ransomware Network Indicators · peteedoo bundleIdentify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis
- ▌ Auditing MCP Servers For Tool Poisoning · peteedoo bundleScan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
- ▌ Benchmarking Kubernetes With Kube Bench · peteedoo bundleRun CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
- ▌ Detecting Compromised Cloud Credentials · peteedoo bundleDetecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
- ▌ Detecting Credential Dumping Techniques · peteedoo bundleDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
- ▌ Extracting Credentials From Memory Dump · peteedoo bundleExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
- ▌ Implementing Ransomware Backup Strategy · peteedoo bundleDesigns and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.
- ▌ Implementing Soar Playbook For Phishing · peteedoo bundleAutomate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
- ▌ Mapping Attack Paths With Bloodhound Ce · peteedoo bundleCollect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
- ▌ Performing Ransomware Tabletop Exercise · peteedoo bundlePlans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
- ▌ Detecting Ransomware Encryption Behavior · peteedoo bundleDetects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting.
- ▌ Hunting Bootkits In Efi System Partition · peteedoo bundleBaseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
- ▌ Implementing Scim Provisioning With Okta · peteedoo bundleImplement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
- ▌ Validating Backup Integrity For Recovery · peteedoo bundleValidate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
- ▌ Validating Tpm Measured Boot Attestation · peteedoo bundleVerify TPM PCRs and measured-boot and remote-attestation integrity.
- ▌ Assessing Vector And Embedding Weaknesses · peteedoo bundleTest vector stores for embedding inversion, cross-tenant leakage, and poisoning.
- ▌ Attacking OAUTH With Device Code Phishing · peteedoo bundleRun OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
- ▌ Continuous LLM Red Teaming With Promptfoo · peteedoo bundleWire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
- ▌ Implementing Anti Ransomware Group Policy · peteedoo bundleConfigures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy.
- ▌ Investigating Ransomware Attack Artifacts · peteedoo bundleIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
- ▌ Performing Red Team Phishing With Gophish · peteedoo bundleAutomate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.
- ▌ Testing Prompt Injection In RAG Pipelines · peteedoo bundleProbe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.
- ▌ Detecting Spearphishing With Email Gateway · peteedoo bundleSpearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
- ▌ Implementing Delinea Secret Server For Pam · peteedoo bundleImplements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.
- ▌ Implementing Sigstore For Software Signing · peteedoo bundleImplements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.
- ▌ Analyzing Ransomware Leak Site Intelligence · peteedoo bundleMonitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
- ▌ Building Phishing Reporting Button Workflow · peteedoo bundleImplement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.
- ▌ Detecting Deepfake Audio In Vishing Attacks · peteedoo bundleDetects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generates confidence scores, and produces forensic reports. Activates for requests involving deepfake voice detection, vishing investigation, AI-generated speech analysis, voice cloning detection, or audio authenticity verification.
- ▌ Detecting T1003 Credential Dumping With Edr · peteedoo bundleDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.