sec-link
- 10 skills
- 0 followers
- 14 hours ago last updated
- ▌ Phishing Email Triage · sec-linkAnalyze suspicious email indicators, sender authentication, URLs, attachments, user impact, and recommended containment. Never claim a link or attachment is malicious without evidence. Return concise findings and follow-up tasks.
- ▌ Cloud Iam Anomaly Triage · sec-linkAnalyze suspicious cloud identity and access events, including role changes, new keys, unusual regions, and privilege escalation. Recommend evidence-preserving response actions.
- ▌ Ransomware Response · sec-linkTriage ransomware indicators such as mass file changes, encryption processes, ransom notes, and lateral movement. Prioritize isolation, evidence preservation, recovery coordination, and safe next tasks.
- ▌ Dns Command And Control Investigation · sec-linkAnalyze suspicious DNS behavior such as high entropy, beaconing, rare domains, unusual record types, and query volume. Distinguish indicators from confirmed C2 and recommend safe validation.
- ▌ Insider Threat Assessment · sec-linkAssess possible insider risk from unusual access, downloads, privilege use, and policy violations. Maintain neutral language, minimize personal data, and recommend auditable investigative steps.
- ▌ Malware Execution Analysis · sec-linkAnalyze process execution, downloaded files, hashes, parent-child chains, persistence, and host impact. Separate observed facts from hypotheses and propose safe collection and containment steps.
- ▌ Data Exfiltration Detection · sec-linkAssess possible data movement using destinations, protocols, volume, files, and user context. Identify evidence gaps and recommend low-risk validation and containment actions.
- ▌ Vulnerability Prioritization · sec-linkPrioritize vulnerabilities using asset criticality, exploitability, exposure, known exploitation, compensating controls, and business impact. Do not invent CVEs or affected versions.
- ▌ Incident Containment Planning · sec-linkCreate a prioritized, reversible containment plan based only on observed evidence. Include owner, verification, rollback, and approval requirements; never perform destructive actions automatically.
- ▌ Suspicious Login Investigation · sec-linkInvestigate unusual authentication activity using source IP, account, time, geolocation, MFA, and privilege context. Recommend validation steps and avoid changing ticket status.