thedixitjain
- 10k skills
- 0 followers
- 2 repo stars
- 2 weeks ago last updated
- ▌ Coercing Authentication With Coercer Petitpotam · thedixitjain bundleTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.
- ▌ Detecting Malicious Scheduled Tasks With Sysmon · thedixitjain bundle'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis. '
- ▌ Implementing API Security Testing With 42crunch · thedixitjain bundleImplement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
- ▌ Implementing Beyondcorp Zero Trust Access Model · thedixitjain bundle'Implementing Google''s BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access. '
- ▌ Implementing Supply Chain Security With In Toto · thedixitjain bundleImplement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
- ▌ Implementing Syslog Centralization With Rsyslog · thedixitjain bundleConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
- ▌ Implementing Zero Trust With Hashicorp Boundary · thedixitjain bundleImplement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
- ▌ Performing Active Directory Forest Trust Attack · thedixitjain bundleEnumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.
- ▌ Performing Automated Malware Analysis With Cape · thedixitjain bundleDeploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
- ▌ Performing GCP Security Assessment With Forseti · thedixitjain bundle'Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark. '
- ▌ Performing Hardware Security Module Integration · thedixitjain bundleIntegrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.
- ▌ Performing Subdomain Enumeration With Subfinder · thedixitjain bundleEnumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
- ▌ Performing Web Application Vulnerability Triage · thedixitjain bundleTriage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
- ▌ Performing Wifi Password Cracking With Aircrack · thedixitjain bundle'Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture. '
- ▌ Implementing Policy As Code With Open Policy Agent · thedixitjain bundle'This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines. '
- ▌ Winter Conference On Applications Of Computer Vision · thedixitjainUse when targeting IEEE/CVF Winter Conference on Applications of Computer Vision (WACV) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for computer vision applications.
- ▌ Implementing Deception Based Detection With Canarytoken · thedixitjain bundleDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
- ▌ Implementing Privileged Access Management With Cyberark · thedixitjain bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
- ▌ Create Github Issues For Unmet Specification Requirements · thedixitjainCreate GitHub Issues for unimplemented requirements from specification files using feature_request.yml template.
- ▌ Analyzing Memory Forensics With Lime And Volatility · thedixitjain bundle'Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems. '
- ▌ Annual Review Of Ecology Evolution And Systematics · thedixitjainUse when targeting Annual Review of Ecology, Evolution, and Systematics (AREES) or deciding whether a proposed synthesis fits this invited-review-only venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Ieee International Symposium On Biomedical Imaging · thedixitjainUse when targeting IEEE International Symposium on Biomedical Imaging (ISBI) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for biomedical imaging.
- ▌ Journal Of The Association For Information Systems · thedixitjainUse when targeting Journal of the Association for Information Systems (JAIS) or deciding whether a theory-rich, methodologically broad information-systems manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Usenix Conference On File And Storage Technologies · thedixitjainUse when targeting USENIX Conference on File and Storage Technologies (FAST) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for storage systems.
- ▌ Analyzing Threat Actor Ttps With Mitre Navigator · thedixitjain bundle'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis. '
- ▌ Annual Computer Security Applications Conference · thedixitjainUse when targeting Annual Computer Security Applications Conference (ACSAC) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for applied security.
- ▌ Building Attack Pattern Library From Cti Reports · thedixitjain bundleExtract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.
- ▌ Building Malware Incident Communication Template · thedixitjain bundleBuild structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
- ▌ Building Ransomware Playbook With Cisa Framework · thedixitjain bundle'Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment. '
- ▌ Building Vulnerability Dashboard With Defectdojo · thedixitjain bundleDeploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.
- ▌ Building Vulnerability Exception Tracking System · thedixitjain bundleBuild a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.
- ▌ Configuring Multi Factor Authentication With Duo · thedixitjain bundleDeploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
- ▌ Designing Adversary Engagement With Mitre Engage · thedixitjain bundle>- Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare, Expose, Affect, Elicit, Understand), the 10-Step Operational Process, mapping engagement Activities to the ATT&CK techniques they expose, and defining measurable Goals and Operational Objectives. Use when a team has honeypots, honeytokens, or canary tokens but no coordinating strategy, when leadership asks "should we engage attackers and how", when building a deception/denial program, when writing an adversary engagement operation plan, or when deciding which deception Activities to deploy against a specific threat actor. Keywords: MITRE Engage, adversary engagement, cyber deception strategy, denial and deception, Engage Matrix, EAC, EGO, Expose Affect Elicit, deception program,...
- ▌ Detecting Golden Ticket Attacks In Kerberos Logs · thedixitjain bundleDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
- ▌ Exploiting Zerologon Vulnerability Cve 2020 1472 · thedixitjain bundleExploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
- ▌ Implementing Canary Tokens For Network Intrusion · thedixitjain bundle'Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms. '
- ▌ Implementing End To End Encryption For Messaging · thedixitjain bundleEnd-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version
- ▌ Implementing Mimecast Targeted Attack Protection · thedixitjain bundleDeploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
- ▌ Performing Paste Site Monitoring For Credentials · thedixitjain bundleMonitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
- ▌ Performing Threat Emulation With Atomic Red Team · thedixitjain bundle'Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises. '
- ▌ Performing Threat Intelligence Sharing With Misp · thedixitjain bundleUse PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
- ▌ Planning Oracle To Postgres Migration Integration Testing · thedixitjainCreates an integration testing plan for .NET data access artifacts during Oracle-to-PostgreSQL database migrations. Analyzes a single project to identify repositories, DAOs, and service layers that interact with the database, then produces a structured testing plan. Use when planning integration test coverage for a migrated project, identifying which data access methods need tests, or preparing for Oracle-to-PostgreSQL migration validation.
- ▌ Google Cloud Solution Agentic AI Bidirectional Streaming · thedixitjain bundle>- Guides agents to interactively discover customer requirements for live, bidirectional multi-agent AI systems that process continuous streams of multimodal data for real-time technical guidance and safety monitoring. Generates a custom Google Cloud solution that uses opinionated best practices and architecture guidance. Use when users need agentic assistance to design and create a multi-product solution in the cloud for live bidirectional multimodal streaming workloads. Don't use for simple text-based chat applications or workloads without real-time streaming requirements.
- ▌ Implementing Image Provenance Verification With Cosign · thedixitjain bundleSign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
- ▌ Acm International Conference On Multimedia Retrieval · thedixitjainUse when targeting ACM International Conference on Multimedia Retrieval (ICMR) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for multimedia retrieval.
- ▌ Performing Memory Forensics With Volatility3 Plugins · thedixitjain bundleAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
- ▌ European Symposium On Research In Computer Security · thedixitjainUse when targeting European Symposium on Research in Computer Security (ESORICS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for security.
- ▌ Journal Of Zhongnan University Of Economics And Law · thedixitjainUse when targeting 《中南财经政法大学学报》(Journal of Zhongnan University of Economics and Law — 中南财经政法大学主办的财经政法综合双月刊, 1958 创刊, CSSCI 来源, 文稿以6000字为宜、中英文摘要200–300字) or deciding whether a Chinese econ/management/law-econ manuscript fits this venue. Encodes the journal's fit, framing, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Analyzing Ethereum Smart Contract Vulnerabilities · thedixitjain bundlePerform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
- ▌ Building Threat Intelligence Enrichment In Splunk · thedixitjain bundleBuild automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
- ▌ Conducting Cyber Risk Assessment With Nist 800 30 · thedixitjain bundle>- Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis,...
- ▌ Implementing Aqua Security For Container Scanning · thedixitjain bundleDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
- ▌ Implementing Google Workspace Phishing Protection · thedixitjain bundleConfigure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
- ▌ Implementing Hardware Security Key Authentication · thedixitjain bundle'Implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Activates for requests involving FIDO2 implementation, WebAuthn registration, hardware security key enrollment, YubiKey integration, or passkey migration from password-based authentication. '
- ▌ Implementing Identity Verification For Zero Trust · thedixitjain bundleImplement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
- ▌ Network And Distributed System Security Symposium · thedixitjainUse when targeting Network and Distributed System Security Symposium (NDSS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for security flagship.
- ▌ Performing Container Security Scanning With Trivy · thedixitjain bundleScan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
- ▌ Performing Static Malware Analysis With Pe Studio · thedixitjain bundle'Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage. '
- ▌ Performing Threat Landscape Assessment For Sector · thedixitjain bundleConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
- ▌ Reverse Engineering Ransomware Encryption Routine · thedixitjain bundleReverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.
- ▌ Acm Sigmod International Conference On Management Of Data · thedixitjainUse when targeting ACM SIGMOD International Conference on Management of Data (SIGMOD) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for database flagship.
- ▌ Journal Of Shanxi University Of Finance And Economics · thedixitjainUse when targeting 《山西财经大学学报》(Journal of Shanxi University of Finance and Economics — 山西财经大学主办的月刊, 只收规范实证研究、正文≥25000字、作者须有博士学位/在读博士、非匿名、查重≤10%) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's strict empirical-only bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ International Conference On Automated Machine Learning · thedixitjainUse when targeting International Conference on Automated Machine Learning (AutoML Conference) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for automated ML.
- ▌ Implementing Container Image Minimal Base With Distroless · thedixitjain bundleReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
- ▌ Performing Cloud Native Threat Hunting With AWS Detective · thedixitjain bundleHunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
- ▌ Ieee Ras International Conference On Humanoid Robots · thedixitjainUse when targeting IEEE-RAS International Conference on Humanoid Robots (Humanoids) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for humanoid robotics.
- ▌ International Conference On Learning Representations · thedixitjainUse when targeting International Conference on Learning Representations (ICLR) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI/ML flagship.
- ▌ International Natural Language Generation Conference · thedixitjainUse when targeting International Natural Language Generation Conference (INLG) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for language generation.
- ▌ Analyzing Email Headers For Phishing Investigation · thedixitjain bundleParse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
- ▌ Implementing Conduit Security For Ot Remote Access · thedixitjain bundle'Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly. '
- ▌ Implementing Network Access Control With Cisco Ise · thedixitjain bundleDeploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
- ▌ Performing Log Analysis For Forensic Investigation · thedixitjain bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ Performing Malware Hash Enrichment With Virustotal · thedixitjain bundleEnrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
- ▌ Performing Mobile Device Forensics With Cellebrite · thedixitjain bundleAcquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
- ▌ Journal Of Central University Of Finance And Economics · thedixitjainUse when targeting 《中央财经大学学报》(Journal of Central University of Finance and Economics — 教育部主管、中央财经大学主办的综合性经济理论刊物, 1981 创刊, 自有网上投稿平台 xbbjb.cufe.edu.cn) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's fit, framing, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Journal Of Jiangxi University Of Finance And Economics · thedixitjainUse when targeting 《江西财经大学学报》(Journal of Jiangxi University of Finance and Economics — 江西财经大学主办的双月刊, 1999 创刊, 双向匿名审稿, 不收审稿费/版面费且发稿酬, 采编系统 cfejxufe.magtech.com.cn) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's fit, framing, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Acm Sigaccess Conference On Computers And Accessibility · thedixitjainUse when targeting ACM SIGACCESS Conference on Computers and Accessibility (ASSETS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for accessibility.
- ▌ Conference On Computational Natural Language Learning · thedixitjainUse when targeting Conference on Computational Natural Language Learning (CoNLL) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for NLP learning.
- ▌ Ieee Acm International Symposium On Microarchitecture · thedixitjainUse when targeting IEEE/ACM International Symposium on Microarchitecture (MICRO) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for microarchitecture flagship.
- ▌ International Conference On Computational Linguistics · thedixitjainUse when targeting International Conference on Computational Linguistics (COLING) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for computational linguistics.
- ▌ Implementing Passwordless Auth With Microsoft Entra · thedixitjain bundle'Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies. '
- ▌ Implementing Passwordless Authentication With Fido2 · thedixitjain bundleDeploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica
- ▌ Implementing Zero Trust Network Access With Zscaler · thedixitjain bundleImplement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.
- ▌ Performing Ot Vulnerability Assessment With Claroty · thedixitjain bundle'This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls. '
- ▌ Performing Threat Modeling With Owasp Threat Dragon · thedixitjain bundleUse OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
- ▌ Performing Wireless Security Assessment With Kismet · thedixitjain bundleConduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
- ▌ Journal Of Shanghai University Of Finance And Economics · thedixitjainUse when targeting 《上海财经大学学报(哲学社会科学版)》(Journal of Shanghai University of Finance and Economics — 上海财经大学主办的双月刊, 财经类为主、经管文法兼容, 双向匿名审稿, 不收审稿费/版面费, 期刊社 qks.sufe.edu.cn) or deciding whether a Chinese social-science/econ/management manuscript fits this venue. Encodes the journal's fit, framing, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Ieee Conference On Virtual Reality And 3d User Interfaces · thedixitjainUse when targeting IEEE Conference on Virtual Reality and 3D User Interfaces (IEEE VR) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for virtual reality.
- ▌ Implementing Data Loss Prevention With Microsoft Purview · thedixitjain bundle'Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Activity Explorer and DLP alert management. Uses PowerShell cmdlets and the Microsoft Graph API for programmatic policy management. Activates for requests involving DLP policy creation, sensitivity label configuration, data classification, endpoint data protection, or Microsoft Purview compliance administration. '
- ▌ Aaai Conference On Human Computation And Crowdsourcing · thedixitjainUse when targeting AAAI Conference on Human Computation and Crowdsourcing (HCOMP) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for human computation.
- ▌ International Conference On Advanced Visual Interfaces · thedixitjainUse when targeting International Conference on Advanced Visual Interfaces (AVI) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for visual interfaces.
- ▌ International Journal Of Machine Tools And Manufacture · thedixitjainUse when targeting the International Journal of Machine Tools and Manufacture (IJMTM) or deciding whether a precision/advanced-manufacturing manuscript fits this venue. Encodes the journal's fit, the manufacturing-science bar combining experiment and modeling, the process-mechanics scope, official-submission re-check, and desk-reject heuristics.
- ▌ Analyzing Malware Family Relationships With Malpedia · thedixitjain bundleUse the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
- ▌ Detecting Broken Object Property Level Authorization · thedixitjain bundleDetect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
- ▌ Exploiting Vulnerabilities With Metasploit Framework · thedixitjain bundleThe Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules
- ▌ Implementing Application Whitelisting With Applocker · thedixitjain bundle'Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control. '
- ▌ Implementing Continuous Security Validation With Bas · thedixitjain bundleDeploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.
- ▌ Implementing Device Posture Assessment In Zero Trust · thedixitjain bundle'Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access. '
- ▌ Implementing Next Generation Firewall With Palo Alto · thedixitjain bundleConfigure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
- ▌ Implementing Ot Network Traffic Analysis With Nozomi · thedixitjain bundle'Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring. '