all publishers

thedixitjain

@thedixitjain source repo

10,417 published skills · page 15 of 105

  1. ▌
    Emulating Cloud Attacks With Stratus Red Team · thedixitjain bundle
    Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
    2 repo stars
  2. ▌
    Hunting For Persistence Via Wmi Subscriptions · thedixitjain bundle
    Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
    2 repo stars
  3. ▌
    Implementing Just In Time Access Provisioning · thedixitjain bundle
    Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access only when needed. This skill covers JIT architecture design, approval workflo
    2 repo stars
  4. ▌
    Integrating Sast Into Github Actions Pipeline · thedixitjain bundle
    'This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected. '
    2 repo stars
  5. ▌
    Performing Cloud Storage Forensic Acquisition · thedixitjain bundle
    Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
    2 repo stars
  6. ▌
    Configuring Tls 1 3 For Secure Communications · thedixitjain bundle
    TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R
    2 repo stars
  7. ▌
    Ieee Transactions On Antennas And Propagation · thedixitjain
    Use when targeting IEEE Transactions on Antennas and Propagation (TAP) or deciding whether an antennas, applied-electromagnetics, or wave-propagation manuscript fits this venue. Encodes the journal's fit, the theory-plus-simulation-plus-measurement evidence bar, EM-contribution rigor, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  8. ▌
    Project Workflow Analysis Blueprint Generator · thedixitjain
    Comprehensive technology-agnostic prompt generator for documenting end-to-end application workflows. Automatically detects project architecture patterns, technology stacks, and data flow patterns to generate detailed implementation blueprints covering entry points, service layers, data access, error handling, and testing approaches across multiple technologies including .NET, Java/Spring, React, and microservices architectures.
    2 repo stars
  9. ▌
    Configuring Certificate Authority With Openssl · thedixitjain bundle
    A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
    2 repo stars
  10. ▌
    Create Github Issue Feature From Specification · thedixitjain
    Create GitHub Issue for feature request from specification file using feature_request.yml template.
    2 repo stars
  11. ▌
    Attacking OAUTH With Device Code Phishing · thedixitjain bundle
    Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
    2 repo stars
  12. ▌
    Detecting Deepfake Audio In Vishing Attacks · thedixitjain bundle
    'Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generates confidence scores, and produces forensic reports. Activates for requests involving deepfake voice detection, vishing investigation, AI-generated speech analysis, voice cloning detection, or audio authenticity verification. '
    2 repo stars
  13. ▌
    Analyzing Lnk File And Jump List Artifacts · thedixitjain bundle
    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.
    2 repo stars
  14. ▌
    Implementing Mobile Application Management · thedixitjain bundle
    'Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security. '
    2 repo stars
  15. ▌
    Performing Dynamic Analysis Of Android App · thedixitjain bundle
    'Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis. '
    2 repo stars
  16. ▌
    Detecting AI Model Prompt Injection Attacks · thedixitjain bundle
    'Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models. The detector analyzes user inputs before they reach the LLM, flagging direct injections (system prompt overrides, role-play escapes, instruction hijacking) and indirect injections (encoded payloads, multi-language obfuscation, delimiter-based escapes). Based on the OWASP LLM Top 10 (LLM01:2025 Prompt Injection) and Simon Willison''s prompt injection taxonomy. Activates for requests involving prompt injection detection, LLM input sanitization, AI security scanning, or prompt attack classification. '
    2 repo stars
  17. ▌
    Assessing Vector And Embedding Weaknesses · thedixitjain bundle
    Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
    2 repo stars
  18. ▌
    Arpsych Transparency And Reproducibility · thedixitjain
    Use when documenting the literature search and making any embedded meta-analysis reproducible for an Annual Review of Psychology (ARPsych) review. Covers search transparency, meta-analytic rigor, and open materials; it does not run the narrative search (arpsych-literature-synthesis) or design exhibits (arpsych-tables-figures).
    2 repo stars
  19. ▌
    Creating Github Issues From Web Research · thedixitjain bundle
    'Execute this skill enhances AI assistant''s ability to conduct web research and translate findings into actionable github issues. it automates the process of extracting key information from web search results and formatting it into a well-structured issue, ready... Use when managing version control. Trigger with phrases like ''commit'', ''branch'', or ''git''. '
    2 repo stars
  20. ▌
    Forum On Science And Technology In China · thedixitjain
    Use when targeting 《中国科技论坛》(Forum on Science and Technology in China — 中国科学技术发展战略研究院主办的科技政策月刊, 匿名初审, 官网 zgkjlt.org.cn 在线投稿) or deciding whether a Chinese S&T-policy manuscript fits this venue. Encodes the journal's fit, framing, anonymized online-submission house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  21. ▌
    Foundations Of Computational Mathematics · thedixitjain
    Use when targeting Foundations of Computational Mathematics (FoCM) or deciding whether a manuscript at the mathematics–computation interface fits this Springer journal. Encodes the journal's fit, framing, proof-and-rigor bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  22. ▌
    Ieee Spoken Language Technology Workshop · thedixitjain
    Use when targeting IEEE Spoken Language Technology Workshop (SLT) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for spoken language technology.
    2 repo stars
  23. ▌
    Journal Of The American Chemical Society · thedixitjain
    Use when targeting Journal of the American Chemical Society (JACS) or deciding whether a chemistry manuscript fits this ACS venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  24. ▌
    Abusing Shadow Credentials For Privesc · thedixitjain bundle
    Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
    2 repo stars
  25. ▌
    Conducting Mobile App Penetration Test · thedixitjain bundle
    'Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment. '
    2 repo stars
  26. ▌
    Deploying Active Directory Honeytokens · thedixitjain bundle
    'Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance. '
    2 repo stars
  27. ▌
    Deploying Honeytokens And Canarytokens · thedixitjain bundle
    Plant canarytokens and honey credentials and alert on breach.
    2 repo stars
  28. ▌
    Deploying Tailscale For Zero Trust Vpn · thedixitjain bundle
    Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
    2 repo stars
  29. ▌
    Detecting AWS Iam Privilege Escalation · thedixitjain bundle
    Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations
    2 repo stars
  30. ▌
    Detecting Bluetooth Low Energy Attacks · thedixitjain bundle
    'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection. '
    2 repo stars
  31. ▌
    Detecting Lateral Movement With Splunk · thedixitjain bundle
    Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
    2 repo stars
  32. ▌
    Detecting Process Injection Techniques · thedixitjain bundle
    'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection. '
    2 repo stars
  33. ▌
    Executing Phishing Simulation Campaign · thedixitjain bundle
    'Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests involving phishing simulation, social engineering assessment, email security testing, or security awareness measurement. '
    2 repo stars
  34. ▌
    Executing Red Team Engagement Planning · thedixitjain bundle
    Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.
    2 repo stars
  35. ▌
    Generating Threat Intelligence Reports · thedixitjain bundle
    'Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting. '
    2 repo stars
  36. ▌
    Hunting For T1098 Account Manipulation · thedixitjain bundle
    Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
    2 repo stars
  37. ▌
    Ieee Symposium On Security And Privacy · thedixitjain
    Use when targeting IEEE Symposium on Security and Privacy (IEEE S&P) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for security flagship.
    2 repo stars
  38. ▌
    Implementing API Key Security Controls · thedixitjain bundle
    'Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Activates for requests involving API key management, API key security, key rotation policy, or API credential protection. '
    2 repo stars
  39. ▌
    Implementing Attack Surface Management · thedixitjain bundle
    'Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments. '
    2 repo stars
  40. ▌
    Implementing Secrets Scanning In CI CD · thedixitjain bundle
    Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
    2 repo stars
  41. ▌
    Implementing Usb Device Control Policy · thedixitjain bundle
    'Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB. '
    2 repo stars
  42. ▌
    Performing AI Driven Osint Correlation · thedixitjain bundle
    Use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
    2 repo stars
  43. ▌
    Performing GRAPHQL Security Assessment · thedixitjain bundle
    Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
    2 repo stars
  44. ▌
    Performing Ssl Tls Security Assessment · thedixitjain bundle
    Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
    2 repo stars
  45. ▌
    Testing API Security With Owasp Top 10 · thedixitjain bundle
    Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
    2 repo stars
  46. ▌
    Continuous LLM Red Teaming With Promptfoo · thedixitjain bundle
    Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
    2 repo stars
  47. ▌
    Implementing API Threat Protection With Apigee · thedixitjain bundle
    Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.
    2 repo stars
  48. ▌
    Migrating Oracle To Postgres Stored Procedures · thedixitjain
    Migrates Oracle PL/SQL stored procedures to PostgreSQL PL/pgSQL. Translates Oracle-specific syntax, preserves method signatures and type-anchored parameters, leverages orafce where appropriate, and applies explicit collation mapping (`COLLATE "C"` only when appropriate, locale collations when required). Use when converting Oracle stored procedures or functions to PostgreSQL equivalents during a database migration.
    2 repo stars
  49. ▌
    Business Operations Skills · thedixitjain
    Use when running, diagnosing, or designing internal business operations — process documentation, vendor SLAs, capacity planning, internal comms, SOP/runbook authoring, procurement spend. Triggers on "BizOps review", "where's the bottleneck", "vendor health", "internal SOP", "all-hands deck", "spend categorization", "capacity for Q3", "process mapping". Forks context to route to one of six BizOps sub-skills (process-mapper, vendor-management, capacity-planner, internal-comms, knowledge-ops, procurement-optimizer) and returns a digest. Distinct from business-growth (external sales motion) and c-level-advisor (strategic, not operational).
    2 repo stars
  50. ▌
    Journal Of International Money And Finance · thedixitjain
    Use when targeting Journal of International Money and Finance (JIMF) or deciding whether an international-finance manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  51. ▌
    Conference And Labs Of The Evaluation Forum · thedixitjain
    Use when targeting Conference and Labs of the Evaluation Forum (CLEF) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for evaluation forum.
    2 repo stars
  52. ▌
    Conference On Health Inference And Learning · thedixitjain
    Use when targeting Conference on Health, Inference, and Learning (CHIL) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI for health.
    2 repo stars
  53. ▌
    International Conference On Computer Vision · thedixitjain
    Use when targeting IEEE/CVF International Conference on Computer Vision (ICCV) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for computer vision flagship.
    2 repo stars
  54. ▌
    Journal Of Business And Economic Statistics · thedixitjain
    Use when targeting Journal of Business and Economic Statistics (JBES) or deciding whether a manuscript at the statistics/econometrics interface fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  55. ▌
    Auditing Terraform Infrastructure For Security · thedixitjain bundle
    'Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment. '
    2 repo stars
  56. ▌
    Building Identity Governance Lifecycle Process · thedixitjain bundle
    'Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design. '
    2 repo stars
  57. ▌
    Building Red Team C2 Infrastructure With Havoc · thedixitjain bundle
    Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
    2 repo stars
  58. ▌
    Deploying Cloud Deception With Decoy Resources · thedixitjain bundle
    >- Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access keys, permission-less decoy users/roles/service principals, honey object-storage buckets, and decoy secrets in Secrets Manager / Key Vault / Secret Manager. Wires detection through CloudTrail + EventBridge, Azure Sentinel honeytoken watchlists + Defender, and GCP Cloud Audit Logs, so any use of a decoy is routed to the SOC with near-zero false positives. Use when protecting cloud accounts and data stores, when an org has only on-prem honeypots and needs cloud coverage, when seeding fake AWS keys to catch credential theft and code-leak exposure, or when detecting cloud reconnaissance and lateral movement. Keywords: cloud deception, canary token AWS, honey S3 bucket, decoy IAM...
    2 repo stars
  59. ▌
    Detecting Container Runtime Threats With Falco · thedixitjain bundle
    Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
    2 repo stars
  60. ▌
    Implementing Cloud Security Posture Management · thedixitjain bundle
    'Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center. '
    2 repo stars
  61. ▌
    Implementing Dragos Platform For Ot Monitoring · thedixitjain bundle
    'Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE. '
    2 repo stars
  62. ▌
    Implementing Kubernetes Pod Security Standards · thedixitjain bundle
    Pod Security Standards (PSS) define three levels of security policies Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
    2 repo stars
  63. ▌
    Implementing Microsegmentation With Guardicore · thedixitjain bundle
    'Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud. '
    2 repo stars
  64. ▌
    Performing AWS Privilege Escalation Assessment · thedixitjain bundle
    'Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques. '
    2 repo stars
  65. ▌
    Performing Cloud Forensics With AWS Cloudtrail · thedixitjain bundle
    Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    2 repo stars
  66. ▌
    Performing Serverless Function Security Review · thedixitjain bundle
    'Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections. '
    2 repo stars
  67. ▌
    Implementing Purdue Model Network Segmentation · thedixitjain bundle
    'Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains. '
    2 repo stars
  68. ▌
    Performing Post Quantum Cryptography Migration · thedixitjain bundle
    'Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure. '
    2 repo stars
  69. ▌
    Prioritizing Vulnerabilities With Cvss Scoring · thedixitjain bundle
    The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r
    2 repo stars
  70. ▌
    Implementing Attack Path Analysis With Xm Cyber · thedixitjain bundle
    Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
    2 repo stars
  71. ▌
    Implementing Identity Governance With Sailpoint · thedixitjain bundle
    Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
    2 repo stars
  72. ▌
    Performing Active Directory Bloodhound Analysis · thedixitjain bundle
    Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin.
    2 repo stars
  73. ▌
    Performing Access Review And Certification · thedixitjain bundle
    Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles. This skill covers review campaign design, reviewer selection, risk-based p
    2 repo stars
  74. ▌
    Performing OAUTH Scope Minimization Review · thedixitjain bundle
    'Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization. '
    2 repo stars
  75. ▌
    Hunting For Registry Persistence Mechanisms · thedixitjain bundle
    Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
    2 repo stars
  76. ▌
    Fda Consultant Specialist · thedixitjain bundle
    FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QMSR (21 CFR 820, which incorporates ISO 13485:2016 by reference since 2026-02-02; formerly QSR) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QMSR, QSR, ISO 13485 for FDA, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity.
    2 repo stars
  77. ▌
    Journal Of International Business Studies · thedixitjain
    Use when targeting Journal of International Business Studies (JIBS) or deciding whether an international-business / cross-border manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  78. ▌
    Journal Of Law Economics And Organization · thedixitjain
    Use when targeting Journal of Law, Economics, and Organization (JLEO) or deciding whether a manuscript at the intersection of law, economics, and organization fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  79. ▌
    Journal Of Management Information Systems · thedixitjain
    Use when targeting Journal of Management Information Systems (JMIS) or deciding whether an information-systems management / IT-business-value / IS-strategy manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  80. ▌
    Progress In Energy And Combustion Science · thedixitjain
    Use when targeting Progress in Energy and Combustion Science or deciding whether an energy/combustion review manuscript fits this venue. Encodes the journal's review-only fit, the critical-synthesis-and-authority bar, comprehensiveness rigor, house style, the review-vs-primary-research routing, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  81. ▌
    Research On Financial And Economic Issues · thedixitjain
    Use when targeting 《财经问题研究》(Research on Financial and Economic Issues — 辽宁省教育厅主管、东北财经大学主办的经济管理类月刊, 1979 创刊, CN 21-1096/F, 双向匿名审稿, 不收任何费用, 在线投稿 cjwt.cbpt.cnki.net) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's fit, framing, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  82. ▌
    Revedres Transparency And Reproducibility · thedixitjain
    Use when settling coding reliability, open materials, PRISMA/MARS reporting, and a reproducible meta-analysis for a Review of Educational Research (RER) manuscript. Makes the review auditable and re-runnable; it does not run the substantive robustness analyses (revedres-comprehensiveness-and-balance) or design the exhibits (revedres-tables-figures).
    2 repo stars
  83. ▌
    Analyzing Mft For Deleted File Recovery · thedixitjain bundle
    Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.
    2 repo stars
  84. ▌
    Analyzing Network Traffic For Incidents · thedixitjain bundle
    'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. '
    2 repo stars
  85. ▌
    Analyzing Ransomware Network Indicators · thedixitjain bundle
    Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis
    2 repo stars
  86. ▌
    Analyzing Web Server Logs For Intrusion · thedixitjain bundle
    Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.
    2 repo stars
  87. ▌
    Building Detection Rule With Splunk Spl · thedixitjain bundle
    Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
    2 repo stars
  88. ▌
    Detecting Credential Dumping Techniques · thedixitjain bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
    2 repo stars
  89. ▌
    Detecting Fileless Attacks On Endpoints · thedixitjain bundle
    'Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques. '
    2 repo stars
  90. ▌
    Detecting Supply Chain Attacks In CI CD · thedixitjain bundle
    'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems. '
    2 repo stars
  91. ▌
    Exploiting Mass Assignment In REST Apis · thedixitjain bundle
    Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
    2 repo stars
  92. ▌
    Implementing AWS Nitro Enclave Security · thedixitjain bundle
    'Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activates for requests involving Nitro Enclave setup, enclave attestation validation, confidential computing on AWS, or KMS enclave policy configuration. '
    2 repo stars
  93. ▌
    Implementing Code Signing For Artifacts · thedixitjain bundle
    'This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines. '
    2 repo stars
  94. ▌
    Implementing Ransomware Backup Strategy · thedixitjain bundle
    'Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration. '
    2 repo stars
  95. ▌
    Implementing Security Chaos Engineering · thedixitjain bundle
    'Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience. '
    2 repo stars
  96. ▌
    Implementing Soar Playbook For Phishing · thedixitjain bundle
    Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
    2 repo stars
  97. ▌
    Implementing Zero Trust With Beyondcorp · thedixitjain bundle
    Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
    2 repo stars
  98. ▌
    Investigating Insider Threat Indicators · thedixitjain bundle
    'Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats. '
    2 repo stars
  99. ▌
    Performing Binary Exploitation Analysis · thedixitjain bundle
    'Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments. '
    2 repo stars
  100. ▌
    Performing Disk Forensics Investigation · thedixitjain bundle
    'Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation. '
    2 repo stars