all publishers

thedixitjain

@thedixitjain source repo

10,417 published skills · page 16 of 105

  1. ▌
    Performing Insider Threat Investigation · thedixitjain bundle
    'Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection. '
    2 repo stars
  2. ▌
    Performing Nist Csf Maturity Assessment · thedixitjain bundle
    The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
    2 repo stars
  3. ▌
    Performing Ransomware Tabletop Exercise · thedixitjain bundle
    'Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill. '
    2 repo stars
  4. ▌
    Performing Soc2 Type2 Audit Preparation · thedixitjain bundle
    'Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification. '
    2 repo stars
  5. ▌
    Reverse Engineering Malware With Ghidra · thedixitjain bundle
    'Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals. '
    2 repo stars
  6. ▌
    Markdown HTML Orchestrator · thedixitjain bundle
    Use when a user wants to convert any markdown file in their Claude project into a single-file, lightly-interactive HTML — long-form documents (specs, plans, RFCs, reports, explainers), code reviews with diffs and severity-tagged annotations, or slide decks. Triggers on "convert this markdown to HTML", "make this an HTML file", "turn this into an interactive document", "render this report as HTML", "PR writeup as HTML", "slides from this markdown". Forks context to route to one of three converter sub-skills (md-document, md-review, md-slides) based on a deterministic doctype classifier, after the user has run the design-system onboarding once. Refuses if input is under 100 lines (per Shihipar — markdown still wins below the threshold) or design-system isn't onboarded. Distinct from Anthropic's official Playground plugin (which is interactive prompt-tuning controls with...
    2 repo stars
  7. ▌
    Sankhya Dashboard HTML Jsp Custom Best Pratices · thedixitjain bundle
    This skill should be used when the user asks for patterns, best practices, creation, or fixing of Sankhya dashboards using HTML, JSP, Java, and SQL.
    2 repo stars
  8. ▌
    Detecting Business Email Compromise With AI · thedixitjain bundle
    Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
    2 repo stars
  9. ▌
    Startup Business Analyst Market Opportunity · thedixitjain
    'Generate comprehensive market opportunity analysis with TAM/SAM/SOM calculations '
    2 repo stars
  10. ▌
    International Conference On Machine Learning · thedixitjain
    Use when targeting International Conference on Machine Learning (ICML) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI/ML flagship.
    2 repo stars
  11. ▌
    Building Identity Federation With Saml Azure Ad · thedixitjain bundle
    Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.
    2 repo stars
  12. ▌
    Performing Ssl Certificate Lifecycle Management · thedixitjain bundle
    SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading
    2 repo stars
  13. ▌
    Configuring Windows Event Logging For Detection · thedixitjain bundle
    'Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging. '
    2 repo stars
  14. ▌
    Implementing Soar Playbook With Palo Alto Xsoar · thedixitjain bundle
    Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
    2 repo stars
  15. ▌
    Display Glasses With Jetpack Compose Glimmer · thedixitjain bundle
    Provides guidelines for developing projected Android XR apps for display glasses using the Jetpack Compose Glimmer UI toolkit. This skill covers foundational Glimmer design principles, workflows for implementing Jetpack Compose Glimmer, and interaction models for the glasses form factor. Use this skill to build an Android XR Augmented Experience app with Jetpack Compose Glimmer that adheres to the Glimmer design system for optimized glasses styling.
    2 repo stars
  16. ▌
    Exploiting Prototype Pollution In Javascript · thedixitjain bundle
    Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
    2 repo stars
  17. ▌
    Performing Entitlement Review With Sailpoint Iiq · thedixitjain bundle
    'Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates for requests involving access reviews, entitlement certifications, SailPoint IIQ governance, or periodic user access recertification. '
    2 repo stars
  18. ▌
    Journal Of The Academy Of Marketing Science · thedixitjain
    Use when targeting Journal of the Academy of Marketing Science (JAMS) or deciding whether a marketing manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  19. ▌
    Conducting Memory Forensics With Volatility · thedixitjain bundle
    'Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition. '
    2 repo stars
  20. ▌
    Aaai Conference On Artificial Intelligence · thedixitjain
    Use when targeting AAAI Conference on Artificial Intelligence (AAAI) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI/ML flagship.
    2 repo stars
  21. ▌
    Acm International Conference On Multimedia · thedixitjain
    Use when targeting ACM International Conference on Multimedia (ACM MM) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for multimedia.
    2 repo stars
  22. ▌
    Annual Review Of Environment And Resources · thedixitjain
    Use when targeting the Annual Review of Environment and Resources or deciding whether an environment-and-resources synthesis fits this invited-review venue. Encodes the journal's invited-review fit, the authoritative-synthesis bar, structure expectations, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  23. ▌
    International Economics And Trade Research · thedixitjain
    Use when targeting 《国际经贸探索》(International Economics and Trade Research — 广东外语外贸大学主办的月刊, CN 44-1302/F) or deciding whether a Chinese trade/open-economy/business manuscript fits this venue. Encodes the journal's fit, 顺序编码制 house style, 粤港澳/开放经济 落点, official re-check, and desk-reject heuristics.
    2 repo stars
  24. ▌
    Journal Of Allergy And Clinical Immunology · thedixitjain
    Use when targeting The Journal of Allergy and Clinical Immunology (JACI) or deciding whether an allergy/asthma/clinical-immunology study fits this venue. Encodes the journal's fit, the clinical-and-mechanistic immunology evidence bar, reporting-guideline and registration requirements, AAAAI/Elsevier house style, official-submission re-check, and desk-reject heuristics. Venue-fit aid only, not clinical advice.
    2 repo stars
  25. ▌
    Science And Technology Progress And Policy · thedixitjain
    Use when targeting 《科技进步与对策》(Science and Technology Progress and Policy — 湖北省科技信息研究院主办的科技创新政策半月刊, 1984 年创刊, 官网 kjjb.org 唯一在线投稿) or deciding whether a Chinese innovation-policy manuscript fits this venue. Encodes the journal's fit, framing, online-only submission house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  26. ▌
    Analyzing Apt Group With Mitre Navigator · thedixitjain bundle
    Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
    2 repo stars
  27. ▌
    Analyzing Linux Audit Logs For Intrusion · thedixitjain bundle
    'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux. '
    2 repo stars
  28. ▌
    Analyzing Supply Chain Malware Artifacts · thedixitjain bundle
    Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
    2 repo stars
  29. ▌
    Auditing Foundry Smart Contract Security · thedixitjain bundle
    >- Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and arithmetic bugs BEFORE deploying to an EVM chain. Also enforces key hygiene (no plaintext private keys, encrypted cast keystore) and a secure deploy workflow. Use when writing, reviewing, testing, or deploying Solidity/Foundry contracts, building a dApp, or working with forge/cast/anvil, MetaMask, or Web3/DeFi code.
    2 repo stars
  30. ▌
    Building Threat Actor Profile From Osint · thedixitjain bundle
    Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
    2 repo stars
  31. ▌
    Building Vulnerability Scanning Workflow · thedixitjain bundle
    'Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards. '
    2 repo stars
  32. ▌
    Collecting Threat Intelligence With Misp · thedixitjain bundle
    MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
    2 repo stars
  33. ▌
    Detecting Ransomware Encryption Behavior · thedixitjain bundle
    'Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting. '
    2 repo stars
  34. ▌
    Evaluating Threat Intelligence Platforms · thedixitjain bundle
    'Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions. '
    2 repo stars
  35. ▌
    Exploiting Type Juggling Vulnerabilities · thedixitjain bundle
    Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
    2 repo stars
  36. ▌
    Financial Cryptography And Data Security · thedixitjain
    Use when targeting Financial Cryptography and Data Security (FC) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for financial security.
    2 repo stars
  37. ▌
    Hunting For Registry Run Key Persistence · thedixitjain bundle
    Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
    2 repo stars
  38. ▌
    Implementing AWS Security Hub Compliance · thedixitjain bundle
    'Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management. '
    2 repo stars
  39. ▌
    Implementing Devsecops Security Scanning · thedixitjain bundle
    'Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation. '
    2 repo stars
  40. ▌
    Implementing LLM Guardrails For Security · thedixitjain bundle
    'Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang definitions, custom Python validators for PII detection and content policy enforcement, and the Guardrails AI framework for structured output validation. The guardrails system intercepts both user inputs (blocking injection attempts, stripping PII, enforcing topic boundaries) and model outputs (detecting hallucinations, filtering toxic content, validating JSON schema compliance). Activates for requests involving LLM output validation, AI content filtering, guardrail implementation, or LLM safety enforcement. '
    2 repo stars
  41. ▌
    Implementing Pci Dss Compliance Controls · thedixitjain bundle
    PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements
    2 repo stars
  42. ▌
    Implementing Zero Trust Dns With Nextdns · thedixitjain bundle
    Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
    2 repo stars
  43. ▌
    Performing Bluetooth Security Assessment · thedixitjain bundle
    Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
    2 repo stars
  44. ▌
    Performing Initial Access With Evilginx3 · thedixitjain bundle
    Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.
    2 repo stars
  45. ▌
    Performing Lateral Movement With Wmiexec · thedixitjain bundle
    Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.
    2 repo stars
  46. ▌
    Performing Physical Intrusion Assessment · thedixitjain bundle
    Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
    2 repo stars
  47. ▌
    Performing Scada Hmi Security Assessment · thedixitjain bundle
    'Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines. '
    2 repo stars
  48. ▌
    Privacy Enhancing Technologies Symposium · thedixitjain
    Use when targeting Privacy Enhancing Technologies Symposium (PETS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for privacy.
    2 repo stars
  49. ▌
    Securing Remote Access To Ot Environment · thedixitjain bundle
    'This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements. '
    2 repo stars
  50. ▌
    Performing Bandwidth Throttling Attack Simulation · thedixitjain bundle
    'Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks. '
    2 repo stars
  51. ▌
    Full Stack Orchestration Full Stack Feature · thedixitjain
    Use when working with full stack orchestration full stack feature
    2 repo stars
  52. ▌
    Post Exploiting Microsoft Graph With Graphrunner · thedixitjain bundle
    Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
    2 repo stars
  53. ▌
    Contract And Proposal Writer · thedixitjain
    Generate professional, jurisdiction-aware business documents: freelance contracts, project proposals, SOWs, NDAs, and MSAs. Structured Markdown output with docx conversion instructions. Covers US (Delaware), EU (GDPR), UK, and DACH (German law) jurisdictions. Not a substitute for legal counsel — use as strong starting points. Use when drafting a freelance contract, preparing a client proposal, writing an SOW for a new engagement, or producing an NDA before sharing sensitive material.
    2 repo stars
  54. ▌
    Hunting For Beaconing With Frequency Analysis · thedixitjain bundle
    Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
    2 repo stars
  55. ▌
    Building C2 Infrastructure With Sliver Framework · thedixitjain bundle
    Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.
    2 repo stars
  56. ▌
    Configuring Identity Aware Proxy With Google Iap · thedixitjain bundle
    'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts. '
    2 repo stars
  57. ▌
    Implementing File Integrity Monitoring With Aide · thedixitjain bundle
    Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
    2 repo stars
  58. ▌
    Implementing GCP Organization Policy Constraints · thedixitjain bundle
    Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.
    2 repo stars
  59. ▌
    Performing Cloud Incident Containment Procedures · thedixitjain bundle
    Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
    2 repo stars
  60. ▌
    Application Performance Performance Optimization · thedixitjain
    Optimize end-to-end application performance with profiling, observability, and backend/frontend tuning. Use when coordinating performance optimization across the stack.
    2 repo stars
  61. ▌
    Creating Oracle To Postgres Migration Bug Report · thedixitjain bundle
    Creates structured bug reports for defects found during Oracle-to-PostgreSQL migration. Use when documenting behavioral differences between Oracle and PostgreSQL as actionable bug reports with severity, root cause, and remediation steps.
    2 repo stars
  62. ▌
    International Symposium On Computer Architecture · thedixitjain
    Use when targeting International Symposium on Computer Architecture (ISCA) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for computer architecture flagship.
    2 repo stars
  63. ▌
    Conducting Spearphishing Simulation Campaign · thedixitjain bundle
    Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf
    2 repo stars
  64. ▌
    Marketing Demand Acquisition · thedixitjain bundle
    Creates demand generation campaigns, optimizes paid ad spend across LinkedIn, Google, and Meta, develops SEO strategies, and structures partnership programs. Use when planning demand gen strategy, growth marketing, advertising campaigns, PPC optimization, lead generation, pipeline generation, or marketing budgets. Covers multi-channel acquisition (Google Ads, LinkedIn Ads, Meta Ads), CAC analysis, MQL/SQL workflows, attribution modeling, technical SEO, and co-marketing partnerships. Default calibration profile is a Series A+ B2B SaaS scaling internationally (EU/US/Canada, hybrid PLG/Sales-Led) — adapt benchmarks for other stages and motions rather than skipping the skill.
    2 repo stars
  65. ▌
    Hunting For Persistence Mechanisms In Windows · thedixitjain bundle
    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
    2 repo stars
  66. ▌
    Reverse Engineering Android Malware With Jadx · thedixitjain bundle
    'Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis. '
    2 repo stars
  67. ▌
    Collecting Open Source Intelligence · thedixitjain bundle
    'Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance. '
    2 repo stars
  68. ▌
    Configuring Ldap Security Hardening · thedixitjain bundle
    Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
    2 repo stars
  69. ▌
    Hunting Advanced Persistent Threats · thedixitjain bundle
    'Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks. '
    2 repo stars
  70. ▌
    Hunting Credential Stuffing Attacks · thedixitjain bundle
    'Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses statistical analysis on Splunk or raw log data. Use when investigating account takeover campaigns or building detection rules for auth abuse. '
    2 repo stars
  71. ▌
    Hunting For Supply Chain Compromise · thedixitjain bundle
    Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
    2 repo stars
  72. ▌
    Implementing Bgp Security With Rpki · thedixitjain bundle
    Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.
    2 repo stars
  73. ▌
    Implementing Diamond Model Analysis · thedixitjain bundle
    The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    2 repo stars
  74. ▌
    Implementing GCP Vpc Firewall Rules · thedixitjain bundle
    'Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs. '
    2 repo stars
  75. ▌
    Implementing Network Access Control · thedixitjain bundle
    'Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices. '
    2 repo stars
  76. ▌
    Performing Malware Triage With Yara · thedixitjain bundle
    'Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection. '
    2 repo stars
  77. ▌
    Scanning Network With Nmap Advanced · thedixitjain bundle
    'Performs advanced network reconnaissance using Nmap''s scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks. '
    2 repo stars
  78. ▌
    Conducting Internal Network Penetration Test · thedixitjain bundle
    Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.
    2 repo stars
  79. ▌
    Conducting Wireless Network Penetration Test · thedixitjain bundle
    'Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Activates for requests involving wireless pentest, WiFi security assessment, WPA2/WPA3 testing, or rogue access point detection. '
    2 repo stars
  80. ▌
    Implementing Patch Management For Ot Systems · thedixitjain bundle
    'This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization, staged deployment through test environments, maintenance window coordination, rollback procedures, and compensating controls when patches cannot be applied due to operational constraints or vendor restrictions. '
    2 repo stars
  81. ▌
    Performing Active Directory Penetration Test · thedixitjain bundle
    Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    2 repo stars
  82. ▌
    Performing External Network Penetration Test · thedixitjain bundle
    Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.
    2 repo stars
  83. ▌
    Performing Wireless Network Penetration Test · thedixitjain bundle
    Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
    2 repo stars
  84. ▌
    Pmla Textual Evidence And Close Reading · thedixitjain
    Use when marshalling textual evidence and close reading as the evidence base of a PMLA (Publications of the Modern Language Association) essay. In literary studies the text is the data — claims are earned through careful reading of language, form, and context, quoted accurately and cited in MLA style. Strengthens the reading; it does not run analyses or invent passages.
    2 repo stars
  85. ▌
    Conference On Lifelong Learning Agents · thedixitjain
    Use when targeting Conference on Lifelong Learning Agents (CoLLAs) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for continual learning.
    2 repo stars
  86. ▌
    Extracting Config From Agent Tesla Rat · thedixitjain bundle
    Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
    2 repo stars
  87. ▌
    Detecting Insider Data Exfiltration Via Dlp · thedixitjain bundle
    'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating insider threats or building user behavior analytics for data loss prevention. '
    2 repo stars
  88. ▌
    Implementing API Schema Validation Security · thedixitjain bundle
    Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.
    2 repo stars
  89. ▌
    Preprocessing Data With Automated Pipelines · thedixitjain bundle
    'Process automate data cleaning, transformation, and validation for ML tasks. Use when requesting "preprocess data", "clean data", "ETL pipeline", or "data transformation". Trigger with relevant phrases based on skill purpose. '
    2 repo stars
  90. ▌
    Securing Historian Server In Ot Environment · thedixitjain bundle
    'This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for historian interfaces, data replication through DMZ using data diodes or PI-to-PI connectors, SQL injection prevention in historian queries, and integrity protection of process data used for safety analysis, regulatory reporting, and process optimization. '
    2 repo stars
  91. ▌
    Economic Theory And Business Management · thedixitjain
    Use when targeting 《经济理论与经济管理》(Economic Theory and Business Management — 教育部主管、中国人民大学主办的经济学月刊, 1981 年创刊, CSSCI) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's fit, framing, abstract/keyword house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  92. ▌
    Building Ioc Defanging And Sharing Pipeline · thedixitjain bundle
    Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
    2 repo stars
  93. ▌
    Configuring Suricata For Network Monitoring · thedixitjain bundle
    'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms for centralized security monitoring. '
    2 repo stars
  94. ▌
    Create Github Action Workflow Specification · thedixitjain
    Create a formal specification for an existing GitHub Actions CI/CD workflow, optimized for AI consumption and workflow maintenance.
    2 repo stars
  95. ▌
    Database Migrations Migration Observability · thedixitjain
    Migration monitoring, CDC, and observability infrastructure
    2 repo stars
  96. ▌
    Detecting AWS Guardduty Findings Automation · thedixitjain bundle
    Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
    2 repo stars
  97. ▌
    Detecting Container Escape With Falco Rules · thedixitjain bundle
    Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
    2 repo stars
  98. ▌
    Detecting Dcsync Attack In Active Directory · thedixitjain bundle
    Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.
    2 repo stars
  99. ▌
    Hunting For Living Off The Cloud Techniques · thedixitjain bundle
    Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse of Azure, AWS, GCP services, and SaaS platforms.
    2 repo stars
  100. ▌
    Performing Dmarc Policy Enforcement Rollout · thedixitjain bundle
    Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
    2 repo stars