all publishers

theheavenlyd3mon

@theheavenlyd3mon source repo

1,063 published skills · page 1 of 11

  1. ▌
    Book Pipeline 2 · theheavenlyd3mon bundle
    Design and run an AI-assisted long-form fiction pipeline that turns small story ideas into publishable short novels / audiobooks. Covers the book-writer profile architecture, specialist-profile delegation lanes, manuscript folder convention, and the draft→review→revise→export loop. Use when the user wants to mass-produce books via Hermes, build a book-writer agent, or automate novel/audiobook production.
    28 repo stars
  2. ▌
    Notion API Basics 2 · theheavenlyd3mon
    Notion API fundamentals: authentication, curl patterns, property types, API version differences, and troubleshooting.
    28 repo stars
  3. ▌
    Heartmula 2 · theheavenlyd3mon
    HeartMuLa: Suno-like song generation from lyrics + tags.
    28 repo stars
  4. ▌
    Video Generation 2 · theheavenlyd3mon bundle
    Use when generating video with FLUX 3 tools or contests.
    28 repo stars
  5. ▌
    Kanban Orchestrator 4 · theheavenlyd3mon
    Decomposition playbook + anti-temptation rules for an orchestrator profile routing work through Kanban. The "don't do the work yourself" rule and the basic lifecycle are auto-injected into every kanban worker's system prompt; this skill is the deeper playbook when you're specifically playing the orchestrator role.
    28 repo stars
  6. ▌
    Narrative 2 · theheavenlyd3mon bundle
    Full-novel craft + anti-slop pipeline with project mode (ledger, characters, foreshadow, worldbuilding bible), draft→review→revise gates, and stability-trap enforcement at scene/chapter/manuscript scale. Single-scene mode retained. Use for fiction, lore, character docs, dialogue, worldbuilding, or book projects.
    28 repo stars
  7. ▌
    Git Master 2 · theheavenlyd3mon bundle
    Teach and guide GitHub workflows. Explains concepts, recommends approaches, and references specialist GitHub skills for execution.
    28 repo stars
  8. ▌
    CLI Builder 2 · theheavenlyd3mon bundle
    Build or refactor CLI tools designed for AI agent consumption: non-interactive, flag-driven, idempotent, with --json output and --dry-run preview. Use when creating a new script the agent will call, adding agent-friendly flags to an existing tool, or debugging why an agent keeps failing to use your CLI.
    28 repo stars
  9. ▌
    Maintain · theheavenlyd3mon
    Team-Wiki Maintain
    28 repo stars
  10. ▌
    Ideation 2 · theheavenlyd3mon bundle
    Generate project ideas via creative constraints.
    28 repo stars
  11. ▌
    Hermes Image Generation 2 · theheavenlyd3mon bundle
    Configure, troubleshoot, and use Hermes image generation — all 5 built-in providers (FAL, OpenAI, OpenAI-Codex, xAI, Krea), model catalogs, env vars, and .env location gotchas.
    28 repo stars
  12. ▌
    Kanban Worker 2 · theheavenlyd3mon
    Pitfalls, examples, and edge cases for Hermes Kanban workers. The lifecycle itself is auto-injected into every worker's system prompt as KANBAN_GUIDANCE (from agent/prompt_builder.py); this skill is what you load when you want deeper detail on specific scenarios.
    28 repo stars
  13. ▌
    Qwen Mm Plugins Video Edit 2 · theheavenlyd3mon bundle
    Video Edit
    28 repo stars
  14. ▌
    Hermes Security Audit 2 · theheavenlyd3mon
    Perform a comprehensive security audit of a Hermes installation — check secrets, permissions, network exposure, code patterns, dependencies, and infrastructure. Returns prioritized findings with remediation steps.
    28 repo stars
  15. ▌
    Hermes Security Hardening 2 · theheavenlyd3mon bundle
    Comprehensive security hardening for Hermes installations — fixes permissions, sets up secret scanning, configures macOS Keychain integration, creates security policies, and installs pre-commit hooks.
    28 repo stars
  16. ▌
    Qwen Mm Plugins Video Edit · theheavenlyd3mon bundle
    Video Edit
    28 repo stars
  17. ▌
    Performing Wireless Security Assessment With Kismet · theheavenlyd3mon bundle
    Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
    28 repo stars
  18. ▌
    Auditing Azure Active Directory Configuration · theheavenlyd3mon bundle
    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
    28 repo stars
  19. ▌
    Hardening Windows Endpoint With Cis Benchmark · theheavenlyd3mon bundle
    Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.
    28 repo stars
  20. ▌
    Implementing API Rate Limiting And Throttling · theheavenlyd3mon bundle
    Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers. Activates for requests involving rate limiting implementation, API throttling setup, request quota management, or API abuse prevention.
    28 repo stars
  21. ▌
    Implementing Zero Trust For Saas Applications · theheavenlyd3mon bundle
    Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.
    28 repo stars
  22. ▌
    Performing Cloud Storage Forensic Acquisition · theheavenlyd3mon bundle
    Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
    28 repo stars
  23. ▌
    Building Vulnerability Scanning Workflow · theheavenlyd3mon bundle
    Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.
    28 repo stars
  24. ▌
    Implementing Scim Provisioning With Okta · theheavenlyd3mon bundle
    Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
    28 repo stars
  25. ▌
    Analyzing Azure Activity Logs For Threats · theheavenlyd3mon bundle
    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
    28 repo stars
  26. ▌
    Eradicating Malware From Infected Systems · theheavenlyd3mon bundle
    Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
    28 repo stars
  27. ▌
    Investigating Ransomware Attack Artifacts · theheavenlyd3mon bundle
    Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
    28 repo stars
  28. ▌
    Analyzing Sbom For Supply Chain Vulnerabilities · theheavenlyd3mon bundle
    Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation.
    28 repo stars
  29. ▌
    Building Identity Federation With Saml Azure Ad · theheavenlyd3mon bundle
    Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.
    28 repo stars
  30. ▌
    Configuring Windows Event Logging For Detection · theheavenlyd3mon bundle
    Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
    28 repo stars
  31. ▌
    Detecting Malicious Scheduled Tasks With Sysmon · theheavenlyd3mon bundle
    Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.
    28 repo stars
  32. ▌
    Implementing Attack Path Analysis With Xm Cyber · theheavenlyd3mon bundle
    Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
    28 repo stars
  33. ▌
    Implementing Soar Playbook With Palo Alto Xsoar · theheavenlyd3mon bundle
    Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
    28 repo stars
  34. ▌
    Implementing Syslog Centralization With Rsyslog · theheavenlyd3mon bundle
    Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
    28 repo stars
  35. ▌
    Performing Automated Malware Analysis With Cape · theheavenlyd3mon bundle
    Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
    28 repo stars
  36. ▌
    Performing GCP Security Assessment With Forseti · theheavenlyd3mon bundle
    Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark.
    28 repo stars
  37. ▌
    Performing Subdomain Enumeration With Subfinder · theheavenlyd3mon bundle
    Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
    28 repo stars
  38. ▌
    Performing Web Application Vulnerability Triage · theheavenlyd3mon bundle
    Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
    28 repo stars
  39. ▌
    Analyzing Malware Family Relationships With Malpedia · theheavenlyd3mon bundle
    Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
    28 repo stars
  40. ▌
    Exploiting Vulnerabilities With Metasploit Framework · theheavenlyd3mon bundle
    The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules
    28 repo stars
  41. ▌
    Performing Active Directory Compromise Investigation · theheavenlyd3mon bundle
    Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
    28 repo stars
  42. ▌
    Performing Thick Client Application Penetration Test · theheavenlyd3mon bundle
    Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
    28 repo stars
  43. ▌
    Auditing Terraform Infrastructure For Security · theheavenlyd3mon bundle
    Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
    28 repo stars
  44. ▌
    Implementing API Threat Protection With Apigee · theheavenlyd3mon bundle
    Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.
    28 repo stars
  45. ▌
    Implementing AWS Macie For Data Classification · theheavenlyd3mon bundle
    Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
    28 repo stars
  46. ▌
    Implementing Cloud Security Posture Management · theheavenlyd3mon bundle
    Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center.
    28 repo stars
  47. ▌
    Implementing Kubernetes Pod Security Standards · theheavenlyd3mon bundle
    Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
    28 repo stars
  48. ▌
    Implementing Microsegmentation With Guardicore · theheavenlyd3mon bundle
    Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.
    28 repo stars
  49. ▌
    Implementing Pod Security Admission Controller · theheavenlyd3mon bundle
    Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.
    28 repo stars
  50. ▌
    Performing Cloud Forensics With AWS Cloudtrail · theheavenlyd3mon bundle
    Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    28 repo stars
  51. ▌
    Performing Kubernetes Etcd Security Assessment · theheavenlyd3mon bundle
    Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
    28 repo stars
  52. ▌
    Analyzing Packed Malware With Upx Unpacker · theheavenlyd3mon bundle
    Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
    28 repo stars
  53. ▌
    Building Incident Timeline With Timesketch · theheavenlyd3mon bundle
    Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
    28 repo stars
  54. ▌
    Performing Network Packet Capture Analysis · theheavenlyd3mon bundle
    Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
    28 repo stars
  55. ▌
    Building Ransomware Playbook With Cisa Framework · theheavenlyd3mon bundle
    Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
    28 repo stars
  56. ▌
    Configuring Identity Aware Proxy With Google Iap · theheavenlyd3mon bundle
    Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
    28 repo stars
  57. ▌
    Configuring Multi Factor Authentication With Duo · theheavenlyd3mon bundle
    Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
    28 repo stars
  58. ▌
    Detecting Golden Ticket Attacks In Kerberos Logs · theheavenlyd3mon bundle
    Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
    28 repo stars
  59. ▌
    Implementing Canary Tokens For Network Intrusion · theheavenlyd3mon bundle
    Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.
    28 repo stars
  60. ▌
    Implementing End To End Encryption For Messaging · theheavenlyd3mon bundle
    End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version
    28 repo stars
  61. ▌
    Implementing Mimecast Targeted Attack Protection · theheavenlyd3mon bundle
    Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
    28 repo stars
  62. ▌
    Performing Cloud Incident Containment Procedures · theheavenlyd3mon bundle
    Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
    28 repo stars
  63. ▌
    Performing Paste Site Monitoring For Credentials · theheavenlyd3mon bundle
    Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
    28 repo stars
  64. ▌
    Performing Threat Intelligence Sharing With Misp · theheavenlyd3mon bundle
    Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
    28 repo stars
  65. ▌
    Exploiting Active Directory Certificate Services Esc1 · theheavenlyd3mon bundle
    Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
    28 repo stars
  66. ▌
    Performing Adversary In The Middle Phishing Detection · theheavenlyd3mon bundle
    Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
    28 repo stars
  67. ▌
    Implementing API Security Testing With 42crunch · theheavenlyd3mon bundle
    Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
    28 repo stars
  68. ▌
    Implementing Beyondcorp Zero Trust Access Model · theheavenlyd3mon bundle
    Implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.
    28 repo stars
  69. ▌
    Implementing Google Workspace Sso Configuration · theheavenlyd3mon bundle
    Configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
    28 repo stars
  70. ▌
    Implementing Supply Chain Security With In Toto · theheavenlyd3mon bundle
    Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
    28 repo stars
  71. ▌
    Implementing Zero Trust With Hashicorp Boundary · theheavenlyd3mon bundle
    Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
    28 repo stars
  72. ▌
    Auditing Tls Certificate Transparency Logs · theheavenlyd3mon bundle
    Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting.
    28 repo stars
  73. ▌
    Implementing Dmarc Dkim Spf Email Security · theheavenlyd3mon bundle
    SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im
    28 repo stars
  74. ▌
    Implementing Log Integrity With Blockchain · theheavenlyd3mon bundle
    Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services.
    28 repo stars
  75. ▌
    Performing OAUTH Scope Minimization Review · theheavenlyd3mon bundle
    Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization.
    28 repo stars
  76. ▌
    Performing Network Forensics With Wireshark · theheavenlyd3mon bundle
    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
    28 repo stars
  77. ▌
    Triaging Security Incident With Ir Playbook · theheavenlyd3mon bundle
    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
    28 repo stars
  78. ▌
    Building Adversary Infrastructure Tracking System · theheavenlyd3mon bundle
    Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
    28 repo stars
  79. ▌
    Building Threat Intelligence Enrichment In Splunk · theheavenlyd3mon bundle
    Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
    28 repo stars
  80. ▌
    Detecting Anomalies In Industrial Control Systems · theheavenlyd3mon bundle
    This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
    28 repo stars
  81. ▌
    Detecting Privilege Escalation In Kubernetes Pods · theheavenlyd3mon bundle
    Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
    28 repo stars
  82. ▌
    Detecting T1548 Abuse Elevation Control Mechanism · theheavenlyd3mon bundle
    Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.
    28 repo stars
  83. ▌
    Implementing Aqua Security For Container Scanning · theheavenlyd3mon bundle
    Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
    28 repo stars
  84. ▌
    Implementing Identity Verification For Zero Trust · theheavenlyd3mon bundle
    Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
    28 repo stars
  85. ▌
    Performing Threat Landscape Assessment For Sector · theheavenlyd3mon bundle
    Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
    28 repo stars
  86. ▌
    Testing API For Broken Object Level Authorization · theheavenlyd3mon bundle
    Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to determine if the server enforces per-object authorization. This is OWASP API Security Top 10 2023 risk API1. Activates for requests involving BOLA testing, IDOR in APIs, object-level authorization testing, or API access control bypass.
    28 repo stars
  87. ▌
    Implementing File Integrity Monitoring With Aide · theheavenlyd3mon bundle
    Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
    28 repo stars
  88. ▌
    Implementing GCP Organization Policy Constraints · theheavenlyd3mon bundle
    Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.
    28 repo stars
  89. ▌
    Implementing Runtime Application Self Protection · theheavenlyd3mon bundle
    Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.
    28 repo stars
  90. ▌
    Implementing Anti Phishing Training Program · theheavenlyd3mon bundle
    Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv
    28 repo stars
  91. ▌
    Performing Memory Forensics With Volatility3 · theheavenlyd3mon bundle
    Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
    28 repo stars
  92. ▌
    Detecting Dns Exfiltration With Dns Query Analysis · theheavenlyd3mon bundle
    Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
    28 repo stars
  93. ▌
    Implementing Conduit Security For Ot Remote Access · theheavenlyd3mon bundle
    Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly.
    28 repo stars
  94. ▌
    Implementing Opa Gatekeeper For Policy Enforcement · theheavenlyd3mon bundle
    Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
    28 repo stars
  95. ▌
    Performing Malware Hash Enrichment With Virustotal · theheavenlyd3mon bundle
    Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
    28 repo stars
  96. ▌
    Detecting AWS Credential Exposure With Trufflehog · theheavenlyd3mon bundle
    Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
    28 repo stars
  97. ▌
    Detecting Azure Storage Account Misconfigurations · theheavenlyd3mon bundle
    Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
    28 repo stars
  98. ▌
    Implementing Conditional Access Policies Azure Ad · theheavenlyd3mon bundle
    Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l
    28 repo stars
  99. ▌
    Implementing Google Workspace Phishing Protection · theheavenlyd3mon bundle
    Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
    28 repo stars
  100. ▌
    Implementing Network Traffic Analysis With Arkime · theheavenlyd3mon bundle
    Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across captured traffic.
    28 repo stars