theheavenlyd3mon
- 1.1k skills
- 0 followers
- 28 repo stars
- 2 weeks ago last updated
- ▌ Book Pipeline 2 · theheavenlyd3mon bundleDesign and run an AI-assisted long-form fiction pipeline that turns small story ideas into publishable short novels / audiobooks. Covers the book-writer profile architecture, specialist-profile delegation lanes, manuscript folder convention, and the draft→review→revise→export loop. Use when the user wants to mass-produce books via Hermes, build a book-writer agent, or automate novel/audiobook production.
- ▌ Notion API Basics 2 · theheavenlyd3monNotion API fundamentals: authentication, curl patterns, property types, API version differences, and troubleshooting.
- ▌
- ▌ Video Generation 2 · theheavenlyd3mon bundleUse when generating video with FLUX 3 tools or contests.
- ▌ Kanban Orchestrator 4 · theheavenlyd3monDecomposition playbook + anti-temptation rules for an orchestrator profile routing work through Kanban. The "don't do the work yourself" rule and the basic lifecycle are auto-injected into every kanban worker's system prompt; this skill is the deeper playbook when you're specifically playing the orchestrator role.
- ▌ Narrative 2 · theheavenlyd3mon bundleFull-novel craft + anti-slop pipeline with project mode (ledger, characters, foreshadow, worldbuilding bible), draft→review→revise gates, and stability-trap enforcement at scene/chapter/manuscript scale. Single-scene mode retained. Use for fiction, lore, character docs, dialogue, worldbuilding, or book projects.
- ▌ Git Master 2 · theheavenlyd3mon bundleTeach and guide GitHub workflows. Explains concepts, recommends approaches, and references specialist GitHub skills for execution.
- ▌ CLI Builder 2 · theheavenlyd3mon bundleBuild or refactor CLI tools designed for AI agent consumption: non-interactive, flag-driven, idempotent, with --json output and --dry-run preview. Use when creating a new script the agent will call, adding agent-friendly flags to an existing tool, or debugging why an agent keeps failing to use your CLI.
- ▌
- ▌
- ▌ Hermes Image Generation 2 · theheavenlyd3mon bundleConfigure, troubleshoot, and use Hermes image generation — all 5 built-in providers (FAL, OpenAI, OpenAI-Codex, xAI, Krea), model catalogs, env vars, and .env location gotchas.
- ▌ Kanban Worker 2 · theheavenlyd3monPitfalls, examples, and edge cases for Hermes Kanban workers. The lifecycle itself is auto-injected into every worker's system prompt as KANBAN_GUIDANCE (from agent/prompt_builder.py); this skill is what you load when you want deeper detail on specific scenarios.
- ▌
- ▌ Hermes Security Audit 2 · theheavenlyd3monPerform a comprehensive security audit of a Hermes installation — check secrets, permissions, network exposure, code patterns, dependencies, and infrastructure. Returns prioritized findings with remediation steps.
- ▌ Hermes Security Hardening 2 · theheavenlyd3mon bundleComprehensive security hardening for Hermes installations — fixes permissions, sets up secret scanning, configures macOS Keychain integration, creates security policies, and installs pre-commit hooks.
- ▌
- ▌ Performing Wireless Security Assessment With Kismet · theheavenlyd3mon bundleConduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
- ▌ Auditing Azure Active Directory Configuration · theheavenlyd3mon bundleAuditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
- ▌ Hardening Windows Endpoint With Cis Benchmark · theheavenlyd3mon bundleHardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.
- ▌ Implementing API Rate Limiting And Throttling · theheavenlyd3mon bundleImplements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers. Activates for requests involving rate limiting implementation, API throttling setup, request quota management, or API abuse prevention.
- ▌ Implementing Zero Trust For Saas Applications · theheavenlyd3mon bundleImplementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.
- ▌ Performing Cloud Storage Forensic Acquisition · theheavenlyd3mon bundlePerform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
- ▌ Building Vulnerability Scanning Workflow · theheavenlyd3mon bundleBuilds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.
- ▌ Implementing Scim Provisioning With Okta · theheavenlyd3mon bundleImplement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
- ▌ Analyzing Azure Activity Logs For Threats · theheavenlyd3mon bundleQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
- ▌ Eradicating Malware From Infected Systems · theheavenlyd3mon bundleSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
- ▌ Investigating Ransomware Attack Artifacts · theheavenlyd3mon bundleIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
- ▌ Analyzing Sbom For Supply Chain Vulnerabilities · theheavenlyd3mon bundleParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation.
- ▌ Building Identity Federation With Saml Azure Ad · theheavenlyd3mon bundleEstablish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.
- ▌ Configuring Windows Event Logging For Detection · theheavenlyd3mon bundleConfigures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
- ▌ Detecting Malicious Scheduled Tasks With Sysmon · theheavenlyd3mon bundleDetect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.
- ▌ Implementing Attack Path Analysis With Xm Cyber · theheavenlyd3mon bundleDeploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
- ▌ Implementing Soar Playbook With Palo Alto Xsoar · theheavenlyd3mon bundleImplement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
- ▌ Implementing Syslog Centralization With Rsyslog · theheavenlyd3mon bundleConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
- ▌ Performing Automated Malware Analysis With Cape · theheavenlyd3mon bundleDeploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
- ▌ Performing GCP Security Assessment With Forseti · theheavenlyd3mon bundlePerforming comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark.
- ▌ Performing Subdomain Enumeration With Subfinder · theheavenlyd3mon bundleEnumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
- ▌ Performing Web Application Vulnerability Triage · theheavenlyd3mon bundleTriage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
- ▌ Analyzing Malware Family Relationships With Malpedia · theheavenlyd3mon bundleUse the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
- ▌ Exploiting Vulnerabilities With Metasploit Framework · theheavenlyd3mon bundleThe Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules
- ▌ Performing Active Directory Compromise Investigation · theheavenlyd3mon bundleInvestigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
- ▌ Performing Thick Client Application Penetration Test · theheavenlyd3mon bundleConduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
- ▌ Auditing Terraform Infrastructure For Security · theheavenlyd3mon bundleAuditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
- ▌ Implementing API Threat Protection With Apigee · theheavenlyd3mon bundleImplement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.
- ▌ Implementing AWS Macie For Data Classification · theheavenlyd3mon bundleImplement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
- ▌ Implementing Cloud Security Posture Management · theheavenlyd3mon bundleImplementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center.
- ▌ Implementing Kubernetes Pod Security Standards · theheavenlyd3mon bundlePod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
- ▌ Implementing Microsegmentation With Guardicore · theheavenlyd3mon bundleImplementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.
- ▌ Implementing Pod Security Admission Controller · theheavenlyd3mon bundleImplement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.
- ▌ Performing Cloud Forensics With AWS Cloudtrail · theheavenlyd3mon bundlePerform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
- ▌ Performing Kubernetes Etcd Security Assessment · theheavenlyd3mon bundleAssess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
- ▌ Analyzing Packed Malware With Upx Unpacker · theheavenlyd3mon bundleIdentifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
- ▌ Building Incident Timeline With Timesketch · theheavenlyd3mon bundleBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
- ▌ Performing Network Packet Capture Analysis · theheavenlyd3mon bundlePerform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
- ▌ Building Ransomware Playbook With Cisa Framework · theheavenlyd3mon bundleBuilds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
- ▌ Configuring Identity Aware Proxy With Google Iap · theheavenlyd3mon bundleConfiguring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
- ▌ Configuring Multi Factor Authentication With Duo · theheavenlyd3mon bundleDeploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
- ▌ Detecting Golden Ticket Attacks In Kerberos Logs · theheavenlyd3mon bundleDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
- ▌ Implementing Canary Tokens For Network Intrusion · theheavenlyd3mon bundleDeploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.
- ▌ Implementing End To End Encryption For Messaging · theheavenlyd3mon bundleEnd-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version
- ▌ Implementing Mimecast Targeted Attack Protection · theheavenlyd3mon bundleDeploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
- ▌ Performing Cloud Incident Containment Procedures · theheavenlyd3mon bundleExecute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
- ▌ Performing Paste Site Monitoring For Credentials · theheavenlyd3mon bundleMonitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
- ▌ Performing Threat Intelligence Sharing With Misp · theheavenlyd3mon bundleUse PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
- ▌ Exploiting Active Directory Certificate Services Esc1 · theheavenlyd3mon bundleExploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
- ▌ Performing Adversary In The Middle Phishing Detection · theheavenlyd3mon bundleDetect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
- ▌ Implementing API Security Testing With 42crunch · theheavenlyd3mon bundleImplement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
- ▌ Implementing Beyondcorp Zero Trust Access Model · theheavenlyd3mon bundleImplementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.
- ▌ Implementing Google Workspace Sso Configuration · theheavenlyd3mon bundleConfigure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
- ▌ Implementing Supply Chain Security With In Toto · theheavenlyd3mon bundleImplement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
- ▌ Implementing Zero Trust With Hashicorp Boundary · theheavenlyd3mon bundleImplement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
- ▌ Auditing Tls Certificate Transparency Logs · theheavenlyd3mon bundleMonitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting.
- ▌ Implementing Dmarc Dkim Spf Email Security · theheavenlyd3mon bundleSPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im
- ▌ Implementing Log Integrity With Blockchain · theheavenlyd3mon bundleBuild an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services.
- ▌ Performing OAUTH Scope Minimization Review · theheavenlyd3mon bundlePerforms OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization.
- ▌ Performing Network Forensics With Wireshark · theheavenlyd3mon bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
- ▌ Triaging Security Incident With Ir Playbook · theheavenlyd3mon bundleClassify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
- ▌ Building Adversary Infrastructure Tracking System · theheavenlyd3mon bundleBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
- ▌ Building Threat Intelligence Enrichment In Splunk · theheavenlyd3mon bundleBuild automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
- ▌ Detecting Anomalies In Industrial Control Systems · theheavenlyd3mon bundleThis skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
- ▌ Detecting Privilege Escalation In Kubernetes Pods · theheavenlyd3mon bundleDetect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
- ▌ Detecting T1548 Abuse Elevation Control Mechanism · theheavenlyd3mon bundleDetect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.
- ▌ Implementing Aqua Security For Container Scanning · theheavenlyd3mon bundleDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
- ▌ Implementing Identity Verification For Zero Trust · theheavenlyd3mon bundleImplement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
- ▌ Performing Threat Landscape Assessment For Sector · theheavenlyd3mon bundleConduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
- ▌ Testing API For Broken Object Level Authorization · theheavenlyd3mon bundleTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to determine if the server enforces per-object authorization. This is OWASP API Security Top 10 2023 risk API1. Activates for requests involving BOLA testing, IDOR in APIs, object-level authorization testing, or API access control bypass.
- ▌ Implementing File Integrity Monitoring With Aide · theheavenlyd3mon bundleConfigure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
- ▌ Implementing GCP Organization Policy Constraints · theheavenlyd3mon bundleImplement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.
- ▌ Implementing Runtime Application Self Protection · theheavenlyd3mon bundleDeploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.
- ▌ Implementing Anti Phishing Training Program · theheavenlyd3mon bundleSecurity awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv
- ▌ Performing Memory Forensics With Volatility3 · theheavenlyd3mon bundleAnalyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
- ▌ Detecting Dns Exfiltration With Dns Query Analysis · theheavenlyd3mon bundleDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
- ▌ Implementing Conduit Security For Ot Remote Access · theheavenlyd3mon bundleImplement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly.
- ▌ Implementing Opa Gatekeeper For Policy Enforcement · theheavenlyd3mon bundleEnforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
- ▌ Performing Malware Hash Enrichment With Virustotal · theheavenlyd3mon bundleEnrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
- ▌ Detecting AWS Credential Exposure With Trufflehog · theheavenlyd3mon bundleDetecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
- ▌ Detecting Azure Storage Account Misconfigurations · theheavenlyd3mon bundleAudit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
- ▌ Implementing Conditional Access Policies Azure Ad · theheavenlyd3mon bundleConfigure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l
- ▌ Implementing Google Workspace Phishing Protection · theheavenlyd3mon bundleConfigure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
- ▌ Implementing Network Traffic Analysis With Arkime · theheavenlyd3mon bundleDeploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across captured traffic.