theheavenlyd3mon
- 1.1k skills
- 0 followers
- 28 repo stars
- 2 weeks ago last updated
- ▌ Performing Cloud Asset Inventory With Cartography · theheavenlyd3mon bundlePerform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure.
- ▌ Performing Container Security Scanning With Trivy · theheavenlyd3mon bundleScan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
- ▌ Implementing Aes Encryption For Data At REST · theheavenlyd3mon bundleAES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m
- ▌ Implementing Digital Signatures With Ed25519 · theheavenlyd3mon bundleEd25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove
- ▌ Analyzing Office365 Audit Logs For Compromise · theheavenlyd3mon bundleParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ Performing Network Traffic Analysis With Zeek · theheavenlyd3mon bundleDeploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
- ▌ Performing AWS Account Enumeration With Scout Suite · theheavenlyd3mon bundlePerform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.
- ▌ Performing Kubernetes Cis Benchmark With Kube Bench · theheavenlyd3mon bundleAudit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
- ▌ Performing Threat Modeling With Owasp Threat Dragon · theheavenlyd3mon bundleUse OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
- ▌ Implementing Fuzz Testing In Cicd With Aflplusplus · theheavenlyd3mon bundleIntegrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.
- ▌ Implementing Kubernetes Network Policy With Calico · theheavenlyd3mon bundleImplement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.
- ▌ Implementing Network Access Control With Cisco Ise · theheavenlyd3mon bundleDeploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
- ▌ Implementing Zero Standing Privilege With Cyberark · theheavenlyd3mon bundleDeploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.
- ▌ Building Vulnerability Aging And Sla Tracking · theheavenlyd3mon bundleImplement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.
- ▌ Implementing Email Sandboxing With Proofpoint · theheavenlyd3mon bundleEmail sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is an industry
- ▌ Implementing Envelope Encryption With AWS Kms · theheavenlyd3mon bundleEnvelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting
- ▌ Detecting Broken Object Property Level Authorization · theheavenlyd3mon bundleDetect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
- ▌ Implementing Continuous Security Validation With Bas · theheavenlyd3mon bundleDeploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.
- ▌ Implementing Ot Network Traffic Analysis With Nozomi · theheavenlyd3mon bundleDeploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
- ▌ Implementing Security Information Sharing With Stix2 · theheavenlyd3mon bundleCreate, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
- ▌ Implementing Vulnerability Management With Greenbone · theheavenlyd3mon bundleDeploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.
- ▌ Implementing Zero Knowledge Proof For Authentication · theheavenlyd3mon bundleZero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati
- ▌ Performing Active Directory Vulnerability Assessment · theheavenlyd3mon bundleAssess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.
- ▌ Implementing API Abuse Detection With Rate Limiting · theheavenlyd3mon bundleImplement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.
- ▌ Implementing Cloud Vulnerability Posture Management · theheavenlyd3mon bundleImplement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.
- ▌ Implementing Container Network Policies With Calico · theheavenlyd3mon bundleEnforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.
- ▌ Implementing Passwordless Auth With Microsoft Entra · theheavenlyd3mon bundleImplements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.
- ▌ Implementing Passwordless Authentication With Fido2 · theheavenlyd3mon bundleDeploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica
- ▌ Implementing Zero Trust Network Access With Zscaler · theheavenlyd3mon bundleImplement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.
- ▌ Performing Network Traffic Analysis With Tshark · theheavenlyd3mon bundleAutomate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
- ▌ Conducting Internal Reconnaissance With Bloodhound Ce · theheavenlyd3mon bundleConduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.
- ▌ Implementing Infrastructure As Code Security Scanning · theheavenlyd3mon bundleThis skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.
- ▌ Implementing Threat Intelligence Lifecycle Management · theheavenlyd3mon bundleImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.
- ▌ Implementing Application Whitelisting With Applocker · theheavenlyd3mon bundleImplements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.
- ▌ Implementing Azure Ad Privileged Identity Management · theheavenlyd3mon bundleConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
- ▌ Implementing Device Posture Assessment In Zero Trust · theheavenlyd3mon bundleImplementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access.
- ▌ Implementing Next Generation Firewall With Palo Alto · theheavenlyd3mon bundleConfigure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
- ▌ Implementing Identity Governance With Sailpoint · theheavenlyd3mon bundleDeploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
- ▌ Implementing Iso 27001 Information Security Management · theheavenlyd3mon bundleISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
- ▌ Performing GCP Penetration Testing With Gcpbucketbrute · theheavenlyd3mon bundlePerform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing
- ▌ Implementing Network Segmentation With Firewall Zones · theheavenlyd3mon bundleDesign and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.
- ▌ Implementing Web Application Logging With Modsecurity · theheavenlyd3mon bundleConfigure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.
- ▌ Building Vulnerability Dashboard With Defectdojo · theheavenlyd3mon bundleDeploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.
- ▌ Building Vulnerability Exception Tracking System · theheavenlyd3mon bundleBuild a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.
- ▌ Implementing Deception Based Detection With Canarytoken · theheavenlyd3mon bundleDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
- ▌ Implementing Github Advanced Security For Code Scanning · theheavenlyd3mon bundleConfigure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
- ▌ Implementing Network Intrusion Prevention With Suricata · theheavenlyd3mon bundleDeploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.
- ▌ Implementing Image Provenance Verification With Cosign · theheavenlyd3mon bundleSign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
- ▌ Implementing Hardware Security Key Authentication · theheavenlyd3mon bundleImplements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Activates for requests involving FIDO2 implementation, WebAuthn registration, hardware security key enrollment, YubiKey integration, or passkey migration from password-based authentication.
- ▌ Collecting Volatile Evidence From Compromised Host · theheavenlyd3mon bundleCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
- ▌ Performing Log Analysis For Forensic Investigation · theheavenlyd3mon bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ Implementing Epss Score For Vulnerability Prioritization · theheavenlyd3mon bundleIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
- ▌ Implementing Privileged Access Management With Cyberark · theheavenlyd3mon bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
- ▌ Implementing Policy As Code With Open Policy Agent · theheavenlyd3mon bundleThis skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.
- ▌ Analyzing Memory Forensics With Lime And Volatility · theheavenlyd3mon bundlePerforms Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
- ▌ Performing Cloud Native Threat Hunting With AWS Detective · theheavenlyd3mon bundleHunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
- ▌ Performing Memory Forensics With Volatility3 Plugins · theheavenlyd3mon bundleAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
- ▌ Implementing Container Image Minimal Base With Distroless · theheavenlyd3mon bundleReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
- ▌ Implementing Data Loss Prevention With Microsoft Purview · theheavenlyd3mon bundleImplements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Activity Explorer and DLP alert management. Uses PowerShell cmdlets and the Microsoft Graph API for programmatic policy management. Activates for requests involving DLP policy creation, sensitivity label configuration, data classification, endpoint data protection, or Microsoft Purview compliance administration.
- ▌ Performing Windows Artifact Analysis With Eric Zimmerman Too · theheavenlyd3mon bundlePerform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.
- ▌ Testing For XML Injection Vulnerabilities · theheavenlyd3mon bundleTest web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
- ▌ Testing For Xxe Injection Vulnerabilities · theheavenlyd3mon bundleDiscovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
- ▌ Building Red Team C2 Infrastructure With Havoc · theheavenlyd3mon bundleDeploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
- ▌ Conducting Man In The Middle Attack Simulation · theheavenlyd3mon bundleSimulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities.
- ▌ Conducting Social Engineering Penetration Test · theheavenlyd3mon bundleDesign and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
- ▌ Exploiting Broken Function Level Authorization · theheavenlyd3mon bundleTests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken Function Level Authorization. Activates for requests involving BFLA testing, admin endpoint bypass, function-level access control testing, or API privilege escalation.
- ▌ Exploiting Smb Vulnerabilities With Metasploit · theheavenlyd3mon bundleIdentifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.
- ▌ Performing Cloud Penetration Testing With Pacu · theheavenlyd3mon bundlePerforming authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation.
- ▌ Performing Power Grid Cybersecurity Assessment · theheavenlyd3mon bundleThis skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and related attacks.
- ▌ Performing Serverless Function Security Review · theheavenlyd3mon bundlePerforming security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
- ▌ Performing Service Account Credential Rotation · theheavenlyd3mon bundleAutomate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
- ▌ Implementing AWS Security Hub Compliance · theheavenlyd3mon bundleImplementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
- ▌ Implementing Network Segmentation For Ot · theheavenlyd3mon bundleThis skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentation strategy, migration from flat networks to segmented architectures without disrupting operations, configuring OT-aware firewalls with industrial protocol deep packet inspection, and validating segmentation effectiveness through traffic analysis.
- ▌ Implementing Zero Trust Dns With Nextdns · theheavenlyd3mon bundleImplement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
- ▌ Performing Cloud Forensics Investigation · theheavenlyd3mon bundleConduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services.
- ▌ Securing Remote Access To Ot Environment · theheavenlyd3mon bundleThis skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements.
- ▌ Analyzing Malicious Url With Urlscan · theheavenlyd3mon bundleURLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat
- ▌ Building Incident Response Dashboard · theheavenlyd3mon bundleBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
- ▌ Performing Sqlite Database Forensics · theheavenlyd3mon bundlePerform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.
- ▌ Building Devsecops Pipeline With Gitlab CI · theheavenlyd3mon bundleDesign and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
- ▌ Building Role Mining For Rbac Optimization · theheavenlyd3mon bundleApply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
- ▌ Building Threat Feed Aggregation With Misp · theheavenlyd3mon bundleDeploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
- ▌ Configuring Host Based Intrusion Detection · theheavenlyd3mon bundleConfigures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitoring, building file integrity monitoring (FIM) policies, or meeting compliance requirements for change detection. Activates for requests involving HIDS configuration, file integrity monitoring, OSSEC/Wazuh deployment, or host-based detection.
- ▌ Deploying Cloudflare Access For Zero Trust · theheavenlyd3mon bundleDeploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
- ▌ Detecting Arp Poisoning In Network Traffic · theheavenlyd3mon bundleDetect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
- ▌ Detecting Modbus Command Injection Attacks · theheavenlyd3mon bundleDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and protocol deep packet inspection.
- ▌ Detecting Ransomware Precursors In Network · theheavenlyd3mon bundleDetects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts. Activates for requests involving pre-ransomware detection, network-based ransomware indicators, or early warning ransomware monitoring.
- ▌ Detecting Spearphishing With Email Gateway · theheavenlyd3mon bundleSpearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
- ▌ Hunting For Anomalous Powershell Execution · theheavenlyd3mon bundleHunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification.
- ▌ Implementing Delinea Secret Server For Pam · theheavenlyd3mon bundleImplements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.
- ▌ Implementing Endpoint Detection With Wazuh · theheavenlyd3mon bundleDeploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
- ▌ Implementing Gdpr Data Protection Controls · theheavenlyd3mon bundleThe General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover
- ▌ Implementing Mitre Attack Coverage Mapping · theheavenlyd3mon bundleImplement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
- ▌ Implementing Mobile Application Management · theheavenlyd3mon bundleImplements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
- ▌ Implementing Ot Incident Response Playbook · theheavenlyd3mon bundleDevelop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
- ▌ Implementing Rapid7 Insightvm For Scanning · theheavenlyd3mon bundleDeploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
- ▌ Implementing Secret Scanning With Gitleaks · theheavenlyd3mon bundleThis skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
- ▌ Implementing Vulnerability Remediation Sla · theheavenlyd3mon bundleVulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs
- ▌ Performing Authenticated Scan With Openvas · theheavenlyd3mon bundleConfigure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.
- ▌ Performing Deception Technology Deployment · theheavenlyd3mon bundleDeploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.