all publishers

theheavenlyd3mon

@theheavenlyd3mon source repo

1,063 published skills · page 4 of 11

  1. ▌
    Detecting T1055 Process Injection With Sysmon · theheavenlyd3mon bundle
    Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
    28 repo stars
  2. ▌
    Hunting For Beaconing With Frequency Analysis · theheavenlyd3mon bundle
    Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
    28 repo stars
  3. ▌
    Hunting For Persistence Mechanisms In Windows · theheavenlyd3mon bundle
    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
    28 repo stars
  4. ▌
    Hunting For Persistence Via Wmi Subscriptions · theheavenlyd3mon bundle
    Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
    28 repo stars
  5. ▌
    Implementing Browser Isolation For Zero Trust · theheavenlyd3mon bundle
    Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention controls within isolated sessions, and integration with Secure Web Gateway and ZTNA platforms. Based on Cloudflare Browser Isolation, Menlo Security, and Zscaler RBI approaches. Use when hardening web access against zero-day exploits, phishing, credential theft, and browser-based data exfiltration.
    28 repo stars
  6. ▌
    Implementing Gdpr Data Subject Access Request · theheavenlyd3mon bundle
    Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
    28 repo stars
  7. ▌
    Implementing Honeytokens For Breach Detection · theheavenlyd3mon bundle
    Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection.
    28 repo stars
  8. ▌
    Implementing Just In Time Access Provisioning · theheavenlyd3mon bundle
    Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access only when needed. This skill covers JIT architecture design, approval workflo
    28 repo stars
  9. ▌
    Implementing Network Deception With Honeypots · theheavenlyd3mon bundle
    Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
    28 repo stars
  10. ▌
    Implementing Ransomware Kill Switch Detection · theheavenlyd3mon bundle
    Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection.
    28 repo stars
  11. ▌
    Implementing Security Monitoring With Datadog · theheavenlyd3mon bundle
    Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.
    28 repo stars
  12. ▌
    Integrating Sast Into Github Actions Pipeline · theheavenlyd3mon bundle
    This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.
    28 repo stars
  13. ▌
    Performing Endpoint Vulnerability Remediation · theheavenlyd3mon bundle
    Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.
    28 repo stars
  14. ▌
    Performing Ip Reputation Analysis With Shodan · theheavenlyd3mon bundle
    Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.
    28 repo stars
  15. ▌
    Performing Timeline Reconstruction With Plaso · theheavenlyd3mon bundle
    Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
    28 repo stars
  16. ▌
    Performing Vulnerability Scanning With Nessus · theheavenlyd3mon bundle
    Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability detection.
    28 repo stars
  17. ▌
    Testing API For Mass Assignment Vulnerability · theheavenlyd3mon bundle
    Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving mass assignment testing, parameter binding abuse, auto-binding vulnerability, or API over-posting.
    28 repo stars
  18. ▌
    Performing Mobile Device Forensics With Cellebrite · theheavenlyd3mon bundle
    Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
    28 repo stars
  19. ▌
    Implementing AWS Config Rules For Compliance · theheavenlyd3mon bundle
    Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts.
    28 repo stars
  20. ▌
    Implementing Google Workspace Admin Security · theheavenlyd3mon bundle
    Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration.
    28 repo stars
  21. ▌
    Implementing Hashicorp Vault Dynamic Secrets · theheavenlyd3mon bundle
    Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation.
    28 repo stars
  22. ▌
    Performing Cloud Native Forensics With Falco · theheavenlyd3mon bundle
    Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
    28 repo stars
  23. ▌
    Performing Nist Csf Maturity Assessment · theheavenlyd3mon bundle
    The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
    28 repo stars
  24. ▌
    Performing Soc2 Type2 Audit Preparation · theheavenlyd3mon bundle
    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.
    28 repo stars
  25. ▌
    Analyzing Network Traffic With Wireshark · theheavenlyd3mon bundle
    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
    28 repo stars
  26. ▌
    Collecting Threat Intelligence With Misp · theheavenlyd3mon bundle
    MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
    28 repo stars
  27. ▌
    Building Automated Malware Submission Pipeline · theheavenlyd3mon bundle
    Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.
    28 repo stars
  28. ▌
    Building Identity Governance Lifecycle Process · theheavenlyd3mon bundle
    Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design.
    28 repo stars
  29. ▌
    Configuring Certificate Authority With Openssl · theheavenlyd3mon bundle
    A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
    28 repo stars
  30. ▌
    Configuring Windows Defender Advanced Settings · theheavenlyd3mon bundle
    Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint security.
    28 repo stars
  31. ▌
    Deploying Decoy Files For Ransomware Detection · theheavenlyd3mon bundle
    Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
    28 repo stars
  32. ▌
    Detecting Network Scanning With Ids Signatures · theheavenlyd3mon bundle
    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
    28 repo stars
  33. ▌
    Detecting Qr Code Phishing With Email Security · theheavenlyd3mon bundle
    Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.
    28 repo stars
  34. ▌
    Detecting Suspicious OAUTH Application Consent · theheavenlyd3mon bundle
    Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
    28 repo stars
  35. ▌
    Hunting For Lolbins Execution In Endpoint Logs · theheavenlyd3mon bundle
    Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.
    28 repo stars
  36. ▌
    Implementing Dragos Platform For Ot Monitoring · theheavenlyd3mon bundle
    Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE.
    28 repo stars
  37. ▌
    Implementing Honeypot For Ransomware Detection · theheavenlyd3mon bundle
    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Activates for requests involving ransomware honeypots, canary files, deception technology for ransomware, or early ransomware alerting.
    28 repo stars
  38. ▌
    Implementing Proofpoint Email Security Gateway · theheavenlyd3mon bundle
    Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
    28 repo stars
  39. ▌
    Implementing Purdue Model Network Segmentation · theheavenlyd3mon bundle
    Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains.
    28 repo stars
  40. ▌
    Implementing Threat Modeling With Mitre Attack · theheavenlyd3mon bundle
    Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.
    28 repo stars
  41. ▌
    Implementing Vulnerability Sla Breach Alerting · theheavenlyd3mon bundle
    Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
    28 repo stars
  42. ▌
    Performing Asset Criticality Scoring For Vulns · theheavenlyd3mon bundle
    Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
    28 repo stars
  43. ▌
    Performing AWS Privilege Escalation Assessment · theheavenlyd3mon bundle
    Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.
    28 repo stars
  44. ▌
    Performing Cve Prioritization With Kev Catalog · theheavenlyd3mon bundle
    Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.
    28 repo stars
  45. ▌
    Performing Post Quantum Cryptography Migration · theheavenlyd3mon bundle
    Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.
    28 repo stars
  46. ▌
    Performing Web Application Scanning With Nikto · theheavenlyd3mon bundle
    Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve
    28 repo stars
  47. ▌
    Performing Yara Rule Development For Detection · theheavenlyd3mon bundle
    Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
    28 repo stars
  48. ▌
    Prioritizing Vulnerabilities With Cvss Scoring · theheavenlyd3mon bundle
    The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r
    28 repo stars
  49. ▌
    Testing For Xss Vulnerabilities With Burpsuite · theheavenlyd3mon bundle
    Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
    28 repo stars
  50. ▌
    Performing Ot Vulnerability Assessment With Claroty · theheavenlyd3mon bundle
    This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
    28 repo stars
  51. ▌
    Detecting Privilege Escalation Attempts · theheavenlyd3mon bundle
    Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
    28 repo stars
  52. ▌
    Extracting Credentials From Memory Dump · theheavenlyd3mon bundle
    Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
    28 repo stars
  53. ▌
    Extracting Memory Artifacts With Rekall · theheavenlyd3mon bundle
    Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis.
    28 repo stars
  54. ▌
    Extracting Windows Event Logs Artifacts · theheavenlyd3mon bundle
    Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
    28 repo stars
  55. ▌
    Hunting For Unusual Network Connections · theheavenlyd3mon bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    28 repo stars
  56. ▌
    Implementing Network Traffic Baselining · theheavenlyd3mon bundle
    Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling
    28 repo stars
  57. ▌
    Implementing Ransomware Backup Strategy · theheavenlyd3mon bundle
    Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.
    28 repo stars
  58. ▌
    Implementing Security Chaos Engineering · theheavenlyd3mon bundle
    Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.
    28 repo stars
  59. ▌
    Implementing Soar Playbook For Phishing · theheavenlyd3mon bundle
    Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
    28 repo stars
  60. ▌
    Performing Ransomware Tabletop Exercise · theheavenlyd3mon bundle
    Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
    28 repo stars
  61. ▌
    Analyzing Cobalt Strike Beacon Configuration · theheavenlyd3mon bundle
    Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
    28 repo stars
  62. ▌
    Analyzing Cobaltstrike Malleable C2 Profiles · theheavenlyd3mon bundle
    Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
    28 repo stars
  63. ▌
    Analyzing Malware Sandbox Evasion Techniques · theheavenlyd3mon bundle
    Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports
    28 repo stars
  64. ▌
    Conducting Internal Network Penetration Test · theheavenlyd3mon bundle
    Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.
    28 repo stars
  65. ▌
    Executing Active Directory Attack Simulation · theheavenlyd3mon bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, and delegation abuse. Activates for requests involving Active Directory pentest, AD attack simulation, domain compromise testing, or Kerberos attack assessment.
    28 repo stars
  66. ▌
    Exploiting Prototype Pollution In Javascript · theheavenlyd3mon bundle
    Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
    28 repo stars
  67. ▌
    Performing Active Directory Penetration Test · theheavenlyd3mon bundle
    Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    28 repo stars
  68. ▌
    Performing Malware Persistence Investigation · theheavenlyd3mon bundle
    Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
    28 repo stars
  69. ▌
    Performing Wireless Network Penetration Test · theheavenlyd3mon bundle
    Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
    28 repo stars
  70. ▌
    Detecting AWS Iam Privilege Escalation · theheavenlyd3mon bundle
    Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations
    28 repo stars
  71. ▌
    Detecting Cloud Threats With Guardduty · theheavenlyd3mon bundle
    This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda.
    28 repo stars
  72. ▌
    Implementing API Key Security Controls · theheavenlyd3mon bundle
    Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Activates for requests involving API key management, API key security, key rotation policy, or API credential protection.
    28 repo stars
  73. ▌
    Implementing Cloud Workload Protection · theheavenlyd3mon bundle
    Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.
    28 repo stars
  74. ▌
    Implementing Secrets Scanning In CI CD · theheavenlyd3mon bundle
    Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
    28 repo stars
  75. ▌
    Implementing Zero Trust Network Access · theheavenlyd3mon bundle
    Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP.
    28 repo stars
  76. ▌
    Scanning Containers With Trivy In Cicd · theheavenlyd3mon bundle
    This skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images.
    28 repo stars
  77. ▌
    Securing Azure With Microsoft Defender · theheavenlyd3mon bundle
    This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and databases, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal for centralized threat management.
    28 repo stars
  78. ▌
    Analyzing Supply Chain Malware Artifacts · theheavenlyd3mon bundle
    Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
    28 repo stars
  79. ▌
    Building Threat Actor Profile From Osint · theheavenlyd3mon bundle
    Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
    28 repo stars
  80. ▌
    Configuring AWS Verified Access For Ztna · theheavenlyd3mon bundle
    Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.
    28 repo stars
  81. ▌
    Detecting Ransomware Encryption Behavior · theheavenlyd3mon bundle
    Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting.
    28 repo stars
  82. ▌
    Evaluating Threat Intelligence Platforms · theheavenlyd3mon bundle
    Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
    28 repo stars
  83. ▌
    Hunting For Data Exfiltration Indicators · theheavenlyd3mon bundle
    Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.
    28 repo stars
  84. ▌
    Hunting For Living Off The Land Binaries · theheavenlyd3mon bundle
    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
    28 repo stars
  85. ▌
    Hunting For Process Injection Techniques · theheavenlyd3mon bundle
    Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry
    28 repo stars
  86. ▌
    Hunting For Registry Run Key Persistence · theheavenlyd3mon bundle
    Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
    28 repo stars
  87. ▌
    Implementing Devsecops Security Scanning · theheavenlyd3mon bundle
    Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation.
    28 repo stars
  88. ▌
    Implementing LLM Guardrails For Security · theheavenlyd3mon bundle
    Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang definitions, custom Python validators for PII detection and content policy enforcement, and the Guardrails AI framework for structured output validation. The guardrails system intercepts both user inputs (blocking injection attempts, stripping PII, enforcing topic boundaries) and model outputs (detecting hallucinations, filtering toxic content, validating JSON schema compliance). Activates for requests involving LLM output validation, AI content filtering, guardrail implementation, or LLM safety enforcement.
    28 repo stars
  89. ▌
    Implementing Log Forwarding With Fluentd · theheavenlyd3mon bundle
    Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure
    28 repo stars
  90. ▌
    Implementing Pci Dss Compliance Controls · theheavenlyd3mon bundle
    PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements
    28 repo stars
  91. ▌
    Implementing Stix Taxii Feed Integration · theheavenlyd3mon bundle
    STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.
    28 repo stars
  92. ▌
    Implementing Taxii Server With Opentaxii · theheavenlyd3mon bundle
    Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
    28 repo stars
  93. ▌
    Performing Log Source Onboarding In Siem · theheavenlyd3mon bundle
    Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility.
    28 repo stars
  94. ▌
    Validating Backup Integrity For Recovery · theheavenlyd3mon bundle
    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    28 repo stars
  95. ▌
    Analyzing Threat Actor Ttps With Mitre Attack · theheavenlyd3mon bundle
    MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
    28 repo stars
  96. ▌
    Bypassing Authentication With Forced Browsing · theheavenlyd3mon bundle
    Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.
    28 repo stars
  97. ▌
    Exploiting Ms17 010 Eternalblue Vulnerability · theheavenlyd3mon bundle
    MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it
    28 repo stars
  98. ▌
    Exploiting Template Injection Vulnerabilities · theheavenlyd3mon bundle
    Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.
    28 repo stars
  99. ▌
    Performing Brand Monitoring For Impersonation · theheavenlyd3mon bundle
    Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization.
    28 repo stars
  100. ▌
    Performing Cryptographic Audit Of Application · theheavenlyd3mon bundle
    A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
    28 repo stars