all publishers

theheavenlyd3mon

@theheavenlyd3mon source repo

1,063 published skills · page 5 of 11

  1. ▌
    Performing Open Source Intelligence Gathering · theheavenlyd3mon bundle
    Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s
    28 repo stars
  2. ▌
    Reverse Engineering Android Malware With Jadx · theheavenlyd3mon bundle
    Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis.
    28 repo stars
  3. ▌
    Reverse Engineering Dotnet Malware With Dnspy · theheavenlyd3mon bundle
    Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis.
    28 repo stars
  4. ▌
    Detecting Azure Service Principal Abuse · theheavenlyd3mon bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    28 repo stars
  5. ▌
    Detecting S3 Data Exfiltration Attempts · theheavenlyd3mon bundle
    Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
    28 repo stars
  6. ▌
    Detecting Serverless Function Injection · theheavenlyd3mon bundle
    Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function modification. The analyst combines static analysis of function code, CloudTrail event correlation, runtime behavior monitoring, and IAM policy auditing to identify injection vectors across the expanded serverless attack surface including API Gateway, S3, SQS, DynamoDB Streams, and CloudWatch event triggers. Activates for requests involving Lambda security assessment, serverless injection detection, function event poisoning analysis, or serverless privilege escalation investigation.
    28 repo stars
  7. ▌
    Detecting Supply Chain Attacks In CI CD · theheavenlyd3mon bundle
    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
    28 repo stars
  8. ▌
    Implementing AWS Nitro Enclave Security · theheavenlyd3mon bundle
    Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activates for requests involving Nitro Enclave setup, enclave attestation validation, confidential computing on AWS, or KMS enclave policy configuration.
    28 repo stars
  9. ▌
    Implementing Code Signing For Artifacts · theheavenlyd3mon bundle
    This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.
    28 repo stars
  10. ▌
    Implementing Zero Trust With Beyondcorp · theheavenlyd3mon bundle
    Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
    28 repo stars
  11. ▌
    Securing Container Registry With Harbor · theheavenlyd3mon bundle
    Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio
    28 repo stars
  12. ▌
    Building Incident Response Playbook · theheavenlyd3mon bundle
    Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design.
    28 repo stars
  13. ▌
    Collecting Indicators Of Compromise · theheavenlyd3mon bundle
    Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
    28 repo stars
  14. ▌
    Collecting Open Source Intelligence · theheavenlyd3mon bundle
    Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.
    28 repo stars
  15. ▌
    Analyzing Persistence Mechanisms In Linux · theheavenlyd3mon bundle
    Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring
    28 repo stars
  16. ▌
    Analyzing Windows Lnk Files For Artifacts · theheavenlyd3mon bundle
    Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
    28 repo stars
  17. ▌
    Building Threat Hunt Hypothesis Framework · theheavenlyd3mon bundle
    Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.
    28 repo stars
  18. ▌
    Conducting Full Scope Red Team Engagement · theheavenlyd3mon bundle
    Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.
    28 repo stars
  19. ▌
    Configuring Active Directory Tiered Model · theheavenlyd3mon bundle
    Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative f
    28 repo stars
  20. ▌
    Deploying Osquery For Endpoint Monitoring · theheavenlyd3mon bundle
    Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
    28 repo stars
  21. ▌
    Detecting Exfiltration Over Dns With Zeek · theheavenlyd3mon bundle
    Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
    28 repo stars
  22. ▌
    Detecting Living Off The Land With Lolbas · theheavenlyd3mon bundle
    Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis
    28 repo stars
  23. ▌
    Detecting Suspicious Powershell Execution · theheavenlyd3mon bundle
    Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
    28 repo stars
  24. ▌
    Hunting For Command And Control Beaconing · theheavenlyd3mon bundle
    Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
    28 repo stars
  25. ▌
    Hunting For Unusual Service Installations · theheavenlyd3mon bundle
    Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
    28 repo stars
  26. ▌
    Implementing Anti Ransomware Group Policy · theheavenlyd3mon bundle
    Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy.
    28 repo stars
  27. ▌
    Implementing Immutable Backup With Restic · theheavenlyd3mon bundle
    Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection. Automates backup creation, integrity verification via restic check --read-data, snapshot retention policy enforcement, and restore testing. Integrates with AWS S3 Object Lock, MinIO, and Backblaze B2 for WORM (Write Once Read Many) storage that prevents backup deletion or encryption by ransomware actors.
    28 repo stars
  28. ▌
    Implementing Nerc Cip Compliance Controls · theheavenlyd3mon bundle
    This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset requirements.
    28 repo stars
  29. ▌
    Implementing Siem Use Cases For Detection · theheavenlyd3mon bundle
    Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
    28 repo stars
  30. ▌
    Implementing Soar Automation With Phantom · theheavenlyd3mon bundle
    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.
    28 repo stars
  31. ▌
    Monitoring Scada Modbus Traffic Anomalies · theheavenlyd3mon bundle
    Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic analysis, SCADA network monitoring, ICS anomaly detection, PLC security monitoring, or OT network threat detection.
    28 repo stars
  32. ▌
    Performing Alert Triage With Elastic Siem · theheavenlyd3mon bundle
    Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.
    28 repo stars
  33. ▌
    Performing Arp Spoofing Attack Simulation · theheavenlyd3mon bundle
    Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
    28 repo stars
  34. ▌
    Performing Indicator Lifecycle Management · theheavenlyd3mon bundle
    Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
    28 repo stars
  35. ▌
    Performing Ot Network Security Assessment · theheavenlyd3mon bundle
    This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infrastructure.
    28 repo stars
  36. ▌
    Performing Supply Chain Attack Simulation · theheavenlyd3mon bundle
    Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit.
    28 repo stars
  37. ▌
    Performing Threat Hunting With Yara Rules · theheavenlyd3mon bundle
    Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
    28 repo stars
  38. ▌
    Testing For Open Redirect Vulnerabilities · theheavenlyd3mon bundle
    Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
    28 repo stars
  39. ▌
    Detecting Lateral Movement With Zeek · theheavenlyd3mon bundle
    Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
    28 repo stars
  40. ▌
    Detecting SQL Injection Via Waf Logs · theheavenlyd3mon bundle
    Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates multi-stage injection attempts, and generates incident reports with OWASP classification.
    28 repo stars
  41. ▌
    Extracting Browser History Artifacts · theheavenlyd3mon bundle
    Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
    28 repo stars
  42. ▌
    Hunting For Lateral Movement Via Wmi · theheavenlyd3mon bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    28 repo stars
  43. ▌
    Hunting For Spearphishing Indicators · theheavenlyd3mon bundle
    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
    28 repo stars
  44. ▌
    Implementing Alert Fatigue Reduction · theheavenlyd3mon bundle
    Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.
    28 repo stars
  45. ▌
    Implementing Pam For Database Access · theheavenlyd3mon bundle
    Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
    28 repo stars
  46. ▌
    Performing Container Image Hardening · theheavenlyd3mon bundle
    This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.
    28 repo stars
  47. ▌
    Performing Ioc Enrichment Automation · theheavenlyd3mon bundle
    Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source enrichment of IPs, domains, URLs, and file hashes during alert triage or incident investigation.
    28 repo stars
  48. ▌
    Performing JWT None Algorithm Attack · theheavenlyd3mon bundle
    Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.
    28 repo stars
  49. ▌
    Analyzing IOS App Security With Objection · theheavenlyd3mon bundle
    Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app security posture, bypassing client-side protections, dumping keychain items, inspecting filesystem storage, and evaluating runtime behavior. Activates for requests involving iOS security testing, Objection runtime analysis, Frida-based iOS assessment, or mobile runtime exploration.
    28 repo stars
  50. ▌
    Conducting Domain Persistence With Dcsync · theheavenlyd3mon bundle
    Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
    28 repo stars
  51. ▌
    Exploiting Excessive Data Exposure In API · theheavenlyd3mon bundle
    Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving API data leakage testing, excessive data exposure, response filtering bypass, or API over-fetching.
    28 repo stars
  52. ▌
    Exploiting JWT Algorithm Confusion Attack · theheavenlyd3mon bundle
    Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to supply attacker-controlled keys. Activates for requests involving JWT algorithm confusion, alg none attack, key confusion attack, or JWT signature bypass.
    28 repo stars
  53. ▌
    Exploiting Race Condition Vulnerabilities · theheavenlyd3mon bundle
    Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
    28 repo stars
  54. ▌
    Performing Content Security Policy Bypass · theheavenlyd3mon bundle
    Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
    28 repo stars
  55. ▌
    Performing Credential Access With Lazagne · theheavenlyd3mon bundle
    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
    28 repo stars
  56. ▌
    Performing Kubernetes Penetration Testing · theheavenlyd3mon bundle
    Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools
    28 repo stars
  57. ▌
    Performing Plc Firmware Security Analysis · theheavenlyd3mon bundle
    This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampering.
    28 repo stars
  58. ▌
    Performing Red Team Phishing With Gophish · theheavenlyd3mon bundle
    Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.
    28 repo stars
  59. ▌
    Detecting Container Escape Attempts · theheavenlyd3mon bundle
    Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
    28 repo stars
  60. ▌
    Hunting For Supply Chain Compromise · theheavenlyd3mon bundle
    Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
    28 repo stars
  61. ▌
    Implementing GCP Vpc Firewall Rules · theheavenlyd3mon bundle
    Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs.
    28 repo stars
  62. ▌
    Implementing Network Access Control · theheavenlyd3mon bundle
    Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices.
    28 repo stars
  63. ▌
    Securing AWS Lambda Execution Roles · theheavenlyd3mon bundle
    Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate permissions, and enforcing role scoping through SCPs.
    28 repo stars
  64. ▌
    Building Soc Metrics And Kpi Tracking · theheavenlyd3mon bundle
    Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
    28 repo stars
  65. ▌
    Building Threat Intelligence Platform · theheavenlyd3mon bundle
    Building a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T
    28 repo stars
  66. ▌
    Configuring Oauth2 Authorization Flow · theheavenlyd3mon bundle
    Configure secure OAuth 2.0 authorization flows including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant. This skill covers flow selection, PKCE implementation, token
    28 repo stars
  67. ▌
    Correlating Security Events In Qradar · theheavenlyd3mon bundle
    Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
    28 repo stars
  68. ▌
    Detecting Fileless Malware Techniques · theheavenlyd3mon bundle
    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination.
    28 repo stars
  69. ▌
    Detecting Lateral Movement In Network · theheavenlyd3mon bundle
    Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
    28 repo stars
  70. ▌
    Detecting Living Off The Land Attacks · theheavenlyd3mon bundle
    Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns.
    28 repo stars
  71. ▌
    Detecting Mimikatz Execution Patterns · theheavenlyd3mon bundle
    Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
    28 repo stars
  72. ▌
    Detecting Misconfigured Azure Storage · theheavenlyd3mon bundle
    Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.
    28 repo stars
  73. ▌
    Detecting Network Anomalies With Zeek · theheavenlyd3mon bundle
    Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.
    28 repo stars
  74. ▌
    Detecting Port Scanning With Fail2ban · theheavenlyd3mon bundle
    Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.
    28 repo stars
  75. ▌
    Detecting Process Hollowing Technique · theheavenlyd3mon bundle
    Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
    28 repo stars
  76. ▌
    Implementing Ics Firewall With Tofino · theheavenlyd3mon bundle
    Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones.
    28 repo stars
  77. ▌
    Implementing Iec 62443 Security Zones · theheavenlyd3mon bundle
    This skill covers designing and implementing security zones and conduits for industrial automation and control systems (IACS) per IEC 62443-3-2. It addresses zone partitioning based on risk assessment, assigning Security Level targets (SL-T), designing conduit security controls, implementing microsegmentation with industrial firewalls, and validating zone architecture through traffic analysis and penetration testing against the Purdue Reference Model.
    28 repo stars
  78. ▌
    Performing File Carving With Foremost · theheavenlyd3mon bundle
    Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
    28 repo stars
  79. ▌
    Performing GRAPHQL Depth Limit Attack · theheavenlyd3mon bundle
    Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.
    28 repo stars
  80. ▌
    Performing Lateral Movement Detection · theheavenlyd3mon bundle
    Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
    28 repo stars
  81. ▌
    Performing Second Order SQL Injection · theheavenlyd3mon bundle
    Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
    28 repo stars
  82. ▌
    Testing API Authentication Weaknesses · theheavenlyd3mon bundle
    Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Activates for requests involving API authentication testing, token validation assessment, credential security testing, or API auth bypass.
    28 repo stars
  83. ▌
    Analyzing Lnk File And Jump List Artifacts · theheavenlyd3mon bundle
    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.
    28 repo stars
  84. ▌
    Analyzing Ransomware Encryption Mechanisms · theheavenlyd3mon bundle
    Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
    28 repo stars
  85. ▌
    Conducting Social Engineering Pretext Call · theheavenlyd3mon bundle
    Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
    28 repo stars
  86. ▌
    Exploiting Insecure Data Storage In Mobile · theheavenlyd3mon bundle
    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences analysis, or mobile data leakage assessment.
    28 repo stars
  87. ▌
    Exploiting Nosql Injection Vulnerabilities · theheavenlyd3mon bundle
    Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
    28 repo stars
  88. ▌
    Intercepting Mobile Traffic With Burpsuite · theheavenlyd3mon bundle
    Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.
    28 repo stars
  89. ▌
    Performing Dark Web Monitoring For Threats · theheavenlyd3mon bundle
    Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre
    28 repo stars
  90. ▌
    Performing Dynamic Analysis Of Android App · theheavenlyd3mon bundle
    Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis.
    28 repo stars
  91. ▌
    Performing HTTP Parameter Pollution Attack · theheavenlyd3mon bundle
    Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
    28 repo stars
  92. ▌
    Performing Privilege Escalation Assessment · theheavenlyd3mon bundle
    Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment.
    28 repo stars
  93. ▌
    Performing Ssrf Vulnerability Exploitation · theheavenlyd3mon bundle
    Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169.254.169.254), internal port scanning via HTTP, URL scheme bypass techniques, and DNS rebinding detection.
    28 repo stars
  94. ▌
    Detecting Container Drift At Runtime · theheavenlyd3mon bundle
    Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
    28 repo stars
  95. ▌
    Scanning Container Images With Grype · theheavenlyd3mon bundle
    Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.
    28 repo stars
  96. ▌
    Analyzing PDF Malware With Pdfid · theheavenlyd3mon bundle
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.
    28 repo stars
  97. ▌
    Conducting Mobile App Penetration Test · theheavenlyd3mon bundle
    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
    28 repo stars
  98. ▌
    Deploying Active Directory Honeytokens · theheavenlyd3mon bundle
    Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
    28 repo stars
  99. ▌
    Deploying Tailscale For Zero Trust Vpn · theheavenlyd3mon bundle
    Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
    28 repo stars
  100. ▌
    Detecting Attacks On Historian Servers · theheavenlyd3mon bundle
    Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
    28 repo stars