all publishers

theheavenlyd3mon

@theheavenlyd3mon source repo

1,063 published skills · page 6 of 11

  1. ▌
    Detecting Beaconing Patterns With Zeek · theheavenlyd3mon bundle
    Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data.
    28 repo stars
  2. ▌
    Detecting Bluetooth Low Energy Attacks · theheavenlyd3mon bundle
    Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
    28 repo stars
  3. ▌
    Detecting Command And Control Over Dns · theheavenlyd3mon bundle
    Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development. Activates for requests involving DNS-based C2 detection, DNS tunnel identification, suspicious DNS traffic investigation, or DGA domain classification.
    28 repo stars
  4. ▌
    Detecting Lateral Movement With Splunk · theheavenlyd3mon bundle
    Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
    28 repo stars
  5. ▌
    Detecting Process Injection Techniques · theheavenlyd3mon bundle
    Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.
    28 repo stars
  6. ▌
    Hunting For Domain Fronting C2 Traffic · theheavenlyd3mon bundle
    Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection
    28 repo stars
  7. ▌
    Hunting For Scheduled Task Persistence · theheavenlyd3mon bundle
    Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
    28 repo stars
  8. ▌
    Hunting For Startup Folder Persistence · theheavenlyd3mon bundle
    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
    28 repo stars
  9. ▌
    Hunting For Suspicious Scheduled Tasks · theheavenlyd3mon bundle
    Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.
    28 repo stars
  10. ▌
    Hunting For T1098 Account Manipulation · theheavenlyd3mon bundle
    Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
    28 repo stars
  11. ▌
    Implementing Attack Surface Management · theheavenlyd3mon bundle
    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.
    28 repo stars
  12. ▌
    Implementing Patch Management Workflow · theheavenlyd3mon bundle
    Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc
    28 repo stars
  13. ▌
    Implementing Usb Device Control Policy · theheavenlyd3mon bundle
    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
    28 repo stars
  14. ▌
    Performing API Inventory And Discovery · theheavenlyd3mon bundle
    Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Activates for requests involving API discovery, shadow API detection, API inventory audit, or attack surface mapping.
    28 repo stars
  15. ▌
    Performing Directory Traversal Testing · theheavenlyd3mon bundle
    Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
    28 repo stars
  16. ▌
    Performing GRAPHQL Security Assessment · theheavenlyd3mon bundle
    Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
    28 repo stars
  17. ▌
    Remediating S3 Bucket Misconfiguration · theheavenlyd3mon bundle
    This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.
    28 repo stars
  18. ▌
    Testing API Security With Owasp Top 10 · theheavenlyd3mon bundle
    Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
    28 repo stars
  19. ▌
    Testing Ransomware Recovery Procedures · theheavenlyd3mon bundle
    Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.
    28 repo stars
  20. ▌
    Analyzing Command And Control Communication · theheavenlyd3mon bundle
    Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.
    28 repo stars
  21. ▌
    Analyzing Macro Malware In Office Documents · theheavenlyd3mon bundle
    Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.
    28 repo stars
  22. ▌
    Analyzing Malware Persistence With Autoruns · theheavenlyd3mon bundle
    Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows systems.
    28 repo stars
  23. ▌
    Analyzing Ransomware Leak Site Intelligence · theheavenlyd3mon bundle
    Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
    28 repo stars
  24. ▌
    Building Ioc Defanging And Sharing Pipeline · theheavenlyd3mon bundle
    Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
    28 repo stars
  25. ▌
    Conducting Memory Forensics With Volatility · theheavenlyd3mon bundle
    Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
    28 repo stars
  26. ▌
    Deobfuscating Powershell Obfuscated Malware · theheavenlyd3mon bundle
    Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
    28 repo stars
  27. ▌
    Exploiting Active Directory With Bloodhound · theheavenlyd3mon bundle
    BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac
    28 repo stars
  28. ▌
    Performing Firmware Extraction With Binwalk · theheavenlyd3mon bundle
    Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
    28 repo stars
  29. ▌
    Performing Ics Asset Discovery With Claroty · theheavenlyd3mon bundle
    Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
    28 repo stars
  30. ▌
    Performing Oil Gas Cybersecurity Assessment · theheavenlyd3mon bundle
    This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure.
    28 repo stars
  31. ▌
    Performing Ot Vulnerability Scanning Safely · theheavenlyd3mon bundle
    Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
    28 repo stars
  32. ▌
    Performing Web Application Penetration Test · theheavenlyd3mon bundle
    Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses Burp Suite as the primary interception proxy alongside manual testing techniques to find flaws that automated scanners miss. Activates for requests involving web app pentest, OWASP testing, application security assessment, or web vulnerability testing.
    28 repo stars
  33. ▌
    Hardening Docker Daemon Configuration · theheavenlyd3mon bundle
    Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.
    28 repo stars
  34. ▌
    Implementing Azure Defender For Cloud · theheavenlyd3mon bundle
    Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.
    28 repo stars
  35. ▌
    Implementing Cloud Trail Log Analysis · theheavenlyd3mon bundle
    Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.
    28 repo stars
  36. ▌
    Implementing Ebpf Security Monitoring · theheavenlyd3mon bundle
    Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
    28 repo stars
  37. ▌
    Implementing GCP Binary Authorization · theheavenlyd3mon bundle
    Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
    28 repo stars
  38. ▌
    Recovering From Ransomware Attack · theheavenlyd3mon bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
    28 repo stars
  39. ▌
    Analyzing Web Server Logs For Intrusion · theheavenlyd3mon bundle
    Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.
    28 repo stars
  40. ▌
    Building Detection Rule With Splunk Spl · theheavenlyd3mon bundle
    Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
    28 repo stars
  41. ▌
    Building Patch Tuesday Response Process · theheavenlyd3mon bundle
    Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
    28 repo stars
  42. ▌
    Detecting Compromised Cloud Credentials · theheavenlyd3mon bundle
    Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    28 repo stars
  43. ▌
    Detecting Credential Dumping Techniques · theheavenlyd3mon bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
    28 repo stars
  44. ▌
    Detecting Email Forwarding Rules Attack · theheavenlyd3mon bundle
    Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
    28 repo stars
  45. ▌
    Detecting Fileless Attacks On Endpoints · theheavenlyd3mon bundle
    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
    28 repo stars
  46. ▌
    Cron Pipeline 2 · theheavenlyd3mon bundle
    Manage scheduled cron job pipelines — review overnight runs, detect missed jobs (machine-sleep pattern), run catch-up batches with proper spacing, and integrate results into the morning briefing. Covers the overnight maintenance pipeline common on macOS machines that sleep at night.
    28 repo stars
  47. ▌
    Agentmail · theheavenlyd3mon
    Give the agent its own inbox: send and receive email.
    28 repo stars
  48. ▌
    Hyperframes · theheavenlyd3mon bundle
    Render MP4/WebM videos from HTML compositions.
    28 repo stars
  49. ▌
    Kanban Orchestrator 2 · theheavenlyd3mon
    Decomposition playbook + anti-temptation rules for an orchestrator profile routing work through Kanban. The "don't do the work yourself" rule and the basic lifecycle are auto-injected into every kanban worker's system prompt; this skill is the deeper playbook when you're specifically playing the orchestrator role.
    28 repo stars
  50. ▌
    Profile Model Fleet 2 · theheavenlyd3mon bundle
    Current model assignments for all Hermes profiles (alibaba qwen3.8-max everywhere except senna+research on deepseek-v4-flash). Use to audit configs, diagnose auth errors, run batch fleet updates, or restart gateways after model changes.
    28 repo stars
  51. ▌
    Concept Diagrams · theheavenlyd3mon bundle
    Generate flat, minimal educational SVG visuals as HTML.
    28 repo stars
  52. ▌
    Kanban Orchestrator 3 · theheavenlyd3mon bundle
    Kanban multi-agent workflow: orchestrator decomposition playbook, worker lifecycle, task routing, and pitfalls.
    28 repo stars
  53. ▌
    Hermes S6 Container Supervision · theheavenlyd3mon
    Modify, debug, or extend the s6-overlay supervision tree inside the Hermes Agent Docker image — adding new services, debugging profile gateways, understanding the Architecture B main-program pattern.
    28 repo stars
  54. ▌
    Executing Red Team Exercise · theheavenlyd3mon bundle
    Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification. Activates for requests involving red team exercise, adversary simulation, adversary emulation, or full-scope offensive security assessment.
    28 repo stars
  55. ▌
    Automating Ioc Enrichment · theheavenlyd3mon bundle
    Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated enrichment workflows integrated with SIEM alerts, email submission pipelines, or bulk IOC processing from threat feeds. Activates for requests involving SOAR enrichment, Cortex XSOAR, Splunk SOAR, TheHive, Python enrichment pipelines, or automated IOC processing.
    28 repo stars
  56. ▌
    Detecting Wmi Persistence · theheavenlyd3mon bundle
    Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
    28 repo stars
  57. ▌
    Performing Vlan Hopping Attack · theheavenlyd3mon bundle
    Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
    28 repo stars
  58. ▌
    Detecting Rootkit Activity · theheavenlyd3mon bundle
    Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.
    28 repo stars
  59. ▌
    Hunting For Dcsync Attacks · theheavenlyd3mon bundle
    Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
    28 repo stars
  60. ▌
    Monitoring Darkweb Sources · theheavenlyd3mon bundle
    Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
    28 repo stars
  61. ▌
    Testing JWT Token Security · theheavenlyd3mon bundle
    Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
    28 repo stars
  62. ▌
    Conducting API Security Testing · theheavenlyd3mon bundle
    Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.
    28 repo stars
  63. ▌
    Exploiting Idor Vulnerabilities · theheavenlyd3mon bundle
    Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.
    28 repo stars
  64. ▌
    Exploiting Ipv6 Vulnerabilities · theheavenlyd3mon bundle
    Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
    28 repo stars
  65. ▌
    Performing Purple Team Exercise · theheavenlyd3mon bundle
    Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
    28 repo stars
  66. ▌
    Detecting OAUTH Token Theft · theheavenlyd3mon bundle
    Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.
    28 repo stars
  67. ▌
    Processing Stix Taxii Feeds · theheavenlyd3mon bundle
    Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.
    28 repo stars
  68. ▌
    Deobfuscating Javascript Malware · theheavenlyd3mon bundle
    Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic. Activates for requests involving JavaScript malware analysis, script deobfuscation, web skimmer analysis, or obfuscated dropper investigation.
    28 repo stars
  69. ▌
    Performing Osint With Spiderfoot · theheavenlyd3mon bundle
    Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources
    28 repo stars
  70. ▌
    Reverse Engineering Rust Malware · theheavenlyd3mon bundle
    Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis.
    28 repo stars
  71. ▌
    Correlating Threat Campaigns · theheavenlyd3mon bundle
    Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract shared indicators for improved detection. Use when multiple incidents exhibit overlapping indicators, when sector-wide attack campaigns require cross-organizational analysis, or when building campaign-level intelligence products. Activates for requests involving campaign analysis, incident clustering, cross-organizational IOC correlation, or MISP correlation engine.
    28 repo stars
  72. ▌
    Analyzing Heap Spray Exploitation · theheavenlyd3mon bundle
    Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
    28 repo stars
  73. ▌
    Conducting Pass The Ticket Attack · theheavenlyd3mon bundle
    Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro
    28 repo stars
  74. ▌
    Exploiting HTTP Request Smuggling · theheavenlyd3mon bundle
    Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
    28 repo stars
  75. ▌
    Exploiting OAUTH Misconfiguration · theheavenlyd3mon bundle
    Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.
    28 repo stars
  76. ▌
    Performing Csrf Attack Simulation · theheavenlyd3mon bundle
    Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
    28 repo stars
  77. ▌
    Performing Malware Ioc Extraction · theheavenlyd3mon bundle
    Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist
    28 repo stars
  78. ▌
    Hunting For Webshell Activity · theheavenlyd3mon bundle
    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
    28 repo stars
  79. ▌
    Profiling Threat Actor Groups · theheavenlyd3mon bundle
    Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries. Activates for requests involving MITRE ATT&CK Groups, Mandiant APT profiles, CrowdStrike adversary naming, or sector-specific threat briefings.
    28 repo stars
  80. ▌
    Securing Serverless Functions · theheavenlyd3mon bundle
    This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input validation, function URL authentication, and runtime monitoring to protect against injection attacks, credential theft, and supply chain compromises.
    28 repo stars
  81. ▌
    Testing Cors Misconfiguration · theheavenlyd3mon bundle
    Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.
    28 repo stars
  82. ▌
    Performing Blind Ssrf Exploitation · theheavenlyd3mon bundle
    Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
    28 repo stars
  83. ▌
    Performing Dns Tunneling Detection · theheavenlyd3mon bundle
    Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality. Uses scapy for packet capture analysis and statistical methods to distinguish legitimate DNS from covert channels. Use when hunting for data exfiltration.
    28 repo stars
  84. ▌
    Performing Packet Injection Attack · theheavenlyd3mon bundle
    Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
    28 repo stars
  85. ▌
    Performing Steganography Detection · theheavenlyd3mon bundle
    Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
    28 repo stars
  86. ▌
    Auditing GCP Iam Permissions · theheavenlyd3mon bundle
    Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
    28 repo stars
  87. ▌
    Implementing Cloud Waf Rules · theheavenlyd3mon bundle
    This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic protection, implementing rate limiting, deploying bot management, and reducing false positives through rule tuning and logging analysis.
    28 repo stars
  88. ▌
    Securing AWS Iam Permissions · theheavenlyd3mon bundle
    This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential rotation strategies to reduce the blast radius of compromised identities.
    28 repo stars
  89. ▌
    Securing Kubernetes On Cloud · theheavenlyd3mon bundle
    This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses cloud-specific security features including IRSA for EKS, Workload Identity for GKE, and Managed Identities for AKS.
    28 repo stars
  90. ▌
    Containing Active Breach · theheavenlyd3mon bundle
    Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.
    28 repo stars
  91. ▌
    Building Soc Escalation Matrix · theheavenlyd3mon bundle
    Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
    28 repo stars
  92. ▌
    Detecting Shadow API Endpoints · theheavenlyd3mon bundle
    Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.
    28 repo stars
  93. ▌
    Hunting For Ntlm Relay Attacks · theheavenlyd3mon bundle
    Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
    28 repo stars
  94. ▌
    Performing Ransomware Response · theheavenlyd3mon bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.
    28 repo stars
  95. ▌
    Testing Websocket API Security · theheavenlyd3mon bundle
    Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates for requests involving WebSocket security testing, WS penetration testing, CSWSH attack, or real-time API security assessment.
    28 repo stars
  96. ▌
    Analyzing Malicious PDF With Peepdf · theheavenlyd3mon bundle
    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
    28 repo stars
  97. ▌
    Exploiting Deeplink Vulnerabilities · theheavenlyd3mon bundle
    Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based navigation. Activates for requests involving deep link security testing, URL scheme exploitation, mobile intent abuse, or link hijacking.
    28 repo stars
  98. ▌
    Exploiting Insecure Deserialization · theheavenlyd3mon bundle
    Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.
    28 repo stars
  99. ▌
    Hunting Advanced Persistent Threats · theheavenlyd3mon bundle
    Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.
    28 repo stars
  100. ▌
    Performing API Fuzzing With Restler · theheavenlyd3mon bundle
    Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability bugs. The tester compiles an OpenAPI specification into a RESTler fuzzing grammar, configures authentication, runs test/fuzz-lean/fuzz modes, and analyzes results for 500 errors, authentication bypasses, resource leaks, and payload injection vulnerabilities. Activates for requests involving API fuzzing, RESTler testing, stateful API testing, or automated API security scanning.
    28 repo stars