all publishers

theheavenlyd3mon

@theheavenlyd3mon source repo

1,063 published skills · page 7 of 11

  1. ▌
    Performing Clickjacking Attack Test · theheavenlyd3mon bundle
    Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
    28 repo stars
  2. ▌
    Performing Fuzzing With Aflplusplus · theheavenlyd3mon bundle
    Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with afl-fuzz, and triages crashes using CASR or GDB scripts. Activates for requests involving binary fuzzing, crash discovery, coverage-guided testing, or AFL++ fuzzing campaigns.
    28 repo stars
  3. ▌
    Performing Malware Triage With Yara · theheavenlyd3mon bundle
    Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.
    28 repo stars
  4. ▌
    Implementing AWS Security Hub · theheavenlyd3mon bundle
    This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations Benchmark, configuring automated remediation, and building executive dashboards for compliance tracking across multi-account AWS organizations.
    28 repo stars
  5. ▌
    Configuring Hsm For Key Storage · theheavenlyd3mon bundle
    Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
    28 repo stars
  6. ▌
    Detecting Golden Ticket Forgery · theheavenlyd3mon bundle
    Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM
    28 repo stars
  7. ▌
    Detecting Kerberoasting Attacks · theheavenlyd3mon bundle
    Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.
    28 repo stars
  8. ▌
    Detecting Pass The Hash Attacks · theheavenlyd3mon bundle
    Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.
    28 repo stars
  9. ▌
    Detecting Service Account Abuse · theheavenlyd3mon bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    28 repo stars
  10. ▌
    Detecting Shadow It Cloud Usage · theheavenlyd3mon bundle
    Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.
    28 repo stars
  11. ▌
    Detecting Stuxnet Style Attacks · theheavenlyd3mon bundle
    This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation from operators. It addresses PLC logic integrity monitoring, physics-based process anomaly detection, engineering workstation compromise indicators, USB-borne attack vectors, and multi-stage attack chain detection spanning IT-to-OT lateral movement through to process manipulation.
    28 repo stars
  12. ▌
    Managing Intelligence Lifecycle · theheavenlyd3mon bundle
    Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
    28 repo stars
  13. ▌
    Mapping Mitre Attack Techniques · theheavenlyd3mon bundle
    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
    28 repo stars
  14. ▌
    Performing Kerberoasting Attack · theheavenlyd3mon bundle
    Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names
    28 repo stars
  15. ▌
    Performing Ssl Stripping Attack · theheavenlyd3mon bundle
    Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.
    28 repo stars
  16. ▌
    Testing For Xss Vulnerabilities · theheavenlyd3mon bundle
    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies all injection points and output contexts, crafts context-appropriate payloads, and bypasses sanitization and CSP protections. Activates for requests involving XSS testing, cross-site scripting assessment, client-side injection testing, or JavaScript injection vulnerability testing.
    28 repo stars
  17. ▌
    Analyzing Golang Malware With Ghidra · theheavenlyd3mon bundle
    Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
    28 repo stars
  18. ▌
    Analyzing Network Traffic Of Malware · theheavenlyd3mon bundle
    Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.
    28 repo stars
  19. ▌
    Analyzing Ransomware Payment Wallets · theheavenlyd3mon bundle
    Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware payment tracing, bitcoin wallet analysis, cryptocurrency forensics, or blockchain intelligence gathering.
    28 repo stars
  20. ▌
    Exploiting SQL Injection With Sqlmap · theheavenlyd3mon bundle
    Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
    28 repo stars
  21. ▌
    Exploiting Websocket Vulnerabilities · theheavenlyd3mon bundle
    Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
    28 repo stars
  22. ▌
    Extracting Iocs From Malware Samples · theheavenlyd3mon bundle
    Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples.
    28 repo stars
  23. ▌
    Performing Firmware Malware Analysis · theheavenlyd3mon bundle
    Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
    28 repo stars
  24. ▌
    Tracking Threat Actor Infrastructure · theheavenlyd3mon bundle
    Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
    28 repo stars
  25. ▌
    Triaging Security Incident · theheavenlyd3mon bundle
    Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis.
    28 repo stars
  26. ▌
    Hunting For Shadow Copy Deletion · theheavenlyd3mon bundle
    Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.
    28 repo stars
  27. ▌
    Performing Service Account Audit · theheavenlyd3mon bundle
    Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
    28 repo stars
  28. ▌
    Performing Soc Tabletop Exercise · theheavenlyd3mon bundle
    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.
    28 repo stars
  29. ▌
    Analyzing Powershell Empire Artifacts · theheavenlyd3mon bundle
    Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
    28 repo stars
  30. ▌
    Conducting Phishing Incident Response · theheavenlyd3mon bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email incident, credential phishing, spear phishing investigation, or phishing remediation.
    28 repo stars
  31. ▌
    Exploiting Nopac Cve 2021 42278 42287 · theheavenlyd3mon bundle
    Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.
    28 repo stars
  32. ▌
    Performing Hash Cracking With Hashcat · theheavenlyd3mon bundle
    Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w
    28 repo stars
  33. ▌
    Performing Purple Team Atomic Testing · theheavenlyd3mon bundle
    Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the ATT&CK matrix, and runs detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines. Activates for requests involving purple team exercises, atomic test execution, ATT&CK coverage assessment, detection engineering validation, or adversary emulation testing.
    28 repo stars
  34. ▌
    Performing Web Cache Deception Attack · theheavenlyd3mon bundle
    Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.
    28 repo stars
  35. ▌
    Performing Web Cache Poisoning Attack · theheavenlyd3mon bundle
    Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
    28 repo stars
  36. ▌
    Detecting Cryptomining In Cloud · theheavenlyd3mon bundle
    This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
    28 repo stars
  37. ▌
    Implementing Saml Sso With Okta · theheavenlyd3mon bundle
    Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
    28 repo stars
  38. ▌
    Securing Helm Chart Deployments · theheavenlyd3mon bundle
    Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
    28 repo stars
  39. ▌
    Building Cloud Siem With Sentinel · theheavenlyd3mon bundle
    This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.
    28 repo stars
  40. ▌
    Deploying Ransomware Canary Files · theheavenlyd3mon bundle
    Deploys and monitors ransomware canary files across critical directories using Python's watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins.
    28 repo stars
  41. ▌
    Detecting API Enumeration Attacks · theheavenlyd3mon bundle
    Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.
    28 repo stars
  42. ▌
    Detecting Dll Sideloading Attacks · theheavenlyd3mon bundle
    Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
    28 repo stars
  43. ▌
    Detecting Dnp3 Protocol Anomalies · theheavenlyd3mon bundle
    Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet inspection and machine learning approaches.
    28 repo stars
  44. ▌
    Detecting Mobile Malware Behavior · theheavenlyd3mon bundle
    Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
    28 repo stars
  45. ▌
    Detecting Pass The Ticket Attacks · theheavenlyd3mon bundle
    Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM
    28 repo stars
  46. ▌
    Detecting Rdp Brute Force Attacks · theheavenlyd3mon bundle
    Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
    28 repo stars
  47. ▌
    Hunting For Cobalt Strike Beacons · theheavenlyd3mon bundle
    Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via Zeek, Suricata, and Python PCAP analysis.
    28 repo stars
  48. ▌
    Hunting For Dcom Lateral Movement · theheavenlyd3mon bundle
    Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation, WMI event analysis, RPC endpoint mapper traffic on port 135, and DCOM-specific parent-child process relationships.
    28 repo stars
  49. ▌
    Hunting For Dns Based Persistence · theheavenlyd3mon bundle
    Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
    28 repo stars
  50. ▌
    Implementing Siem Use Case Tuning · theheavenlyd3mon bundle
    Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic
    28 repo stars
  51. ▌
    Managing Cloud Identity With Okta · theheavenlyd3mon bundle
    This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.
    28 repo stars
  52. ▌
    Performing Security Headers Audit · theheavenlyd3mon bundle
    Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
    28 repo stars
  53. ▌
    Securing API Gateway With AWS Waf · theheavenlyd3mon bundle
    Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness.
    28 repo stars
  54. ▌
    Testing For Broken Access Control · theheavenlyd3mon bundle
    Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
    28 repo stars
  55. ▌
    Testing For Host Header Injection · theheavenlyd3mon bundle
    Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
    28 repo stars
  56. ▌
    Testing Mobile API Authentication · theheavenlyd3mon bundle
    Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management. Activates for requests involving mobile API auth testing, token security assessment, OAuth mobile flow testing, or API authorization bypass.
    28 repo stars
  57. ▌
    Analyzing Android Malware With Apktool · theheavenlyd3mon bundle
    Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
    28 repo stars
  58. ▌
    Executing Phishing Simulation Campaign · theheavenlyd3mon bundle
    Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests involving phishing simulation, social engineering assessment, email security testing, or security awareness measurement.
    28 repo stars
  59. ▌
    Executing Red Team Engagement Planning · theheavenlyd3mon bundle
    Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.
    28 repo stars
  60. ▌
    Exploiting Kerberoasting With Impacket · theheavenlyd3mon bundle
    Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
    28 repo stars
  61. ▌
    Exploiting Server Side Request Forgery · theheavenlyd3mon bundle
    Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
    28 repo stars
  62. ▌
    Extracting Config From Agent Tesla Rat · theheavenlyd3mon bundle
    Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
    28 repo stars
  63. ▌
    Generating Threat Intelligence Reports · theheavenlyd3mon bundle
    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.
    28 repo stars
  64. ▌
    Performing AI Driven Osint Correlation · theheavenlyd3mon bundle
    Use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
    28 repo stars
  65. ▌
    Performing IOS App Security Assessment · theheavenlyd3mon bundle
    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls. Activates for requests involving iOS app pentesting, Frida-based iOS instrumentation, mobile app SSL pinning bypass, or IPA reverse engineering.
    28 repo stars
  66. ▌
    Performing Ssl Tls Security Assessment · theheavenlyd3mon bundle
    Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
    28 repo stars
  67. ▌
    Auditing Kubernetes Cluster Rbac · theheavenlyd3mon bundle
    Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
    28 repo stars
  68. ▌
    Detecting Azure Lateral Movement · theheavenlyd3mon bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    28 repo stars
  69. ▌
    Implementing Zero Trust In Cloud · theheavenlyd3mon bundle
    This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.
    28 repo stars
  70. ▌
    Analyzing Uefi Bootkit Persistence · theheavenlyd3mon bundle
    Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing. Activates for requests involving UEFI malware analysis, firmware persistence investigation, boot chain integrity verification, or Secure Boot bypass detection.
    28 repo stars
  71. ▌
    Configuring Pfsense Firewall Rules · theheavenlyd3mon bundle
    Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments.
    28 repo stars
  72. ▌
    Detecting Attacks On Scada Systems · theheavenlyd3mon bundle
    This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly detection, and process data analytics to identify attacks that traditional IT security tools miss.
    28 repo stars
  73. ▌
    Detecting Email Account Compromise · theheavenlyd3mon bundle
    Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
    28 repo stars
  74. ▌
    Detecting Insider Threat Behaviors · theheavenlyd3mon bundle
    Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
    28 repo stars
  75. ▌
    Detecting Insider Threat With Ueba · theheavenlyd3mon bundle
    Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.
    28 repo stars
  76. ▌
    Implementing Endpoint Dlp Controls · theheavenlyd3mon bundle
    Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating content inspection policies, or preventing unauthorized data movement from endpoints. Activates for requests involving DLP, data exfiltration prevention, content inspection, or sensitive data protection on endpoints.
    28 repo stars
  77. ▌
    Performing Iot Security Assessment · theheavenlyd3mon bundle
    Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware debugging via UART and JTAG, network protocol analysis, and runtime exploitation to identify vulnerabilities across all layers of the IoT stack. Activates for requests involving IoT security testing, embedded device assessment, firmware security analysis, or smart device penetration testing.
    28 repo stars
  78. ▌
    Testing For Email Header Injection · theheavenlyd3mon bundle
    Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
    28 repo stars
  79. ▌
    Triaging Security Alerts In Splunk · theheavenlyd3mon bundle
    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.
    28 repo stars
  80. ▌
    Analyzing Campaign Attribution Evidence · theheavenlyd3mon bundle
    Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr
    28 repo stars
  81. ▌
    Analyzing Ransomware Network Indicators · theheavenlyd3mon bundle
    Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis
    28 repo stars
  82. ▌
    Exploiting Constrained Delegation Abuse · theheavenlyd3mon bundle
    Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
    28 repo stars
  83. ▌
    Exploiting Mass Assignment In REST Apis · theheavenlyd3mon bundle
    Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
    28 repo stars
  84. ▌
    Performing Binary Exploitation Analysis · theheavenlyd3mon bundle
    Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.
    28 repo stars
  85. ▌
    Performing GRAPHQL Introspection Attack · theheavenlyd3mon bundle
    Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive fields and mutations, tests for query depth and complexity limits, and exploits GraphQL-specific vulnerabilities including batching attacks, alias-based brute force, and nested query DoS. Activates for requests involving GraphQL security testing, introspection attack, GraphQL enumeration, or GraphQL API penetration testing.
    28 repo stars
  86. ▌
    Performing Privileged Account Discovery · theheavenlyd3mon bundle
    Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account
    28 repo stars
  87. ▌
    Reverse Engineering Malware With Ghidra · theheavenlyd3mon bundle
    Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals.
    28 repo stars
  88. ▌
    Scanning Docker Images With Trivy · theheavenlyd3mon bundle
    Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati
    28 repo stars
  89. ▌
    Securing Github Actions Workflows · theheavenlyd3mon bundle
    This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes.
    28 repo stars
  90. ▌
    Analyzing Security Logs With Splunk · theheavenlyd3mon bundle
    Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
    28 repo stars
  91. ▌
    Analyzing Threat Intelligence Feeds · theheavenlyd3mon bundle
    Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.
    28 repo stars
  92. ▌
    Building Detection Rules With Sigma · theheavenlyd3mon bundle
    Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.
    28 repo stars
  93. ▌
    Conducting Network Penetration Test · theheavenlyd3mon bundle
    Conducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security posture of network infrastructure. The tester follows PTES methodology from reconnaissance through post-exploitation and reporting. Activates for requests involving network pentest, infrastructure security assessment, internal network testing, or external perimeter testing.
    28 repo stars
  94. ▌
    Configuring Ldap Security Hardening · theheavenlyd3mon bundle
    Harden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
    28 repo stars
  95. ▌
    Detecting Business Email Compromise · theheavenlyd3mon bundle
    Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
    28 repo stars
  96. ▌
    Detecting Modbus Protocol Anomalies · theheavenlyd3mon bundle
    This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for malformed Modbus frames. The skill leverages Zeek with Modbus protocol analyzers, Suricata IDS with OT rules, and custom Python-based detection using Markov chain models for normal Modbus transaction sequences.
    28 repo stars
  97. ▌
    Hunting Credential Stuffing Attacks · theheavenlyd3mon bundle
    Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses statistical analysis on Splunk or raw log data. Use when investigating account takeover campaigns or building detection rules for auth abuse.
    28 repo stars
  98. ▌
    Hunting For Dns Tunneling With Zeek · theheavenlyd3mon bundle
    Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.
    28 repo stars
  99. ▌
    Implementing Bgp Security With Rpki · theheavenlyd3mon bundle
    Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.
    28 repo stars
  100. ▌
    Implementing Diamond Model Analysis · theheavenlyd3mon bundle
    The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    28 repo stars