all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 10 of 18

  1. ▌
    Performing Kubernetes Penetration Testing · yanacuti1121 bundle
    Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools
    2 repo stars
  2. ▌
    Performing Ot Network Security Assessment · yanacuti1121 bundle
    This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infrastructure.
    2 repo stars
  3. ▌
    Performing Plc Firmware Security Analysis · yanacuti1121 bundle
    This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampering.
    2 repo stars
  4. ▌
    Performing Red Team Phishing With Gophish · yanacuti1121 bundle
    Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.
    2 repo stars
  5. ▌
    Performing Supply Chain Attack Simulation · yanacuti1121 bundle
    Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit.
    2 repo stars
  6. ▌
    Performing Threat Hunting With Yara Rules · yanacuti1121 bundle
    Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
    2 repo stars
  7. ▌
    Testing For Open Redirect Vulnerabilities · yanacuti1121 bundle
    Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
    2 repo stars
  8. ▌
    Testing For XML Injection Vulnerabilities · yanacuti1121 bundle
    Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
    2 repo stars
  9. ▌
    Testing For Xxe Injection Vulnerabilities · yanacuti1121 bundle
    Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
    2 repo stars
  10. ▌
    Analyzing Browser Forensics With Hindsight · yanacuti1121 bundle
    Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.
    2 repo stars
  11. ▌
    Analyzing Lnk File And Jump List Artifacts · yanacuti1121 bundle
    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.
    2 repo stars
  12. ▌
    Analyzing Packed Malware With Upx Unpacker · yanacuti1121 bundle
    Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
    2 repo stars
  13. ▌
    Analyzing Ransomware Encryption Mechanisms · yanacuti1121 bundle
    Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
    2 repo stars
  14. ▌
    Auditing Tls Certificate Transparency Logs · yanacuti1121 bundle
    Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting.
    2 repo stars
  15. ▌
    Book Domain Driven Design Distilled Full · yanacuti1121
    DDD Distilled (Vaughn Vernon) — Full rules — comprehensive mandatory coding standards. Use when asked to apply DDD Distilled principles or review code against DDD Distilled standards.
    2 repo stars
  16. ▌
    Book Domain Driven Design Distilled Mini · yanacuti1121
    DDD Distilled (Vaughn Vernon) — Condensed rules — key principles distilled. Use when asked to apply DDD Distilled principles or review code against DDD Distilled standards.
    2 repo stars
  17. ▌
    Book Domain Driven Design Distilled Nano · yanacuti1121
    DDD Distilled (Vaughn Vernon) — Minimal rules — essential one-liners only. Use when asked to apply DDD Distilled principles or review code against DDD Distilled standards.
    2 repo stars
  18. ▌
    Building Devsecops Pipeline With Gitlab CI · yanacuti1121 bundle
    Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
    2 repo stars
  19. ▌
    Building Incident Timeline With Timesketch · yanacuti1121 bundle
    Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
    2 repo stars
  20. ▌
    Building Role Mining For Rbac Optimization · yanacuti1121 bundle
    Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
    2 repo stars
  21. ▌
    Building Threat Feed Aggregation With Misp · yanacuti1121 bundle
    Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
    2 repo stars
  22. ▌
    Conducting Social Engineering Pretext Call · yanacuti1121 bundle
    Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
    2 repo stars
  23. ▌
    Configuring Host Based Intrusion Detection · yanacuti1121 bundle
    Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitoring, building file integrity monitoring (FIM) policies, or meeting compliance requirements for change detection. Activates for requests involving HIDS configuration, file integrity monitoring, OSSEC/Wazuh deployment, or host-based detection.
    2 repo stars
  24. ▌
    Deploying Cloudflare Access For Zero Trust · yanacuti1121 bundle
    Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.
    2 repo stars
  25. ▌
    Detecting Arp Poisoning In Network Traffic · yanacuti1121 bundle
    Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
    2 repo stars
  26. ▌
    Detecting Modbus Command Injection Attacks · yanacuti1121 bundle
    Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and protocol deep packet inspection.
    2 repo stars
  27. ▌
    Detecting Ransomware Precursors In Network · yanacuti1121 bundle
    Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts. Activates for requests involving pre-ransomware detection, network-based ransomware indicators, or early warning ransomware monitoring.
    2 repo stars
  28. ▌
    Detecting Spearphishing With Email Gateway · yanacuti1121 bundle
    Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
    2 repo stars
  29. ▌
    Exploiting Insecure Data Storage In Mobile · yanacuti1121 bundle
    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences analysis, or mobile data leakage assessment.
    2 repo stars
  30. ▌
    Exploiting Nosql Injection Vulnerabilities · yanacuti1121 bundle
    Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
    2 repo stars
  31. ▌
    Hardening Docker Containers For Production · yanacuti1121 bundle
    Hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce leas
    2 repo stars
  32. ▌
    Hunting For Anomalous Powershell Execution · yanacuti1121 bundle
    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification.
    2 repo stars
  33. ▌
    Implementing API Gateway Security Controls · yanacuti1121 bundle
    Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM, Apigee) to act as a centralized security enforcement point that validates, throttles, and monitors all API traffic before it reaches backend services. Activates for requests involving API gateway security, API management security, gateway authentication, or centralized API protection.
    2 repo stars
  34. ▌
    Implementing AWS Iam Permission Boundaries · yanacuti1121 bundle
    Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.
    2 repo stars
  35. ▌
    Implementing Cloud Dlp For Data Protection · yanacuti1121 bundle
    Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines.
    2 repo stars
  36. ▌
    Implementing Delinea Secret Server For Pam · yanacuti1121 bundle
    Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.
    2 repo stars
  37. ▌
    Implementing Dmarc Dkim Spf Email Security · yanacuti1121 bundle
    SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im
    2 repo stars
  38. ▌
    Implementing Endpoint Detection With Wazuh · yanacuti1121 bundle
    Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    2 repo stars
  39. ▌
    Implementing Gdpr Data Protection Controls · yanacuti1121 bundle
    The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover
    2 repo stars
  40. ▌
    Implementing Log Integrity With Blockchain · yanacuti1121 bundle
    Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services.
    2 repo stars
  41. ▌
    Implementing Mitre Attack Coverage Mapping · yanacuti1121 bundle
    Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
    2 repo stars
  42. ▌
    Implementing Mobile Application Management · yanacuti1121 bundle
    Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
    2 repo stars
  43. ▌
    Implementing Ot Incident Response Playbook · yanacuti1121 bundle
    Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
    2 repo stars
  44. ▌
    Implementing Privileged Access Workstation · yanacuti1121 bundle
    Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
    2 repo stars
  45. ▌
    Implementing Privileged Session Monitoring · yanacuti1121 bundle
    Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke logging, real-time monitoring, risk-based session analysis, and compliance audit trail generation. Activates for requests involving privileged session recording, PAM session monitoring, CyberArk PSM configuration, administrator activity monitoring, or compliance session auditing.
    2 repo stars
  46. ▌
    Implementing Rapid7 Insightvm For Scanning · yanacuti1121 bundle
    Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
    2 repo stars
  47. ▌
    Implementing Rbac Hardening For Kubernetes · yanacuti1121 bundle
    Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
    2 repo stars
  48. ▌
    Implementing Secret Scanning With Gitleaks · yanacuti1121 bundle
    This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
    2 repo stars
  49. ▌
    Implementing Secrets Management With Vault · yanacuti1121 bundle
    This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It addresses eliminating hardcoded credentials from application code and CI/CD pipelines by implementing short-lived, automatically rotated secrets.
    2 repo stars
  50. ▌
    Implementing Sigstore For Software Signing · yanacuti1121 bundle
    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.
    2 repo stars
  51. ▌
    Implementing Vulnerability Remediation Sla · yanacuti1121 bundle
    Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs
    2 repo stars
  52. ▌
    Intercepting Mobile Traffic With Burpsuite · yanacuti1121 bundle
    Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.
    2 repo stars
  53. ▌
    Openai Cloudflare Workers Best Practices · yanacuti1121
    Reviews and authors Cloudflare Workers code against production best practices. Load when writing new Workers, reviewing Worker code, configuring wrangler.jsonc, or checking for common Workers anti-patterns (streaming, floating promises, global state, secrets, bindings, observability). Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
    2 repo stars
  54. ▌
    Openai Codex Security Deep Security Scan · yanacuti1121
    Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths.
    2 repo stars
  55. ▌
    Openai Codex Security Security Diff Scan · yanacuti1121
    Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
    2 repo stars
  56. ▌
    Openai Superpowers Receiving Code Review · yanacuti1121
    Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation
    2 repo stars
  57. ▌
    Performing Access Review And Certification · yanacuti1121 bundle
    Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles. This skill covers review campaign design, reviewer selection, risk-based p
    2 repo stars
  58. ▌
    Performing Authenticated Scan With Openvas · yanacuti1121 bundle
    Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.
    2 repo stars
  59. ▌
    Performing Cloud Log Forensics With Athena · yanacuti1121 bundle
    Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and privilege escalation. Use when investigating AWS security incidents or building cloud-native forensic workflows at scale.
    2 repo stars
  60. ▌
    Performing Dark Web Monitoring For Threats · yanacuti1121 bundle
    Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre
    2 repo stars
  61. ▌
    Performing Deception Technology Deployment · yanacuti1121 bundle
    Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.
    2 repo stars
  62. ▌
    Performing Dynamic Analysis Of Android App · yanacuti1121 bundle
    Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis.
    2 repo stars
  63. ▌
    Performing HTTP Parameter Pollution Attack · yanacuti1121 bundle
    Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
    2 repo stars
  64. ▌
    Performing Network Packet Capture Analysis · yanacuti1121 bundle
    Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
    2 repo stars
  65. ▌
    Performing OAUTH Scope Minimization Review · yanacuti1121 bundle
    Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization.
    2 repo stars
  66. ▌
    Performing Privilege Escalation Assessment · yanacuti1121 bundle
    Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment.
    2 repo stars
  67. ▌
    Performing Ssrf Vulnerability Exploitation · yanacuti1121 bundle
    Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169.254.169.254), internal port scanning via HTTP, URL scheme bypass techniques, and DNS rebinding detection.
    2 repo stars
  68. ▌
    Performing Web Application Firewall Bypass · yanacuti1121 bundle
    Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.
    2 repo stars
  69. ▌
    Scanning Kubernetes Manifests With Kubesec · yanacuti1121 bundle
    Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
    2 repo stars
  70. ▌
    Testing For Business Logic Vulnerabilities · yanacuti1121 bundle
    Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect.
    2 repo stars
  71. ▌
    Testing For JSON Web Token Vulnerabilities · yanacuti1121 bundle
    Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
    2 repo stars
  72. ▌
    Analyzing Command And Control Communication · yanacuti1121 bundle
    Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.
    2 repo stars
  73. ▌
    Analyzing Macro Malware In Office Documents · yanacuti1121 bundle
    Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.
    2 repo stars
  74. ▌
    Analyzing Malware Persistence With Autoruns · yanacuti1121 bundle
    Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows systems.
    2 repo stars
  75. ▌
    Analyzing Ransomware Leak Site Intelligence · yanacuti1121 bundle
    Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.
    2 repo stars
  76. ▌
    Analyzing Tls Certificate Transparency Logs · yanacuti1121 bundle
    Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for proactive phishing domain detection and certificate monitoring.
    2 repo stars
  77. ▌
    Book A Philosophy Of Software Design Full · yanacuti1121
    Philosophy of Software Design (John Ousterhout) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Philosophy of Software Design principles or review code against Philosophy of Software Design standards.
    2 repo stars
  78. ▌
    Book A Philosophy Of Software Design Mini · yanacuti1121
    Philosophy of Software Design (John Ousterhout) — Condensed rules — key principles distilled. Use when asked to apply Philosophy of Software Design principles or review code against Philosophy of Software Design standards.
    2 repo stars
  79. ▌
    Book A Philosophy Of Software Design Nano · yanacuti1121
    Philosophy of Software Design (John Ousterhout) — Minimal rules — essential one-liners only. Use when asked to apply Philosophy of Software Design principles or review code against Philosophy of Software Design standards.
    2 repo stars
  80. ▌
    Building Ioc Defanging And Sharing Pipeline · yanacuti1121 bundle
    Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.
    2 repo stars
  81. ▌
    Building Phishing Reporting Button Workflow · yanacuti1121 bundle
    Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.
    2 repo stars
  82. ▌
    Conducting Memory Forensics With Volatility · yanacuti1121 bundle
    Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
    2 repo stars
  83. ▌
    Configuring Network Segmentation With Vlans · yanacuti1121 bundle
    Designs and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
    2 repo stars
  84. ▌
    Configuring Suricata For Network Monitoring · yanacuti1121 bundle
    Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms for centralized security monitoring.
    2 repo stars
  85. ▌
    Conducting Malware Incident Response · yanacuti1121 bundle
    Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment, analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal, worm containment, malware triage, or infected endpoint remediation.
    2 repo stars
  86. ▌
    Deploying Edr Agent With Crowdstrike · yanacuti1121 bundle
    Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
    2 repo stars
  87. ▌
    Deploying Software Defined Perimeter · yanacuti1121 bundle
    Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
    2 repo stars
  88. ▌
    Detecting Container Drift At Runtime · yanacuti1121 bundle
    Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
    2 repo stars
  89. ▌
    Detecting Lateral Movement With Zeek · yanacuti1121 bundle
    Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
    2 repo stars
  90. ▌
    Detecting SQL Injection Via Waf Logs · yanacuti1121 bundle
    Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates multi-stage injection attempts, and generates incident reports with OWASP classification.
    2 repo stars
  91. ▌
    Exploiting SQL Injection With Sqlmap · yanacuti1121 bundle
    Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
    2 repo stars
  92. ▌
    Exploiting Websocket Vulnerabilities · yanacuti1121 bundle
    Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
    2 repo stars
  93. ▌
    Extracting Browser History Artifacts · yanacuti1121 bundle
    Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
    2 repo stars
  94. ▌
    Extracting Iocs From Malware Samples · yanacuti1121 bundle
    Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples.
    2 repo stars
  95. ▌
    Email Deliverability Security · yanacuti1121
    Configure email authentication so legitimate mail lands and spoofed mail is blocked. Covers SPF, DKIM, DMARC (with the p=none → p=quarantine → p=reject migration path), MTA-STS, TLS-RPT, ARC, and BIMI. Invoke when launching a new sending domain, when domains are being spoofed, or when transactional email is landing in spam.
    2 repo stars
  96. ▌
    Hunting For Lateral Movement Via Wmi · yanacuti1121 bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    2 repo stars
  97. ▌
    Hunting For Spearphishing Indicators · yanacuti1121 bundle
    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
    2 repo stars
  98. ▌
    Implementing Alert Fatigue Reduction · yanacuti1121 bundle
    Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.
    2 repo stars
  99. ▌
    Implementing Pam For Database Access · yanacuti1121 bundle
    Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia
    2 repo stars
  100. ▌
    Implementing Rsa Key Pair Management · yanacuti1121 bundle
    RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,
    2 repo stars