all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 5 of 18

  1. ▌
    Agent Payment X402 · yanacuti1121
    Add x402 payment execution to AI agents with per-task budgets, spending controls, and non-custodial wallets. Supports Base through agentwallet-sdk and X Layer through OKX Payments / OKX Agent Payments Protocol.
    2 repo stars
  2. ▌
    Homelab Pihole Dns · yanacuti1121
    Pi-hole installation, blocklist management, DNS-over-HTTPS setup, DHCP integration, local DNS records, and troubleshooting broken DNS resolution on a home network.
    2 repo stars
  3. ▌
    Motion Foundations · yanacuti1121
    Motion tokens, spring presets, performance rules, device adaptation, accessibility enforcement, and SSR safety for React / Next.js using motion/react. Foundation layer — all other motion skills depend on this.
    2 repo stars
  4. ▌
    Visa Doc Translate · yanacuti1121
    Translate visa application documents (images) to English and create a bilingual PDF with original and translation
    2 repo stars
  5. ▌
    Liquid Glass Design · yanacuti1121
    iOS 26 Liquid Glass design system — dynamic glass material with blur, reflection, and interactive morphing for SwiftUI, UIKit, and WidgetKit.
    2 repo stars
  6. ▌
    Benchmark Methodology · yanacuti1121
    Use after competitive-platform-analysis has produced a tiered competitor set. Scores each competitor across nine weighted dimensions (positioning, voice, visual craft, offer packaging, evidence, enterprise-readiness, thought leadership, pricing, client's strategic tension) with explicit 1–5 rubrics and a tension-plot. Precedes competitive-report-structure.
    2 repo stars
  7. ▌
    Homelab Wireguard Vpn · yanacuti1121
    WireGuard VPN server setup, peer configuration, key generation, split tunneling vs full tunnel routing, and remote access to a home network from mobile and laptop clients.
    2 repo stars
  8. ▌
    Swift Concurrency 6 2 · yanacuti1121
    Swift 6.2 Approachable Concurrency — single-threaded by default, @concurrent for explicit background offloading, isolated conformances for main actor types.
    2 repo stars
  9. ▌
    High End Visual Design · yanacuti1121
    Teaches the AI to design like a high-end agency. Defines the exact fonts, spacing, shadows, card structures, and animations that make a website feel expensive. Blocks all the common defaults that make AI designs look cheap or generic.
    2 repo stars
  10. ▌
    Openclaw Persona Forge · yanacuti1121
    为 OpenClaw AI Agent 锻造完整的龙虾灵魂方案。根据用户偏好或随机抽卡, 输出身份定位、灵魂描述(SOUL.md)、角色化底线规则、名字和头像生图提示词。 如当前环境提供已审核的生图 skill,可自动生成统一风格头像图片。 当用户需要创建、设计或定制 OpenClaw 龙虾灵魂时使用。 不适用于:微调已有 SOUL.md、非 OpenClaw 平台的角色设计、纯工具型无性格 Agent。 触发词:龙虾灵魂、虾魂、OpenClaw 灵魂、养虾灵魂、龙虾角色、龙虾定位、 龙虾剧本杀角色、龙虾游戏角色、龙虾 NPC、龙虾性格、龙虾背景故事、 lobster soul、lobster character、抽卡、随机龙虾、龙虾 SOUL、gacha。
    2 repo stars
  11. ▌
    Code Review 2 · yanacuti1121
    Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/PRD asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to "review since X".
    2 repo stars
  12. ▌
    Homelab Vlan Segmentation · yanacuti1121
    Segmenting home networks into VLANs for IoT, guest, trusted, and server traffic using UniFi, pfSense/OPNsense, and MikroTik — including switch trunk config, firewall rules, and wireless SSID mapping.
    2 repo stars
  13. ▌
    Redesign Existing Projects · yanacuti1121
    Upgrades existing websites and apps to premium quality. Audits current design, identifies generic AI patterns, and applies high-end design standards without breaking functionality. Works with any CSS framework or vanilla CSS.
    2 repo stars
  14. ▌
    Foundation Models On Device · yanacuti1121
    Apple FoundationModels framework for on-device LLM — text generation, guided generation with @Generable, tool calling, and snapshot streaming in iOS 26+.
    2 repo stars
  15. ▌
    Claude Md Enhancer · yanacuti1121
    Analyzes, generates, and enhances CLAUDE.md files for any project type using best practices, modular architecture support, and tech stack customization. Use when setting up new projects, improving existing CLAUDE.md files, or establishing AI-assisted development standards.
    2 repo stars
  16. ▌
    Openai Superpowers Systematic Debugging · yanacuti1121
    Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes
    2 repo stars
  17. ▌
    Analyzing Certificate Transparency For Phishing · yanacuti1121 bundle
    Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
    2 repo stars
  18. ▌
    Analyzing Email Headers For Phishing Investigation · yanacuti1121 bundle
    Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
    2 repo stars
  19. ▌
    Implementing Network Traffic Analysis With Arkime · yanacuti1121 bundle
    Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across captured traffic.
    2 repo stars
  20. ▌
    Performing Android App Static Analysis With Mobsf · yanacuti1121 bundle
    Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application. Use when assessing Android APK/AAB files for security vulnerabilities before deployment, during penetration testing, or as part of CI/CD security gates. Activates for requests involving Android static analysis, MobSF scanning, APK security assessment, or mobile application code review.
    2 repo stars
  21. ▌
    Performing Bandwidth Throttling Attack Simulation · yanacuti1121 bundle
    Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks.
    2 repo stars
  22. ▌
    Performing Cloud Asset Inventory With Cartography · yanacuti1121 bundle
    Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure.
    2 repo stars
  23. ▌
    Performing Container Security Scanning With Trivy · yanacuti1121 bundle
    Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
    2 repo stars
  24. ▌
    Performing Static Malware Analysis With Pe Studio · yanacuti1121 bundle
    Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.
    2 repo stars
  25. ▌
    Performing Threat Landscape Assessment For Sector · yanacuti1121 bundle
    Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.
    2 repo stars
  26. ▌
    Reverse Engineering Ransomware Encryption Routine · yanacuti1121 bundle
    Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.
    2 repo stars
  27. ▌
    Testing API For Broken Object Level Authorization · yanacuti1121 bundle
    Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to determine if the server enforces per-object authorization. This is OWASP API Security Top 10 2023 risk API1. Activates for requests involving BOLA testing, IDOR in APIs, object-level authorization testing, or API access control bypass.
    2 repo stars
  28. ▌
    Collecting Volatile Evidence From Compromised Host · yanacuti1121 bundle
    Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
    2 repo stars
  29. ▌
    Detecting Dns Exfiltration With Dns Query Analysis · yanacuti1121 bundle
    Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.
    2 repo stars
  30. ▌
    Implementing Conduit Security For Ot Remote Access · yanacuti1121 bundle
    Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control systems without exposing OT networks directly.
    2 repo stars
  31. ▌
    Implementing Fuzz Testing In Cicd With Aflplusplus · yanacuti1121 bundle
    Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.
    2 repo stars
  32. ▌
    Implementing Kubernetes Network Policy With Calico · yanacuti1121 bundle
    Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.
    2 repo stars
  33. ▌
    Implementing Network Access Control With Cisco Ise · yanacuti1121 bundle
    Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.
    2 repo stars
  34. ▌
    Implementing Opa Gatekeeper For Policy Enforcement · yanacuti1121 bundle
    Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.
    2 repo stars
  35. ▌
    Implementing Policy As Code With Open Policy Agent · yanacuti1121 bundle
    This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines.
    2 repo stars
  36. ▌
    Implementing Zero Standing Privilege With Cyberark · yanacuti1121 bundle
    Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.
    2 repo stars
  37. ▌
    Openai Supabase Supabase Postgres Best Practices · yanacuti1121
    Postgres performance optimization and best practices from Supabase. Use this skill when writing, reviewing, or optimizing Postgres queries, schema designs, or database configurations.
    2 repo stars
  38. ▌
    Performing Log Analysis For Forensic Investigation · yanacuti1121 bundle
    Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
    2 repo stars
  39. ▌
    Performing Malware Hash Enrichment With Virustotal · yanacuti1121 bundle
    Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.
    2 repo stars
  40. ▌
    Performing Mobile Device Forensics With Cellebrite · yanacuti1121 bundle
    Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
    2 repo stars
  41. ▌
    Analyzing Memory Forensics With Lime And Volatility · yanacuti1121 bundle
    Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
    2 repo stars
  42. ▌
    Implementing API Abuse Detection With Rate Limiting · yanacuti1121 bundle
    Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.
    2 repo stars
  43. ▌
    Implementing Cloud Vulnerability Posture Management · yanacuti1121 bundle
    Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.
    2 repo stars
  44. ▌
    Implementing Container Network Policies With Calico · yanacuti1121 bundle
    Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.
    2 repo stars
  45. ▌
    Implementing Passwordless Auth With Microsoft Entra · yanacuti1121 bundle
    Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.
    2 repo stars
  46. ▌
    Implementing Passwordless Authentication With Fido2 · yanacuti1121 bundle
    Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica
    2 repo stars
  47. ▌
    Implementing Zero Trust Network Access With Zscaler · yanacuti1121 bundle
    Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.
    2 repo stars
  48. ▌
    Openai Superpowers Finishing A Development Branch · yanacuti1121
    Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
    2 repo stars
  49. ▌
    Performing AWS Account Enumeration With Scout Suite · yanacuti1121 bundle
    Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.
    2 repo stars
  50. ▌
    Performing Kubernetes Cis Benchmark With Kube Bench · yanacuti1121 bundle
    Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
    2 repo stars
  51. ▌
    Performing Ot Vulnerability Assessment With Claroty · yanacuti1121 bundle
    This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.
    2 repo stars
  52. ▌
    Performing Threat Modeling With Owasp Threat Dragon · yanacuti1121 bundle
    Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.
    2 repo stars
  53. ▌
    Performing Wireless Security Assessment With Kismet · yanacuti1121 bundle
    Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.
    2 repo stars
  54. ▌
    Analyzing Malware Family Relationships With Malpedia · yanacuti1121 bundle
    Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
    2 repo stars
  55. ▌
    Detecting Broken Object Property Level Authorization · yanacuti1121 bundle
    Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
    2 repo stars
  56. ▌
    Exploiting Vulnerabilities With Metasploit Framework · yanacuti1121 bundle
    The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules
    2 repo stars
  57. ▌
    Implementing Application Whitelisting With Applocker · yanacuti1121 bundle
    Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.
    2 repo stars
  58. ▌
    Implementing Azure Ad Privileged Identity Management · yanacuti1121 bundle
    Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
    2 repo stars
  59. ▌
    Implementing Continuous Security Validation With Bas · yanacuti1121 bundle
    Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.
    2 repo stars
  60. ▌
    Implementing Device Posture Assessment In Zero Trust · yanacuti1121 bundle
    Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access.
    2 repo stars
  61. ▌
    Implementing Next Generation Firewall With Palo Alto · yanacuti1121 bundle
    Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.
    2 repo stars
  62. ▌
    Implementing Ot Network Traffic Analysis With Nozomi · yanacuti1121 bundle
    Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
    2 repo stars
  63. ▌
    Implementing Security Information Sharing With Stix2 · yanacuti1121 bundle
    Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
    2 repo stars
  64. ▌
    Implementing Vulnerability Management With Greenbone · yanacuti1121 bundle
    Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.
    2 repo stars
  65. ▌
    Implementing Zero Knowledge Proof For Authentication · yanacuti1121 bundle
    Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati
    2 repo stars
  66. ▌
    Performing Active Directory Compromise Investigation · yanacuti1121 bundle
    Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
    2 repo stars
  67. ▌
    Performing Active Directory Vulnerability Assessment · yanacuti1121 bundle
    Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.
    2 repo stars
  68. ▌
    Performing Memory Forensics With Volatility3 Plugins · yanacuti1121 bundle
    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
    2 repo stars
  69. ▌
    Performing Thick Client Application Penetration Test · yanacuti1121 bundle
    Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
    2 repo stars
  70. ▌
    Conducting Internal Reconnaissance With Bloodhound Ce · yanacuti1121 bundle
    Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.
    2 repo stars
  71. ▌
    Exploiting Active Directory Certificate Services Esc1 · yanacuti1121 bundle
    Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.
    2 repo stars
  72. ▌
    Implementing Infrastructure As Code Security Scanning · yanacuti1121 bundle
    This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before deployment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.
    2 repo stars
  73. ▌
    Implementing Network Segmentation With Firewall Zones · yanacuti1121 bundle
    Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.
    2 repo stars
  74. ▌
    Implementing Threat Intelligence Lifecycle Management · yanacuti1121 bundle
    Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.
    2 repo stars
  75. ▌
    Implementing Web Application Logging With Modsecurity · yanacuti1121 bundle
    Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.
    2 repo stars
  76. ▌
    Performing Adversary In The Middle Phishing Detection · yanacuti1121 bundle
    Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens.
    2 repo stars
  77. ▌
    Implementing Image Provenance Verification With Cosign · yanacuti1121 bundle
    Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
    2 repo stars
  78. ▌
    Implementing Iso 27001 Information Security Management · yanacuti1121 bundle
    ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
    2 repo stars
  79. ▌
    Performing GCP Penetration Testing With Gcpbucketbrute · yanacuti1121 bundle
    Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing
    2 repo stars
  80. ▌
    Implementing Deception Based Detection With Canarytoken · yanacuti1121 bundle
    Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.
    2 repo stars
  81. ▌
    Implementing Github Advanced Security For Code Scanning · yanacuti1121 bundle
    Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
    2 repo stars
  82. ▌
    Implementing Network Intrusion Prevention With Suricata · yanacuti1121 bundle
    Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.
    2 repo stars
  83. ▌
    Implementing Privileged Access Management With Cyberark · yanacuti1121 bundle
    Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c
    2 repo stars
  84. ▌
    Implementing Data Loss Prevention With Microsoft Purview · yanacuti1121 bundle
    Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Activity Explorer and DLP alert management. Uses PowerShell cmdlets and the Microsoft Graph API for programmatic policy management. Activates for requests involving DLP policy creation, sensitivity label configuration, data classification, endpoint data protection, or Microsoft Purview compliance administration.
    2 repo stars
  85. ▌
    Implementing Epss Score For Vulnerability Prioritization · yanacuti1121 bundle
    Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
    2 repo stars
  86. ▌
    Implementing Container Image Minimal Base With Distroless · yanacuti1121 bundle
    Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
    2 repo stars
  87. ▌
    Performing Cloud Native Threat Hunting With AWS Detective · yanacuti1121 bundle
    Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
    2 repo stars
  88. ▌
    Book Patterns Of Enterprise Application Architecture Full · yanacuti1121
    PoEAA (Martin Fowler) — Full rules — comprehensive mandatory coding standards. Use when asked to apply PoEAA principles or review code against PoEAA standards.
    2 repo stars
  89. ▌
    Book Patterns Of Enterprise Application Architecture Mini · yanacuti1121
    PoEAA (Martin Fowler) — Condensed rules — key principles distilled. Use when asked to apply PoEAA principles or review code against PoEAA standards.
    2 repo stars
  90. ▌
    Book Patterns Of Enterprise Application Architecture Nano · yanacuti1121
    PoEAA (Martin Fowler) — Minimal rules — essential one-liners only. Use when asked to apply PoEAA principles or review code against PoEAA standards.
    2 repo stars
  91. ▌
    Performing Windows Artifact Analysis With Eric Zimmerman Too · yanacuti1121 bundle
    Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.
    2 repo stars
  92. ▌
    Configuring Zscaler Private Access For Ztna · yanacuti1121 bundle
    Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and device posture, and integrating with IdPs.
    2 repo stars
  93. ▌
    Deobfuscating Powershell Obfuscated Malware · yanacuti1121 bundle
    Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
    2 repo stars
  94. ▌
    Detecting AI Model Prompt Injection Attacks · yanacuti1121 bundle
    Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models. The detector analyzes user inputs before they reach the LLM, flagging direct injections (system prompt overrides, role-play escapes, instruction hijacking) and indirect injections (encoded payloads, multi-language obfuscation, delimiter-based escapes). Based on the OWASP LLM Top 10 (LLM01:2025 Prompt Injection) and Simon Willison's prompt injection taxonomy. Activates for requests involving prompt injection detection, LLM input sanitization, AI security scanning, or prompt attack classification.
    2 repo stars
  95. ▌
    Detecting Anomalous Authentication Patterns · yanacuti1121 bundle
    Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication logs. Activates for requests involving authentication anomaly detection, login behavior analysis, UEBA implementation, or suspicious sign-in investigation.
    2 repo stars
  96. ▌
    Detecting AWS Guardduty Findings Automation · yanacuti1121 bundle
    Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.
    2 repo stars
  97. ▌
    Detecting Business Email Compromise With AI · yanacuti1121 bundle
    Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
    2 repo stars
  98. ▌
    Detecting Container Escape With Falco Rules · yanacuti1121 bundle
    Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
    2 repo stars
  99. ▌
    Detecting Dcsync Attack In Active Directory · yanacuti1121 bundle
    Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.
    2 repo stars
  100. ▌
    Detecting Deepfake Audio In Vishing Attacks · yanacuti1121 bundle
    Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models. Supports batch analysis of audio files, generates confidence scores, and produces forensic reports. Activates for requests involving deepfake voice detection, vishing investigation, AI-generated speech analysis, voice cloning detection, or audio authenticity verification.
    2 repo stars