all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 6 of 18

  1. ▌
    Detecting Insider Data Exfiltration Via Dlp · yanacuti1121 bundle
    Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating insider threats or building user behavior analytics for data loss prevention.
    2 repo stars
  2. ▌
    Detecting Ntlm Relay With Event Correlation · yanacuti1121 bundle
    Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis.
    2 repo stars
  3. ▌
    Detecting T1003 Credential Dumping With Edr · yanacuti1121 bundle
    Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
    2 repo stars
  4. ▌
    Exploiting Active Directory With Bloodhound · yanacuti1121 bundle
    BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac
    2 repo stars
  5. ▌
    Hardening Linux Endpoint With Cis Benchmark · yanacuti1121 bundle
    Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit findings, or establishing security baselines for Linux infrastructure. Activates for requests involving Linux hardening, CIS benchmarks for Linux, server security baselines, or Linux configuration compliance.
    2 repo stars
  6. ▌
    Hunting For Living Off The Cloud Techniques · yanacuti1121 bundle
    Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse of Azure, AWS, GCP services, and SaaS platforms.
    2 repo stars
  7. ▌
    Hunting For Registry Persistence Mechanisms · yanacuti1121 bundle
    Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
    2 repo stars
  8. ▌
    Implementing Anti Phishing Training Program · yanacuti1121 bundle
    Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv
    2 repo stars
  9. ▌
    Implementing API Schema Validation Security · yanacuti1121 bundle
    Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.
    2 repo stars
  10. ▌
    Implementing Cisa Zero Trust Maturity Model · yanacuti1121 bundle
    Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.
    2 repo stars
  11. ▌
    Implementing Disk Encryption With Bitlocker · yanacuti1121 bundle
    Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.
    2 repo stars
  12. ▌
    Implementing Runtime Security With Tetragon · yanacuti1121 bundle
    Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
    2 repo stars
  13. ▌
    Implementing Siem Correlation Rules For Apt · yanacuti1121 bundle
    Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.
    2 repo stars
  14. ▌
    Implementing Ticketing System For Incidents · yanacuti1121 bundle
    Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.
    2 repo stars
  15. ▌
    Implementing Velociraptor For Ir Collection · yanacuti1121 bundle
    Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.
    2 repo stars
  16. ▌
    Integrating Dast With Owasp Zap In Pipeline · yanacuti1121 bundle
    This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and establishing DAST quality gates in GitHub Actions and GitLab CI.
    2 repo stars
  17. ▌
    Openai Superpowers Requesting Code Review · yanacuti1121
    Use when completing tasks, implementing major features, or before merging to verify work meets requirements
    2 repo stars
  18. ▌
    Performing Agentless Vulnerability Scanning · yanacuti1121 bundle
    Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
    2 repo stars
  19. ▌
    Performing Authenticated Vulnerability Scan · yanacuti1121 bundle
    Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security sett
    2 repo stars
  20. ▌
    Performing Dmarc Policy Enforcement Rollout · yanacuti1121 bundle
    Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.
    2 repo stars
  21. ▌
    Performing Docker Bench Security Assessment · yanacuti1121 bundle
    Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying Docker containers in production. Based on the CIS Docker Benchmark, it audits host confi
    2 repo stars
  22. ▌
    Performing Endpoint Forensics Investigation · yanacuti1121 bundle
    Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.
    2 repo stars
  23. ▌
    Performing False Positive Reduction In Siem · yanacuti1121 bundle
    Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
    2 repo stars
  24. ▌
    Performing Firmware Extraction With Binwalk · yanacuti1121 bundle
    Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
    2 repo stars
  25. ▌
    Performing Ics Asset Discovery With Claroty · yanacuti1121 bundle
    Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
    2 repo stars
  26. ▌
    Performing Network Forensics With Wireshark · yanacuti1121 bundle
    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
    2 repo stars
  27. ▌
    Performing Oil Gas Cybersecurity Assessment · yanacuti1121 bundle
    This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure.
    2 repo stars
  28. ▌
    Performing Ot Vulnerability Scanning Safely · yanacuti1121 bundle
    Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
    2 repo stars
  29. ▌
    Performing Phishing Simulation With Gophish · yanacuti1121 bundle
    GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag
    2 repo stars
  30. ▌
    Performing Privileged Account Access Review · yanacuti1121 bundle
    Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
    2 repo stars
  31. ▌
    Performing Ssl Tls Inspection Configuration · yanacuti1121 bundle
    Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
    2 repo stars
  32. ▌
    Performing Threat Hunting With Elastic Siem · yanacuti1121 bundle
    Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.
    2 repo stars
  33. ▌
    Performing Web Application Penetration Test · yanacuti1121 bundle
    Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses Burp Suite as the primary interception proxy alongside manual testing techniques to find flaws that automated scanners miss. Activates for requests involving web app pentest, OWASP testing, application security assessment, or web vulnerability testing.
    2 repo stars
  34. ▌
    Securing Historian Server In Ot Environment · yanacuti1121 bundle
    This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for historian interfaces, data replication through DMZ using data diodes or PI-to-PI connectors, SQL injection prevention in historian queries, and integrity protection of process data used for safety analysis, regulatory reporting, and process optimization.
    2 repo stars
  35. ▌
    Testing Android Intents For Vulnerabilities · yanacuti1121 bundle
    Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.
    2 repo stars
  36. ▌
    Triaging Security Incident With Ir Playbook · yanacuti1121 bundle
    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
    2 repo stars
  37. ▌
    Analyzing Cobalt Strike Beacon Configuration · yanacuti1121 bundle
    Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
    2 repo stars
  38. ▌
    Analyzing Cobaltstrike Malleable C2 Profiles · yanacuti1121 bundle
    Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
    2 repo stars
  39. ▌
    Analyzing Malware Sandbox Evasion Techniques · yanacuti1121 bundle
    Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports
    2 repo stars
  40. ▌
    Analyzing Network Covert Channels In Malware · yanacuti1121 bundle
    Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.
    2 repo stars
  41. ▌
    Conducting Internal Network Penetration Test · yanacuti1121 bundle
    Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.
    2 repo stars
  42. ▌
    Conducting Spearphishing Simulation Campaign · yanacuti1121 bundle
    Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf
    2 repo stars
  43. ▌
    Conducting Wireless Network Penetration Test · yanacuti1121 bundle
    Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Activates for requests involving wireless pentest, WiFi security assessment, WPA2/WPA3 testing, or rogue access point detection.
    2 repo stars
  44. ▌
    Configuring Microsegmentation For Zero Trust · yanacuti1121 bundle
    Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.
    2 repo stars
  45. ▌
    Deploying Palo Alto Prisma Access Zero Trust · yanacuti1121 bundle
    Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.
    2 repo stars
  46. ▌
    Detecting Typosquatting Packages In NPM Pypi · yanacuti1121 bundle
    Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. The analyst queries the PyPI JSON API and npm registry API to gather package metadata for automated comparison. Activates for requests involving package typosquatting detection, dependency confusion analysis, malicious package identification, or software supply chain threat hunting in package registries.
    2 repo stars
  47. ▌
    Executing Active Directory Attack Simulation · yanacuti1121 bundle
    Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, and delegation abuse. Activates for requests involving Active Directory pentest, AD attack simulation, domain compromise testing, or Kerberos attack assessment.
    2 repo stars
  48. ▌
    Exploiting Prototype Pollution In Javascript · yanacuti1121 bundle
    Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
    2 repo stars
  49. ▌
    Hunting For Data Staging Before Exfiltration · yanacuti1121 bundle
    Detect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry
    2 repo stars
  50. ▌
    Hunting For Defense Evasion Via Timestomping · yanacuti1121 bundle
    Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity.
    2 repo stars
  51. ▌
    Implementing Aes Encryption For Data At REST · yanacuti1121 bundle
    AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m
    2 repo stars
  52. ▌
    Implementing API Security Posture Management · yanacuti1121 bundle
    Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.
    2 repo stars
  53. ▌
    Implementing AWS Config Rules For Compliance · yanacuti1121 bundle
    Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts.
    2 repo stars
  54. ▌
    Implementing Ddos Mitigation With Cloudflare · yanacuti1121 bundle
    Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
    2 repo stars
  55. ▌
    Implementing Digital Signatures With Ed25519 · yanacuti1121 bundle
    Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove
    2 repo stars
  56. ▌
    Implementing Google Workspace Admin Security · yanacuti1121 bundle
    Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration.
    2 repo stars
  57. ▌
    Implementing Hashicorp Vault Dynamic Secrets · yanacuti1121 bundle
    Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation.
    2 repo stars
  58. ▌
    Implementing Memory Protection With Dep Aslr · yanacuti1121 bundle
    Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks. Use when hardening endpoints against buffer overflow exploits, ROP chains, and code injection. Activates for requests involving memory protection, exploit mitigation, DEP, ASLR, or CFG configuration.
    2 repo stars
  59. ▌
    Implementing Network Policies For Kubernetes · yanacuti1121 bundle
    Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu
    2 repo stars
  60. ▌
    Implementing Patch Management For Ot Systems · yanacuti1121 bundle
    This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization, staged deployment through test environments, maintenance window coordination, rollback procedures, and compensating controls when patches cannot be applied due to operational constraints or vendor restrictions.
    2 repo stars
  61. ▌
    Openai Codex Security Attack Path Analysis · yanacuti1121
    Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    2 repo stars
  62. ▌
    Openai Superpowers Test Driven Development · yanacuti1121
    Use when implementing any feature or bugfix, before writing implementation code
    2 repo stars
  63. ▌
    Performing Active Directory Penetration Test · yanacuti1121 bundle
    Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.
    2 repo stars
  64. ▌
    Performing API Security Testing With Postman · yanacuti1121 bundle
    Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writes test scripts for automated security validation, and integrates Postman with OWASP ZAP and Newman for CI/CD security testing. Activates for requests involving Postman security testing, API security collection, automated API testing, or OWASP API testing with Postman.
    2 repo stars
  65. ▌
    Performing Cloud Native Forensics With Falco · yanacuti1121 bundle
    Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
    2 repo stars
  66. ▌
    Performing Dns Enumeration And Zone Transfer · yanacuti1121 bundle
    Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.
    2 repo stars
  67. ▌
    Performing External Network Penetration Test · yanacuti1121 bundle
    Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.
    2 repo stars
  68. ▌
    Performing Linux Log Forensics Investigation · yanacuti1121 bundle
    Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised Linux systems.
    2 repo stars
  69. ▌
    Performing Malware Persistence Investigation · yanacuti1121 bundle
    Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
    2 repo stars
  70. ▌
    Performing Memory Forensics With Volatility3 · yanacuti1121 bundle
    Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
    2 repo stars
  71. ▌
    Performing S7comm Protocol Security Analysis · yanacuti1121 bundle
    Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers.
    2 repo stars
  72. ▌
    Performing Sca Dependency Scanning With Snyk · yanacuti1121 bundle
    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
    2 repo stars
  73. ▌
    Performing Soap Web Service Security Testing · yanacuti1121 bundle
    Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
    2 repo stars
  74. ▌
    Performing Wireless Network Penetration Test · yanacuti1121 bundle
    Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.
    2 repo stars
  75. ▌
    Triaging Vulnerabilities With Ssvc Framework · yanacuti1121 bundle
    Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
    2 repo stars
  76. ▌
    Observability And Instrumentation · yanacuti1121
    Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting. Use when shipping any feature that runs in production and you need evidence it works. Use when production issues are reported but you can't tell what happened from the available data.
    2 repo stars
  77. ▌
    Analyzing Office365 Audit Logs For Compromise · yanacuti1121 bundle
    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
    2 repo stars
  78. ▌
    Analyzing Threat Actor Ttps With Mitre Attack · yanacuti1121 bundle
    MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
    2 repo stars
  79. ▌
    Analyzing Typosquatting Domains With Dnstwist · yanacuti1121 bundle
    Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
    2 repo stars
  80. ▌
    Auditing Azure Active Directory Configuration · yanacuti1121 bundle
    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
    2 repo stars
  81. ▌
    Book Implementing Domain Driven Design Full · yanacuti1121
    Implementing DDD (Vaughn Vernon) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Implementing DDD principles or review code against Implementing DDD standards.
    2 repo stars
  82. ▌
    Book Implementing Domain Driven Design Mini · yanacuti1121
    Implementing DDD (Vaughn Vernon) — Condensed rules — key principles distilled. Use when asked to apply Implementing DDD principles or review code against Implementing DDD standards.
    2 repo stars
  83. ▌
    Book Implementing Domain Driven Design Nano · yanacuti1121
    Implementing DDD (Vaughn Vernon) — Minimal rules — essential one-liners only. Use when asked to apply Implementing DDD principles or review code against Implementing DDD standards.
    2 repo stars
  84. ▌
    Building Ioc Enrichment Pipeline With Opencti · yanacuti1121 bundle
    OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O
    2 repo stars
  85. ▌
    Building Threat Intelligence Feed Integration · yanacuti1121 bundle
    Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
    2 repo stars
  86. ▌
    Building Vulnerability Aging And Sla Tracking · yanacuti1121 bundle
    Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.
    2 repo stars
  87. ▌
    Bypassing Authentication With Forced Browsing · yanacuti1121 bundle
    Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.
    2 repo stars
  88. ▌
    Conducting External Reconnaissance With Osint · yanacuti1121 bundle
    Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization's external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records, certificate transparency logs, search engines, social media, code repositories, and data breach databases to build a comprehensive target profile. Activates for requests involving OSINT reconnaissance, external footprinting, attack surface mapping, or passive information gathering.
    2 repo stars
  89. ▌
    Configuring Snort Ids For Intrusion Detection · yanacuti1121 bundle
    Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments.
    2 repo stars
  90. ▌
    Configuring Tls 1 3 For Secure Communications · yanacuti1121 bundle
    TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R
    2 repo stars
  91. ▌
    Detecting Evasion Techniques In Endpoint Logs · yanacuti1121 bundle
    Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
    2 repo stars
  92. ▌
    Detecting T1055 Process Injection With Sysmon · yanacuti1121 bundle
    Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
    2 repo stars
  93. ▌
    Exploiting Ms17 010 Eternalblue Vulnerability · yanacuti1121 bundle
    MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it
    2 repo stars
  94. ▌
    Exploiting Template Injection Vulnerabilities · yanacuti1121 bundle
    Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.
    2 repo stars
  95. ▌
    Hardening Windows Endpoint With Cis Benchmark · yanacuti1121 bundle
    Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.
    2 repo stars
  96. ▌
    Hunting For Beaconing With Frequency Analysis · yanacuti1121 bundle
    Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints.
    2 repo stars
  97. ▌
    Hunting For Persistence Mechanisms In Windows · yanacuti1121 bundle
    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
    2 repo stars
  98. ▌
    Hunting For Persistence Via Wmi Subscriptions · yanacuti1121 bundle
    Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.
    2 repo stars
  99. ▌
    Implementing API Rate Limiting And Throttling · yanacuti1121 bundle
    Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers. Activates for requests involving rate limiting implementation, API throttling setup, request quota management, or API abuse prevention.
    2 repo stars
  100. ▌
    Implementing Browser Isolation For Zero Trust · yanacuti1121 bundle
    Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention controls within isolated sessions, and integration with Secure Web Gateway and ZTNA platforms. Based on Cloudflare Browser Isolation, Menlo Security, and Zscaler RBI approaches. Use when hardening web access against zero-day exploits, phishing, credential theft, and browser-based data exfiltration.
    2 repo stars