all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 7 of 18

  1. ▌
    Implementing Email Sandboxing With Proofpoint · yanacuti1121 bundle
    Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is an industry
    2 repo stars
  2. ▌
    Implementing Envelope Encryption With AWS Kms · yanacuti1121 bundle
    Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting
    2 repo stars
  3. ▌
    Implementing Gdpr Data Subject Access Request · yanacuti1121 bundle
    Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging. Covers ICO/EDPB guidance compliance, exemption handling, and scalable batch processing. Use when building or auditing DSAR response capabilities under GDPR/UK GDPR.
    2 repo stars
  4. ▌
    Implementing Honeytokens For Breach Detection · yanacuti1121 bundle
    Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection.
    2 repo stars
  5. ▌
    Implementing Just In Time Access Provisioning · yanacuti1121 bundle
    Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access only when needed. This skill covers JIT architecture design, approval workflo
    2 repo stars
  6. ▌
    Implementing Network Deception With Honeypots · yanacuti1121 bundle
    Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
    2 repo stars
  7. ▌
    Implementing Ransomware Kill Switch Detection · yanacuti1121 bundle
    Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection.
    2 repo stars
  8. ▌
    Implementing Security Monitoring With Datadog · yanacuti1121 bundle
    Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.
    2 repo stars
  9. ▌
    Implementing Zero Trust For Saas Applications · yanacuti1121 bundle
    Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.
    2 repo stars
  10. ▌
    Integrating Sast Into Github Actions Pipeline · yanacuti1121 bundle
    This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.
    2 repo stars
  11. ▌
    Performing Brand Monitoring For Impersonation · yanacuti1121 bundle
    Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization.
    2 repo stars
  12. ▌
    Performing Cloud Storage Forensic Acquisition · yanacuti1121 bundle
    Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.
    2 repo stars
  13. ▌
    Performing Cryptographic Audit Of Application · yanacuti1121 bundle
    A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
    2 repo stars
  14. ▌
    Performing Endpoint Vulnerability Remediation · yanacuti1121 bundle
    Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.
    2 repo stars
  15. ▌
    Performing Ip Reputation Analysis With Shodan · yanacuti1121 bundle
    Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.
    2 repo stars
  16. ▌
    Performing Network Traffic Analysis With Zeek · yanacuti1121 bundle
    Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
    2 repo stars
  17. ▌
    Performing Open Source Intelligence Gathering · yanacuti1121 bundle
    Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s
    2 repo stars
  18. ▌
    Performing Timeline Reconstruction With Plaso · yanacuti1121 bundle
    Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
    2 repo stars
  19. ▌
    Performing Vulnerability Scanning With Nessus · yanacuti1121 bundle
    Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability detection.
    2 repo stars
  20. ▌
    Reverse Engineering Android Malware With Jadx · yanacuti1121 bundle
    Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis.
    2 repo stars
  21. ▌
    Reverse Engineering Dotnet Malware With Dnspy · yanacuti1121 bundle
    Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis.
    2 repo stars
  22. ▌
    Testing API For Mass Assignment Vulnerability · yanacuti1121 bundle
    Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving mass assignment testing, parameter binding abuse, auto-binding vulnerability, or API over-posting.
    2 repo stars
  23. ▌
    Analyzing Malware Behavior With Cuckoo Sandbox · yanacuti1121 bundle
    Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.
    2 repo stars
  24. ▌
    Analyzing Prefetch Files For Execution History · yanacuti1121 bundle
    Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
    2 repo stars
  25. ▌
    Auditing Terraform Infrastructure For Security · yanacuti1121 bundle
    Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.
    2 repo stars
  26. ▌
    Building Automated Malware Submission Pipeline · yanacuti1121 bundle
    Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage.
    2 repo stars
  27. ▌
    Building Identity Governance Lifecycle Process · yanacuti1121 bundle
    Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests involving identity lifecycle management, JML processes, role-based access provisioning, or identity governance program design.
    2 repo stars
  28. ▌
    Building Red Team C2 Infrastructure With Havoc · yanacuti1121 bundle
    Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
    2 repo stars
  29. ▌
    Conducting Man In The Middle Attack Simulation · yanacuti1121 bundle
    Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities.
    2 repo stars
  30. ▌
    Conducting Social Engineering Penetration Test · yanacuti1121 bundle
    Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
    2 repo stars
  31. ▌
    Configuring Certificate Authority With Openssl · yanacuti1121 bundle
    A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
    2 repo stars
  32. ▌
    Configuring Windows Defender Advanced Settings · yanacuti1121 bundle
    Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint security.
    2 repo stars
  33. ▌
    Deploying Decoy Files For Ransomware Detection · yanacuti1121 bundle
    Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
    2 repo stars
  34. ▌
    Detecting Network Scanning With Ids Signatures · yanacuti1121 bundle
    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.
    2 repo stars
  35. ▌
    Detecting Qr Code Phishing With Email Security · yanacuti1121 bundle
    Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.
    2 repo stars
  36. ▌
    Detecting Suspicious OAUTH Application Consent · yanacuti1121 bundle
    Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
    2 repo stars
  37. ▌
    Exploiting Broken Function Level Authorization · yanacuti1121 bundle
    Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken Function Level Authorization. Activates for requests involving BFLA testing, admin endpoint bypass, function-level access control testing, or API privilege escalation.
    2 repo stars
  38. ▌
    Exploiting Smb Vulnerabilities With Metasploit · yanacuti1121 bundle
    Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.
    2 repo stars
  39. ▌
    Hunting For Lolbins Execution In Endpoint Logs · yanacuti1121 bundle
    Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.
    2 repo stars
  40. ▌
    Implementing API Threat Protection With Apigee · yanacuti1121 bundle
    Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.
    2 repo stars
  41. ▌
    Implementing AWS Macie For Data Classification · yanacuti1121 bundle
    Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
    2 repo stars
  42. ▌
    Implementing Cloud Security Posture Management · yanacuti1121 bundle
    Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command Center.
    2 repo stars
  43. ▌
    Implementing Dragos Platform For Ot Monitoring · yanacuti1121 bundle
    Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like VOLTZITE, GRAPHITE, and BAUXITE.
    2 repo stars
  44. ▌
    Implementing Honeypot For Ransomware Detection · yanacuti1121 bundle
    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage. Configures canary tokens embedded in strategic file locations that trigger alerts when ransomware attempts encryption, uses honeypot network shares that mimic high-value targets, and deploys Thinkst Canary appliances for comprehensive deception-based detection. Activates for requests involving ransomware honeypots, canary files, deception technology for ransomware, or early ransomware alerting.
    2 repo stars
  45. ▌
    Implementing Kubernetes Pod Security Standards · yanacuti1121 bundle
    Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
    2 repo stars
  46. ▌
    Implementing Microsegmentation With Guardicore · yanacuti1121 bundle
    Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.
    2 repo stars
  47. ▌
    Implementing Pod Security Admission Controller · yanacuti1121 bundle
    Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.
    2 repo stars
  48. ▌
    Implementing Proofpoint Email Security Gateway · yanacuti1121 bundle
    Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
    2 repo stars
  49. ▌
    Implementing Purdue Model Network Segmentation · yanacuti1121 bundle
    Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains.
    2 repo stars
  50. ▌
    Implementing Threat Modeling With Mitre Attack · yanacuti1121 bundle
    Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.
    2 repo stars
  51. ▌
    Implementing Vulnerability Sla Breach Alerting · yanacuti1121 bundle
    Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.
    2 repo stars
  52. ▌
    Performing Access Recertification With Saviynt · yanacuti1121 bundle
    Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.
    2 repo stars
  53. ▌
    Performing Asset Criticality Scoring For Vulns · yanacuti1121 bundle
    Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.
    2 repo stars
  54. ▌
    Performing AWS Privilege Escalation Assessment · yanacuti1121 bundle
    Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.
    2 repo stars
  55. ▌
    Performing Cloud Forensics With AWS Cloudtrail · yanacuti1121 bundle
    Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    2 repo stars
  56. ▌
    Performing Cloud Penetration Testing With Pacu · yanacuti1121 bundle
    Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation.
    2 repo stars
  57. ▌
    Performing Cve Prioritization With Kev Catalog · yanacuti1121 bundle
    Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.
    2 repo stars
  58. ▌
    Performing Kubernetes Etcd Security Assessment · yanacuti1121 bundle
    Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
    2 repo stars
  59. ▌
    Performing Post Quantum Cryptography Migration · yanacuti1121 bundle
    Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.
    2 repo stars
  60. ▌
    Performing Power Grid Cybersecurity Assessment · yanacuti1121 bundle
    This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and related attacks.
    2 repo stars
  61. ▌
    Performing Serverless Function Security Review · yanacuti1121 bundle
    Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
    2 repo stars
  62. ▌
    Performing Service Account Credential Rotation · yanacuti1121 bundle
    Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.
    2 repo stars
  63. ▌
    Performing Web Application Scanning With Nikto · yanacuti1121 bundle
    Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve
    2 repo stars
  64. ▌
    Performing Yara Rule Development For Detection · yanacuti1121 bundle
    Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.
    2 repo stars
  65. ▌
    Prioritizing Vulnerabilities With Cvss Scoring · yanacuti1121 bundle
    The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r
    2 repo stars
  66. ▌
    Testing For Xss Vulnerabilities With Burpsuite · yanacuti1121 bundle
    Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
    2 repo stars
  67. ▌
    Analyzing Sbom For Supply Chain Vulnerabilities · yanacuti1121 bundle
    Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation.
    2 repo stars
  68. ▌
    Analyzing Slack Space And File System Artifacts · yanacuti1121 bundle
    Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.
    2 repo stars
  69. ▌
    Building Identity Federation With Saml Azure Ad · yanacuti1121 bundle
    Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.
    2 repo stars
  70. ▌
    Configuring Windows Event Logging For Detection · yanacuti1121 bundle
    Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.
    2 repo stars
  71. ▌
    Detecting Malicious Scheduled Tasks With Sysmon · yanacuti1121 bundle
    Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.
    2 repo stars
  72. ▌
    Implementing API Security Testing With 42crunch · yanacuti1121 bundle
    Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
    2 repo stars
  73. ▌
    Implementing Attack Path Analysis With Xm Cyber · yanacuti1121 bundle
    Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.
    2 repo stars
  74. ▌
    Implementing Beyondcorp Zero Trust Access Model · yanacuti1121 bundle
    Implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.
    2 repo stars
  75. ▌
    Implementing Google Workspace Sso Configuration · yanacuti1121 bundle
    Configure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
    2 repo stars
  76. ▌
    Implementing Identity Governance With Sailpoint · yanacuti1121 bundle
    Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy
    2 repo stars
  77. ▌
    Implementing Soar Playbook With Palo Alto Xsoar · yanacuti1121 bundle
    Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.
    2 repo stars
  78. ▌
    Implementing Supply Chain Security With In Toto · yanacuti1121 bundle
    Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
    2 repo stars
  79. ▌
    Implementing Syslog Centralization With Rsyslog · yanacuti1121 bundle
    Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.
    2 repo stars
  80. ▌
    Implementing Zero Trust With Hashicorp Boundary · yanacuti1121 bundle
    Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
    2 repo stars
  81. ▌
    Performing Active Directory Bloodhound Analysis · yanacuti1121 bundle
    Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin.
    2 repo stars
  82. ▌
    Performing Active Directory Forest Trust Attack · yanacuti1121 bundle
    Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.
    2 repo stars
  83. ▌
    Performing Automated Malware Analysis With Cape · yanacuti1121 bundle
    Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
    2 repo stars
  84. ▌
    Performing GCP Security Assessment With Forseti · yanacuti1121 bundle
    Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations Benchmark.
    2 repo stars
  85. ▌
    Performing Hardware Security Module Integration · yanacuti1121 bundle
    Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.
    2 repo stars
  86. ▌
    Performing Network Traffic Analysis With Tshark · yanacuti1121 bundle
    Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
    2 repo stars
  87. ▌
    Performing Ssl Certificate Lifecycle Management · yanacuti1121 bundle
    SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading
    2 repo stars
  88. ▌
    Performing Subdomain Enumeration With Subfinder · yanacuti1121 bundle
    Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.
    2 repo stars
  89. ▌
    Performing Web Application Vulnerability Triage · yanacuti1121 bundle
    Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.
    2 repo stars
  90. ▌
    Performing Wifi Password Cracking With Aircrack · yanacuti1121 bundle
    Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.
    2 repo stars
  91. ▌
    Analyzing Threat Actor Ttps With Mitre Navigator · yanacuti1121 bundle
    Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis.
    2 repo stars
  92. ▌
    Book Working Effectively With Legacy Code Full · yanacuti1121
    Working with Legacy Code (Michael Feathers) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Working with Legacy Code principles or review code against Working with Legacy Code standards.
    2 repo stars
  93. ▌
    Book Working Effectively With Legacy Code Mini · yanacuti1121
    Working with Legacy Code (Michael Feathers) — Condensed rules — key principles distilled. Use when asked to apply Working with Legacy Code principles or review code against Working with Legacy Code standards.
    2 repo stars
  94. ▌
    Book Working Effectively With Legacy Code Nano · yanacuti1121
    Working with Legacy Code (Michael Feathers) — Minimal rules — essential one-liners only. Use when asked to apply Working with Legacy Code principles or review code against Working with Legacy Code standards.
    2 repo stars
  95. ▌
    Building Attack Pattern Library From Cti Reports · yanacuti1121 bundle
    Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.
    2 repo stars
  96. ▌
    Building C2 Infrastructure With Sliver Framework · yanacuti1121 bundle
    Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.
    2 repo stars
  97. ▌
    Building Malware Incident Communication Template · yanacuti1121 bundle
    Build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
    2 repo stars
  98. ▌
    Building Ransomware Playbook With Cisa Framework · yanacuti1121 bundle
    Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Activates for requests involving ransomware response planning, CISA compliance, incident response playbook creation, or ransomware preparedness assessment.
    2 repo stars
  99. ▌
    Building Vulnerability Dashboard With Defectdojo · yanacuti1121 bundle
    Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.
    2 repo stars
  100. ▌
    Building Vulnerability Exception Tracking System · yanacuti1121 bundle
    Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.
    2 repo stars