all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 8 of 18

  1. ▌
    Configuring Identity Aware Proxy With Google Iap · yanacuti1121 bundle
    Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
    2 repo stars
  2. ▌
    Configuring Multi Factor Authentication With Duo · yanacuti1121 bundle
    Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust
    2 repo stars
  3. ▌
    Detecting Golden Ticket Attacks In Kerberos Logs · yanacuti1121 bundle
    Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
    2 repo stars
  4. ▌
    Exploiting Zerologon Vulnerability Cve 2020 1472 · yanacuti1121 bundle
    Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
    2 repo stars
  5. ▌
    Implementing Canary Tokens For Network Intrusion · yanacuti1121 bundle
    Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments. Use when building deception-based network intrusion detection with Canarytokens.org and Thinkst Canary platforms.
    2 repo stars
  6. ▌
    Implementing End To End Encryption For Messaging · yanacuti1121 bundle
    End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version
    2 repo stars
  7. ▌
    Implementing File Integrity Monitoring With Aide · yanacuti1121 bundle
    Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
    2 repo stars
  8. ▌
    Implementing GCP Organization Policy Constraints · yanacuti1121 bundle
    Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.
    2 repo stars
  9. ▌
    Implementing Mimecast Targeted Attack Protection · yanacuti1121 bundle
    Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
    2 repo stars
  10. ▌
    Implementing Runtime Application Self Protection · yanacuti1121 bundle
    Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.
    2 repo stars
  11. ▌
    Openai Superpowers Dispatching Parallel Agents · yanacuti1121
    Use when facing 2+ independent tasks that can be worked on without shared state or sequential dependencies
    2 repo stars
  12. ▌
    Openai Superpowers Subagent Driven Development · yanacuti1121
    Use when executing implementation plans with independent tasks in the current session
    2 repo stars
  13. ▌
    Performing Cloud Incident Containment Procedures · yanacuti1121 bundle
    Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
    2 repo stars
  14. ▌
    Performing Entitlement Review With Sailpoint Iiq · yanacuti1121 bundle
    Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates for requests involving access reviews, entitlement certifications, SailPoint IIQ governance, or periodic user access recertification.
    2 repo stars
  15. ▌
    Performing Mobile App Certificate Pinning Bypass · yanacuti1121 bundle
    Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.
    2 repo stars
  16. ▌
    Performing Paste Site Monitoring For Credentials · yanacuti1121 bundle
    Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.
    2 repo stars
  17. ▌
    Performing Threat Emulation With Atomic Red Team · yanacuti1121 bundle
    Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises.
    2 repo stars
  18. ▌
    Performing Threat Intelligence Sharing With Misp · yanacuti1121 bundle
    Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
    2 repo stars
  19. ▌
    Analyzing Ethereum Smart Contract Vulnerabilities · yanacuti1121 bundle
    Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
    2 repo stars
  20. ▌
    Book Designing Data Intensive Applications Full · yanacuti1121
    DDIA (Martin Kleppmann) — Full rules — comprehensive mandatory coding standards. Use when asked to apply DDIA principles or review code against DDIA standards.
    2 repo stars
  21. ▌
    Book Designing Data Intensive Applications Mini · yanacuti1121
    DDIA (Martin Kleppmann) — Condensed rules — key principles distilled. Use when asked to apply DDIA principles or review code against DDIA standards.
    2 repo stars
  22. ▌
    Book Designing Data Intensive Applications Nano · yanacuti1121
    DDIA (Martin Kleppmann) — Minimal rules — essential one-liners only. Use when asked to apply DDIA principles or review code against DDIA standards.
    2 repo stars
  23. ▌
    Building Adversary Infrastructure Tracking System · yanacuti1121 bundle
    Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.
    2 repo stars
  24. ▌
    Building Threat Intelligence Enrichment In Splunk · yanacuti1121 bundle
    Build automated threat intelligence enrichment pipelines in Splunk Enterprise Security using lookup tables, modular inputs, and the Threat Intelligence Framework.
    2 repo stars
  25. ▌
    Detecting Anomalies In Industrial Control Systems · yanacuti1121 bundle
    This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians.
    2 repo stars
  26. ▌
    Detecting AWS Credential Exposure With Trufflehog · yanacuti1121 bundle
    Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
    2 repo stars
  27. ▌
    Detecting Azure Storage Account Misconfigurations · yanacuti1121 bundle
    Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.
    2 repo stars
  28. ▌
    Detecting Privilege Escalation In Kubernetes Pods · yanacuti1121 bundle
    Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
    2 repo stars
  29. ▌
    Detecting T1548 Abuse Elevation Control Mechanism · yanacuti1121 bundle
    Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.
    2 repo stars
  30. ▌
    Implementing Aqua Security For Container Scanning · yanacuti1121 bundle
    Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
    2 repo stars
  31. ▌
    Implementing Conditional Access Policies Azure Ad · yanacuti1121 bundle
    Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l
    2 repo stars
  32. ▌
    Implementing Google Workspace Phishing Protection · yanacuti1121 bundle
    Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.
    2 repo stars
  33. ▌
    Implementing Hardware Security Key Authentication · yanacuti1121 bundle
    Implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Activates for requests involving FIDO2 implementation, WebAuthn registration, hardware security key enrollment, YubiKey integration, or passkey migration from password-based authentication.
    2 repo stars
  34. ▌
    Implementing Identity Verification For Zero Trust · yanacuti1121 bundle
    Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.
    2 repo stars
  35. ▌
    Detecting Bluetooth Low Energy Attacks · yanacuti1121 bundle
    Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
    2 repo stars
  36. ▌
    Detecting Cloud Threats With Guardduty · yanacuti1121 bundle
    This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda.
    2 repo stars
  37. ▌
    Detecting Command And Control Over Dns · yanacuti1121 bundle
    Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development. Activates for requests involving DNS-based C2 detection, DNS tunnel identification, suspicious DNS traffic investigation, or DGA domain classification.
    2 repo stars
  38. ▌
    Detecting Lateral Movement With Splunk · yanacuti1121 bundle
    Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
    2 repo stars
  39. ▌
    Detecting Process Injection Techniques · yanacuti1121 bundle
    Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.
    2 repo stars
  40. ▌
    Executing Phishing Simulation Campaign · yanacuti1121 bundle
    Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests involving phishing simulation, social engineering assessment, email security testing, or security awareness measurement.
    2 repo stars
  41. ▌
    Executing Red Team Engagement Planning · yanacuti1121 bundle
    Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.
    2 repo stars
  42. ▌
    Exploiting Kerberoasting With Impacket · yanacuti1121 bundle
    Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
    2 repo stars
  43. ▌
    Exploiting Server Side Request Forgery · yanacuti1121 bundle
    Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
    2 repo stars
  44. ▌
    Extracting Config From Agent Tesla Rat · yanacuti1121 bundle
    Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.
    2 repo stars
  45. ▌
    Generating Threat Intelligence Reports · yanacuti1121 bundle
    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.
    2 repo stars
  46. ▌
    Hunting For Domain Fronting C2 Traffic · yanacuti1121 bundle
    Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection
    2 repo stars
  47. ▌
    Hunting For Scheduled Task Persistence · yanacuti1121 bundle
    Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
    2 repo stars
  48. ▌
    Hunting For Startup Folder Persistence · yanacuti1121 bundle
    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
    2 repo stars
  49. ▌
    Hunting For Suspicious Scheduled Tasks · yanacuti1121 bundle
    Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.
    2 repo stars
  50. ▌
    Hunting For T1098 Account Manipulation · yanacuti1121 bundle
    Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
    2 repo stars
  51. ▌
    Implementing API Key Security Controls · yanacuti1121 bundle
    Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for storage, enforces per-key scoping and rate limiting, monitors for leaked keys in public repositories, and builds key rotation workflows. Activates for requests involving API key management, API key security, key rotation policy, or API credential protection.
    2 repo stars
  52. ▌
    Implementing Attack Surface Management · yanacuti1121 bundle
    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments.
    2 repo stars
  53. ▌
    Implementing Cloud Workload Protection · yanacuti1121 bundle
    Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.
    2 repo stars
  54. ▌
    Implementing Patch Management Workflow · yanacuti1121 bundle
    Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc
    2 repo stars
  55. ▌
    Implementing Secrets Scanning In CI CD · yanacuti1121 bundle
    Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
    2 repo stars
  56. ▌
    Implementing Usb Device Control Policy · yanacuti1121 bundle
    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
    2 repo stars
  57. ▌
    Implementing Zero Trust Network Access · yanacuti1121 bundle
    Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP.
    2 repo stars
  58. ▌
    Git Guardrails Claude Code · yanacuti1121 bundle
    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.
    2 repo stars
  59. ▌
    Openai Superpowers Using Superpowers · yanacuti1121
    Use when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions
    2 repo stars
  60. ▌
    Performing AI Driven Osint Correlation · yanacuti1121 bundle
    Use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring and link analysis.
    2 repo stars
  61. ▌
    Performing API Inventory And Discovery · yanacuti1121 bundle
    Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Activates for requests involving API discovery, shadow API detection, API inventory audit, or attack surface mapping.
    2 repo stars
  62. ▌
    Performing Directory Traversal Testing · yanacuti1121 bundle
    Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
    2 repo stars
  63. ▌
    Performing GRAPHQL Security Assessment · yanacuti1121 bundle
    Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.
    2 repo stars
  64. ▌
    Performing IOS App Security Assessment · yanacuti1121 bundle
    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls. Activates for requests involving iOS app pentesting, Frida-based iOS instrumentation, mobile app SSL pinning bypass, or IPA reverse engineering.
    2 repo stars
  65. ▌
    Performing Ssl Tls Security Assessment · yanacuti1121 bundle
    Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
    2 repo stars
  66. ▌
    Recovering Deleted Files With Photorec · yanacuti1121 bundle
    Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.
    2 repo stars
  67. ▌
    Remediating S3 Bucket Misconfiguration · yanacuti1121 bundle
    This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.
    2 repo stars
  68. ▌
    Reverse Engineering IOS App With Frida · yanacuti1121 bundle
    Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
    2 repo stars
  69. ▌
    Scanning Containers With Trivy In Cicd · yanacuti1121 bundle
    This skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images.
    2 repo stars
  70. ▌
    Securing Azure With Microsoft Defender · yanacuti1121 bundle
    This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and databases, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal for centralized threat management.
    2 repo stars
  71. ▌
    Testing API Security With Owasp Top 10 · yanacuti1121 bundle
    Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.
    2 repo stars
  72. ▌
    Testing Ransomware Recovery Procedures · yanacuti1121 bundle
    Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.
    2 repo stars
  73. ▌
    Acquiring Disk Image With Dd And Dcfldd · yanacuti1121 bundle
    Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
    2 repo stars
  74. ▌
    Git Workflow And Versioning · yanacuti1121
    Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, or when you need to organize work across multiple parallel streams.
    2 repo stars
  75. ▌
    Planning And Task Breakdown · yanacuti1121
    Breaks work into ordered tasks. Use when you have a spec or clear requirements and need to break work into implementable tasks. Use when a task feels too large to start, when you need to estimate scope, or when parallel work is possible.
    2 repo stars
  76. ▌
    Analyzing Campaign Attribution Evidence · yanacuti1121 bundle
    Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr
    2 repo stars
  77. ▌
    Analyzing Cloud Storage Access Patterns · yanacuti1121 bundle
    Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly detection.
    2 repo stars
  78. ▌
    Analyzing Mft For Deleted File Recovery · yanacuti1121 bundle
    Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.
    2 repo stars
  79. ▌
    Analyzing Network Traffic For Incidents · yanacuti1121 bundle
    Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.
    2 repo stars
  80. ▌
    Analyzing Ransomware Network Indicators · yanacuti1121 bundle
    Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis
    2 repo stars
  81. ▌
    Analyzing Usb Device Connection History · yanacuti1121 bundle
    Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
    2 repo stars
  82. ▌
    Analyzing Web Server Logs For Intrusion · yanacuti1121 bundle
    Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.
    2 repo stars
  83. ▌
    Building Detection Rule With Splunk Spl · yanacuti1121 bundle
    Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
    2 repo stars
  84. ▌
    Building Patch Tuesday Response Process · yanacuti1121 bundle
    Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
    2 repo stars
  85. ▌
    Detecting Azure Service Principal Abuse · yanacuti1121 bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    2 repo stars
  86. ▌
    Detecting Compromised Cloud Credentials · yanacuti1121 bundle
    Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    2 repo stars
  87. ▌
    Detecting Credential Dumping Techniques · yanacuti1121 bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
    2 repo stars
  88. ▌
    Detecting Email Forwarding Rules Attack · yanacuti1121 bundle
    Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
    2 repo stars
  89. ▌
    Detecting Fileless Attacks On Endpoints · yanacuti1121 bundle
    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
    2 repo stars
  90. ▌
    Detecting Privilege Escalation Attempts · yanacuti1121 bundle
    Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
    2 repo stars
  91. ▌
    Detecting S3 Data Exfiltration Attempts · yanacuti1121 bundle
    Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
    2 repo stars
  92. ▌
    Detecting Serverless Function Injection · yanacuti1121 bundle
    Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function modification. The analyst combines static analysis of function code, CloudTrail event correlation, runtime behavior monitoring, and IAM policy auditing to identify injection vectors across the expanded serverless attack surface including API Gateway, S3, SQS, DynamoDB Streams, and CloudWatch event triggers. Activates for requests involving Lambda security assessment, serverless injection detection, function event poisoning analysis, or serverless privilege escalation investigation.
    2 repo stars
  93. ▌
    Detecting Supply Chain Attacks In CI CD · yanacuti1121 bundle
    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
    2 repo stars
  94. ▌
    Exploiting Constrained Delegation Abuse · yanacuti1121 bundle
    Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
    2 repo stars
  95. ▌
    Exploiting Mass Assignment In REST Apis · yanacuti1121 bundle
    Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
    2 repo stars
  96. ▌
    Extracting Credentials From Memory Dump · yanacuti1121 bundle
    Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.
    2 repo stars
  97. ▌
    Extracting Memory Artifacts With Rekall · yanacuti1121 bundle
    Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis.
    2 repo stars
  98. ▌
    Extracting Windows Event Logs Artifacts · yanacuti1121 bundle
    Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
    2 repo stars
  99. ▌
    Hunting For Unusual Network Connections · yanacuti1121 bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    2 repo stars
  100. ▌
    Implementing AWS Nitro Enclave Security · yanacuti1121 bundle
    Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activates for requests involving Nitro Enclave setup, enclave attestation validation, confidential computing on AWS, or KMS enclave policy configuration.
    2 repo stars