all publishers

yanacuti1121

@yanacuti1121 source repo

1,774 published skills · page 9 of 18

  1. ▌
    Implementing Code Signing For Artifacts · yanacuti1121 bundle
    This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.
    2 repo stars
  2. ▌
    Implementing Network Traffic Baselining · yanacuti1121 bundle
    Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling
    2 repo stars
  3. ▌
    Implementing Ransomware Backup Strategy · yanacuti1121 bundle
    Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.
    2 repo stars
  4. ▌
    Implementing Security Chaos Engineering · yanacuti1121 bundle
    Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.
    2 repo stars
  5. ▌
    Implementing Soar Playbook For Phishing · yanacuti1121 bundle
    Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
    2 repo stars
  6. ▌
    Implementing Zero Trust With Beyondcorp · yanacuti1121 bundle
    Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal applications.
    2 repo stars
  7. ▌
    Investigating Insider Threat Indicators · yanacuti1121 bundle
    Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
    2 repo stars
  8. ▌
    Performing Binary Exploitation Analysis · yanacuti1121 bundle
    Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.
    2 repo stars
  9. ▌
    Performing Disk Forensics Investigation · yanacuti1121 bundle
    Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation.
    2 repo stars
  10. ▌
    Performing GRAPHQL Introspection Attack · yanacuti1121 bundle
    Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive fields and mutations, tests for query depth and complexity limits, and exploits GraphQL-specific vulnerabilities including batching attacks, alias-based brute force, and nested query DoS. Activates for requests involving GraphQL security testing, introspection attack, GraphQL enumeration, or GraphQL API penetration testing.
    2 repo stars
  11. ▌
    Performing Insider Threat Investigation · yanacuti1121 bundle
    Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection.
    2 repo stars
  12. ▌
    Performing Nist Csf Maturity Assessment · yanacuti1121 bundle
    The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
    2 repo stars
  13. ▌
    Performing Privileged Account Discovery · yanacuti1121 bundle
    Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account
    2 repo stars
  14. ▌
    Performing Ransomware Tabletop Exercise · yanacuti1121 bundle
    Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
    2 repo stars
  15. ▌
    Performing Soc2 Type2 Audit Preparation · yanacuti1121 bundle
    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.
    2 repo stars
  16. ▌
    Reverse Engineering Malware With Ghidra · yanacuti1121 bundle
    Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals.
    2 repo stars
  17. ▌
    Securing Container Registry With Harbor · yanacuti1121 bundle
    Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio
    2 repo stars
  18. ▌
    Debugging And Error Recovery · yanacuti1121
    Guides systematic root-cause debugging. Use when tests fail, builds break, behavior doesn't match expectations, or you encounter any unexpected error. Use when you need a systematic approach to finding and fixing the root cause rather than guessing.
    2 repo stars
  19. ▌
    Content Trend Researcher · yanacuti1121
    Advanced content and topic research skill that analyzes trends across Google Analytics, Google Trends, Substack, Medium, Reddit, LinkedIn, X, blogs, podcasts, and YouTube to generate data-driven article outlines based on user intent analysis
    2 repo stars
  20. ▌
    Analyzing Apt Group With Mitre Navigator · yanacuti1121 bundle
    Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
    2 repo stars
  21. ▌
    Analyzing Linux Audit Logs For Intrusion · yanacuti1121 bundle
    Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.
    2 repo stars
  22. ▌
    Analyzing Network Flow Data With Netflow · yanacuti1121 bundle
    Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns.
    2 repo stars
  23. ▌
    Analyzing Network Traffic With Wireshark · yanacuti1121 bundle
    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
    2 repo stars
  24. ▌
    Analyzing Supply Chain Malware Artifacts · yanacuti1121 bundle
    Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.
    2 repo stars
  25. ▌
    Analyzing Windows Registry For Artifacts · yanacuti1121 bundle
    Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
    2 repo stars
  26. ▌
    Building Threat Actor Profile From Osint · yanacuti1121 bundle
    Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
    2 repo stars
  27. ▌
    Building Vulnerability Scanning Workflow · yanacuti1121 bundle
    Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.
    2 repo stars
  28. ▌
    Collecting Threat Intelligence With Misp · yanacuti1121 bundle
    MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
    2 repo stars
  29. ▌
    Conducting Post Incident Lessons Learned · yanacuti1121 bundle
    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
    2 repo stars
  30. ▌
    Configuring AWS Verified Access For Ztna · yanacuti1121 bundle
    Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.
    2 repo stars
  31. ▌
    Detecting Ransomware Encryption Behavior · yanacuti1121 bundle
    Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting.
    2 repo stars
  32. ▌
    Evaluating Threat Intelligence Platforms · yanacuti1121 bundle
    Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP procurement, migrating between TIP solutions, or assessing whether the current TIP meets program maturity requirements. Activates for requests involving ThreatConnect, MISP, OpenCTI, Anomali, EclecticIQ, or TIP procurement decisions.
    2 repo stars
  33. ▌
    Exploiting API Injection Vulnerabilities · yanacuti1121 bundle
    Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:2023 Security Misconfiguration and API7:2023 SSRF. Activates for requests involving API injection testing, SQLi in APIs, NoSQL injection, SSRF testing, or API input validation assessment.
    2 repo stars
  34. ▌
    Exploiting Bgp Hijacking Vulnerabilities · yanacuti1121 bundle
    Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.
    2 repo stars
  35. ▌
    Exploiting SQL Injection Vulnerabilities · yanacuti1121 bundle
    Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
    2 repo stars
  36. ▌
    Exploiting Type Juggling Vulnerabilities · yanacuti1121 bundle
    Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
    2 repo stars
  37. ▌
    Hunting For Data Exfiltration Indicators · yanacuti1121 bundle
    Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.
    2 repo stars
  38. ▌
    Hunting For Living Off The Land Binaries · yanacuti1121 bundle
    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
    2 repo stars
  39. ▌
    Hunting For Process Injection Techniques · yanacuti1121 bundle
    Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry
    2 repo stars
  40. ▌
    Hunting For Registry Run Key Persistence · yanacuti1121 bundle
    Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
    2 repo stars
  41. ▌
    Implementing AWS Security Hub Compliance · yanacuti1121 bundle
    Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
    2 repo stars
  42. ▌
    Implementing Devsecops Security Scanning · yanacuti1121 bundle
    Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration, or shift-left security implementation.
    2 repo stars
  43. ▌
    Implementing LLM Guardrails For Security · yanacuti1121 bundle
    Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang definitions, custom Python validators for PII detection and content policy enforcement, and the Guardrails AI framework for structured output validation. The guardrails system intercepts both user inputs (blocking injection attempts, stripping PII, enforcing topic boundaries) and model outputs (detecting hallucinations, filtering toxic content, validating JSON schema compliance). Activates for requests involving LLM output validation, AI content filtering, guardrail implementation, or LLM safety enforcement.
    2 repo stars
  44. ▌
    Implementing Log Forwarding With Fluentd · yanacuti1121 bundle
    Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure
    2 repo stars
  45. ▌
    Implementing Network Segmentation For Ot · yanacuti1121 bundle
    This skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentation strategy, migration from flat networks to segmented architectures without disrupting operations, configuring OT-aware firewalls with industrial protocol deep packet inspection, and validating segmentation effectiveness through traffic analysis.
    2 repo stars
  46. ▌
    Implementing Pci Dss Compliance Controls · yanacuti1121 bundle
    PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements
    2 repo stars
  47. ▌
    Implementing Scim Provisioning With Okta · yanacuti1121 bundle
    Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.
    2 repo stars
  48. ▌
    Implementing Stix Taxii Feed Integration · yanacuti1121 bundle
    STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.
    2 repo stars
  49. ▌
    Implementing Taxii Server With Opentaxii · yanacuti1121 bundle
    Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.
    2 repo stars
  50. ▌
    Implementing Zero Trust Dns With Nextdns · yanacuti1121 bundle
    Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
    2 repo stars
  51. ▌
    Openai Superpowers Using Git Worktrees · yanacuti1121
    Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback
    2 repo stars
  52. ▌
    Performing Bluetooth Security Assessment · yanacuti1121 bundle
    Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
    2 repo stars
  53. ▌
    Performing Cloud Forensics Investigation · yanacuti1121 bundle
    Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services.
    2 repo stars
  54. ▌
    Performing Dynamic Analysis With Any Run · yanacuti1121 bundle
    Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage.
    2 repo stars
  55. ▌
    Performing Initial Access With Evilginx3 · yanacuti1121 bundle
    Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.
    2 repo stars
  56. ▌
    Performing Lateral Movement With Wmiexec · yanacuti1121 bundle
    Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.
    2 repo stars
  57. ▌
    Performing Log Source Onboarding In Siem · yanacuti1121 bundle
    Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility.
    2 repo stars
  58. ▌
    Performing Physical Intrusion Assessment · yanacuti1121 bundle
    Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
    2 repo stars
  59. ▌
    Performing Privilege Escalation On Linux · yanacuti1121 bundle
    Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised system. Red teams exploit misconfigurations, vulnerable services, kernel exploits, and w
    2 repo stars
  60. ▌
    Performing Scada Hmi Security Assessment · yanacuti1121 bundle
    Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.
    2 repo stars
  61. ▌
    Securing Remote Access To Ot Environment · yanacuti1121 bundle
    This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server architecture, multi-factor authentication, session recording, privileged access management, vendor remote access controls, and compliance with IEC 62443 and NERC CIP-005 remote access requirements.
    2 repo stars
  62. ▌
    Validating Backup Integrity For Recovery · yanacuti1121 bundle
    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    2 repo stars
  63. ▌
    Browser Testing With Devtools · yanacuti1121
    Tests in real browsers via Chrome DevTools MCP. Use when building or debugging anything that runs in a browser. Use when you need to inspect the DOM, capture console errors, analyze network requests, profile performance, or verify visual output with real runtime data. Requires the chrome-devtools MCP server to be configured.
    2 repo stars
  64. ▌
    Analyzing Azure Activity Logs For Threats · yanacuti1121 bundle
    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
    2 repo stars
  65. ▌
    Analyzing IOS App Security With Objection · yanacuti1121 bundle
    Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
    2 repo stars
  66. ▌
    Analyzing Outlook Pst For Email Forensics · yanacuti1121 bundle
    Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
    2 repo stars
  67. ▌
    Analyzing Persistence Mechanisms In Linux · yanacuti1121 bundle
    Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring
    2 repo stars
  68. ▌
    Analyzing Powershell Script Block Logging · yanacuti1121 bundle
    Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression abuse, download cradles, and AMSI bypass attempts.
    2 repo stars
  69. ▌
    Analyzing Windows Lnk Files For Artifacts · yanacuti1121 bundle
    Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
    2 repo stars
  70. ▌
    Building Threat Hunt Hypothesis Framework · yanacuti1121 bundle
    Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.
    2 repo stars
  71. ▌
    Conducting Domain Persistence With Dcsync · yanacuti1121 bundle
    Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.
    2 repo stars
  72. ▌
    Conducting Full Scope Red Team Engagement · yanacuti1121 bundle
    Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.
    2 repo stars
  73. ▌
    Configuring Active Directory Tiered Model · yanacuti1121 bundle
    Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative f
    2 repo stars
  74. ▌
    Deploying Osquery For Endpoint Monitoring · yanacuti1121 bundle
    Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
    2 repo stars
  75. ▌
    Detecting Exfiltration Over Dns With Zeek · yanacuti1121 bundle
    Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
    2 repo stars
  76. ▌
    Detecting Living Off The Land With Lolbas · yanacuti1121 bundle
    Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis
    2 repo stars
  77. ▌
    Detecting Suspicious Powershell Execution · yanacuti1121 bundle
    Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
    2 repo stars
  78. ▌
    Eradicating Malware From Infected Systems · yanacuti1121 bundle
    Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
    2 repo stars
  79. ▌
    Exploiting Excessive Data Exposure In API · yanacuti1121 bundle
    Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving API data leakage testing, excessive data exposure, response filtering bypass, or API over-fetching.
    2 repo stars
  80. ▌
    Exploiting JWT Algorithm Confusion Attack · yanacuti1121 bundle
    Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to supply attacker-controlled keys. Activates for requests involving JWT algorithm confusion, alg none attack, key confusion attack, or JWT signature bypass.
    2 repo stars
  81. ▌
    Exploiting Race Condition Vulnerabilities · yanacuti1121 bundle
    Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
    2 repo stars
  82. ▌
    Hunting For Command And Control Beaconing · yanacuti1121 bundle
    Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
    2 repo stars
  83. ▌
    Hunting For Unusual Service Installations · yanacuti1121 bundle
    Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
    2 repo stars
  84. ▌
    Implementing Anti Ransomware Group Policy · yanacuti1121 bundle
    Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates for requests involving Windows GPO hardening against ransomware, AppLocker configuration, Controlled Folder Access setup, or endpoint protection via Group Policy.
    2 repo stars
  85. ▌
    Implementing Immutable Backup With Restic · yanacuti1121 bundle
    Implements immutable backup strategy using restic with S3-compatible storage and object lock for ransomware-resistant data protection. Automates backup creation, integrity verification via restic check --read-data, snapshot retention policy enforcement, and restore testing. Integrates with AWS S3 Object Lock, MinIO, and Backblaze B2 for WORM (Write Once Read Many) storage that prevents backup deletion or encryption by ransomware actors.
    2 repo stars
  86. ▌
    Implementing JWT Signing And Verification · yanacuti1121 bundle
    JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization in web applications. This skill covers implementing secure JWT signing with HMAC-SHA256
    2 repo stars
  87. ▌
    Implementing Mtls For Zero Trust Services · yanacuti1121 bundle
    Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains, checks expiration, and audits mTLS deployment status. Use when implementing zero-trust service-to-service authentication.
    2 repo stars
  88. ▌
    Implementing Nerc Cip Compliance Controls · yanacuti1121 bundle
    This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset requirements.
    2 repo stars
  89. ▌
    Implementing Siem Use Cases For Detection · yanacuti1121 bundle
    Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
    2 repo stars
  90. ▌
    Implementing Soar Automation With Phantom · yanacuti1121 bundle
    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.
    2 repo stars
  91. ▌
    Investigating Ransomware Attack Artifacts · yanacuti1121 bundle
    Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
    2 repo stars
  92. ▌
    Improve Codebase Architecture · yanacuti1121 bundle
    Scan a codebase for deepening opportunities, present them as a visual HTML report, then grill through whichever one you pick.
    2 repo stars
  93. ▌
    Monitoring Scada Modbus Traffic Anomalies · yanacuti1121 bundle
    Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic analysis, SCADA network monitoring, ICS anomaly detection, PLC security monitoring, or OT network threat detection.
    2 repo stars
  94. ▌
    Openai Codex Security Finding Discovery · yanacuti1121
    Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
    2 repo stars
  95. ▌
    Openai Plugin Eval Metric Pack Designer · yanacuti1121
    Design custom metric packs for plugin-eval so teams can add local evaluation rubrics that emit schema-compatible checks and metrics. Use when the user wants their own evaluation criteria or visualizations.
    2 repo stars
  96. ▌
    Performing Alert Triage With Elastic Siem · yanacuti1121 bundle
    Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.
    2 repo stars
  97. ▌
    Performing Arp Spoofing Attack Simulation · yanacuti1121 bundle
    Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
    2 repo stars
  98. ▌
    Performing Content Security Policy Bypass · yanacuti1121 bundle
    Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.
    2 repo stars
  99. ▌
    Performing Credential Access With Lazagne · yanacuti1121 bundle
    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
    2 repo stars
  100. ▌
    Performing Indicator Lifecycle Management · yanacuti1121 bundle
    Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
    2 repo stars