security/
946 total · showing first 300springboot-verification
Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
songwriting-and-ai-music
Songwriting craft and Suno AI music prompts.
web-pentest
A phased pentesting workflow for running web applications. Adapted from
Command Development
This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter"…
cso
Chief Security Officer mode. (gstack)
security-and-hardening
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted…
security-research
security-research
security-audit
Security scanning and vulnerability detection.
agent-test-long-runner
Agent skill for test-long-runner - invoke with $agent-test-long-runner
harness-genome
7-section repo readiness report from `metaharness genome <path>`. Returns repo_type / agent_topology / risk_score / mcp_surface / test_confidence / publish_readiness. Pure-read…
harness-threat-model
Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings.…
V3 Security Overhaul
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3…
security-audit
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
multi-agent-task-orchestrator
Route tasks to specialized AI agents with anti-duplication, quality gates, and 30-minute heartbeat monitoring
parallel-agents
Multi-agent orchestration patterns. Use when multiple independent tasks can run with different domain expertise or when comprehensive analysis requires multiple perspectives.
sast-configuration
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
supply-chain-risk-auditor
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security…
variant-analysis
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security…
laravel-security-audit
Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
payment-integration
Integrate Stripe, PayPal, and payment processors. Handles checkout flows, subscriptions, webhooks, and PCI compliance. Use PROACTIVELY when implementing payments, billing, or…
red-team-tactics
Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.
vibers-code-review
Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.
web-security-testing
Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
auth-implementation-patterns
Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.
anti-reversing-techniques
AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.
api-patterns
API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.
bdistill-behavioral-xray
X-ray any AI model's behavioral patterns — refusal boundaries, hallucination tendencies, reasoning style, formatting defaults. No API key needed.
codebase-cleanup-deps-audit
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known…
dependency-management-deps-audit
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known…
find-bugs
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current…
security-scanning-security-dependencies
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to…
solidity-security
Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.
anti-reversing-techniques
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when…
sast-configuration
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing…
solidity-security
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing…
attack-tree-construction
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
pci-compliance
Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or…
agent-owasp-compliance
Evaluate AI agent systems against the OWASP Agentic Security Initiative (ASI) Top 10 — the industry standard for agent security posture.
audit-integrity
Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards…
dependabot
Dependabot is GitHub's built-in dependency management tool with three core capabilities:
git-flow-branch-creator
Intelligent Git Flow branch creator that analyzes git status/diff and creates appropriate branches following the nvie Git Flow branching model.
github-actions-hardening
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters…
mcp-implementation-security-review
Check MCP protocol version 2025-03-26 or later (current: 2025-11-25). Flag older versions as a finding but continue the review.
security-review
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities…
sql-code-review
Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server…
threat-model-analyst
Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. Supports two modes: (1) Single analysis — full STRIDE-A threat model of a…
command-development
This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter"…
security-review
Security-focused code review checklist for identifying vulnerabilities
building-automated-malware-submission-pipeline
'Builds an automated malware submission and analysis pipeline that collects
detecting-anomalous-authentication-patterns
'Detects anomalous authentication patterns using UEBA analytics, statistical
detecting-attacks-on-scada-systems
'This skill covers detecting cyber attacks targeting Supervisory Control
detecting-command-and-control-over-dns
'Detects command-and-control (C2) communications tunneled through DNS
detecting-living-off-the-land-attacks
'Detect abuse of legitimate Windows binaries (LOLBins) used for living
detecting-modbus-command-injection-attacks
'Detect command injection attacks against Modbus TCP/RTU protocol in
detecting-ntlm-relay-with-event-correlation
'Detect NTLM relay attacks through Windows Security Event correlation
detecting-serverless-function-injection
'Detects and prevents code injection attacks targeting serverless functions
detecting-stuxnet-style-attacks
'This skill covers detecting sophisticated cyber-physical attacks that
exploiting-api-injection-vulnerabilities
'Tests APIs for injection vulnerabilities including SQL injection, NoSQL
exploiting-jwt-algorithm-confusion-attack
'Exploits JWT algorithm confusion vulnerabilities where the server''s
hunting-for-dcom-lateral-movement
'Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application,
implementing-api-rate-limiting-and-throttling
'Implements API rate limiting and throttling controls using token bucket,
implementing-hardware-security-key-authentication
'Implements FIDO2/WebAuthn hardware security key authentication including
implementing-hashicorp-vault-dynamic-secrets
'Implements HashiCorp Vault dynamic secrets engines for database credentials,
implementing-iec-62443-security-zones
'This skill covers designing and implementing security zones and conduits
implementing-network-segmentation-for-ot
'This skill covers implementing network segmentation in Operational Technology
monitoring-scada-modbus-traffic-anomalies
'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous
performing-api-rate-limiting-bypass
'Tests API rate limiting implementations for bypass vulnerabilities by
performing-graphql-introspection-attack
'Performs GraphQL introspection attacks to extract the full API schema
performing-malware-persistence-investigation
Systematically investigate all persistence mechanisms on Windows and
performing-ot-network-security-assessment
'This skill covers conducting comprehensive security assessments of Operational
performing-plc-firmware-security-analysis
'This skill covers analyzing Programmable Logic Controller (PLC) firmware
performing-purple-team-atomic-testing
'Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs
testing-websocket-api-security
'Tests WebSocket API implementations for security vulnerabilities including
abusing-dpapi-for-credential-access
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
abusing-shadow-credentials-for-privesc
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy…
achieving-cmmc-level-2-compliance
When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.
acquiring-disk-image-with-dd-and-dcfldd
Create forensically sound bit-for-bit disk images using dd and dcfldd
analyzing-active-directory-acl-abuse
Detect dangerous ACL misconfigurations in Active Directory using ldap3
analyzing-android-malware-with-apktool
Perform static analysis of Android APK malware samples using apktool
analyzing-api-gateway-access-logs
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
analyzing-apt-group-with-mitre-navigator
Analyze advanced persistent threat (APT) group techniques using MITRE
analyzing-azure-activity-logs-for-threats
'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
analyzing-bootkit-and-rootkit-samples
'Analyzes bootkit and advanced rootkit malware that infects the Master
analyzing-browser-forensics-with-hindsight
Analyze Chromium-based browser artifacts using Hindsight to extract browsing
analyzing-campaign-attribution-evidence
Campaign attribution analysis involves systematically evaluating evidence
analyzing-certificate-transparency-for-phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to
analyzing-cloud-storage-access-patterns
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage
analyzing-cobalt-strike-beacon-configuration
Extract and analyze Cobalt Strike beacon configuration from PE files
analyzing-cobaltstrike-malleable-c2-profiles
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike
analyzing-command-and-control-communication
'Analyzes malware command-and-control (C2) communication protocols to
analyzing-cyber-kill-chain
'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
analyzing-disk-image-with-autopsy
Perform comprehensive forensic analysis of disk images using Autopsy
analyzing-dns-logs-for-exfiltration
'Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
analyzing-docker-container-forensics
Investigate compromised Docker containers by analyzing images, layers,
analyzing-email-headers-for-phishing-investigation
Parse and analyze email headers to trace the origin of phishing emails,
analyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware using Ghidra with specialized scripts
analyzing-heap-spray-exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3
analyzing-indicators-of-compromise
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
analyzing-ios-app-security-with-objection
Use this skill when:
analyzing-kubernetes-audit-logs
'Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,
analyzing-linux-audit-logs-for-intrusion
'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
analyzing-linux-elf-malware
'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
analyzing-linux-kernel-rootkits
Detect kernel-level rootkits in Linux memory dumps using Volatility3
analyzing-linux-system-artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell
analyzing-lnk-file-and-jump-list-artifacts
Analyze Windows LNK shortcut files and Jump List artifacts to establish
analyzing-macro-malware-in-office-documents
'Analyzes malicious VBA macros embedded in Microsoft Office documents
analyzing-malicious-pdf-with-peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid,
analyzing-malicious-url-with-urlscan
URLScan.io is a free service for scanning and analyzing suspicious URLs.
analyzing-malware-behavior-with-cuckoo-sandbox
'Executes malware samples in Cuckoo Sandbox to observe runtime behavior
analyzing-malware-family-relationships-with-malpedia
Use the Malpedia platform and API to research malware family relationships,
analyzing-malware-persistence-with-autoruns
Use Sysinternals Autoruns to systematically identify and analyze malware
analyzing-malware-sandbox-evasion-techniques
Detect sandbox evasion techniques in malware samples by analyzing timing
analyzing-memory-dumps-with-volatility
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
analyzing-memory-forensics-with-lime-and-volatility
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
analyzing-mft-for-deleted-file-recovery
Analyze the NTFS Master File Table ($MFT) to recover metadata and content
analyzing-network-covert-channels-in-malware
Detect and analyze covert communication channels used by malware including
analyzing-network-flow-data-with-netflow
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
analyzing-network-packets-with-scapy
Craft, send, sniff, and dissect network packets using Scapy for protocol
analyzing-network-traffic-for-incidents
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
analyzing-network-traffic-of-malware
'Analyzes network traffic generated by malware during sandbox execution
analyzing-network-traffic-with-wireshark
'Captures and analyzes network packet data using Wireshark and tshark
analyzing-office365-audit-logs-for-compromise
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
analyzing-outlook-pst-for-email-forensics
Analyze Microsoft Outlook PST and OST files for email forensic evidence
analyzing-packed-malware-with-upx-unpacker
'Identifies and unpacks UPX-packed and other packed malware samples to
analyzing-pdf-malware-with-pdfid
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
analyzing-persistence-mechanisms-in-linux
Detect and analyze Linux persistence mechanisms including crontab entries,
analyzing-powershell-empire-artifacts
Detect PowerShell Empire framework artifacts in Windows event logs by
analyzing-powershell-script-block-logging
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
analyzing-prefetch-files-for-execution-history
Parse Windows Prefetch files to determine program execution history including
analyzing-ransomware-encryption-mechanisms
'Analyzes encryption algorithms, key management, and file encryption
analyzing-ransomware-leak-site-intelligence
Monitor and analyze ransomware group data leak sites (DLS) to track victim
analyzing-ransomware-network-indicators
Identify ransomware network indicators including C2 beaconing patterns,
analyzing-ransomware-payment-wallets
'Traces ransomware cryptocurrency payment flows using blockchain analysis
analyzing-sbom-for-supply-chain-vulnerabilities
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
analyzing-security-logs-with-splunk
'Leverages Splunk Enterprise Security and SPL (Search Processing Language)
analyzing-slack-space-and-file-system-artifacts
Examine file system slack space, MFT entries, USN journal, and alternate
analyzing-supply-chain-malware-artifacts
Investigate supply chain attack artifacts including trojanized software
analyzing-threat-actor-ttps-with-mitre-attack
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,
analyzing-threat-actor-ttps-with-mitre-navigator
'Map advanced persistent threat (APT) group tactics, techniques, and
analyzing-threat-intelligence-feeds
'Analyzes structured and unstructured threat intelligence feeds to extract
analyzing-threat-landscape-with-misp
Analyze the threat landscape using MISP (Malware Information Sharing
analyzing-tls-certificate-transparency-logs
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
analyzing-typosquatting-domains-with-dnstwist
Detect typosquatting, homograph phishing, and brand impersonation domains
analyzing-uefi-bootkit-persistence
'Analyzes UEFI bootkit persistence mechanisms including firmware implants
analyzing-usb-device-connection-history
Investigate USB device connection history from Windows registry, event
analyzing-web-server-logs-for-intrusion
Parse Apache and Nginx access logs to detect SQL injection attempts,
analyzing-windows-amcache-artifacts
'Parses and analyzes the Windows Amcache.hve registry hive to extract
analyzing-windows-event-logs-in-splunk
'Analyzes Windows Security, System, and Sysmon event logs in Splunk to
analyzing-windows-lnk-files-for-artifacts
Parse Windows LNK shortcut files to extract target paths, timestamps,
analyzing-windows-prefetch-with-python
Parse Windows Prefetch files using the windowsprefetch Python library
analyzing-windows-registry-for-artifacts
Extract and analyze Windows Registry hives to uncover user activity,
analyzing-windows-shellbag-artifacts
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing
assessing-vector-and-embedding-weaknesses
Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
attacking-entra-id-with-roadtools
Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.
attacking-oauth-with-device-code-phishing
Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
auditing-cloud-with-cis-benchmarks
'This skill details how to conduct cloud security audits using Center
auditing-entra-id-with-aadinternals
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate…
auditing-foundry-smart-contract-security
Deployed smart contracts are immutable and custody real funds, so a bug
auditing-gcp-iam-permissions
'Auditing Google Cloud Platform IAM permissions to identify overly permissive
auditing-kubernetes-rbac-privilege-escalation
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster…
auditing-mcp-servers-for-tool-poisoning
Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
auditing-terraform-infrastructure-for-security
'Auditing Terraform infrastructure-as-code for security misconfigurations
auditing-uefi-firmware-with-chipsec
Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI…
automating-ioc-enrichment
'Automates the enrichment of raw indicators of compromise with multi-source
benchmarking-kubernetes-with-kube-bench
Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
building-adversary-infrastructure-tracking-system
Build an automated system to track adversary infrastructure using passive
building-attack-pattern-library-from-cti-reports
Extract and catalog attack patterns from cyber threat intelligence reports
building-c2-infrastructure-with-sliver-framework
Build and configure a resilient command-and-control infrastructure using
building-c2-redirector-infrastructure
Architect redirectors with nginx and Apache, malleable profiles, and OPSEC
building-detection-rule-with-splunk-spl
Build effective detection rules using Splunk Search Processing Language
building-detection-rules-with-sigma
'Builds vendor-agnostic detection rules using the Sigma rule format for
building-devsecops-pipeline-with-gitlab-ci
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD
building-identity-federation-with-saml-azure-ad
Establish SAML 2.0 identity federation between on-premises Active Directory
building-incident-timeline-with-timesketch
Build collaborative forensic incident timelines using Timesketch to ingest,
building-ioc-defanging-and-sharing-pipeline
Build an automated pipeline to defang indicators of compromise (URLs,
building-ioc-enrichment-pipeline-with-opencti
OpenCTI is an open-source platform for managing cyber threat intelligence
building-patch-tuesday-response-process
Establish a structured operational process to triage, test, and deploy
building-phishing-reporting-button-workflow
Implement a phishing report button in email clients with automated triage
building-red-team-c2-infrastructure-with-havoc
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,
building-role-mining-for-rbac-optimization
Apply bottom-up and top-down role mining techniques to discover optimal
building-soc-escalation-matrix
Build a structured SOC escalation matrix defining severity tiers, response
building-soc-playbook-for-ransomware
'Builds a structured SOC incident response playbook for ransomware attacks
building-super-timelines-with-plaso
Generate log2timeline and Plaso super-timelines and triage them in Timesketch.
building-threat-feed-aggregation-with-misp
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate,
building-threat-hunt-hypothesis-framework
Build a systematic threat hunt hypothesis framework that transforms threat
building-threat-intelligence-enrichment-in-splunk
Build automated threat intelligence enrichment pipelines in Splunk Enterprise
building-threat-intelligence-feed-integration
'Builds automated threat intelligence feed integration pipelines connecting
building-threat-intelligence-platform
Building a Threat Intelligence Platform (TIP) involves deploying and
building-vulnerability-aging-and-sla-tracking
Implement a vulnerability aging dashboard and SLA tracking system to
building-vulnerability-exception-tracking-system
Build a vulnerability exception and risk acceptance tracking system with
building-vulnerability-scanning-workflow
'Builds a structured vulnerability scanning workflow using tools like
bypassing-authentication-with-forced-browsing
Discovering and accessing unprotected pages, APIs, and administrative
coercing-authentication-with-coercer-petitpotam
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other…
collecting-indicators-of-compromise
'Systematically collects, categorizes, and distributes indicators of
collecting-open-source-intelligence
'Collects and synthesizes open-source intelligence (OSINT) about threat
conducting-cloud-incident-response
'Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
conducting-cloud-penetration-testing
'This skill outlines methodologies for performing authorized penetration
conducting-domain-persistence-with-dcsync
Perform DCSync attacks to replicate Active Directory credentials and
conducting-full-scope-red-team-engagement
Plan and execute a comprehensive red team engagement covering reconnaissance
conducting-internal-network-penetration-test
Execute an internal network penetration test simulating an insider threat
conducting-internal-reconnaissance-with-bloodhound-ce
Conduct internal Active Directory reconnaissance using BloodHound Community
conducting-man-in-the-middle-attack-simulation
'Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap
conducting-memory-forensics-with-volatility
'Performs memory forensics analysis using Volatility 3 to extract evidence
conducting-pass-the-ticket-attack
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen
conducting-phishing-incident-response
'Responds to phishing incidents by analyzing reported emails, extracting
conducting-post-incident-lessons-learned
Facilitate structured post-incident reviews to identify root causes,
conducting-social-engineering-pretext-call
Plan and execute authorized vishing (voice phishing) pretext calls to
conducting-spearphishing-simulation-campaign
Spearphishing simulation is a targeted social engineering attack vector
conducting-wireless-network-penetration-test
'Conducts authorized wireless network penetration tests to assess the
configuring-active-directory-tiered-model
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
configuring-aws-verified-access-for-ztna
Configure AWS Verified Access to provide VPN-less zero trust network
configuring-certificate-authority-with-openssl
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy,
configuring-host-based-intrusion-detection
'Configures host-based intrusion detection systems (HIDS) to monitor
configuring-identity-aware-proxy-with-google-iap
'Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request
configuring-ldap-security-hardening
Harden LDAP directory services against common attacks including credential
configuring-microsegmentation-for-zero-trust
Configure microsegmentation policies to enforce least-privilege workload-to-workload
configuring-multi-factor-authentication-with-duo
Deploy Cisco Duo multi-factor authentication across enterprise applications,
configuring-oauth2-authorization-flow
Configure secure OAuth 2.0 authorization flows including Authorization
configuring-pfsense-firewall-rules
'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic
configuring-snort-ids-for-intrusion-detection
'Installs, configures, and tunes Snort 3 intrusion detection system to
configuring-suricata-for-network-monitoring
'Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets,
configuring-tls-1-3-for-secure-communications
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security
configuring-windows-defender-advanced-settings
'Configures Microsoft Defender for Endpoint (MDE) advanced protection
configuring-windows-event-logging-for-detection
'Configures Windows Event Logging with advanced audit policies to generate
configuring-zscaler-private-access-for-ztna
'Configuring Zscaler Private Access (ZPA) to replace traditional VPN
correlating-threat-campaigns
'Correlates disparate security incidents, IOCs, and adversary behaviors
defending-llms-with-guardrails
Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
deobfuscating-javascript-malware
'Deobfuscates malicious JavaScript code used in web-based attacks, phishing
deobfuscating-powershell-obfuscated-malware
Systematically deobfuscate multi-layer PowerShell malware using AST analysis,
deploying-active-directory-honeytokens
'Deploys deception-based honeytokens in Active Directory including fake
deploying-cloud-deception-with-decoy-resources
When cloud accounts (AWS/Azure/GCP) hold crown-jewel data or infrastructure and you need a tripwire that fires the moment an attacker who has gained access starts to operate.
deploying-cloudflare-access-for-zero-trust
'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust
deploying-honeytokens-and-canarytokens
Plant canarytokens and honey credentials and alert on breach.
deploying-osquery-for-endpoint-monitoring
'Deploys and configures osquery for real-time endpoint monitoring using
deploying-palo-alto-prisma-access-zero-trust
'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust
deploying-software-defined-perimeter
Deploy a Software-Defined Perimeter using the CSA v2.0 specification
deploying-tailscale-for-zero-trust-vpn
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN
designing-adversary-engagement-with-mitre-engage
When an organization owns deception tooling (honeypots, honeytokens, canary tokens, decoy files) but deploys it tactically with no unifying strategy or measurable outcome.
detecting-ai-model-prompt-injection-attacks
'Detects prompt injection attacks targeting LLM-based applications using
detecting-anomalies-in-industrial-control-systems
'This skill covers deploying anomaly detection systems for industrial
detecting-api-enumeration-attacks
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation
detecting-arp-poisoning-in-network-traffic
Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection,
detecting-attacks-on-historian-servers
'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,
detecting-aws-cloudtrail-anomalies
Detect unusual API call patterns in AWS CloudTrail logs using boto3,
detecting-aws-guardduty-findings-automation
Automate AWS GuardDuty threat detection findings processing using EventBridge
detecting-aws-iam-privilege-escalation
Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining
detecting-azure-lateral-movement
Detect lateral movement in Azure AD/Entra ID environments using Microsoft
detecting-azure-service-principal-abuse
Detect and investigate Azure service principal abuse including privilege
detecting-azure-storage-account-misconfigurations
Audit Azure Blob and ADLS storage accounts for public access exposure,
detecting-beaconing-patterns-with-zeek
'Performs statistical analysis of Zeek conn.log connection intervals
detecting-broken-object-property-level-authorization
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization
detecting-business-email-compromise-with-ai
Deploy AI and NLP-powered detection systems to identify business email
detecting-cloud-threats-with-guardduty
'This skill teaches security teams how to deploy and operationalize Amazon
detecting-compromised-cloud-credentials
'Detecting compromised cloud credentials across AWS, Azure, and GCP by
detecting-container-drift-at-runtime
Detect unauthorized modifications to running containers by monitoring
detecting-container-escape-attempts
Container escape is a critical attack technique where an adversary breaks
detecting-container-escape-with-falco-rules
Detect container escape attempts in real-time using Falco runtime security
detecting-container-runtime-threats-with-falco
Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.
detecting-credential-dumping-techniques
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit
detecting-cryptomining-in-cloud
'This skill teaches security teams how to detect and respond to unauthorized
detecting-data-and-model-poisoning
Identify poisoned training data and backdoored models across the ML pipeline.
detecting-dcsync-attack-in-active-directory
Detect DCSync attacks where adversaries abuse Active Directory replication
detecting-deepfake-audio-in-vishing-attacks
'Detects AI-generated deepfake audio used in voice phishing (vishing)
detecting-dll-sideloading-attacks
Detect DLL side-loading attacks where adversaries place malicious DLLs
detecting-dnp3-protocol-anomalies
'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications
detecting-dns-exfiltration-with-dns-query-analysis
Detect data exfiltration through DNS tunneling by analyzing query entropy,
detecting-email-forwarding-rules-attack
Detect malicious email forwarding rules created by adversaries to maintain
detecting-entra-offensive-tools-in-graph-logs
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and…
detecting-evasion-techniques-in-endpoint-logs
'Detects defense evasion techniques used by adversaries in endpoint logs
detecting-exfiltration-over-dns-with-zeek
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy
detecting-fileless-attacks-on-endpoints
'Detects fileless malware and in-memory attacks that execute entirely
detecting-fileless-malware-techniques
'Detects and analyzes fileless malware that operates entirely in memory
detecting-golden-ticket-attacks-in-kerberos-logs
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos
detecting-golden-ticket-forgery
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769
detecting-indirect-prompt-injection
Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
detecting-insider-data-exfiltration-via-dlp
'Detects insider data exfiltration by analyzing DLP policy violations,
detecting-insider-threat-with-ueba
Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch
detecting-kerberoasting-attacks
Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS
detecting-lateral-movement-in-network
'Identifies lateral movement techniques in enterprise networks by analyzing
detecting-lateral-movement-with-splunk
Detect adversary lateral movement across networks using Splunk SPL queries
detecting-lateral-movement-with-zeek
'Detect lateral movement in network traffic using Zeek (formerly Bro)
detecting-living-off-the-land-with-lolbas
Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including
detecting-malicious-scheduled-tasks-with-sysmon
'Detect malicious scheduled task creation and modification using Sysmon
detecting-mimikatz-execution-patterns
Detect Mimikatz execution through command-line patterns, LSASS access
detecting-mobile-malware-behavior
'Detects and analyzes malicious behavior in mobile applications through
detecting-modbus-protocol-anomalies
'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications
detecting-network-anomalies-with-zeek
'Deploys and configures Zeek (formerly Bro) network security monitor
detecting-network-scanning-with-ids-signatures
Detect network reconnaissance and port scanning using Suricata and Snort
detecting-oauth-token-theft
'Detects and responds to OAuth token theft and replay attacks in cloud
detecting-pass-the-hash-attacks
Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns,
detecting-pass-the-ticket-attacks
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event
detecting-port-scanning-with-fail2ban
'Configures Fail2ban with custom filters and actions to detect port scanning
detecting-privilege-escalation-attempts
Detect privilege escalation attempts including token manipulation, UAC
detecting-privilege-escalation-in-kubernetes-pods
Detect and prevent privilege escalation in Kubernetes pods by monitoring
detecting-process-hollowing-technique
Detect process hollowing (T1055.012) by analyzing memory-mapped sections,
detecting-process-injection-techniques
'Detects and analyzes process injection techniques used by malware including
detecting-qr-code-phishing-with-email-security
Detect and prevent QR code phishing (quishing) attacks that bypass traditional
detecting-ransomware-encryption-behavior
'Detects ransomware encryption activity in real time using entropy analysis,
detecting-ransomware-precursors-in-network
'Detects early-stage ransomware indicators in network traffic before
detecting-rdp-brute-force-attacks
Detect RDP brute force attacks by analyzing Windows Security Event Logs