mukul975/anthropic-cybersecurity-skills

833 skills97.8K total installsGithubGithubGitHub

analyzing-api-gateway-access-logs

670

acquiring-disk-image-with-dd-and-dcfldd

615

analyzing-android-malware-with-apktool

564

analyzing-cyber-kill-chain

546

analyzing-email-headers-for-phishing-investigation

535

analyzing-browser-forensics-with-hindsight

532

analyzing-docker-container-forensics

515

conducting-api-security-testing

512

testing-api-security-with-owasp-top-10

511

analyzing-cloud-storage-access-patterns

507

analyzing-active-directory-acl-abuse

498

analyzing-certificate-transparency-for-phishing

496

analyzing-dns-logs-for-exfiltration

489

analyzing-apt-group-with-mitre-navigator

482

performing-web-application-penetration-test

471

analyzing-command-and-control-communication

469

analyzing-linux-audit-logs-for-intrusion

460

testing-for-xss-vulnerabilities

453

analyzing-network-traffic-with-wireshark

453

analyzing-bootkit-and-rootkit-samples

438

analyzing-azure-activity-logs-for-threats

436

analyzing-indicators-of-compromise

420

analyzing-campaign-attribution-evidence

415

analyzing-disk-image-with-autopsy

406

analyzing-linux-system-artifacts

404

analyzing-linux-kernel-rootkits

402

testing-api-for-broken-object-level-authorization

401

analyzing-linux-elf-malware

400

analyzing-ios-app-security-with-objection

398

analyzing-network-packets-with-scapy

396

testing-jwt-token-security

394

exploiting-sql-injection-vulnerabilities

394

analyzing-network-traffic-for-incidents

392

analyzing-golang-malware-with-ghidra

386

analyzing-network-traffic-of-malware

384

analyzing-malicious-url-with-urlscan

384

analyzing-cobaltstrike-malleable-c2-profiles

383

analyzing-kubernetes-audit-logs

377

testing-api-authentication-weaknesses

376

abusing-dpapi-for-credential-access

375

analyzing-cobalt-strike-beacon-configuration

373

analyzing-ethereum-smart-contract-vulnerabilities

367

analyzing-sbom-for-supply-chain-vulnerabilities

364

analyzing-web-server-logs-for-intrusion

363

testing-for-broken-access-control

355

analyzing-malicious-pdf-with-peepdf

350

testing-for-json-web-token-vulnerabilities

348

analyzing-heap-spray-exploitation

345

testing-cors-misconfiguration

344

analyzing-network-covert-channels-in-malware

343

analyzing-network-flow-data-with-netflow

343

reverse-engineering-android-malware-with-jadx

335

analyzing-malware-sandbox-evasion-techniques

329

analyzing-malware-behavior-with-cuckoo-sandbox

326

analyzing-memory-dumps-with-volatility

325

performing-web-application-vulnerability-triage

323

analyzing-malware-family-relationships-with-malpedia

318

analyzing-malware-persistence-with-autoruns

318

analyzing-lnk-file-and-jump-list-artifacts

316

analyzing-macro-malware-in-office-documents

313

testing-api-for-mass-assignment-vulnerability

304

analyzing-pdf-malware-with-pdfid

302

testing-for-sensitive-data-exposure

296

analyzing-memory-forensics-with-lime-and-volatility

296

analyzing-threat-intelligence-feeds

296

analyzing-powershell-script-block-logging

294

analyzing-mft-for-deleted-file-recovery

294

analyzing-ransomware-network-indicators

292

analyzing-threat-actor-ttps-with-mitre-attack

290

analyzing-persistence-mechanisms-in-linux

289

testing-oauth2-implementation-flaws

288

analyzing-ransomware-encryption-mechanisms

288

exploiting-idor-vulnerabilities

286

bypassing-authentication-with-forced-browsing

286

analyzing-outlook-pst-for-email-forensics

285

analyzing-ransomware-leak-site-intelligence

284

conducting-external-reconnaissance-with-osint

282

analyzing-office365-audit-logs-for-compromise

282

analyzing-powershell-empire-artifacts

280

testing-websocket-api-security

278

testing-for-business-logic-vulnerabilities

275

auditing-aws-s3-bucket-permissions

275

testing-for-xxe-injection-vulnerabilities

272

testing-for-xss-vulnerabilities-with-burpsuite

269

exploiting-sql-injection-with-sqlmap

269

analyzing-packed-malware-with-upx-unpacker

269

conducting-network-penetration-test

267

testing-for-open-redirect-vulnerabilities

266

analyzing-supply-chain-malware-artifacts

266

exploiting-api-injection-vulnerabilities

261

analyzing-tls-certificate-transparency-logs

259

analyzing-threat-actor-ttps-with-mitre-navigator

259

analyzing-security-logs-with-splunk

258

abusing-shadow-credentials-for-privesc

257

testing-for-host-header-injection

256

analyzing-prefetch-files-for-execution-history

254

implementing-secret-scanning-with-gitleaks

252

analyzing-typosquatting-domains-with-dnstwist

250

conducting-mobile-app-penetration-test

250

auditing-terraform-infrastructure-for-security

248

performing-web-application-firewall-bypass

247

auditing-kubernetes-cluster-rbac

246

building-incident-response-playbook

245

analyzing-ransomware-payment-wallets

245

performing-web-application-scanning-with-nikto

244

implementing-api-rate-limiting-and-throttling

244

achieving-cmmc-level-2-compliance

244

analyzing-threat-landscape-with-misp

242

auditing-cloud-with-cis-benchmarks

240

analyzing-windows-event-logs-in-splunk

238

exploiting-server-side-request-forgery

238

exploiting-jwt-algorithm-confusion-attack

235

collecting-open-source-intelligence

235

building-vulnerability-scanning-workflow

235

testing-for-xml-injection-vulnerabilities

230

performing-security-headers-audit

227

exploiting-websocket-vulnerabilities

226

conducting-cloud-penetration-testing

226

analyzing-windows-registry-for-artifacts

225

analyzing-usb-device-connection-history

225

analyzing-slack-space-and-file-system-artifacts

224

testing-mobile-api-authentication

223

hardening-docker-containers-for-production

222

auditing-azure-active-directory-configuration

221

analyzing-windows-prefetch-with-python

220

detecting-ai-model-prompt-injection-attacks

217

auditing-gcp-iam-permissions

214

exploiting-broken-function-level-authorization

214

analyzing-windows-lnk-files-for-artifacts

213

auditing-tls-certificate-transparency-logs

212

exploiting-nosql-injection-vulnerabilities

212

conducting-full-scope-red-team-engagement

210

exploiting-http-request-smuggling

210

testing-for-email-header-injection

210

analyzing-windows-amcache-artifacts

208

automating-ioc-enrichment

208

building-attack-pattern-library-from-cti-reports

207

performing-csrf-attack-simulation

206

exploiting-oauth-misconfiguration

205

building-devsecops-pipeline-with-gitlab-ci

204

performing-ssrf-vulnerability-exploitation

204

detecting-api-enumeration-attacks

204

analyzing-windows-shellbag-artifacts

203

exploiting-template-injection-vulnerabilities

201

performing-api-rate-limiting-bypass

201

performing-web-cache-poisoning-attack

201

configuring-oauth2-authorization-flow

200

performing-web-cache-deception-attack

199

exploiting-race-condition-vulnerabilities

199

analyzing-uefi-bootkit-persistence

196

exploiting-mass-assignment-in-rest-apis

196

building-adversary-infrastructure-tracking-system

195

conducting-internal-network-penetration-test

195

building-c2-infrastructure-with-sliver-framework

194

implementing-api-schema-validation-security

193

exploiting-insecure-deserialization

193

performing-api-security-testing-with-postman

192

building-incident-response-dashboard

191

scanning-network-with-nmap-advanced

189

building-threat-actor-profile-from-osint

185

performing-threat-modeling-with-owasp-threat-dragon

185

implementing-api-key-security-controls

184

building-vulnerability-dashboard-with-defectdojo

183

building-soc-escalation-matrix

183

building-automated-malware-submission-pipeline

181

exploiting-excessive-data-exposure-in-api

181

building-detection-rules-with-sigma

180

building-soc-metrics-and-kpi-tracking

177

exploiting-prototype-pollution-in-javascript

177

building-soc-playbook-for-ransomware

177

building-threat-intelligence-platform

175

implementing-jwt-signing-and-verification

174

building-red-team-c2-infrastructure-with-havoc

174

building-cloud-siem-with-sentinel

173

building-detection-rule-with-splunk-spl

172

deobfuscating-javascript-malware

172

building-threat-intelligence-feed-integration

169

building-vulnerability-exception-tracking-system

169

performing-sca-dependency-scanning-with-snyk

167

scanning-docker-images-with-trivy

166

performing-api-inventory-and-discovery

165

building-malware-incident-communication-template

165

conducting-wireless-network-penetration-test

165

building-incident-timeline-with-timesketch

163

building-threat-hunt-hypothesis-framework

162

collecting-threat-intelligence-with-misp

162

building-ransomware-playbook-with-cisa-framework

162

building-identity-governance-lifecycle-process

161

collecting-indicators-of-compromise

161

building-vulnerability-aging-and-sla-tracking

161

auditing-mcp-servers-for-tool-poisoning

161

securing-github-actions-workflows

161

conducting-phishing-incident-response

159

conducting-cloud-incident-response

158

detecting-sql-injection-via-waf-logs

157

triaging-security-incident

157

performing-api-fuzzing-with-restler

155

conducting-man-in-the-middle-attack-simulation

155

building-phishing-reporting-button-workflow

154

conducting-internal-reconnaissance-with-bloodhound-ce

153

building-ioc-enrichment-pipeline-with-opencti

153

building-identity-federation-with-saml-azure-ad

152

implementing-api-gateway-security-controls

151

reverse-engineering-malware-with-ghidra

150

building-role-mining-for-rbac-optimization

150

building-threat-intelligence-enrichment-in-splunk

150

detecting-broken-object-property-level-authorization

150

building-ioc-defanging-and-sharing-pipeline

149

implementing-api-abuse-detection-with-rate-limiting

149

configuring-tls-1-3-for-secure-communications

147

exploiting-type-juggling-vulnerabilities

146

building-threat-feed-aggregation-with-misp

146

conducting-social-engineering-penetration-test

144

implementing-devsecops-security-scanning

142

exploiting-insecure-data-storage-in-mobile

142

detecting-shadow-api-endpoints

142

exploiting-vulnerabilities-with-metasploit-framework

140

performing-wifi-password-cracking-with-aircrack

138

exploiting-broken-link-hijacking

138

performing-jwt-none-algorithm-attack

138

attacking-oauth-with-device-code-phishing

138

implementing-secrets-scanning-in-ci-cd

138

testing-android-intents-for-vulnerabilities

137

performing-second-order-sql-injection

137

collecting-volatile-evidence-from-compromised-host

136

conducting-pass-the-ticket-attack

136

conducting-domain-persistence-with-dcsync

136

building-patch-tuesday-response-process

136

executing-red-team-exercise

135

exploiting-deeplink-vulnerabilities

135

reverse-engineering-ios-app-with-frida

134

conducting-malware-incident-response

134

implementing-api-security-posture-management

133

performing-graphql-security-assessment

132

executing-red-team-engagement-planning

132

performing-subdomain-enumeration-with-subfinder

129

performing-directory-traversal-testing

127

detecting-oauth-token-theft

127

performing-vulnerability-scanning-with-nessus

125

performing-ssl-tls-security-assessment

125

performing-blind-ssrf-exploitation

123

conducting-memory-forensics-with-volatility

123

implementing-api-security-testing-with-42crunch

122

triaging-vulnerabilities-with-ssvc-framework

122

hardening-docker-daemon-configuration

122

exploiting-smb-vulnerabilities-with-metasploit

121

configuring-network-segmentation-with-vlans

121

assessing-vector-and-embedding-weaknesses

121

detecting-anomalous-authentication-patterns

120

configuring-pfsense-firewall-rules

120

integrating-dast-with-owasp-zap-in-pipeline

119

scanning-containers-with-trivy-in-cicd

118

conducting-post-incident-lessons-learned

117

deobfuscating-powershell-obfuscated-malware

117

integrating-sast-into-github-actions-pipeline

117

implementing-semgrep-for-custom-sast-rules

116

performing-clickjacking-attack-test

115

conducting-spearphishing-simulation-campaign

114

auditing-kubernetes-rbac-privilege-escalation

113

triaging-security-incident-with-ir-playbook

113

performing-content-security-policy-bypass

112

validating-backup-integrity-for-recovery

112

securing-api-gateway-with-aws-waf

112

detecting-aws-credential-exposure-with-trufflehog

112

hardening-linux-endpoint-with-cis-benchmark

111

detecting-supply-chain-attacks-in-ci-cd

110

testing-ransomware-recovery-procedures

110

exploiting-ipv6-vulnerabilities

109

performing-graphql-introspection-attack

109

reverse-engineering-dotnet-malware-with-dnspy

108

configuring-certificate-authority-with-openssl

108

performing-osint-with-spiderfoot

107

implementing-web-application-logging-with-modsecurity

107

performing-http-parameter-pollution-attack

107

attacking-entra-id-with-roadtools

106

performing-soc2-type2-audit-preparation

105

conducting-social-engineering-pretext-call

105

performing-android-app-static-analysis-with-mobsf

105

exploiting-zerologon-vulnerability-cve-2020-1472

105

performing-network-traffic-analysis-with-tshark

104

exploiting-active-directory-with-bloodhound

104

tracking-threat-actor-infrastructure

104

detecting-attacks-on-scada-systems

104

monitoring-darkweb-sources

103

configuring-host-based-intrusion-detection

103

hunting-for-webshell-activity

103

prioritizing-vulnerabilities-with-cvss-scoring

103

performing-oauth-scope-minimization-review

102

performing-cryptographic-audit-of-application

101

securing-serverless-functions

100

configuring-suricata-for-network-monitoring

100

auditing-entra-id-with-aadinternals

100

extracting-browser-history-artifacts

100

performing-open-source-intelligence-gathering

100

performing-graphql-depth-limit-attack

100

configuring-ldap-security-hardening

99

performing-authenticated-vulnerability-scan

99

implementing-api-threat-protection-with-apigee

99

securing-aws-iam-permissions

99

exploiting-kerberoasting-with-impacket

99

benchmarking-kubernetes-with-kube-bench

99

exploiting-active-directory-certificate-services-esc1

99

configuring-windows-defender-advanced-settings

98

scanning-container-images-with-grype

97

performing-wireless-network-penetration-test

97

exploiting-bgp-hijacking-vulnerabilities

97

performing-network-packet-capture-analysis

97

extracting-credentials-from-memory-dump

97

performing-network-forensics-with-wireshark

96

performing-ai-driven-osint-correlation

96

auditing-foundry-smart-contract-security

96

detecting-dependency-confusion

96

securing-container-registry-images

96

performing-container-image-hardening

95

triaging-security-alerts-in-splunk

95

configuring-windows-event-logging-for-detection

95

performing-privilege-escalation-on-linux

94

building-c2-redirector-infrastructure

94

performing-container-security-scanning-with-trivy

94

performing-dark-web-monitoring-for-threats

94

implementing-gdpr-data-protection-controls

93

exploiting-nopac-cve-2021-42278-42287

93

testing-prompt-injection-in-rag-pipelines

93

detecting-typosquatting-packages-in-npm-pypi

93

performing-soap-web-service-security-testing

93

conducting-cyber-risk-assessment-with-nist-800-30

92

performing-mobile-app-certificate-pinning-bypass

92

deploying-cloudflare-access-for-zero-trust

91

detecting-email-account-compromise

91

hunting-credential-stuffing-attacks

91

performing-wireless-security-assessment-with-kismet

91

implementing-llm-guardrails-for-security

91

reverse-engineering-rust-malware

90

performing-sqlite-database-forensics

90

implementing-github-advanced-security-for-code-scanning

89

auditing-uefi-firmware-with-chipsec

89

exploiting-ms17-010-eternalblue-vulnerability

88

remediating-s3-bucket-misconfiguration

88

configuring-microsegmentation-for-zero-trust

88

intercepting-mobile-traffic-with-burpsuite

88

containing-active-breach

88

performing-privilege-escalation-assessment

87

generating-threat-intelligence-reports

87

detecting-credential-dumping-techniques

87

performing-kubernetes-penetration-testing

87

performing-ssl-certificate-lifecycle-management

87

securing-kubernetes-on-cloud

86

detecting-s3-data-exfiltration-attempts

86

detecting-aws-iam-privilege-escalation

86

exploiting-constrained-delegation-abuse

85

detecting-aws-cloudtrail-anomalies

85

detecting-network-scanning-with-ids-signatures

85

detecting-business-email-compromise

85

scanning-kubernetes-manifests-with-kubesec

85

performing-ssl-tls-inspection-configuration

85

configuring-active-directory-tiered-model

84

performing-docker-bench-security-assessment

84

performing-dns-enumeration-and-zone-transfer

84

detecting-compromised-cloud-credentials

84

hardening-windows-endpoint-with-cis-benchmark

84

detecting-privilege-escalation-attempts

84

performing-active-directory-penetration-test

84

configuring-multi-factor-authentication-with-duo

84

implementing-aes-encryption-for-data-at-rest

83

detecting-malicious-npm-packages

83

reverse-engineering-ransomware-encryption-routine

83

securing-aws-lambda-execution-roles

82

configuring-hsm-for-key-storage

82

configuring-snort-ids-for-intrusion-detection

82

performing-hash-cracking-with-hashcat

82

testing-for-system-prompt-leakage

82

deploying-tailscale-for-zero-trust-vpn

82

scanning-infrastructure-with-nessus

81

implementing-cloud-waf-rules

81

securing-remote-access-to-ot-environment

81

hunting-advanced-persistent-threats

81

performing-external-network-penetration-test

80

configuring-aws-verified-access-for-ztna

80

performing-privileged-account-discovery

80

detecting-pass-the-hash-attacks

80

detecting-arp-poisoning-in-network-traffic

80

performing-cloud-penetration-testing-with-pacu

79

detecting-suspicious-oauth-application-consent

79

detecting-container-escape-attempts

79

detecting-dns-exfiltration-with-dns-query-analysis

78

performing-red-team-phishing-with-gophish

78

detecting-email-forwarding-rules-attack

78

performing-ios-app-security-assessment

78

performing-ssl-stripping-attack

78

correlating-threat-campaigns

77

mapping-mitre-attack-techniques

76

performing-memory-forensics-with-volatility3

76

performing-privacy-impact-assessment

76

detecting-indirect-prompt-injection

76

executing-phishing-simulation-campaign

76

performing-privileged-account-access-review

75

configuring-identity-aware-proxy-with-google-iap

75

hunting-for-unusual-network-connections

75

performing-agentless-vulnerability-scanning

75

implementing-attack-surface-management

75

detecting-port-scanning-with-fail2ban

74

securing-container-registry-with-harbor

74

detecting-lateral-movement-in-network

74

performing-active-directory-vulnerability-assessment

74

implementing-secrets-management-with-vault

74

performing-cve-prioritization-with-kev-catalog

74

performing-serverless-function-security-review

73

detecting-process-injection-techniques

73

securing-helm-chart-deployments

72

detecting-anomalies-in-industrial-control-systems

72

deploying-ransomware-canary-files

72

performing-mobile-device-forensics-with-cellebrite

72

extracting-windows-event-logs-artifacts

71

performing-threat-hunting-with-elastic-siem

71

performing-authenticated-scan-with-openvas

71

performing-endpoint-vulnerability-remediation

71

performing-arp-spoofing-attack-simulation

71

detecting-qr-code-phishing-with-email-security

70

continuous-llm-red-teaming-with-promptfoo

70

detecting-serverless-function-injection

70

detecting-container-drift-at-runtime

70

building-super-timelines-with-plaso

70

detecting-business-email-compromise-with-ai

70

performing-red-team-with-covenant

69

implementing-network-access-control

69

performing-dynamic-analysis-of-android-app

69

detecting-aws-guardduty-findings-automation

69

performing-nist-csf-maturity-assessment

69

performing-threat-hunting-with-yara-rules

69

performing-binary-exploitation-analysis

69

detecting-cloud-threats-with-guardduty

68

performing-network-traffic-analysis-with-zeek

68

coercing-authentication-with-coercer-petitpotam

68

implementing-infrastructure-as-code-security-scanning

68

hunting-for-supply-chain-compromise

68

performing-ot-vulnerability-scanning-safely

68

performing-endpoint-forensics-investigation

68

performing-threat-emulation-with-atomic-red-team

67

detecting-insider-threat-behaviors

67

detecting-attacks-on-historian-servers

67

performing-thick-client-application-penetration-test

67

implementing-zero-trust-for-saas-applications

67

detecting-azure-storage-account-misconfigurations

67

implementing-pci-dss-compliance-controls

67

performing-linux-log-forensics-investigation

67

performing-aws-privilege-escalation-assessment

67

executing-active-directory-attack-simulation

67

detecting-cryptomining-in-cloud

67

performing-packet-injection-attack

67

performing-active-directory-bloodhound-analysis

67

implementing-threat-modeling-with-mitre-attack

66

performing-ot-vulnerability-assessment-with-claroty

66

hunting-for-data-exfiltration-indicators

66

detecting-mobile-malware-behavior

66

detecting-rootkit-activity

66

performing-dns-tunneling-detection

66

detecting-command-and-control-over-dns

66

detecting-pass-the-ticket-attacks

66

detecting-container-escape-with-falco-rules

66

implementing-network-segmentation-with-firewall-zones

66

implementing-gdpr-data-subject-access-request

66

investigating-phishing-email-incident

66

detecting-kerberoasting-attacks

66

extracting-iocs-from-malware-samples

66

performing-phishing-simulation-with-gophish

65

implementing-dmarc-dkim-spf-email-security

65

detecting-dll-sideloading-attacks

65

hunting-for-dns-based-persistence

65

performing-purple-team-exercise

65

implementing-aws-iam-permission-boundaries

65

performing-supply-chain-attack-simulation

65

detecting-deepfake-audio-in-vishing-attacks

65

securing-historian-server-in-ot-environment

65

hunting-for-anomalous-powershell-execution

65

performing-cloud-asset-inventory-with-cartography

64

implementing-aqua-security-for-container-scanning

64

performing-yara-rule-development-for-detection

64

implementing-kubernetes-pod-security-standards

64

detecting-privilege-escalation-in-kubernetes-pods

64

hunting-for-unusual-service-installations

64

performing-ransomware-response

64

detecting-azure-service-principal-abuse

63

implementing-ddos-mitigation-with-cloudflare

63

performing-service-account-credential-rotation

63

implementing-cloud-vulnerability-posture-management

63

performing-aws-account-enumeration-with-scout-suite

63

implementing-endpoint-detection-with-wazuh

63

implementing-zero-trust-network-access

63

performing-steganography-detection

63

detecting-golden-ticket-attacks-in-kerberos-logs

63

implementing-aws-config-rules-for-compliance

63

performing-asset-criticality-scoring-for-vulns

63

detecting-network-anomalies-with-zeek

63

verifying-build-provenance-with-slsa-sigstore

63

performing-windows-artifact-analysis-with-eric-zimmerman-tools

62

detecting-shadow-it-cloud-usage

62

detecting-fileless-attacks-on-endpoints

62

performing-vlan-hopping-attack

62

detecting-dcsync-attack-in-active-directory

62

performing-log-analysis-for-forensic-investigation

62

performing-container-escape-detection

62

hunting-for-process-injection-techniques

62

performing-purple-team-atomic-testing

61

performing-cloud-log-forensics-with-athena

61

correlating-security-events-in-qradar

61

detecting-rdp-brute-force-attacks

61

performing-cloud-forensics-investigation

61

detecting-service-account-abuse

61

performing-user-behavior-analytics

61

securing-azure-with-microsoft-defender

61

performing-malware-triage-with-yara

61

implementing-hashicorp-vault-dynamic-secrets

60

detecting-suspicious-powershell-execution

60

performing-plc-firmware-security-analysis

60

implementing-zero-trust-in-cloud

60

performing-service-account-audit

60

performing-threat-landscape-assessment-for-sector

60

performing-firmware-malware-analysis

60

detecting-azure-lateral-movement

60

performing-lateral-movement-with-wmiexec

60

performing-ip-reputation-analysis-with-shodan

60

hunting-for-command-and-control-beaconing

60

hunting-for-dns-tunneling-with-zeek

60

detecting-ransomware-precursors-in-network

60

recovering-from-ransomware-attack

59

configuring-zscaler-private-access-for-ztna

59

profiling-threat-actor-groups

59

performing-malware-hash-enrichment-with-virustotal

59

implementing-network-policies-for-kubernetes

59

detecting-fileless-malware-techniques

59

performing-ot-network-security-assessment

59

deploying-active-directory-honeytokens

59

performing-kubernetes-cis-benchmark-with-kube-bench

59

detecting-modbus-command-injection-attacks

59

performing-power-grid-cybersecurity-assessment

58

deploying-osquery-for-endpoint-monitoring

58

hunting-for-living-off-the-cloud-techniques

58

performing-cloud-native-threat-hunting-with-aws-detective

58

performing-ransomware-tabletop-exercise

58

detecting-bluetooth-low-energy-attacks

58

detecting-ransomware-encryption-behavior

58

detecting-process-hollowing-technique

58

implementing-code-signing-for-artifacts

58

implementing-container-image-minimal-base-with-distroless

57

performing-cloud-native-forensics-with-falco

57

deploying-software-defined-perimeter

57

implementing-pam-for-database-access

57

deploying-palo-alto-prisma-access-zero-trust

57

extracting-memory-artifacts-with-rekall

57

implementing-aws-security-hub-compliance

57

hunting-for-persistence-mechanisms-in-windows

57

performing-cloud-forensics-with-aws-cloudtrail

57

performing-post-quantum-cryptography-migration

57

performing-threat-intelligence-sharing-with-misp

57

detecting-living-off-the-land-attacks

57

implementing-cloud-security-posture-management

57

performing-timeline-reconstruction-with-plaso

57

performing-gcp-penetration-testing-with-gcpbucketbrute

57

detecting-golden-ticket-forgery

56

implementing-network-intrusion-prevention-with-suricata

56

implementing-attack-path-analysis-with-xm-cyber

56

performing-credential-access-with-lazagne

56

hunting-for-suspicious-scheduled-tasks

56

implementing-mitre-attack-coverage-mapping

56

performing-firmware-extraction-with-binwalk

56

implementing-aws-security-hub

56

performing-cloud-storage-forensic-acquisition

56

deploying-decoy-files-for-ransomware-detection

56

hunting-for-spearphishing-indicators

55

detecting-exfiltration-over-dns-with-zeek

55

detecting-living-off-the-land-with-lolbas

55

deploying-edr-agent-with-crowdstrike

55

performing-kubernetes-etcd-security-assessment

55

implementing-passwordless-authentication-with-fido2

55

performing-malware-ioc-extraction

55

implementing-ransomware-backup-strategy

55

implementing-vulnerability-management-with-greenbone

55

performing-adversary-in-the-middle-phishing-detection

55

hunting-for-cobalt-strike-beacons

55

hunting-for-domain-fronting-c2-traffic

55

performing-soc-tabletop-exercise

55

performing-static-malware-analysis-with-pe-studio

55

implementing-google-workspace-phishing-protection

55

detecting-insider-threat-with-ueba

55

hunting-for-data-staging-before-exfiltration

55

performing-physical-intrusion-assessment

55

scanning-iac-and-images-with-trivy

55

performing-disk-forensics-investigation

55

performing-kerberoasting-attack

54

hunting-for-ntlm-relay-attacks

54

performing-malware-persistence-investigation

54

implementing-kubernetes-network-policy-with-calico

54

performing-fuzzing-with-aflplusplus

54

performing-memory-forensics-with-volatility3-plugins

54

implementing-anti-phishing-training-program

54

performing-cloud-incident-containment-procedures

54

implementing-end-to-end-encryption-for-messaging

54

hunting-for-registry-run-key-persistence

54

hunting-for-scheduled-task-persistence

53

implementing-passwordless-auth-with-microsoft-entra

53

investigating-ransomware-attack-artifacts

53

securing-agentic-ai-tool-invocation

53

implementing-digital-signatures-with-ed25519

53

performing-false-positive-reduction-in-siem

53

implementing-iso-27001-information-security-management

53

detecting-lateral-movement-with-splunk

53

performing-active-directory-compromise-investigation

53

detecting-ntlm-relay-with-event-correlation

53

detecting-malicious-scheduled-tasks-with-sysmon

53

performing-paste-site-monitoring-for-credentials

53

hunting-for-lolbins-execution-in-endpoint-logs

53

evaluating-threat-intelligence-platforms

53

implementing-zero-knowledge-proof-for-authentication

53

hunting-for-lateral-movement-via-wmi

53

hunting-for-registry-persistence-mechanisms

53

implementing-vulnerability-remediation-sla

52

implementing-google-workspace-admin-security

52

implementing-privileged-session-monitoring

52

hunting-for-shadow-copy-deletion

52

detecting-insider-data-exfiltration-via-dlp

52

implementing-gcp-vpc-firewall-rules

52

implementing-supply-chain-security-with-in-toto

52

eradicating-malware-from-infected-systems

52

implementing-google-workspace-sso-configuration

51

performing-oil-gas-cybersecurity-assessment

51

implementing-rbac-hardening-for-kubernetes

51

detecting-spearphishing-with-email-gateway

51

implementing-network-traffic-analysis-with-arkime

51

hunting-for-dcsync-attacks

51

implementing-network-traffic-baselining

51

performing-active-directory-forest-trust-attack

51

extracting-config-from-agent-tesla-rat

50

performing-scada-hmi-security-assessment

50

hunting-for-persistence-via-wmi-subscriptions

50

implementing-mobile-application-management

50

implementing-hardware-security-key-authentication

50

detecting-beaconing-patterns-with-zeek

50

detecting-dnp3-protocol-anomalies

50

generating-and-analyzing-sboms

50

hunting-for-dcom-lateral-movement

50

detecting-evasion-techniques-in-endpoint-logs

50

detecting-stuxnet-style-attacks

50

defending-llms-with-guardrails

50

implementing-anti-ransomware-group-policy

50

implementing-network-access-control-with-cisco-ise

49

performing-bluetooth-security-assessment

49

implementing-cloud-dlp-for-data-protection

49

red-teaming-llms-with-garak

49

hunting-for-beaconing-with-frequency-analysis

49

implementing-fuzz-testing-in-cicd-with-aflplusplus

48

implementing-network-segmentation-for-ot

48

detecting-mimikatz-execution-patterns

48

implementing-alert-fatigue-reduction

48

hunting-for-startup-folder-persistence

48

hunting-for-living-off-the-land-binaries

48

implementing-envelope-encryption-with-aws-kms

48

recovering-deleted-files-with-photorec

48

implementing-cloud-trail-log-analysis

47

performing-gcp-security-assessment-with-forseti

47

implementing-pod-security-admission-controller

47

implementing-rsa-key-pair-management

47

detecting-modbus-protocol-anomalies

47

implementing-epss-score-for-vulnerability-prioritization

47

implementing-policy-as-code-with-open-policy-agent

47

detecting-wmi-persistence

47

detecting-t1003-credential-dumping-with-edr

47

hunting-for-defense-evasion-via-timestomping

47

managing-cloud-identity-with-okta

47

performing-brand-monitoring-for-impersonation

47

detecting-misconfigured-azure-storage

47

performing-automated-malware-analysis-with-cape

47

investigating-insider-threat-indicators

46

implementing-vulnerability-sla-breach-alerting

46

implementing-azure-defender-for-cloud

46

implementing-threat-intelligence-lifecycle-management

46

implementing-privileged-access-workstation

46

performing-dmarc-policy-enforcement-rollout

46

performing-dynamic-analysis-with-any-run

46

detecting-t1055-process-injection-with-sysmon

45

implementing-application-whitelisting-with-applocker

45

implementing-aws-macie-for-data-classification

45

implementing-siem-use-cases-for-detection

45

performing-lateral-movement-detection

45

implementing-cloud-workload-protection

45

detecting-lateral-movement-with-zeek

45

detecting-t1548-abuse-elevation-control-mechanism

45

implementing-patch-management-workflow

45

implementing-ot-incident-response-playbook

45

performing-iot-security-assessment

45

implementing-azure-ad-privileged-identity-management

45

implementing-gcp-binary-authorization

45

implementing-privileged-access-management-with-cyberark

44

implementing-next-generation-firewall-with-palo-alto

44

implementing-mtls-for-zero-trust-services

44

implementing-network-deception-with-honeypots

44

processing-stix-taxii-feeds

44

implementing-aws-nitro-enclave-security

44

implementing-ot-network-traffic-analysis-with-nozomi

44

implementing-file-integrity-monitoring-with-aide

43

performing-bandwidth-throttling-attack-simulation

43

implementing-saml-sso-with-okta

43

hunting-for-t1098-account-manipulation

43

performing-alert-triage-with-elastic-siem

43

implementing-opa-gatekeeper-for-policy-enforcement

43

implementing-image-provenance-verification-with-cosign

43

implementing-immutable-backup-with-restic

42

implementing-sigstore-for-software-signing

42

performing-deception-technology-deployment

42

performing-log-source-onboarding-in-siem

42

implementing-soar-playbook-for-phishing

42

implementing-cisa-zero-trust-maturity-model

42

implementing-endpoint-dlp-controls

41

implementing-patch-management-for-ot-systems

41

performing-entitlement-review-with-sailpoint-iiq

41

implementing-siem-use-case-tuning

41

implementing-runtime-application-self-protection

41

implementing-security-chaos-engineering

41

implementing-container-network-policies-with-calico

41

implementing-identity-verification-for-zero-trust

41

implementing-siem-correlation-rules-for-apt

41

implementing-delinea-secret-server-for-pam

41

implementing-rapid7-insightvm-for-scanning

41

implementing-browser-isolation-for-zero-trust

41

performing-s7comm-protocol-security-analysis

41

performing-hardware-security-module-integration

41

implementing-email-sandboxing-with-proofpoint

41

performing-initial-access-with-evilginx3

41

implementing-continuous-security-validation-with-bas

41

implementing-zero-standing-privilege-with-cyberark

40

implementing-zero-trust-with-hashicorp-boundary

40

implementing-gcp-organization-policy-constraints

40

managing-intelligence-lifecycle

40

emulating-cloud-attacks-with-stratus-red-team

40

implementing-beyondcorp-zero-trust-access-model

40

performing-access-review-and-certification

39

implementing-device-posture-assessment-in-zero-trust

39

implementing-nerc-cip-compliance-controls

39

implementing-conduit-security-for-ot-remote-access

39

implementing-zero-trust-dns-with-nextdns

39

implementing-syslog-centralization-with-rsyslog

39

implementing-canary-tokens-for-network-intrusion

39

performing-ioc-enrichment-automation

39

implementing-honeypot-for-ransomware-detection

39

implementing-zero-trust-network-access-with-zscaler

38

implementing-conditional-access-policies-azure-ad

38

performing-file-carving-with-foremost

38

implementing-ics-firewall-with-tofino

37

implementing-security-monitoring-with-datadog

37

performing-access-recertification-with-saviynt

37

performing-insider-threat-investigation

37

implementing-purdue-model-network-segmentation

37

implementing-ticketing-system-for-incidents

37

implementing-data-loss-prevention-with-microsoft-purview

36

implementing-honeytokens-for-breach-detection

36

implementing-bgp-security-with-rpki

36

implementing-ransomware-kill-switch-detection

36

escaping-containers-to-host

36

implementing-soar-playbook-with-palo-alto-xsoar

36

implementing-diamond-model-analysis

35

exploiting-adcs-with-certipy

35

implementing-just-in-time-access-provisioning

35

implementing-disk-encryption-with-bitlocker

35

implementing-identity-governance-with-sailpoint

34

implementing-proofpoint-email-security-gateway

34

implementing-dragos-platform-for-ot-monitoring

34

implementing-usb-device-control-policy

34

implementing-taxii-server-with-opentaxii

34

implementing-log-integrity-with-blockchain

34

implementing-zero-trust-with-beyondcorp

34

implementing-iec-62443-security-zones

34

performing-indicator-lifecycle-management

34

implementing-deception-based-detection-with-canarytoken

34

implementing-scim-provisioning-with-okta

33

implementing-stix-taxii-feed-integration

33

implementing-log-forwarding-with-fluentd

33

implementing-soar-automation-with-phantom

33

implementing-mimecast-targeted-attack-protection

33

monitoring-scada-modbus-traffic-anomalies

33

hunting-saas-sso-token-abuse

33

implementing-ebpf-security-monitoring

33

implementing-velociraptor-for-ir-collection

32

performing-ics-asset-discovery-with-claroty

32

triaging-windows-with-kape

32

exploiting-aws-with-pacu

32

implementing-memory-protection-with-dep-aslr

31

validating-tpm-measured-boot-attestation

31

implementing-security-information-sharing-with-stix2

31

implementing-microsegmentation-with-guardicore

31

detecting-typosquatting-packages

31

implementing-runtime-security-with-tetragon

31

detecting-secure-boot-bypass

30

mapping-attack-paths-with-bloodhound-ce

30

migrating-to-post-quantum-cryptography

30

deploying-cloud-deception-with-decoy-resources

30

post-exploiting-microsoft-graph-with-graphrunner

30

detecting-container-runtime-threats-with-falco

29

enumerating-cloud-with-cloudfox

29

implementing-hipaa-security-rule-safeguards

28

moving-laterally-with-netexec

27

detecting-data-and-model-poisoning

26

detecting-entra-offensive-tools-in-graph-logs

26

orchestrating-llm-attacks-with-pyrit

26

executing-nist-rmf-authorization-to-operate

26

hunting-evtx-with-chainsaw

26

relaying-ntlm-for-adcs-esc8

25

designing-adversary-engagement-with-mitre-engage

25

operating-sliver-c2

25

detecting-model-extraction-attacks

23

generating-forensic-timelines-with-hayabusa

23

managing-third-party-vendor-risk

22

parsing-artifacts-with-eric-zimmerman-tools

21

hunting-bootkits-in-efi-system-partition

21

modeling-threats-with-opencti

20

deploying-honeytokens-and-canarytokens

20

operating-havoc-c2

19

fleet-hunting-with-velociraptor

16

analyzing-cobalt-strike-malleable-profiles

15

operationalizing-misp-threat-feeds

15

building-cloud-security-posture-management

13

analyzing-phishing-email-headers

13

conducting-mobile-application-penetration-test

12

conducting-cloud-infrastructure-penetration-test

11

auditing-kubernetes-rbac-permissions

8

performing-cloud-penetration-testing

6

containing-active-security-breach

5

detecting-cloud-cryptomining-activity

3

hunting-living-off-the-land-binaries

3

performing-ransomware-incident-response

3

implementing-threat-intelligence-platform

2

implementing-rbac-for-kubernetes-cluster

2

hunting-for-webshells-in-web-servers

2

detecting-golden-ticket-attacks

2

executing-diamond-model-analysis

2