mukul975/anthropic-cybersecurity-skills
Skill
Installs
analyzing-api-gateway-access-logs
670
acquiring-disk-image-with-dd-and-dcfldd
615
analyzing-android-malware-with-apktool
564
analyzing-cyber-kill-chain
546
analyzing-email-headers-for-phishing-investigation
535
analyzing-browser-forensics-with-hindsight
532
analyzing-docker-container-forensics
515
conducting-api-security-testing
512
testing-api-security-with-owasp-top-10
511
analyzing-cloud-storage-access-patterns
507
analyzing-active-directory-acl-abuse
498
analyzing-certificate-transparency-for-phishing
496
analyzing-dns-logs-for-exfiltration
489
analyzing-apt-group-with-mitre-navigator
482
performing-web-application-penetration-test
471
analyzing-command-and-control-communication
469
analyzing-linux-audit-logs-for-intrusion
460
testing-for-xss-vulnerabilities
453
analyzing-network-traffic-with-wireshark
453
analyzing-bootkit-and-rootkit-samples
438
analyzing-azure-activity-logs-for-threats
436
analyzing-indicators-of-compromise
420
analyzing-campaign-attribution-evidence
415
analyzing-disk-image-with-autopsy
406
analyzing-linux-system-artifacts
404
analyzing-linux-kernel-rootkits
402
testing-api-for-broken-object-level-authorization
401
analyzing-linux-elf-malware
400
analyzing-ios-app-security-with-objection
398
analyzing-network-packets-with-scapy
396
testing-jwt-token-security
394
exploiting-sql-injection-vulnerabilities
394
analyzing-network-traffic-for-incidents
392
analyzing-golang-malware-with-ghidra
386
analyzing-network-traffic-of-malware
384
analyzing-malicious-url-with-urlscan
384
analyzing-cobaltstrike-malleable-c2-profiles
383
analyzing-kubernetes-audit-logs
377
testing-api-authentication-weaknesses
376
abusing-dpapi-for-credential-access
375
analyzing-cobalt-strike-beacon-configuration
373
analyzing-ethereum-smart-contract-vulnerabilities
367
analyzing-sbom-for-supply-chain-vulnerabilities
364
analyzing-web-server-logs-for-intrusion
363
testing-for-broken-access-control
355
analyzing-malicious-pdf-with-peepdf
350
testing-for-json-web-token-vulnerabilities
348
analyzing-heap-spray-exploitation
345
testing-cors-misconfiguration
344
analyzing-network-covert-channels-in-malware
343
analyzing-network-flow-data-with-netflow
343
reverse-engineering-android-malware-with-jadx
335
analyzing-malware-sandbox-evasion-techniques
329
analyzing-malware-behavior-with-cuckoo-sandbox
326
analyzing-memory-dumps-with-volatility
325
performing-web-application-vulnerability-triage
323
analyzing-malware-family-relationships-with-malpedia
318
analyzing-malware-persistence-with-autoruns
318
analyzing-lnk-file-and-jump-list-artifacts
316
analyzing-macro-malware-in-office-documents
313
testing-api-for-mass-assignment-vulnerability
304
analyzing-pdf-malware-with-pdfid
302
testing-for-sensitive-data-exposure
296
analyzing-memory-forensics-with-lime-and-volatility
296
analyzing-threat-intelligence-feeds
296
analyzing-powershell-script-block-logging
294
analyzing-mft-for-deleted-file-recovery
294
analyzing-ransomware-network-indicators
292
analyzing-threat-actor-ttps-with-mitre-attack
290
analyzing-persistence-mechanisms-in-linux
289
testing-oauth2-implementation-flaws
288
analyzing-ransomware-encryption-mechanisms
288
exploiting-idor-vulnerabilities
286
bypassing-authentication-with-forced-browsing
286
analyzing-outlook-pst-for-email-forensics
285
analyzing-ransomware-leak-site-intelligence
284
conducting-external-reconnaissance-with-osint
282
analyzing-office365-audit-logs-for-compromise
282
analyzing-powershell-empire-artifacts
280
testing-websocket-api-security
278
testing-for-business-logic-vulnerabilities
275
auditing-aws-s3-bucket-permissions
275
testing-for-xxe-injection-vulnerabilities
272
testing-for-xss-vulnerabilities-with-burpsuite
269
exploiting-sql-injection-with-sqlmap
269
analyzing-packed-malware-with-upx-unpacker
269
conducting-network-penetration-test
267
testing-for-open-redirect-vulnerabilities
266
analyzing-supply-chain-malware-artifacts
266
exploiting-api-injection-vulnerabilities
261
analyzing-tls-certificate-transparency-logs
259
analyzing-threat-actor-ttps-with-mitre-navigator
259
analyzing-security-logs-with-splunk
258
abusing-shadow-credentials-for-privesc
257
testing-for-host-header-injection
256
analyzing-prefetch-files-for-execution-history
254
implementing-secret-scanning-with-gitleaks
252
analyzing-typosquatting-domains-with-dnstwist
250
conducting-mobile-app-penetration-test
250
auditing-terraform-infrastructure-for-security
248
performing-web-application-firewall-bypass
247
auditing-kubernetes-cluster-rbac
246
building-incident-response-playbook
245
analyzing-ransomware-payment-wallets
245
performing-web-application-scanning-with-nikto
244
implementing-api-rate-limiting-and-throttling
244
achieving-cmmc-level-2-compliance
244
analyzing-threat-landscape-with-misp
242
auditing-cloud-with-cis-benchmarks
240
analyzing-windows-event-logs-in-splunk
238
exploiting-server-side-request-forgery
238
exploiting-jwt-algorithm-confusion-attack
235
collecting-open-source-intelligence
235
building-vulnerability-scanning-workflow
235
testing-for-xml-injection-vulnerabilities
230
performing-security-headers-audit
227
exploiting-websocket-vulnerabilities
226
conducting-cloud-penetration-testing
226
analyzing-windows-registry-for-artifacts
225
analyzing-usb-device-connection-history
225
analyzing-slack-space-and-file-system-artifacts
224
testing-mobile-api-authentication
223
hardening-docker-containers-for-production
222
auditing-azure-active-directory-configuration
221
analyzing-windows-prefetch-with-python
220
detecting-ai-model-prompt-injection-attacks
217
auditing-gcp-iam-permissions
214
exploiting-broken-function-level-authorization
214
analyzing-windows-lnk-files-for-artifacts
213
auditing-tls-certificate-transparency-logs
212
exploiting-nosql-injection-vulnerabilities
212
conducting-full-scope-red-team-engagement
210
exploiting-http-request-smuggling
210
testing-for-email-header-injection
210
analyzing-windows-amcache-artifacts
208
automating-ioc-enrichment
208
building-attack-pattern-library-from-cti-reports
207
performing-csrf-attack-simulation
206
exploiting-oauth-misconfiguration
205
building-devsecops-pipeline-with-gitlab-ci
204
performing-ssrf-vulnerability-exploitation
204
detecting-api-enumeration-attacks
204
analyzing-windows-shellbag-artifacts
203
exploiting-template-injection-vulnerabilities
201
performing-api-rate-limiting-bypass
201
performing-web-cache-poisoning-attack
201
configuring-oauth2-authorization-flow
200
performing-web-cache-deception-attack
199
exploiting-race-condition-vulnerabilities
199
analyzing-uefi-bootkit-persistence
196
exploiting-mass-assignment-in-rest-apis
196
building-adversary-infrastructure-tracking-system
195
conducting-internal-network-penetration-test
195
building-c2-infrastructure-with-sliver-framework
194
implementing-api-schema-validation-security
193
exploiting-insecure-deserialization
193
performing-api-security-testing-with-postman
192
building-incident-response-dashboard
191
scanning-network-with-nmap-advanced
189
building-threat-actor-profile-from-osint
185
performing-threat-modeling-with-owasp-threat-dragon
185
implementing-api-key-security-controls
184
building-vulnerability-dashboard-with-defectdojo
183
building-soc-escalation-matrix
183
building-automated-malware-submission-pipeline
181
exploiting-excessive-data-exposure-in-api
181
building-detection-rules-with-sigma
180
building-soc-metrics-and-kpi-tracking
177
exploiting-prototype-pollution-in-javascript
177
building-soc-playbook-for-ransomware
177
building-threat-intelligence-platform
175
implementing-jwt-signing-and-verification
174
building-red-team-c2-infrastructure-with-havoc
174
building-cloud-siem-with-sentinel
173
building-detection-rule-with-splunk-spl
172
deobfuscating-javascript-malware
172
building-threat-intelligence-feed-integration
169
building-vulnerability-exception-tracking-system
169
performing-sca-dependency-scanning-with-snyk
167
scanning-docker-images-with-trivy
166
performing-api-inventory-and-discovery
165
building-malware-incident-communication-template
165
conducting-wireless-network-penetration-test
165
building-incident-timeline-with-timesketch
163
building-threat-hunt-hypothesis-framework
162
collecting-threat-intelligence-with-misp
162
building-ransomware-playbook-with-cisa-framework
162
building-identity-governance-lifecycle-process
161
collecting-indicators-of-compromise
161
building-vulnerability-aging-and-sla-tracking
161
auditing-mcp-servers-for-tool-poisoning
161
securing-github-actions-workflows
161
conducting-phishing-incident-response
159
conducting-cloud-incident-response
158
detecting-sql-injection-via-waf-logs
157
triaging-security-incident
157
performing-api-fuzzing-with-restler
155
conducting-man-in-the-middle-attack-simulation
155
building-phishing-reporting-button-workflow
154
conducting-internal-reconnaissance-with-bloodhound-ce
153
building-ioc-enrichment-pipeline-with-opencti
153
building-identity-federation-with-saml-azure-ad
152
implementing-api-gateway-security-controls
151
reverse-engineering-malware-with-ghidra
150
building-role-mining-for-rbac-optimization
150
building-threat-intelligence-enrichment-in-splunk
150
detecting-broken-object-property-level-authorization
150
building-ioc-defanging-and-sharing-pipeline
149
implementing-api-abuse-detection-with-rate-limiting
149
configuring-tls-1-3-for-secure-communications
147
exploiting-type-juggling-vulnerabilities
146
building-threat-feed-aggregation-with-misp
146
conducting-social-engineering-penetration-test
144
implementing-devsecops-security-scanning
142
exploiting-insecure-data-storage-in-mobile
142
detecting-shadow-api-endpoints
142
exploiting-vulnerabilities-with-metasploit-framework
140
performing-wifi-password-cracking-with-aircrack
138
exploiting-broken-link-hijacking
138
performing-jwt-none-algorithm-attack
138
attacking-oauth-with-device-code-phishing
138
implementing-secrets-scanning-in-ci-cd
138
testing-android-intents-for-vulnerabilities
137
performing-second-order-sql-injection
137
collecting-volatile-evidence-from-compromised-host
136
conducting-pass-the-ticket-attack
136
conducting-domain-persistence-with-dcsync
136
building-patch-tuesday-response-process
136
executing-red-team-exercise
135
exploiting-deeplink-vulnerabilities
135
reverse-engineering-ios-app-with-frida
134
conducting-malware-incident-response
134
implementing-api-security-posture-management
133
performing-graphql-security-assessment
132
executing-red-team-engagement-planning
132
performing-subdomain-enumeration-with-subfinder
129
performing-directory-traversal-testing
127
detecting-oauth-token-theft
127
performing-vulnerability-scanning-with-nessus
125
performing-ssl-tls-security-assessment
125
performing-blind-ssrf-exploitation
123
conducting-memory-forensics-with-volatility
123
implementing-api-security-testing-with-42crunch
122
triaging-vulnerabilities-with-ssvc-framework
122
hardening-docker-daemon-configuration
122
exploiting-smb-vulnerabilities-with-metasploit
121
configuring-network-segmentation-with-vlans
121
assessing-vector-and-embedding-weaknesses
121
detecting-anomalous-authentication-patterns
120
configuring-pfsense-firewall-rules
120
integrating-dast-with-owasp-zap-in-pipeline
119
scanning-containers-with-trivy-in-cicd
118
conducting-post-incident-lessons-learned
117
deobfuscating-powershell-obfuscated-malware
117
integrating-sast-into-github-actions-pipeline
117
implementing-semgrep-for-custom-sast-rules
116
performing-clickjacking-attack-test
115
conducting-spearphishing-simulation-campaign
114
auditing-kubernetes-rbac-privilege-escalation
113
triaging-security-incident-with-ir-playbook
113
performing-content-security-policy-bypass
112
validating-backup-integrity-for-recovery
112
securing-api-gateway-with-aws-waf
112
detecting-aws-credential-exposure-with-trufflehog
112
hardening-linux-endpoint-with-cis-benchmark
111
detecting-supply-chain-attacks-in-ci-cd
110
testing-ransomware-recovery-procedures
110
exploiting-ipv6-vulnerabilities
109
performing-graphql-introspection-attack
109
reverse-engineering-dotnet-malware-with-dnspy
108
configuring-certificate-authority-with-openssl
108
performing-osint-with-spiderfoot
107
implementing-web-application-logging-with-modsecurity
107
performing-http-parameter-pollution-attack
107
attacking-entra-id-with-roadtools
106
performing-soc2-type2-audit-preparation
105
conducting-social-engineering-pretext-call
105
performing-android-app-static-analysis-with-mobsf
105
exploiting-zerologon-vulnerability-cve-2020-1472
105
performing-network-traffic-analysis-with-tshark
104
exploiting-active-directory-with-bloodhound
104
tracking-threat-actor-infrastructure
104
detecting-attacks-on-scada-systems
104
monitoring-darkweb-sources
103
configuring-host-based-intrusion-detection
103
hunting-for-webshell-activity
103
prioritizing-vulnerabilities-with-cvss-scoring
103
performing-oauth-scope-minimization-review
102
performing-cryptographic-audit-of-application
101
securing-serverless-functions
100
configuring-suricata-for-network-monitoring
100
auditing-entra-id-with-aadinternals
100
extracting-browser-history-artifacts
100
performing-open-source-intelligence-gathering
100
performing-graphql-depth-limit-attack
100
configuring-ldap-security-hardening
99
performing-authenticated-vulnerability-scan
99
implementing-api-threat-protection-with-apigee
99
securing-aws-iam-permissions
99
exploiting-kerberoasting-with-impacket
99
benchmarking-kubernetes-with-kube-bench
99
exploiting-active-directory-certificate-services-esc1
99
configuring-windows-defender-advanced-settings
98
scanning-container-images-with-grype
97
performing-wireless-network-penetration-test
97
exploiting-bgp-hijacking-vulnerabilities
97
performing-network-packet-capture-analysis
97
extracting-credentials-from-memory-dump
97
performing-network-forensics-with-wireshark
96
performing-ai-driven-osint-correlation
96
auditing-foundry-smart-contract-security
96
detecting-dependency-confusion
96
securing-container-registry-images
96
performing-container-image-hardening
95
triaging-security-alerts-in-splunk
95
configuring-windows-event-logging-for-detection
95
performing-privilege-escalation-on-linux
94
building-c2-redirector-infrastructure
94
performing-container-security-scanning-with-trivy
94
performing-dark-web-monitoring-for-threats
94
implementing-gdpr-data-protection-controls
93
exploiting-nopac-cve-2021-42278-42287
93
testing-prompt-injection-in-rag-pipelines
93
detecting-typosquatting-packages-in-npm-pypi
93
performing-soap-web-service-security-testing
93
conducting-cyber-risk-assessment-with-nist-800-30
92
performing-mobile-app-certificate-pinning-bypass
92
deploying-cloudflare-access-for-zero-trust
91
detecting-email-account-compromise
91
hunting-credential-stuffing-attacks
91
performing-wireless-security-assessment-with-kismet
91
implementing-llm-guardrails-for-security
91
reverse-engineering-rust-malware
90
performing-sqlite-database-forensics
90
implementing-github-advanced-security-for-code-scanning
89
auditing-uefi-firmware-with-chipsec
89
exploiting-ms17-010-eternalblue-vulnerability
88
remediating-s3-bucket-misconfiguration
88
configuring-microsegmentation-for-zero-trust
88
intercepting-mobile-traffic-with-burpsuite
88
containing-active-breach
88
performing-privilege-escalation-assessment
87
generating-threat-intelligence-reports
87
detecting-credential-dumping-techniques
87
performing-kubernetes-penetration-testing
87
performing-ssl-certificate-lifecycle-management
87
securing-kubernetes-on-cloud
86
detecting-s3-data-exfiltration-attempts
86
detecting-aws-iam-privilege-escalation
86
exploiting-constrained-delegation-abuse
85
detecting-aws-cloudtrail-anomalies
85
detecting-network-scanning-with-ids-signatures
85
detecting-business-email-compromise
85
scanning-kubernetes-manifests-with-kubesec
85
performing-ssl-tls-inspection-configuration
85
configuring-active-directory-tiered-model
84
performing-docker-bench-security-assessment
84
performing-dns-enumeration-and-zone-transfer
84
detecting-compromised-cloud-credentials
84
hardening-windows-endpoint-with-cis-benchmark
84
detecting-privilege-escalation-attempts
84
performing-active-directory-penetration-test
84
configuring-multi-factor-authentication-with-duo
84
implementing-aes-encryption-for-data-at-rest
83
detecting-malicious-npm-packages
83
reverse-engineering-ransomware-encryption-routine
83
securing-aws-lambda-execution-roles
82
configuring-hsm-for-key-storage
82
configuring-snort-ids-for-intrusion-detection
82
performing-hash-cracking-with-hashcat
82
testing-for-system-prompt-leakage
82
deploying-tailscale-for-zero-trust-vpn
82
scanning-infrastructure-with-nessus
81
implementing-cloud-waf-rules
81
securing-remote-access-to-ot-environment
81
hunting-advanced-persistent-threats
81
performing-external-network-penetration-test
80
configuring-aws-verified-access-for-ztna
80
performing-privileged-account-discovery
80
detecting-pass-the-hash-attacks
80
detecting-arp-poisoning-in-network-traffic
80
performing-cloud-penetration-testing-with-pacu
79
detecting-suspicious-oauth-application-consent
79
detecting-container-escape-attempts
79
detecting-dns-exfiltration-with-dns-query-analysis
78
performing-red-team-phishing-with-gophish
78
detecting-email-forwarding-rules-attack
78
performing-ios-app-security-assessment
78
performing-ssl-stripping-attack
78
correlating-threat-campaigns
77
mapping-mitre-attack-techniques
76
performing-memory-forensics-with-volatility3
76
performing-privacy-impact-assessment
76
detecting-indirect-prompt-injection
76
executing-phishing-simulation-campaign
76
performing-privileged-account-access-review
75
configuring-identity-aware-proxy-with-google-iap
75
hunting-for-unusual-network-connections
75
performing-agentless-vulnerability-scanning
75
implementing-attack-surface-management
75
detecting-port-scanning-with-fail2ban
74
securing-container-registry-with-harbor
74
detecting-lateral-movement-in-network
74
performing-active-directory-vulnerability-assessment
74
implementing-secrets-management-with-vault
74
performing-cve-prioritization-with-kev-catalog
74
performing-serverless-function-security-review
73
detecting-process-injection-techniques
73
securing-helm-chart-deployments
72
detecting-anomalies-in-industrial-control-systems
72
deploying-ransomware-canary-files
72
performing-mobile-device-forensics-with-cellebrite
72
extracting-windows-event-logs-artifacts
71
performing-threat-hunting-with-elastic-siem
71
performing-authenticated-scan-with-openvas
71
performing-endpoint-vulnerability-remediation
71
performing-arp-spoofing-attack-simulation
71
detecting-qr-code-phishing-with-email-security
70
continuous-llm-red-teaming-with-promptfoo
70
detecting-serverless-function-injection
70
detecting-container-drift-at-runtime
70
building-super-timelines-with-plaso
70
detecting-business-email-compromise-with-ai
70
performing-red-team-with-covenant
69
implementing-network-access-control
69
performing-dynamic-analysis-of-android-app
69
detecting-aws-guardduty-findings-automation
69
performing-nist-csf-maturity-assessment
69
performing-threat-hunting-with-yara-rules
69
performing-binary-exploitation-analysis
69
detecting-cloud-threats-with-guardduty
68
performing-network-traffic-analysis-with-zeek
68
coercing-authentication-with-coercer-petitpotam
68
implementing-infrastructure-as-code-security-scanning
68
hunting-for-supply-chain-compromise
68
performing-ot-vulnerability-scanning-safely
68
performing-endpoint-forensics-investigation
68
performing-threat-emulation-with-atomic-red-team
67
detecting-insider-threat-behaviors
67
detecting-attacks-on-historian-servers
67
performing-thick-client-application-penetration-test
67
implementing-zero-trust-for-saas-applications
67
detecting-azure-storage-account-misconfigurations
67
implementing-pci-dss-compliance-controls
67
performing-linux-log-forensics-investigation
67
performing-aws-privilege-escalation-assessment
67
executing-active-directory-attack-simulation
67
detecting-cryptomining-in-cloud
67
performing-packet-injection-attack
67
performing-active-directory-bloodhound-analysis
67
implementing-threat-modeling-with-mitre-attack
66
performing-ot-vulnerability-assessment-with-claroty
66
hunting-for-data-exfiltration-indicators
66
detecting-mobile-malware-behavior
66
detecting-rootkit-activity
66
performing-dns-tunneling-detection
66
detecting-command-and-control-over-dns
66
detecting-pass-the-ticket-attacks
66
detecting-container-escape-with-falco-rules
66
implementing-network-segmentation-with-firewall-zones
66
implementing-gdpr-data-subject-access-request
66
investigating-phishing-email-incident
66
detecting-kerberoasting-attacks
66
extracting-iocs-from-malware-samples
66
performing-phishing-simulation-with-gophish
65
implementing-dmarc-dkim-spf-email-security
65
detecting-dll-sideloading-attacks
65
hunting-for-dns-based-persistence
65
performing-purple-team-exercise
65
implementing-aws-iam-permission-boundaries
65
performing-supply-chain-attack-simulation
65
detecting-deepfake-audio-in-vishing-attacks
65
securing-historian-server-in-ot-environment
65
hunting-for-anomalous-powershell-execution
65
performing-cloud-asset-inventory-with-cartography
64
implementing-aqua-security-for-container-scanning
64
performing-yara-rule-development-for-detection
64
implementing-kubernetes-pod-security-standards
64
detecting-privilege-escalation-in-kubernetes-pods
64
hunting-for-unusual-service-installations
64
performing-ransomware-response
64
detecting-azure-service-principal-abuse
63
implementing-ddos-mitigation-with-cloudflare
63
performing-service-account-credential-rotation
63
implementing-cloud-vulnerability-posture-management
63
performing-aws-account-enumeration-with-scout-suite
63
implementing-endpoint-detection-with-wazuh
63
implementing-zero-trust-network-access
63
performing-steganography-detection
63
detecting-golden-ticket-attacks-in-kerberos-logs
63
implementing-aws-config-rules-for-compliance
63
performing-asset-criticality-scoring-for-vulns
63
detecting-network-anomalies-with-zeek
63
verifying-build-provenance-with-slsa-sigstore
63
performing-windows-artifact-analysis-with-eric-zimmerman-tools
62
detecting-shadow-it-cloud-usage
62
detecting-fileless-attacks-on-endpoints
62
performing-vlan-hopping-attack
62
detecting-dcsync-attack-in-active-directory
62
performing-log-analysis-for-forensic-investigation
62
performing-container-escape-detection
62
hunting-for-process-injection-techniques
62
performing-purple-team-atomic-testing
61
performing-cloud-log-forensics-with-athena
61
correlating-security-events-in-qradar
61
detecting-rdp-brute-force-attacks
61
performing-cloud-forensics-investigation
61
detecting-service-account-abuse
61
performing-user-behavior-analytics
61
securing-azure-with-microsoft-defender
61
performing-malware-triage-with-yara
61
implementing-hashicorp-vault-dynamic-secrets
60
detecting-suspicious-powershell-execution
60
performing-plc-firmware-security-analysis
60
implementing-zero-trust-in-cloud
60
performing-service-account-audit
60
performing-threat-landscape-assessment-for-sector
60
performing-firmware-malware-analysis
60
detecting-azure-lateral-movement
60
performing-lateral-movement-with-wmiexec
60
performing-ip-reputation-analysis-with-shodan
60
hunting-for-command-and-control-beaconing
60
hunting-for-dns-tunneling-with-zeek
60
detecting-ransomware-precursors-in-network
60
recovering-from-ransomware-attack
59
configuring-zscaler-private-access-for-ztna
59
profiling-threat-actor-groups
59
performing-malware-hash-enrichment-with-virustotal
59
implementing-network-policies-for-kubernetes
59
detecting-fileless-malware-techniques
59
performing-ot-network-security-assessment
59
deploying-active-directory-honeytokens
59
performing-kubernetes-cis-benchmark-with-kube-bench
59
detecting-modbus-command-injection-attacks
59
performing-power-grid-cybersecurity-assessment
58
deploying-osquery-for-endpoint-monitoring
58
hunting-for-living-off-the-cloud-techniques
58
performing-cloud-native-threat-hunting-with-aws-detective
58
performing-ransomware-tabletop-exercise
58
detecting-bluetooth-low-energy-attacks
58
detecting-ransomware-encryption-behavior
58
detecting-process-hollowing-technique
58
implementing-code-signing-for-artifacts
58
implementing-container-image-minimal-base-with-distroless
57
performing-cloud-native-forensics-with-falco
57
deploying-software-defined-perimeter
57
implementing-pam-for-database-access
57
deploying-palo-alto-prisma-access-zero-trust
57
extracting-memory-artifacts-with-rekall
57
implementing-aws-security-hub-compliance
57
hunting-for-persistence-mechanisms-in-windows
57
performing-cloud-forensics-with-aws-cloudtrail
57
performing-post-quantum-cryptography-migration
57
performing-threat-intelligence-sharing-with-misp
57
detecting-living-off-the-land-attacks
57
implementing-cloud-security-posture-management
57
performing-timeline-reconstruction-with-plaso
57
performing-gcp-penetration-testing-with-gcpbucketbrute
57
detecting-golden-ticket-forgery
56
implementing-network-intrusion-prevention-with-suricata
56
implementing-attack-path-analysis-with-xm-cyber
56
performing-credential-access-with-lazagne
56
hunting-for-suspicious-scheduled-tasks
56
implementing-mitre-attack-coverage-mapping
56
performing-firmware-extraction-with-binwalk
56
implementing-aws-security-hub
56
performing-cloud-storage-forensic-acquisition
56
deploying-decoy-files-for-ransomware-detection
56
hunting-for-spearphishing-indicators
55
detecting-exfiltration-over-dns-with-zeek
55
detecting-living-off-the-land-with-lolbas
55
deploying-edr-agent-with-crowdstrike
55
performing-kubernetes-etcd-security-assessment
55
implementing-passwordless-authentication-with-fido2
55
performing-malware-ioc-extraction
55
implementing-ransomware-backup-strategy
55
implementing-vulnerability-management-with-greenbone
55
performing-adversary-in-the-middle-phishing-detection
55
hunting-for-cobalt-strike-beacons
55
hunting-for-domain-fronting-c2-traffic
55
performing-soc-tabletop-exercise
55
performing-static-malware-analysis-with-pe-studio
55
implementing-google-workspace-phishing-protection
55
detecting-insider-threat-with-ueba
55
hunting-for-data-staging-before-exfiltration
55
performing-physical-intrusion-assessment
55
scanning-iac-and-images-with-trivy
55
performing-disk-forensics-investigation
55
performing-kerberoasting-attack
54
hunting-for-ntlm-relay-attacks
54
performing-malware-persistence-investigation
54
implementing-kubernetes-network-policy-with-calico
54
performing-fuzzing-with-aflplusplus
54
performing-memory-forensics-with-volatility3-plugins
54
implementing-anti-phishing-training-program
54
performing-cloud-incident-containment-procedures
54
implementing-end-to-end-encryption-for-messaging
54
hunting-for-registry-run-key-persistence
54
hunting-for-scheduled-task-persistence
53
implementing-passwordless-auth-with-microsoft-entra
53
investigating-ransomware-attack-artifacts
53
securing-agentic-ai-tool-invocation
53
implementing-digital-signatures-with-ed25519
53
performing-false-positive-reduction-in-siem
53
implementing-iso-27001-information-security-management
53
detecting-lateral-movement-with-splunk
53
performing-active-directory-compromise-investigation
53
detecting-ntlm-relay-with-event-correlation
53
detecting-malicious-scheduled-tasks-with-sysmon
53
performing-paste-site-monitoring-for-credentials
53
hunting-for-lolbins-execution-in-endpoint-logs
53
evaluating-threat-intelligence-platforms
53
implementing-zero-knowledge-proof-for-authentication
53
hunting-for-lateral-movement-via-wmi
53
hunting-for-registry-persistence-mechanisms
53
implementing-vulnerability-remediation-sla
52
implementing-google-workspace-admin-security
52
implementing-privileged-session-monitoring
52
hunting-for-shadow-copy-deletion
52
detecting-insider-data-exfiltration-via-dlp
52
implementing-gcp-vpc-firewall-rules
52
implementing-supply-chain-security-with-in-toto
52
eradicating-malware-from-infected-systems
52
implementing-google-workspace-sso-configuration
51
performing-oil-gas-cybersecurity-assessment
51
implementing-rbac-hardening-for-kubernetes
51
detecting-spearphishing-with-email-gateway
51
implementing-network-traffic-analysis-with-arkime
51
hunting-for-dcsync-attacks
51
implementing-network-traffic-baselining
51
performing-active-directory-forest-trust-attack
51
extracting-config-from-agent-tesla-rat
50
performing-scada-hmi-security-assessment
50
hunting-for-persistence-via-wmi-subscriptions
50
implementing-mobile-application-management
50
implementing-hardware-security-key-authentication
50
detecting-beaconing-patterns-with-zeek
50
detecting-dnp3-protocol-anomalies
50
generating-and-analyzing-sboms
50
hunting-for-dcom-lateral-movement
50
detecting-evasion-techniques-in-endpoint-logs
50
detecting-stuxnet-style-attacks
50
defending-llms-with-guardrails
50
implementing-anti-ransomware-group-policy
50
implementing-network-access-control-with-cisco-ise
49
performing-bluetooth-security-assessment
49
implementing-cloud-dlp-for-data-protection
49
red-teaming-llms-with-garak
49
hunting-for-beaconing-with-frequency-analysis
49
implementing-fuzz-testing-in-cicd-with-aflplusplus
48
implementing-network-segmentation-for-ot
48
detecting-mimikatz-execution-patterns
48
implementing-alert-fatigue-reduction
48
hunting-for-startup-folder-persistence
48
hunting-for-living-off-the-land-binaries
48
implementing-envelope-encryption-with-aws-kms
48
recovering-deleted-files-with-photorec
48
implementing-cloud-trail-log-analysis
47
performing-gcp-security-assessment-with-forseti
47
implementing-pod-security-admission-controller
47
implementing-rsa-key-pair-management
47
detecting-modbus-protocol-anomalies
47
implementing-epss-score-for-vulnerability-prioritization
47
implementing-policy-as-code-with-open-policy-agent
47
detecting-wmi-persistence
47
detecting-t1003-credential-dumping-with-edr
47
hunting-for-defense-evasion-via-timestomping
47
managing-cloud-identity-with-okta
47
performing-brand-monitoring-for-impersonation
47
detecting-misconfigured-azure-storage
47
performing-automated-malware-analysis-with-cape
47
investigating-insider-threat-indicators
46
implementing-vulnerability-sla-breach-alerting
46
implementing-azure-defender-for-cloud
46
implementing-threat-intelligence-lifecycle-management
46
implementing-privileged-access-workstation
46
performing-dmarc-policy-enforcement-rollout
46
performing-dynamic-analysis-with-any-run
46
detecting-t1055-process-injection-with-sysmon
45
implementing-application-whitelisting-with-applocker
45
implementing-aws-macie-for-data-classification
45
implementing-siem-use-cases-for-detection
45
performing-lateral-movement-detection
45
implementing-cloud-workload-protection
45
detecting-lateral-movement-with-zeek
45
detecting-t1548-abuse-elevation-control-mechanism
45
implementing-patch-management-workflow
45
implementing-ot-incident-response-playbook
45
performing-iot-security-assessment
45
implementing-azure-ad-privileged-identity-management
45
implementing-gcp-binary-authorization
45
implementing-privileged-access-management-with-cyberark
44
implementing-next-generation-firewall-with-palo-alto
44
implementing-mtls-for-zero-trust-services
44
implementing-network-deception-with-honeypots
44
processing-stix-taxii-feeds
44
implementing-aws-nitro-enclave-security
44
implementing-ot-network-traffic-analysis-with-nozomi
44
implementing-file-integrity-monitoring-with-aide
43
performing-bandwidth-throttling-attack-simulation
43
implementing-saml-sso-with-okta
43
hunting-for-t1098-account-manipulation
43
performing-alert-triage-with-elastic-siem
43
implementing-opa-gatekeeper-for-policy-enforcement
43
implementing-image-provenance-verification-with-cosign
43
implementing-immutable-backup-with-restic
42
implementing-sigstore-for-software-signing
42
performing-deception-technology-deployment
42
performing-log-source-onboarding-in-siem
42
implementing-soar-playbook-for-phishing
42
implementing-cisa-zero-trust-maturity-model
42
implementing-endpoint-dlp-controls
41
implementing-patch-management-for-ot-systems
41
performing-entitlement-review-with-sailpoint-iiq
41
implementing-siem-use-case-tuning
41
implementing-runtime-application-self-protection
41
implementing-security-chaos-engineering
41
implementing-container-network-policies-with-calico
41
implementing-identity-verification-for-zero-trust
41
implementing-siem-correlation-rules-for-apt
41
implementing-delinea-secret-server-for-pam
41
implementing-rapid7-insightvm-for-scanning
41
implementing-browser-isolation-for-zero-trust
41
performing-s7comm-protocol-security-analysis
41
performing-hardware-security-module-integration
41
implementing-email-sandboxing-with-proofpoint
41
performing-initial-access-with-evilginx3
41
implementing-continuous-security-validation-with-bas
41
implementing-zero-standing-privilege-with-cyberark
40
implementing-zero-trust-with-hashicorp-boundary
40
implementing-gcp-organization-policy-constraints
40
managing-intelligence-lifecycle
40
emulating-cloud-attacks-with-stratus-red-team
40
implementing-beyondcorp-zero-trust-access-model
40
performing-access-review-and-certification
39
implementing-device-posture-assessment-in-zero-trust
39
implementing-nerc-cip-compliance-controls
39
implementing-conduit-security-for-ot-remote-access
39
implementing-zero-trust-dns-with-nextdns
39
implementing-syslog-centralization-with-rsyslog
39
implementing-canary-tokens-for-network-intrusion
39
performing-ioc-enrichment-automation
39
implementing-honeypot-for-ransomware-detection
39
implementing-zero-trust-network-access-with-zscaler
38
implementing-conditional-access-policies-azure-ad
38
performing-file-carving-with-foremost
38
implementing-ics-firewall-with-tofino
37
implementing-security-monitoring-with-datadog
37
performing-access-recertification-with-saviynt
37
performing-insider-threat-investigation
37
implementing-purdue-model-network-segmentation
37
implementing-ticketing-system-for-incidents
37
implementing-data-loss-prevention-with-microsoft-purview
36
implementing-honeytokens-for-breach-detection
36
implementing-bgp-security-with-rpki
36
implementing-ransomware-kill-switch-detection
36
escaping-containers-to-host
36
implementing-soar-playbook-with-palo-alto-xsoar
36
implementing-diamond-model-analysis
35
exploiting-adcs-with-certipy
35
implementing-just-in-time-access-provisioning
35
implementing-disk-encryption-with-bitlocker
35
implementing-identity-governance-with-sailpoint
34
implementing-proofpoint-email-security-gateway
34
implementing-dragos-platform-for-ot-monitoring
34
implementing-usb-device-control-policy
34
implementing-taxii-server-with-opentaxii
34
implementing-log-integrity-with-blockchain
34
implementing-zero-trust-with-beyondcorp
34
implementing-iec-62443-security-zones
34
performing-indicator-lifecycle-management
34
implementing-deception-based-detection-with-canarytoken
34
implementing-scim-provisioning-with-okta
33
implementing-stix-taxii-feed-integration
33
implementing-log-forwarding-with-fluentd
33
implementing-soar-automation-with-phantom
33
implementing-mimecast-targeted-attack-protection
33
monitoring-scada-modbus-traffic-anomalies
33
hunting-saas-sso-token-abuse
33
implementing-ebpf-security-monitoring
33
implementing-velociraptor-for-ir-collection
32
performing-ics-asset-discovery-with-claroty
32
triaging-windows-with-kape
32
exploiting-aws-with-pacu
32
implementing-memory-protection-with-dep-aslr
31
validating-tpm-measured-boot-attestation
31
implementing-security-information-sharing-with-stix2
31
implementing-microsegmentation-with-guardicore
31
detecting-typosquatting-packages
31
implementing-runtime-security-with-tetragon
31
detecting-secure-boot-bypass
30
mapping-attack-paths-with-bloodhound-ce
30
migrating-to-post-quantum-cryptography
30
deploying-cloud-deception-with-decoy-resources
30
post-exploiting-microsoft-graph-with-graphrunner
30
detecting-container-runtime-threats-with-falco
29
enumerating-cloud-with-cloudfox
29
implementing-hipaa-security-rule-safeguards
28
moving-laterally-with-netexec
27
detecting-data-and-model-poisoning
26
detecting-entra-offensive-tools-in-graph-logs
26
orchestrating-llm-attacks-with-pyrit
26
executing-nist-rmf-authorization-to-operate
26
hunting-evtx-with-chainsaw
26
relaying-ntlm-for-adcs-esc8
25
designing-adversary-engagement-with-mitre-engage
25
operating-sliver-c2
25
detecting-model-extraction-attacks
23
generating-forensic-timelines-with-hayabusa
23
managing-third-party-vendor-risk
22
parsing-artifacts-with-eric-zimmerman-tools
21
hunting-bootkits-in-efi-system-partition
21
modeling-threats-with-opencti
20
deploying-honeytokens-and-canarytokens
20
operating-havoc-c2
19
fleet-hunting-with-velociraptor
16
analyzing-cobalt-strike-malleable-profiles
15
operationalizing-misp-threat-feeds
15
building-cloud-security-posture-management
13
analyzing-phishing-email-headers
13
conducting-mobile-application-penetration-test
12
conducting-cloud-infrastructure-penetration-test
11
auditing-kubernetes-rbac-permissions
8
performing-cloud-penetration-testing
6
containing-active-security-breach
5
detecting-cloud-cryptomining-activity
3
hunting-living-off-the-land-binaries
3
performing-ransomware-incident-response
3
implementing-threat-intelligence-platform
2
implementing-rbac-for-kubernetes-cluster
2
hunting-for-webshells-in-web-servers
2
detecting-golden-ticket-attacks
2
executing-diamond-model-analysis
2