Skip to main content
transilienceai
ملف منشئ GitHub

transilienceai

عرض على مستوى المستودعات لـ ١٣٩ skills مجمعة عبر ٤ مستودعات GitHub.

skills مجمعة
١٣٩
مستودعات
٤
محدث
٢٦ أغسطس ٢٠٢٦
مستكشف المستودعات

المستودعات و skills الممثلة

business-context-kb
غير مصنف

Apply organisation-specific criticality, ownership, consequence, and terminology while preserving customer corrections. Use when a Business Context workflow needs the know stage.

٢٢ أغسطس ٢٠٢٦
collect-business-context
غير مصنف

Collect organisation, application, owner, vendor, policy, architecture, and objective context from approved sources. Use when a Business Context workflow needs the collect stage.

٢٢ أغسطس ٢٠٢٦
model-business-portrait
غير مصنف

Model applications, resources, data, exposure, owners, vendors, objectives, and evidence provenance. Use when a Business Context workflow needs the model stage.

٢٢ أغسطس ٢٠٢٦
normalize-business-entities
غير مصنف

Normalize applications, people, vendors, documents, objectives, observations, inferences, and confirmations. Use when a Business Context workflow needs the normalize stage.

٢٢ أغسطس ٢٠٢٦
package-business-context
غير مصنف

Package the durable business portrait, confidence, confirmed corrections, gaps, and questions. Use when a Business Context workflow needs the package stage.

٢٢ أغسطس ٢٠٢٦
resolve-knowledge-gaps
غير مصنف

Ask only questions whose answers change a named scope, owner, obligation, priority, or decision. Use when a Business Context workflow needs the decide stage.

٢٢ أغسطس ٢٠٢٦
cloud-control-kb
غير مصنف

Apply versioned hardening, compliance, exposure, and provider-control knowledge. Use when a Cloud Assurance workflow needs the know stage.

٢٢ أغسطس ٢٠٢٦
collect-cloud-inventory
غير مصنف

Collect read-only cloud inventory with explicit account, region, service, and permission coverage. Use when a Cloud Assurance workflow needs the collect stage.

٢٢ أغسطس ٢٠٢٦
عرض 8 من أصل ٦٠ skills مجمعة.
ai-threat-testing
محللو أمن المعلومات

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to…

٢٩ يوليو ٢٠٢٦
cloud-containers
محللو أمن المعلومات

Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.

٢٩ يوليو ٢٠٢٦
pentest-engagement
المهن الحاسوبية الأخرى

Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation,…

٢٨ يوليو ٢٠٢٦
coordination
المهن الحاسوبية الأخرى

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

٢٨ يوليو ٢٠٢٦
transilience-report-style
محللو أمن المعلومات

Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. Use whenever an engagement needs its final report/deliverable PDF in Transilience house style.

٢٨ يوليو ٢٠٢٦
mobile-security
محللو أمن المعلومات

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC, storage, crypto, signing), dynamic analysis (Frida/objection,…

٢٨ يوليو ٢٠٢٦
firewall-review
محللو أمن المعلومات

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and…

٢٨ يوليو ٢٠٢٦
hackthebox
المهن الحاسوبية الأخرى

HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions

٢٨ يوليو ٢٠٢٦
عرض 8 من أصل ٥٠ skills مجمعة.
aws-remediation-leverage
محللو أمن المعلومات

Rank AWS remediations by how many attack chains each one severs, so a team gets maximum blast-radius reduction per fix. Use when you have an aws_attack_chains/v1 file from the chain enumerator and need to turn it into a prioritized "biggest bang for the buck"…

٩ أغسطس ٢٠٢٦
aws-attack-chain-enumerator
محللو أمن المعلومات

Traverse a merged aws_attack_model/v1 attack graph and emit aws_attack_chains/v1 - ranked kill chains from an entry (internet or a single stolen credential) to crown jewels, the atomic technique catalog of attack primitives actually present, and root causes…

٩ أغسطس ٢٠٢٦
aws-attack-graph-builder
محللو أمن المعلومات

Merge one or more aws_attack_model/v1 envelopes from the AWS attack-surface / identity-trust / crown-jewel / active-threat collectors into a single, de-duplicated attack graph ready for chain enumeration. Use when combining multiple collector outputs into one…

٩ أغسطس ٢٠٢٦
aws-attack-primitive-kb
محللو أمن المعلومات

Extensible AWS attack-primitive knowledge base that maps a misconfiguration signature to an attack primitive, its MITRE ATT&CK technique and tactic, what it enables downstream, and its remediation. Use when you need to tag attack-model findings/nodes/edges…

٩ أغسطس ٢٠٢٦
aws-attack-surface-collector
محللو أمن المعلومات

Collects the internet-facing AWS exposure that standard CSPM baselines routinely miss and emits it as an aws_attack_model/v1 envelope for the red-team attack-chain suite. Use when you need to enumerate public EBS snapshots, public AMIs, public or…

٩ أغسطس ٢٠٢٦
aws-crown-jewel-mapper
محللو أمن المعلومات

Enumerate and RANK the high-value AWS targets (crown jewels) an attacker would aim at, plus the connectivity edges that reach them, and emit them in the shared aws_attack_model/v1 contract. Classifies S3 buckets, databases (RDS/Redshift/DocumentDB/DynamoDB),…

٩ أغسطس ٢٠٢٦
aws-identity-trust-collector
محللو أمن المعلومات

Deep AWS IAM, identity, and trust-relationship collector that goes further than a user-centric access-key report so future runs automatically surface privilege escalation and cross-account pivots. Collects per account IAM users, roles, groups with attached…

٩ أغسطس ٢٠٢٦
aws-redteam-report-packager
محللو أمن المعلومات

Package an enumerated AWS attack-chain model into customer-facing red-team reports — a Markdown attack-chain catalog and a Transilience-styled dark-theme PDF. Use as the FINAL stage of the AWS red-team attack-chain suite, after aws-attack-graph-builder has…

٩ أغسطس ٢٠٢٦
عرض 8 من أصل ٢٣ skills مجمعة.
apply-approved-diff
غير مصنف

Apply a human-approved character diff from experience/journal/proposed-character-diffs/ to self/character.md. The ONLY sanctioned path for self/ to change. Use when the user invokes /apply-diff with a path to an approved diff file. Do NOT invoke autonomously…

٢٦ أغسطس ٢٠٢٦
promote-pattern
غير مصنف

Scan recent craft notes for clusters that meet promotion criteria, and promote them to craft/patterns/ with explicit evidence pointers. Use when the user invokes /promote-patterns, when session-end-reflect surfaces a pattern-promotion suggestion (notes have…

٢٦ أغسطس ٢٠٢٦
refresh-trends
غير مصنف

Refresh craft/trends/current.md by pulling current security and engineering narratives from configured sources, filtering noise from real trends, and writing a fresh trends file. Use when the user invokes /refresh-trends, when run-campaign detects the trends…

٢٦ أغسطس ٢٠٢٦
run-campaign
غير مصنف

Orchestrate a cold-outreach campaign end-to-end — read input JSON, iterate leads through researcher → profiler → drafting → witness, write output JSON. Use when the user invokes /run-campaign, asks Rysy to process a campaign, or hands you a path to a campaign…

٢٦ أغسطس ٢٠٢٦
take-craft-note
غير مصنف

Writes a dated atomic observation to craft/notes/ with consistent frontmatter. Invoke when Rysy notices something worth recording during or after prospect engagement.

٢٦ أغسطس ٢٠٢٦
reindex-memory
غير مصنف

Rebuilds INDEX.md files across craft/ and experience/. Run after note-taking, pattern-promotion, character-diff application, or by the session-end hook for safety.

٧ يوليو ٢٠٢٦
عرض ٤ من أصل ٤ مستودعات
تم تحميل كل المستودعات