Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة
مستودع GitHub

security-skill

يحتوي security-skill على 58 من skills المجمعة من woohyun212، مع تغطية مهنية على مستوى المستودع وصفحات skill داخل الموقع.

skills مجمعة
58
Stars
20
محدث
2026-04-15
Forks
1
التغطية المهنية
2 فئات مهنية · 100% مصنفة
مستكشف المستودعات

Skills في هذا المستودع

isms-checklist
محللو أمن المعلومات

Interactive gap analysis against Korea's ISMS-P 102-control certification framework (management, protection, personal information)

2026-04-15
log-analysis
محللو أمن المعلومات

Security log analysis and anomaly detection for access, auth, and syslog files

2026-04-15
malware-analysis
محللو أمن المعلومات

Analyze suspicious files through triage/static/dynamic/code phases to produce IOCs, YARA/Sigma rules, and MITRE ATT&CK mappings

2026-04-15
malware-hash
محللو أمن المعلومات

File hash reputation lookup via VirusTotal API v3 for MD5/SHA1/SHA256 detection ratio, threat classification, and vendor results

2026-04-15
owasp-check
محللو أمن المعلومات

OWASP Top 10 (2021) checklist-based inspection and compliance matrix generation

2026-04-15
building-secure-contracts
محللو أمن المعلومات

Multi-chain smart contract security for Solana, Algorand, Cairo, Cosmos, Substrate, and TON with pre-audit readiness checks

2026-04-14
constant-time-analysis
محللو أمن المعلومات

Detect timing side-channel vulnerabilities in cryptographic code caused by secret-dependent branching and memory access patterns

2026-04-14
differential-review
محللو أمن المعلومات

Security-focused git diff analysis to detect regressions, new vulnerabilities, and unsafe changes in code reviews

2026-04-14
entry-point-analyzer
محللو أمن المعلومات

Identify and classify state-changing entry points in smart contracts and applications to map the attack surface

2026-04-14
insecure-defaults
محللو أمن المعلومات

Detect insecure default configurations including weak crypto, fail-open patterns, default credentials, and unsafe framework settings

2026-04-14
property-based-testing
محللو ضمان جودة البرمجيات والمختبرون

Property-based fuzzing and testing to find security edge cases in crypto, smart contracts, and parsers across multiple languages

2026-04-14
spec-to-code-compliance
محللو ضمان جودة البرمجيات والمختبرون

Verify code implementation matches security specifications, detecting deviations that could introduce vulnerabilities

2026-04-14
testing-handbook
محللو أمن المعلومات

Security testing methodology using fuzzers (AFL++, libFuzzer), sanitizers (ASan, MSan, UBSan), and static analysis for vulnerability discovery

2026-04-14
ad-pentest
محللو أمن المعلومات

Active Directory pentest with BloodHound attack path analysis, Kerberos/ADCS attacks, credential harvesting, and lateral movement

2026-04-14
bug-bounty-methodology
محللو أمن المعلومات

Guided bug bounty hunting session with recon, mapping, discovery, exploitation, and reporting phases with escalation routing

2026-04-14
bug-bounty-validation
محللو أمن المعلومات

Pre-submission validation for bug bounty findings with scope/impact/exploitability gates, CVSS scoring, and submit/kill verdict

2026-04-14
cert-transparency
محللو أمن المعلومات

Certificate Transparency log search via crt.sh API to discover subdomains and certificates

2026-04-14
cloud-pentest
محللو أمن المعلومات

Multi-cloud CSPM assessment using ScoutSuite/Prowler with IAM privilege escalation, storage exposure, and network posture for AWS/Azure/GCP

2026-04-14
cors-check
محللو أمن المعلومات

Detect CORS misconfiguration by testing various Origin headers and analyzing Access-Control responses

2026-04-14
cve-lookup
محللو أمن المعلومات

CVE detail lookup from NVD API v2 with CVSS scores, vectors, and affected products

2026-04-14
dependency-audit
محللو أمن المعلومات

Dependency vulnerability audit across Node.js, Python, and Go ecosystems

2026-04-14
devsecops-pipeline
محللو أمن المعلومات

Assess CI/CD pipeline security maturity, identify DevSecOps gaps, and generate GitHub Actions/GitLab CI configs with security gates

2026-04-14
dns-recon
محللو أمن المعلومات

DNS record reconnaissance and zone transfer attempts using dig, host, and nslookup

2026-04-14
encoding-toolkit
محللو أمن المعلومات

Encode/decode strings (Base64, URL, Hex, HTML, ROT13, JWT) for payload transformation, WAF bypass, and encoded data analysis

2026-04-14
exploit-chain-building
محللو أمن المعلومات

Escalate confirmed low/medium findings into high-impact exploit chains (A→B→C) with combined CVSS scoring

2026-04-14
hash-identify
محللو أمن المعلومات

Identify hash algorithm type from a hash string and optionally verify against a known plaintext

2026-04-14
llm-ai-security
محللو أمن المعلومات

LLM/AI application security testing for prompt injection, system prompt leakage, tool abuse, and output handling per OWASP AI Security Top 10

2026-04-14
mobile-pentest
محللو أمن المعلومات

Mobile app security testing with Frida instrumentation, OWASP MASVS compliance, and SSL pinning/root detection bypass for Android/iOS

2026-04-14
nuclei-scan
محللو أمن المعلومات

Nuclei template-based vulnerability scanning with severity filtering and structured output

2026-04-14
osint-email
محللو أمن المعلومات

Email-based OSINT collection including breach database checks and social account enumeration

2026-04-14
pentest-report
محللو أمن المعلومات

Pentest report authoring with executive summary, CVSS-scored findings, attack narrative, and remediation roadmap (writing methodology)

2026-04-14
port-scan
محللو أمن المعلومات

Port scanning and service detection with nmap for authorized security assessments

2026-04-14
secret-scan
محللو أمن المعلومات

Secret and credential detection in source code and git history using trufflehog or gitleaks

2026-04-14
secure-code-review
محللو أمن المعلومات

Security code review across input validation, auth, injection, crypto, error handling, dependencies, and concurrency with CWE mapping

2026-04-14
siem-rule
محللو أمن المعلومات

Create and convert SIEM detection rules (Sigma/Splunk SPL/Elastic KQL/Sentinel KQL) from threat objectives, IOCs, or CVE reports

2026-04-14
subdomain-enum
محللو أمن المعلومات

Subdomain enumeration using subfinder and amass to discover attack surface

2026-04-14
subdomain-takeover
محللو أمن المعلومات

Subdomain takeover detection and verification for dangling DNS records

2026-04-14
supply-chain-audit
محللو أمن المعلومات

Supply chain security audit with SCA scanning (trivy/grype), SLSA compliance assessment, and SBOM generation (CycloneDX/SPDX)

2026-04-14
threat-model
محللو أمن المعلومات

Structured threat modeling producing threat catalog with STRIDE categorization, DREAD risk scores, and prioritized mitigation roadmap

2026-04-14
waf-detect
محللو أمن المعلومات

Detect the presence and type of a Web Application Firewall using wafw00f or manual fingerprinting

2026-04-14
عرض أهم 40 من أصل 58 skills مجمعة في هذا المستودع.