AWS security configuration scanning and hardening using Prowler, Security Hub, and AWS Config
Skills in this repository
a5c-ai/babysitter - Page 41
SkillsMP has collected 2,079 skills from a5c-ai/babysitter. Open a skill to review its source and details.
a5c-ai/babysitterShowing 40 of 2,079 collected skills.
Azure security configuration scanning and hardening using Azure Security Center, Azure Policy, and ScoutSuite
Automated evidence collection across compliance frameworks from cloud providers, identity systems, and security tools
Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance
Cryptographic implementation analysis and validation for encryption algorithms, key sizes, and certificate management
Dynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope, correlate findings with SAST results, and generate comprehensive vulnerability reports.
GCP security configuration scanning and hardening using Security Command Center, Forseti, and ScoutSuite
GDPR compliance assessment and automation for data mapping, consent management, DSAR handling, and privacy impact assessments
Git diff forensics for surfacing and classifying code changes for trojan detection
HIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation
Byte-level Unicode homoglyph detection for identifying invisible character substitutions in code
Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi
Cryptographic key lifecycle management orchestration including generation, rotation, and destruction across key management systems
Unified cloud security posture management across AWS, Azure, and GCP with normalized metrics and CIS benchmark comparison
Automated OWASP Top 10 vulnerability detection and assessment. Run OWASP ZAP automated scans, detect injection vulnerabilities, identify broken authentication patterns, check for sensitive data exposure, analyze security misconfigurations, and generate…
PCI DSS compliance assessment and reporting for cardholder data protection, SAQ automation, and ASV scan orchestration
Phishing simulation campaign execution and analysis for security awareness assessment
Detect secrets, credentials, and sensitive data in code and configurations. Scan git history for secrets, detect API keys, tokens, passwords, check environment files, monitor CI/CD logs for exposure, generate remediation steps, and track secret rotation…
Developer security training and assessment for secure coding practices and vulnerability prevention
LLM-powered semantic analysis of code diffs to detect business-logic trojans
SOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation
Continuous vendor security monitoring for security ratings, breach notifications, and risk change detection
Automated vendor security assessment through questionnaire generation, response parsing, and risk scoring
AI/ML model security testing and adversarial research capabilities. Generate adversarial examples, test model robustness, perform model extraction attacks, test for data poisoning, analyze model fairness, and support ART framework integration.
Advanced binary exploitation and mitigation bypass
Web application security testing with Burp Suite integration
Multi-cloud security assessment and penetration testing capabilities. Execute Prowler/ScoutSuite assessments, analyze IAM policies, identify cloud misconfigurations, test permissions, and enumerate cloud resources across AWS/GCP/Azure.
CVE and CWE database querying and management
Advanced debugging integration for vulnerability research
Comprehensive fuzzing operations with AFL++, libFuzzer, and OSS-Fuzz integration
Deep integration with Ghidra and IDA Pro for binary analysis and reverse engineering
Hardware and embedded security research capabilities. Interface with JTAG debuggers, analyze SPI/I2C communications, dump and analyze firmware, support fault injection, side-channel analysis, and hardware exploitation research.
Digital forensics and incident response capabilities. Analyze memory dumps with Volatility, parse filesystem artifacts, extract browser forensics, analyze Windows event logs, create forensic timelines, recover deleted files, and generate forensic reports.
MITRE ATT&CK framework mapping and analysis
Android and iOS application security testing
Offensive security tools and techniques integration
Network protocol capture, analysis, and fuzzing capabilities
Exploit development automation using pwntools framework
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and process changes.
Ethereum and blockchain smart contract security analysis