Skip to main content

Skills in this repository

killvxk/cybersecurity-skills-zh - Page 16

SkillsMP has collected 735 skills from killvxk/cybersecurity-skills-zh. Open a skill to review its source and details.

killvxk/cybersecurity-skills-zh

Showing 40 of 735 collected skills.

occupation
Information Security Analysts
description

使用 Postman 构建测试集合,执行结构化 API 安全测试,覆盖 OWASP API 安全 Top 10 漏洞, 包括认证绕过、授权缺陷、注入和数据暴露。测试人员创建包含多个用户角色的环境, 编写自动化安全验证测试脚本,并将 Postman 与 OWASP ZAP 和 Newman 集成以进行 CI/CD 安全测试。 当请求涉及 Postman 安全测试、API 安全集合、自动化 API 测试或使用 Postman 进行 OWASP API 测试时触发。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权的实验室或渗透测试环境中,使用 arpspoof、Ettercap 和 Scapy 模拟 ARP 欺骗攻击, 以演示中间人攻击风险、测试网络检测能力并验证 ARP 检测对策。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在 AWS 环境中执行已授权的权限提升(Privilege Escalation)评估,使用 Pacu、CloudFox、Principal Mapper 和手动 IAM 策略分析技术,识别允许用户或角色提升权限的 IAM 配置错误。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权环境中使用 tc、iperf3 和 Scapy 模拟带宽限速(Bandwidth Throttling)和网络降级攻击, 测试服务质量(QoS)控制、应用程序弹性以及网络监控对流量操纵攻击的检测能力。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 pwntools Python 库分析二进制漏洞利用技术,包括缓冲区溢出(Buffer Overflow)和 ROP 链(ROP Chain)。涵盖 checksec 安全检查分析、使用 ROPgadget 发现 Gadget, 以及针对 CTF 竞赛和授权安全评估的漏洞利用开发。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用带外技术、DNS 交互和时序分析检测并利用盲 SSRF 漏洞,以访问内部服务和云元数据端点。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过扫描、枚举 GATT 服务并检测漏洞,评估蓝牙低功耗(BLE)设备的安全性。

Source text: Chinese

updated
occupation
Information Security Analysts
description

监控域名、社交媒体、移动应用和暗网渠道中的品牌仿冒攻击,检测针对组织的网络钓鱼活动、虚假站点和未授权品牌使用行为。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权安全评估中,通过评估框架嵌入控制和构建概念验证覆盖层攻击来测试 Web 应用程序的点击劫持漏洞。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过收集和分析来自 AWS、Azure 和 GCP 服务的日志、快照和元数据,在云环境中开展取证调查。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 CloudTrail 日志对 AWS 环境执行取证调查,重建攻击者活动、识别受损凭据并分析 API 调用模式。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 Falco YAML 规则在容器和 Kubernetes 中进行运行时威胁检测,监控系统调用以检测 shell 生成、文件篡改、网络异常和权限提升。通过 Falco gRPC API 管理 Falco 规则并解析 Falco 告警输出。适用于构建容器运行时安全或调查 k8s 集群入侵。

Source text: Chinese

updated
occupation
Information Security Analysts
description

对 AWS、Azure 和 GCP 云环境执行授权渗透测试,识别 IAM 错误配置、暴露的存储桶、过度宽松的安全组、 无服务器函数漏洞以及从初始访问到账户沦陷的云特定攻击路径。测试人员使用云原生工具及 Pacu、 ScoutSuite 等专用框架枚举并利用云基础设施。适用于云渗透测试、AWS 安全评估、Azure 渗透测试 或云基础设施安全测试等请求场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用开源 AWS 利用框架 Pacu 执行已授权的 AWS 渗透测试,枚举 IAM 配置、发现权限提升路径、测试凭据收集,并通过系统化的攻击模拟验证安全控制。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过分析命名空间配置、特权容器检查、危险能力分配和宿主机路径挂载,使用 kubernetes Python 客户端检测容器逃逸尝试。识别通过 cgroup 滥用的 CVE-2022-0492 类型逃逸。 适用于审计容器安全态势或调查逃逸尝试。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 Aqua Security Trivy 扫描容器镜像、文件系统和 Kubernetes 清单,检测漏洞(Vulnerability)、错误配置、暴露的密钥和许可证合规问题,并生成 SBOM(Software Bill of Materials,软件物料清单)及集成到 CI/CD 流水线。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过利用错误配置、JSONP 端点、不安全指令和策略注入技术,分析并绕过内容安全策略(CSP)实现,以实现跨站脚本攻击。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权安全评估中,通过构造利用已认证用户会话的伪造请求,测试 Web 应用程序的跨站请求伪造(CSRF)漏洞。

Source text: Chinese

updated
occupation
Information Security Analysts
description

暗网威胁监控涉及系统性扫描 Tor 隐藏服务、地下论坛、粘贴站点和暗网市场,以识别针对组织的威胁,包括泄露凭据、数据泄露、威胁行为者讨论、漏洞利用工具和预谋攻击。

Source text: Chinese

updated
occupation
Information Security Analysts
description

部署欺骗技术(Deception Technology),包括蜜罐(Honeypot)、诱饵令牌(Honeytoken)和诱饵系统(Decoy System), 用于检测已绕过外围防御的攻击者,提供极低误报率的高置信度告警。适用于 SOC 团队需要提前预警横向移动(Lateral Movement)、 凭据滥用(Credential Abuse)或内部侦察(Internal Reconnaissance)的场景,通过在网络中部署逼真陷阱实现检测。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过操控文件路径参数,测试 Web 应用程序中允许读取或写入服务器任意文件的路径遍历漏洞。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用取证镜像、文件系统分析、产物恢复和时间线重建进行磁盘取证调查,以支持事件响应案例。 使用 FTK Imager、Autopsy 和 The Sleuth Kit 等工具进行证据采集、已删除文件恢复和产物检查。 适用于磁盘取证、硬盘分析、取证镜像、文件恢复、证据采集或数字取证调查等请求场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权侦察期间枚举 DNS 记录、尝试区域传输(Zone Transfer)、暴力枚举子域名, 并绘制 DNS 基础架构图,以识别目标域名中的攻击面、错误配置和信息泄露。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过计算 DNS 查询名称的香农熵(Shannon Entropy)、分析查询长度分布、检测 TXT 记录载荷以及 识别高子域名基数,检测 DNS 隧道(DNS Tunneling)攻击。使用 scapy 进行数据包捕获分析, 结合统计方法区分合法 DNS 流量和隐蔽信道。适用于数据泄露猎威场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 ANY.RUN 云沙箱进行交互式动态恶意软件分析,实时观察执行行为、与恶意软件提示进行交互, 并捕获进程树、网络流量和系统变化。适用于交互式沙箱分析、基于云的恶意软件引爆、 实时行为观察或 ANY.RUN 使用等请求场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 SailPoint IdentityIQ 执行权限审查和访问认证活动, 包括经理认证、定向权限审查、基于角色的访问验证、 SoD 违规整改和自动化撤销工作流。 适用于访问审查、权限认证、SailPoint IIQ 治理或定期用户访问重认证相关请求。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 Foremost 的文件头/文件尾签名雕刻技术,从磁盘镜像和未分配空间中恢复文件,无论文件系统状态如何均可提取证据。

Source text: Chinese

updated
occupation
Information Security Analysts
description

分析固件镜像中嵌入的恶意软件、后门和未授权修改,目标包括路由器、IoT 设备、UEFI/BIOS 和嵌入式系统。涵盖固件提取、文件系统分析、二进制逆向工程和 Bootkit 检测。适用于固件安全 分析、IoT 恶意软件调查、UEFI Rootkit 检测或嵌入式设备入侵评估等请求场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 AFL++(American Fuzzy Lop Plus Plus)对编译后的二进制文件执行覆盖率引导模糊测试(Coverage-Guided Fuzzing), 以发现内存损坏、崩溃和安全漏洞。测试人员使用 afl-cc/afl-clang-fast 对目标二进制文件进行插桩, 使用 afl-cmin 和 afl-tmin 管理输入语料库,运行并行模糊测试活动,并使用 CASR 或 GDB 脚本对崩溃进行分类。 适用于涉及二进制模糊测试、崩溃发现、覆盖率引导测试或 AFL++ 模糊测试活动的请求。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 GCPBucketBrute 执行 GCP 安全测试,进行存储桶(Storage Bucket)枚举、gcloud IAM 权限提升路径分析和服务账号权限审计。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 Forseti Security、Security Command Center(安全指挥中心)和 gcloud CLI 对 Google Cloud Platform 环境进行全面安全评估,审计 IAM 策略、防火墙规则、存储权限,并对照 CIS GCP Foundations Benchmark 进行合规检查。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用深度嵌套递归查询执行和测试 GraphQL 深度限制攻击,以识别 GraphQL API 中的拒绝服务(DoS)漏洞。

Source text: Chinese

updated
occupation
Information Security Analysts
description

执行 GraphQL 自省(Introspection)攻击,从 GraphQL 端点提取完整的 API Schema, 包括类型、查询(Query)、变更(Mutation)、订阅(Subscription)和字段定义。 测试人员使用自省查询绘制攻击面,识别敏感字段和变更操作,测试查询深度和复杂度限制, 并利用 GraphQL 特有漏洞,包括批量攻击、基于别名的暴力破解和嵌套查询 DoS。 适用于涉及 GraphQL 安全测试、自省攻击、GraphQL 枚举或 GraphQL API 渗透测试的请求。

Source text: Chinese

updated
occupation
Information Security Analysts
description

在授权安全测试期间,评估 GraphQL API 端点的内省泄漏、注入攻击、授权缺陷和拒绝服务漏洞。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用 PKCS#11 接口集成硬件安全模块(HSM),通过 python-pkcs11、AWS CloudHSM 和 YubiHSM2 实现密码学密钥管理、签名操作和安全密钥存储。

Source text: Chinese

updated
occupation
Information Security Analysts
description

执行 HTTP 参数污染(HPP)攻击,通过注入由前端和后端系统以不同方式处理的重复参数,绕过输入验证、WAF 规则和安全控制。

Source text: Chinese

updated
occupation
Information Security Analysts
description

使用Claroty xDome平台执行全面的ICS/OT资产发现,利用被动监控、Claroty Edge主动查询和集成生态系统,在Purdue模型各级别获得对工业控制系统资产(包括PLC、RTU、HMI和网络基础设施)的完整可见性。

Source text: Chinese

updated
occupation
Information Security Analysts
description

指标生命周期管理跟踪 IOC 从初始发现到验证、富化、部署、监控和最终停用的全过程。本技能涵盖实施 IOC 质量评估、老化策略、置信度衰减评分、误报跟踪、命中率监控和自动到期的系统化流程,以维护高质量、可操作的指标数据库,最大限度减少分析师疲劳并提高检测效能。

Source text: Chinese

updated
occupation
Information Security Analysts
description

调查内部威胁事件,涉及滥用授权访问权限窃取数据、破坏系统或违反安全策略的员工、承包商或受信任合作伙伴。 结合数字取证、用户行为分析以及 HR/法务协调,构建基于证据的案例。适用于内部威胁调查、 员工数据盗窃、权限滥用、用户行为异常或内部威胁检测等请求场景。

Source text: Chinese

updated
occupation
Information Security Analysts
description

通过编排 VirusTotal、AbuseIPDB、Shodan、MISP 和其他情报源的查询, 自动化入侵指标(IOC)丰富化,提供上下文评分和处置建议。 适用于 SOC 分析师在告警分诊或事件调查期间需要对 IP、域名、URL 和文件哈希 进行快速多源丰富化时。

Source text: Chinese

updated
Showing 40 of 735 collected skills.