Skip to main content

Skills in this repository

oyi77/1ai-skills - Page 22

SkillsMP has collected 1,311 skills from oyi77/1ai-skills. Open a skill to review its source and details.

oyi77/1ai-skills

Showing 40 of 1,311 collected skills.

occupation
Information Security Analysts
description

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue. Use when performing systematic siem false positive reduction through rule tuning,…

updated
occupation
Information Security Analysts
description

Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state. Use when working with performing file carving with foremost.

updated
occupation
Information Security Analysts
description

Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing. Use when performing gcp security testing using gcpbucketbrute for storage bucket…

updated
occupation
Information Security Analysts
description

Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations…

updated
occupation
Information Security Analysts
description

Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs. Use when working with performing graphql depth limit attack.

updated
occupation
Information Security Analysts
description

Use when performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies…

updated
occupation
Information Security Analysts
description

Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests. Use when working with performing graphql security assessment.

updated
occupation
Information Security Analysts
description

Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2. Use when integrateing hardware security modules (hsms) using…

updated
occupation
Information Security Analysts
description

Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w. Use when working with performing hash cracking with…

updated
occupation
Information Security Analysts
description

Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems. Use when working with performing http parameter pollution…

updated
occupation
Information Security Analysts
description

Perform comprehensive ICS/OT asset discovery using Claroty xDome platform, leveraging passive monitoring, Claroty Edge active queries, and integration ecosystem to gain full visibility into industrial control system assets including PLCs, RTUs, HMIs, and…

updated
occupation
Information Security Analysts
description

Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements. Use when performing authorized initial access using evilginx3…

updated
occupation
Information Security Analysts
description

Use when investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal…

updated
occupation
Information Security Analysts
description

Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source…

updated
occupation
Information Security Analysts
description

Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for…

updated
occupation
Information Security Analysts
description

Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware…

updated
occupation
Information Security Analysts
description

Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage. Use when analyzeing ip address reputation using the shodan api to…

updated
occupation
Information Security Analysts
description

Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens. Use when working with performing jwt none algorithm attack.

updated
occupation
Information Security Analysts
description

Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names. Use when working with performing kerberoasting attack.

updated
occupation
Information Security Analysts
description

Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation. Use when working with performing kubernetes etcd security assessment.

updated
occupation
Information Security Analysts
description

Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools. Use when working with performing kubernetes penetration…

updated
occupation
Information Security Analysts
description

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008)…

updated
occupation
Information Security Analysts
description

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements. Use when performing lateral movement…

updated
occupation
Information Security Analysts
description

Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal, kern.log, and application logs to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised Linux systems. Use when…

updated
occupation
Information Security Analysts
description

Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations. Use when working with performing log analysis for forensic investigation.

updated
occupation
Information Security Analysts
description

Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility. Use when performing structured log source onboarding into siem platforms by configuring.

updated
occupation
Information Security Analysts
description

Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation. Use when working with performing malware hash enrichment with…

updated
occupation
Information Security Analysts
description

Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist. Use when working with performing malware ioc extraction.

updated
occupation
Information Security Analysts
description

Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access. Use when working with performing malware persistence investigation.

updated
occupation
Information Security Analysts
description

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. Use when analyzeing memory dumps using volatility3 plugins to detect injected code,.

updated
occupation
Information Security Analysts
description

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts. Use when working with performing mobile device forensics with cellebrite.

updated
occupation
Information Security Analysts
description

Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications. Use when working with performing network forensics with wireshark.

updated
occupation
Information Security Analysts
description

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or…

updated
occupation
Information Security Analysts
description

Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation. Use when deploying zeek network security monitor to capture, parse, and analyze.

updated
occupation
Information Security Analysts
description

Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests…

updated
occupation
Information Security Analysts
description

Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s. Use when working with performing open source intelligence…

updated
occupation
Information Security Analysts
description

Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing…

updated
occupation
Information Security Analysts
description

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic. . Use when working…

updated
occupation
Information Security Analysts
description

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag. Use when working with performing phishing simulation with…

updated
occupation
Information Security Analysts
description

Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls. Use when conducting authorized physical penetration testing using tailgating, badge cloning,…

updated
Showing 40 of 1,311 collected skills.