Acts as an Application Security (AppSec) Specialist based on OWASP ASVS v5.0.0 integrated with NIST SSDF, CWE, and CERT Secure Coding, applying secure coding controls in design and implementation.
Idioma del texto original: inglés
Menú
Skills en este repositorio
SkillsMP ha recopilado 365 skills de dandgabr/Coacus. Abre una skill para revisar su origen y sus detalles.
dandgabr/CoacusMostrando 40 de 365 skills recopiladas.
Acts as an Application Security (AppSec) Specialist based on OWASP ASVS v5.0.0 integrated with NIST SSDF, CWE, and CERT Secure Coding, applying secure coding controls in design and implementation.
Idioma del texto original: inglés
Acts as a Mobile Application Security (Mobile AppSec) Specialist based on OWASP MASVS v2.1.0 and MASTG v2 (Android and iOS), covering secure storage, mobile cryptography, network protection, platform/WebView security, reverse engineering, resilience and the…
Idioma del texto original: inglés
Acts as a Specialist in Dynamic Application Security Testing (DAST), covering black-box/gray-box scans, route crawling (traditional crawling and headless SPA crawling through Playwright/Selenium), parameter injection and fuzzing, authentication (OAuth 2.0,…
Idioma del texto original: inglés
Acts as a Specialist in Interactive Application Security Testing (IAST), covering the hybrid runtime-agent architecture combined with automated test traffic (Active IAST through a DAST crawler vs. Passive IAST through QA/CI suites such as Playwright, Cypress,…
Idioma del texto original: inglés
Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers…
Idioma del texto original: inglés
Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and…
Idioma del texto original: inglés
Acts as a Specialist in Runtime Application Self-Protection (RASP), covering bytecode instrumentation (Java Virtual Machine Tool Interface / Java Agent, .NET CLR Profiler API, PHP Zend Engine extensions, monkey patching in Python and Node.js, and eBPF probes…
Idioma del texto original: inglés
Acts as a Specialist in Static Application Security Testing (SAST) and Security Code Review, identifying vulnerabilities in source code, applying static verification rules, AST, CFG, interprocedural taint analysis, remediating flaws (Injection, XSS, CSRF,…
Idioma del texto original: inglés
Acts as a Specialist in Software Supply Chain Security, Software Composition Analysis (SCA), and Dependency Management based on Cassie Crossley and NIST SSDF / SP 800-161. Covers SBOM generation and auditing (CycloneDX v1.7.2 / ECMA-424 and SPDX v3.0.1), VEX,…
Idioma del texto original: inglés
Acts as a specialist in CIS Critical Security Controls v8/v8.1, CIS Safeguards (IG1, IG2, IG3), CIS hardening benchmarks, and the CIS RAM risk assessment methodology.
Idioma del texto original: inglés
Acts as a Specialist in Information Security Governance and Secure Software Lifecycle based on the (ISC)² CISSP and CSSLP Common Bodies of Knowledge (CBK) (Mano Paul). Covers the 8 CISSP domains (Risk Management, Asset Security, Security Engineering,…
Idioma del texto original: inglés
Acts as a specialist in NIST frameworks and special publications (National Institute of Standards and Technology), including NIST CSF v2.0, SP 800-53 Rev. 5, SP 800-63-3/4, SP 800-30/37 (RMF), SP 800-207 (Zero Trust), and SP 800-171/172.
Idioma del texto original: inglés
Acts as a Data Privacy, PII Governance, and De-identification/Anonymization Engineering Specialist. Covers compliance with LGPD, GDPR, HIPAA, ISO/IEC 27701:2025, and the NIST Privacy Framework, the 7 principles of Privacy by Design, formal mathematical…
Idioma del texto original: inglés
Acts as a specialist in AWS IAM and access control, covering IAM Policies (JSON), Permission Boundaries, SCPs (AWS Organizations), AWS IAM Identity Center, STS, ABAC, KMS Key Policies, and Access Analyzer.
Idioma del texto original: inglés
Acts as a specialist in Microsoft Entra ID (Azure AD) and Azure IAM, covering Azure RBAC, custom roles, PIM (Privileged Identity Management), Conditional Access, Managed Identities, ABAC, and Entra ID Governance.
Idioma del texto original: inglés
Acts as a specialist in GCP IAM (Google Cloud Access Management), covering resource hierarchy, predefined/custom roles, service account impersonation, Workload Identity Federation, VPC Service Controls, and IAM Recommender.
Idioma del texto original: inglés
Acts as a specialist in IAM (Identity and Access Management) and access management, covering Active Directory, Windows, Linux, AWS, Azure, GCP, and OCI, and adaptable to ERPs and SaaS such as SAP, Salesforce, Okta, and ServiceNow.
Idioma del texto original: inglés
Acts as a specialist in OCI IAM (Oracle Cloud Infrastructure Access Management), covering OCI policy syntax, compartments, identity domains, dynamic groups, instance principals, and sign-on policies.
Idioma del texto original: inglés
Acts as a specialist in IAM (Identity and Access Management) for Microsoft Power Platform, Power Apps, and Dataverse, covering Security Roles, Privileges, Business Units, Teams (Owner/Access/Group), Column-Level Security, Hierarchy Security, DLP Policies,…
Idioma del texto original: inglés
Acts as a Specialist in Bug Bounty and Large-Scale Vulnerability Hunting methodologies based on Bug Bounty Bootcamp (Vickie Li). Covers active/passive subdomain reconnaissance, hidden asset discovery, distributed port scanning, parameter fuzzing automation,…
Idioma del texto original: inglés
Acts as a Pentester and Red Teamer specialized in Cloud Environments (AWS, Azure, and GCP), covering reconnaissance of exposed assets, lateral movement in containers/K8s, IAM/policy exploitation, attacks on managed services (S3, Blob, Key Vault, Metadata…
Idioma del texto original: inglés
Acts as a specialist in authentication and authorization protocols (RADIUS, TACACS+, Kerberos, OAuth 2.0/2.1, OpenID Connect, SAML 2.0, SCIM 2.0, WebAuthn/FIDO2, LDAP, EAP, JWT) and Multi-Factor Authentication architecture (MFA, Passkeys, TOTP,…
Idioma del texto original: inglés
Acts as a specialist in network security architecture, engineering, and operations across On-Premise, Hybrid, and Multicloud environments (AWS, Azure, GCP, OCI), covering NGFW, microsegmentation, SASE/SSE, ZTNA, IDS/IPS, SD-WAN, WAF, and DDoS mitigation.
Idioma del texto original: inglés
Acts as a Systems Security Architect using the SABSA framework (Sherwood Applied Business Security Architecture) aligned with TOGAF, NIST CSF, ISO 27001, and Zero Trust, executing the SABSA 6x6 Matrix, Business Attribute Profiles (BAP), Trust Domains, and the…
Idioma del texto original: inglés
Provides a guide and procedure for autonomously drafting Information Security Technical Opinions, architecture risk assessments, integrations, and third parties (TPRM). Supports dynamic selection of Threat Modeling methodologies (STRIDE, PASTA, LINDDUN, VAST,…
Idioma del texto original: inglés
Acts as a Specialist in Security, Reverse Engineering, and Anti-Cheat in Game Engines (Unity, Unreal Engine, and Godot). Covers C#/IL2CPP code protection and global-metadata.dat metadata, encryption and secure packaging (.pak, .pck, asset bundles), network…
Idioma del texto original: inglés
Provides definitive guidance and engineering standards for DongTai IAST (github.com/HXSecurity/DongTai), covering the open-source passive Interactive Application Security Testing framework, DongTai Server deployment with Docker Compose, agent installation…
Idioma del texto original: inglés
Provides definitive guidance and engineering standards for Opengrep (opengrep.dev), covering the open-source static code analysis (SAST) engine, complete YAML rule syntax, syntactic and semantic patterns, advanced Taint Analysis mode, CLI, rule testing, CI/CD…
Idioma del texto original: inglés
Provides definitive guidance and engineering standards for Baidu OpenRASP (github.com/baidu/openrasp), covering the open-source Runtime Application Self-Protection (RASP) framework, Java and PHP agent installation, the OpenRASP Cloud panel, JavaScript (V8…
Idioma del texto original: inglés
Provides definitive guidance and engineering standards for OWASP Dependency-Check (owasp.org/www-project-dependency-check), covering Software Composition Analysis (SCA), CLI, Maven and Gradle plugins, GitHub Actions, integration with the NVD API v2,…
Idioma del texto original: inglés
Provides definitive guidance and engineering standards for OWASP ZAP (zaproxy.org), covering the dynamic web application and API security scanner (DAST), the ZAP Automation Framework (AF plans in YAML), Docker-packaged scans (zap-baseline, zap-full-scan,…
Idioma del texto original: inglés
Provides color contrast and accessibility engineering: WCAG 2.2 thresholds (4.5:1, 3:1, 7:1, non-text 3:1), the relative-luminance and contrast-ratio math, known WCAG limitations and APCA (Lc values, WCAG 3 status), color vision deficiency types and…
Idioma del texto original: inglés
Provides color for data visualization and charts: colormap taxonomy (sequential, diverging, cyclic, qualitative), perceptually uniform maps (viridis family) and why jet is banned, colorblind-safe categorical palettes (Okabe-Ito, tol), encoding rules (never…
Idioma del texto original: inglés
Provides color harmony and palette construction based on color-wheel history and modern practice: Newton/Goethe/Itten/Albers lineage, harmony schemes (monochromatic, analogous, complementary, split-complementary, triadic, tetradic, square), shade-ramp…
Idioma del texto original: inglés
Provides color science foundations for UI work based on perceptual color research: trichromacy and metamerism, additive vs subtractive models, why HSL lightness is perceptually broken, CIE Lab/LCh, the OKLab/OKLCH perceptual space, CAM16/HCT and wide-gamut…
Idioma del texto original: inglés
Provides color architecture for UI design systems: primitive/semantic/component token layers, role-based naming (M3's 26 roles, on/container/variant grammar), theming (light/dark/brand from one role set), dynamic color and HCT tonal palettes,…
Idioma del texto original: inglés
Provides the UI design discipline craft (interface/visual design separated from UX): visual hierarchy and composition, 8pt spacing systems, type scales and legibility, semantic color tokens, component state design, design tokens (DTCG), dark mode and…
Idioma del texto original: inglés
Provides the UX design discipline (experience design separated from UI craft): the ISO 9241-210 definition and UX honeycomb, process frameworks (Double Diamond, design thinking, Lean UX, JTBD, continuous discovery), the user-research method map, usability…
Idioma del texto original: inglés
Provides the 3D immersive web design style (2019-present): WebGL/Three.js scenes as first-class marketing and portfolio media, covering scene architecture, scroll-linked cameras, frame budgets, Spline/model-viewer tooling, context-loss handling and canvas…
Idioma del texto original: inglés
Provides the acid graphics / deconstructivist anti-design style (2020-present): toxic palettes, blackletter-chrome type collisions, glitch and broken grids from club-flyer culture, covering David Rudnick lineage, CSS reconstruction, accessibility regressions…
Idioma del texto original: inglés