Skip to main content

Skills dans ce dépôt

AgentFlocks/flocks - Page 10

SkillsMP a collecté 771 skills depuis AgentFlocks/flocks. Ouvrez un skill pour examiner sa source et ses détails.

AgentFlocks/flocks

Affichage de 40 skills collectés sur 771.

métier
Analystes en sécurité de l'information
description

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when…

Langue du texte source : anglais

mis à jour
métier
Spécialistes en gestion de projets
description

Security awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Activates…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file sanitization, data loss prevention…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor and engineer access to industrial control…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 771.