Skip to main content

Skills dans ce dépôt

AgentFlocks/flocks - Page 13

SkillsMP a collecté 771 skills depuis AgentFlocks/flocks. Ouvrez un skill pour examiner sa source et ses détails.

AgentFlocks/flocks

Affichage de 40 skills collectés sur 771.

métier
Analystes en sécurité de l'information
description

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 771.