Skip to main content

Skills dans ce dépôt

autohandai/community-skills - Page 16

SkillsMP a collecté 1 040 skills depuis autohandai/community-skills. Ouvrez un skill pour examiner sa source et ses détails.

autohandai/community-skills

Affichage de 40 skills collectés sur 1 040.

métier
Analystes en sécurité de l'information
description

Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify suspicious network flows. Monitors DNS…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traffic manipulation attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 1 040.