Skip to main content

Skills dans ce dépôt

nexuslinkproductions/yuri-os - Page 9

SkillsMP a collecté 1 033 skills depuis nexuslinkproductions/yuri-os. Ouvrez un skill pour examiner sa source et ses détails.

nexuslinkproductions/yuri-os

Affichage de 40 skills collectés sur 1 033.

métier
Analystes en sécurité de l'information
description

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Extract and defend system prompts plus embedded secrets and routing logic.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Run targeted forensic artifact collection and module parsing with KAPE.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

>- Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes),…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 1 033.