Skip to main content

Skills dans ce dépôt

Undermybelt/hermes-skills - Page 23

SkillsMP a collecté 1 242 skills depuis Undermybelt/hermes-skills. Ouvrez un skill pour examiner sa source et ses détails.

Undermybelt/hermes-skills

Affichage de 40 skills collectés sur 1 242.

métier
Analystes en sécurité de l'information
description

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag

Langue du texte source : anglais

mis à jour
métier
Travailleurs des services de protection, autres
description

Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.

Langue du texte source : anglais

mis à jour
métier
Spécialistes des opérations commerciales, autres
description

Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 1 242.