Skip to main content

Skills dans ce dépôt

xalgord/xalgorix - Page 4

SkillsMP a collecté 855 skills depuis xalgord/xalgorix. Ouvrez un skill pour examiner sa source et ses détails.

xalgord/xalgorix

Affichage de 40 skills collectés sur 855.

métier
Analystes en sécurité de l'information
description

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce leas

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Harden the Docker daemon by configuring daemon.json with user namespace remapping, TLS authentication, rootless mode, and CIS benchmark controls.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous capability assignments, and host path mounts using the kubernetes Python client. Identifies CVE-2022-0492 style escapes via cgroup abuse. Use when…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying Docker containers in production. Based on the CIS Docker Benchmark, it audits host confi

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization in web applications. This skill covers implementing secure JWT signing with HMAC-SHA256

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for cryptographic key management, signing operations, and secure key storage with python-pkcs11, AWS CloudHSM, and YubiHSM2.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 855.