Skip to main content

Skills dans ce dépôt

yanacuti1121/Yana-AI - Page 5

SkillsMP a collecté 1 566 skills depuis yanacuti1121/Yana-AI. Ouvrez un skill pour examiner sa source et ses détails.

yanacuti1121/Yana-AI

Affichage de 40 skills collectés sur 1 566.

métier
Analystes en sécurité de l'information
description

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Generates Angular code and provides architectural guidance. Trigger when creating projects, components, or services, or for best practices on reactivity (signals, linkedSignal, resource), forms, dependency injection, routing, SSR, accessibility (ARIA),…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Design and implement API rate limiting — algorithm selection (token bucket, sliding window, fixed window), Redis-based distributed limiting, per-user and per-IP limits, rate limit headers, retry-after, and burst handling. Use when asked to "add rate…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Use when asked to check an iOS/macOS app before App Store submission, scan for App Store rejection patterns, validate app metadata/privacy manifest/subscription compliance, or run pre-submission Apple Review guidelines checks. Triggers on: 'app store…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Merkle-tree-backed append-only log for distributed audit trails. Hypercore feed creation, append entries, replicate over network, sparse access, and integration with L0 audit hash-chain. Sources: holepunchto/hypercore.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Streaming ZIP and TAR archive creation for agent release packaging. node-archiver streaming API, append files/directories, compression levels, progress events, and integrity verification. Sources: archiverjs/node-archiver.

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Argo CD GitOps reconciliation loop for agent infrastructure. App-of-Apps pattern, sync policies, drift detection, progressive rollouts, and automated self-healing from Git as single source of truth. Sources: argoproj/argo-cd (Apache-2.0).

Langue du texte source : anglais

mis à jour
métier
Enseignants postsecondaires, autres
description

Use when asked to search for academic papers, find related work, look up research on a topic, or retrieve papers from arXiv. Triggers on: 'search papers', 'find papers about', 'arxiv search', 'academic search', 'find related work', 'research papers on',…

Langue du texte source : vietnamien

mis à jour
métier
Scientifiques des données
description

Kho tổng hợp 500+ project AI/ML/DL/CV/NLP kèm code — reference nhanh khi cần implementation mẫu. Bao gồm CV, NLP, healthcare ML, time series, production ML.

Langue du texte source : vietnamien

mis à jour
métier
Développeurs de logiciels
description

Statically scan agent-generated JavaScript and shell scripts for dangerous patterns using AST analysis (acorn/swc). Detect eval(), process.env access, dynamic require(), child_process usage, and path traversal before code execution.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Async key-value storage with automatic driver selection. localForage API patterns, IndexedDB/WebSQL/localStorage fallback chain, binary data storage, expiry patterns, and offline-first agent state persistence. Sources: localForage/localForage.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Design authentication and authorization systems — JWT lifecycle, OAuth 2.0 / OIDC flows, token storage, refresh strategy, RBAC and ABAC permission models. Use when asked about "login flow", "JWT", "OAuth", "refresh token", "access control", "permissions",…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 1 566.