Skip to main content

EvilFreelancer/secs

SkillsMP は EvilFreelancer/secs から 33 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

記録された最新のソース活動
SkillsMP カタログ更新
収集済み skills
33
GitHub スター
9
GitHub フォーク
2

このリポジトリの skills

1 件の職業カテゴリ · 100% 分類済み

収集済み skill 33 件中 33 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O file, firmware image, or stripped binary, recovering an…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Use when handed a suspicious file, hash, or sample, when triaging an alert artifact, or when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction from memory-resident data. Use when examining a memory capture…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze a reported or suspected phishing email safely — parse the Received chain and Return-Path, validate SPF/DKIM/DMARC alignment, extract and defang URLs and attachments, detonate payloads in a sandbox, and pivot on sender infrastructure to produce IOCs…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Attack and enumerate Active Directory environments using Kerberos attacks (Kerberoasting, ASREPRoasting), credential dumping (DCSync, Mimikatz), lateral movement (PtH, PtT), and BloodHound analysis. Use when pentesting Windows domains or exploiting AD…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Attack WiFi networks using WPA/WPA2 cracking, WPS exploitation, Evil Twin attacks, deauthentication, and wireless reconnaissance. Use when pentesting wireless networks or performing WiFi security assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. Use when reviewing a codebase or diff for security bugs, performing a security audit, hunting for vulnerabilities in a…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit a Model Context Protocol server's own implementation for how it can subvert or exfiltrate from the agent that connects to it — tool-description injection (tool poisoning), tool shadowing and rug pulls, per-tool authorization and input schemas, SSRF via…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit software supply chain risk — dependency and transitive package review, typosquatting and dependency confusion, lockfile and SBOM analysis, CI/CD pipeline and GitHub Actions security, build provenance, and secrets exposure. Use when assessing third-party…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Enumerate and exploit network services including SMB, FTP, SSH, RDP, HTTP, databases (MySQL, MSSQL, PostgreSQL, MongoDB), LDAP, NFS, DNS, and SNMP. Use when testing network service security or performing port-based exploitation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Escalate privileges on Linux systems using SUID/SGID binaries, capabilities, sudo misconfigurations, cron jobs, kernel exploits, and container escapes. Use when performing Linux post-exploitation or privilege escalation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Escalate privileges on Windows systems using service misconfigurations, DLL hijacking, token manipulation, UAC bypasses, registry exploits, and credential dumping. Use when performing Windows post-exploitation or privilege escalation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Maintain authorized access across reboots and credential changes during red-team post-exploitation — Windows autostart (Run keys, services, scheduled tasks, WMI subscriptions), Linux (cron, systemd, shell profiles, SSH keys), Active Directory (accounts,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit AWS, Azure, and GCP cloud misconfigurations including S3 buckets, IAM roles, metadata services, serverless functions, and cloud-specific privilege escalation. Use when pentesting cloud environments or assessing cloud security.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data),…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Hunt for planted webshells and server-side backdoors on web infrastructure — recently-changed files in web roots, dangerous-callable content signatures (eval/system/base64), YARA scans, web-server log anomalies (POST to static-looking paths, rare user…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate a suspected AWS compromise from the control plane — CloudTrail management and data events (queried with Athena or CloudTrail Lake), GuardDuty findings, VPC Flow Logs, and CloudWatch — to reconstruct IAM/STS abuse, persistence, data access, and log…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate a suspected Azure and Entra ID compromise from the control plane — Azure Activity Log, Entra sign-in and audit logs, and the Microsoft 365 unified audit log, queried with KQL in Log Analytics/Sentinel — to reconstruct identity abuse, MFA and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate a suspected Google Cloud compromise from the control plane — Cloud Audit Logs (Admin Activity, Data Access, System Event, Policy Denied), Cloud Logging, and VPC Flow Logs — to reconstruct IAM and service-account abuse, key creation, data access,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate a live or triaged Windows host for intrusion evidence using disk and registry artifacts — MFT/$UsnJrnl, registry hives, AmCache/ShimCache, Prefetch, LNK/JumpLists, ShellBags, and event logs — parsed with the Eric Zimmerman suite and consolidated…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Run authorized social-engineering assessments — pretext development from OSINT, phishing and spearphishing campaigns (Gophish), vishing and smishing, and physical pretexting — to measure the human attack surface and produce awareness-driving metrics. Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Turn raw observations, extracted IOCs, and open sources into finished threat intelligence — running the intelligence cycle (direction, collection, processing, analysis, dissemination, feedback), enriching and grading indicators, pivoting on TTPs over atomic…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Test REST and GraphQL APIs for authentication bypasses, authorization flaws, IDOR, mass assignment, injection attacks, and rate limiting issues. Use when pentesting APIs or testing microservices security.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Safely assess industrial control system and OT networks and their protocols (Modbus, DNP3, S7comm, EtherNet/IP-CIP, OPC UA, IEC 60870-5-104, BACnet) using a passive-first, safety-gated methodology aligned to the Purdue model and IEC 62443. Use when mapping an…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Test Android and iOS applications for security flaws following OWASP MASVS/MASTG — insecure data storage, weak transport security and certificate pinning, broken authentication and session handling, cryptography misuse, exported-component and deep-link abuse,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Test web applications for security vulnerabilities including SQLi, XSS, command injection, JWT attacks, SSRF, file uploads, XXE, and API flaws. Use when pentesting web apps, analyzing authentication, or exploiting OWASP Top 10 vulnerabilities.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is loaded into a model's context and its config can run on startup. Use when reviewing a skill pack, Claude Code / Cursor / Cline plugin, or MCP…

原文の言語: 英語

更新
収集済み skill 33 件中 33 件を表示しています。