Skip to main content

このリポジトリの skills

mukul975/Anthropic-Cybersecurity-Skills - 8ページ

SkillsMP は mukul975/Anthropic-Cybersecurity-Skills から 817 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

mukul975/Anthropic-Cybersecurity-Skills

収集済み skill 817 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Reduces container attack surface by building application images on Google distroless base images that contain only the app runtime with no shell, package manager, or OS utilities, using multi-stage Docker build patterns and debug/scanning techniques for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Enforces Kubernetes network segmentation by creating and auditing Calico NetworkPolicy and GlobalNetworkPolicy resources via calicoctl and the Kubernetes API, controlling pod-to-pod traffic, namespace isolation, egress restrictions, and DNS-based rules. Use…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and incident-response effectiveness by safely emulating MITRE ATT&CK…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including sensitivity labels, custom sensitive information types with regex,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys and monitors Canary Tokens via the Thinkst Canary REST API for deception-based breach detection, programmatically creating web bug, DNS, MS Word document, and AWS API key tokens and generating deception coverage reports from triggered alerts. Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording, and Active Directory/cloud integration. Use when centralizing privileged…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting access. Use when requiring…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. Use when setting up automated security scanning in CI/CD, shifting security left, meeting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements digital signatures using the Ed25519 algorithm (Curve25519), covering key-pair generation, signing, signature verification, and security tradeoffs versus RSA and ECDSA. Use when adding message or artifact signing and authentication-integrity checks…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures SPF, DKIM, and DMARC DNS TXT records to authenticate outbound email, prevent domain spoofing, and enforce a rejection/quarantine policy on unauthenticated mail, including auditing a domain's current DNS state. Use when hardening a domain's email…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys and configures Dragos Platform sensors and detection analytics for OT/ICS network monitoring, using industrial protocol parsers and threat-intel packs to detect groups like VOLTZITE, CHERNOVITE, and KAMACITE. Use when standing up OT-specific network…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements a simplified Signal Protocol-style end-to-end encryption scheme for messaging, covering key exchange, forward secrecy, and the core cryptographic components so no server or intermediary can decrypt messages. Use when designing or building E2EE…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing with wazuh-logtest, and automated active-response actions.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements envelope encryption with AWS KMS, encrypting data locally with a data encryption key (DEK) and protecting that DEK with a KMS-managed key (KEK), covering the encrypt/decrypt flow, KMS key types, and security validation criteria. Use when designing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Queries FIRST's Exploit Prediction Scoring System (EPSS) API to fetch exploitation-probability and percentile scores for CVEs, then uses those scores to prioritize vulnerability remediation. Use when triaging or ranking a vulnerability backlog by real-world…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and alerting on unauthorized modifications. Use when setting up…

原文の言語: 英語

更新
職業分類
ソフトウェア品質保証アナリスト・テスター
説明

Integrates AFL++ coverage-guided fuzzing into CI/CD pipelines, covering harness construction, AFL++/AddressSanitizer/CmpLog instrumentation builds, and persistent-mode fuzzing to discover memory-corruption and input-handling vulnerabilities in C/C++ code. Use…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted, verified images deploy to GKE and Cloud Run. Use when enforcing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements GCP Organization Policy constraints via gcloud and Terraform, such as restricting external IPs, resource locations, default service accounts, and service account keys, plus dry-run testing of policy impact before enforcement. Use when enforcing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements and audits GCP VPC firewall rules using gcloud, covering auditing overly permissive rules, creating restrictive ingress/egress rules, hierarchical firewall policies, and monitoring rule effectiveness with VPC Flow Logs. Use when deploying GCP…

原文の言語: 英語

更新
職業分類
コンプライアンスオフィサー
説明

Implements GDPR (EU 2016/679) technical and organizational measures — privacy by design/default, DPIAs, data subject rights management, 72-hour breach notification, and cross-border transfer mechanisms (SCCs, BCRs, adequacy). Use when designing or auditing…

原文の言語: 英語

更新
職業分類
ソフトウェア品質保証アナリスト・テスター
説明

Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across repositories at enterprise scale, including custom CodeQL…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and external sharing restrictions. Use when hardening a Google Workspace…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication and enable immediate access revocation. Use when setting up…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Builds a FIDO2/WebAuthn relying party server with the python-fido2 library, covering registration and authentication ceremonies, YubiKey enrollment, resident key (discoverable credential/passkey) workflows, and user verification policies. Use when…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets in application configuration. Use when eliminating…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys and configures Tofino industrial firewalls (Belden/Hirschmann) to protect SCADA systems and PLCs, using deep packet inspection of OT protocols (Modbus, EtherNet/IP, OPC, S7comm) to enforce access control between ICS zones. Use when deploying…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys SailPoint IdentityNow or IdentityIQ for identity governance and administration, covering identity lifecycle management, access request workflows, certification campaigns, role mining, separation-of-duties (SOD) policy enforcement, and compliance…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Designs security zones and conduits for industrial control systems (IACS) per IEC 62443-3-2 — risk-based zone partitioning, Security Level target (SL-T) assignment, conduit controls, and firewall microsegmentation validated against the Purdue Reference Model.…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Signs and verifies container image provenance using Sigstore Cosign, covering key-based and keyless OIDC-based signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature verification via Kubernetes admission control. Use when signing…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data, retention enforcement, and restore testing. Use when building…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Implements automated security scanning for Infrastructure as Code using Checkov, tfsec, and KICS to detect misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts, plus policy-based governance and CI/CD integration. Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Guides implementation of an ISO/IEC 27001:2022 Information Security Management System (ISMS) end to end: gap analysis and scoping, risk assessment methodology, Annex A control selection, Statement of Applicability (SoA) creation, and continuous improvement.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access, covering approval workflows, automatic expiration/revocation, and PAM/IGA integration. Use when designing access approval workflows or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements secure JWT (RFC 7519) signing and verification using HMAC-SHA256, RSA-PSS, ES256, and EdDSA, including token expiration, claims validation, and defenses against algorithm-confusion, none-algorithm, and key-injection attacks. Use when adding or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements Kubernetes network segmentation using Calico's Kubernetes NetworkPolicy and GlobalNetworkPolicy resources, including default-deny rules, policy ordering, and service-account-based selectors for zero-trust pod-to-pod communication. Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures Kubernetes Pod Security Standards (Privileged, Baseline, Restricted) enforced via the built-in Pod Security Admission (PSA) controller (Kubernetes 1.25+), including namespace labeling and enforce/audit/warn modes. Use when hardening pod…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements input/output validation guardrails for LLM applications using NVIDIA NeMo Guardrails (Colang), custom Python validators for PII detection, and the Guardrails AI framework, intercepting user inputs (prompt injection, PII, off-topic queries) and…

原文の言語: 英語

更新
収集済み skill 817 件中 40 件を表示しています。