Skip to main content

このリポジトリの skills

nexuslinkproductions/yuri-os - 4ページ

SkillsMP は nexuslinkproductions/yuri-os から 1,033 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

nexuslinkproductions/yuri-os

収集済み skill 1,033 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

>- Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare, Expose, Affect, Elicit, Understand), the 10-Step…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors across authentication…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Map AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

>- Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes authorized phishing simulation campaigns to assess an organization''s susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization''s people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF)…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Use Pacu modules for AWS privilege escalation, persistence, and backdooring.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent…

原文の言語: 英語

更新
収集済み skill 1,033 件中 40 件を表示しています。