Skip to main content

このリポジトリの skills

oyi77/1ai-skills - 14ページ

SkillsMP は oyi77/1ai-skills から 1,311 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

oyi77/1ai-skills

収集済み skill 1,311 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks. Use when detecting and test for owasp api3:2023 broken object property level.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,. Use when working with detecting business email compromise.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image. Use when detecting unauthorized modifications to running containers by…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators. Use when working with detecting container escape attempts.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation. Use when detecting container escape attempts in real-time using falco runtime security.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules. Use when detecting lsass credential dumping, sam database extraction, and ntds.dit theft.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges. Use when detecting dcsync attacks where…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion. Use when detecting dll side-loading attacks where adversaries place malicious dlls alongside.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring. Use when detecting data exfiltration through dns tunneling by analyzing query…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs. Use when detecting compromised o365 and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks. Use when detecting malicious email forwarding rules created by adversaries to maintain.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs. Use when detecting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft. Use when detecting insider threat behavioral indicators including unusual data access,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking. Use when detecting kerberoasting attacks by monitoring for anomalous kerberos tgs requests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems. . Use when working…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse. Use when detecting adversary lateral movement across networks using splunk spl queries.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns. . Use when working with detecting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules. Use when detecting mimikatz execution through command-line patterns, lsass access signatures, binary.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity. Use when detecting network reconnaissance and port…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping. Use when detecting pass-the-hash attacks by analyzing ntlm authentication…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM. Use when detecting kerberos pass-the-ticket (ptt) attacks by analyzing windows event ids.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. . Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux. Use when detecting privilege escalation attempts including token manipulation, uac bypass,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies. Use when detecting and prevent privilege escalation in kubernetes pods by monitoring.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry. Use when detecting process hollowing (t1055.012) by analyzing memory-mapped sections, hollowed process.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails. Use when detecting and prevent qr code phishing (quishing) attacks that bypass.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use when detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use when detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network…

原文の言語: 英語

更新
収集済み skill 1,311 件中 40 件を表示しています。