Skip to main content

このリポジトリの skills

Undermybelt/hermes-skills - 16ページ

SkillsMP は Undermybelt/hermes-skills から 1,242 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

Undermybelt/hermes-skills

収集済み skill 1,242 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying Docker containers in production. Based on the CIS Docker Benchmark, it audits host confi

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Trivy is a comprehensive open-source vulnerability scanner by Aqua Security that detects vulnerabilities in OS packages, language-specific dependencies, misconfigurations, secrets, and license violati

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Execute a phased DMARC rollout from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources are authenticated before blocking unauthorized senders.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic patterns using deep packet…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXT record abuse, and response payload sizes using passive DNS monitoring.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality. Uses scapy for packet capture analysis and statistical methods to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS environments against threat groups like…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Email sandboxing detonates suspicious attachments and URLs in isolated environments to detect zero-day malware and evasive phishing payloads. Proofpoint Targeted Attack Protection (TAP) is an industry

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (including the server) able to decrypt them. This skill implements a simplified version

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating content inspection policies, or preventing unauthorized data…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.

原文の言語: 英語

更新
収集済み skill 1,242 件中 40 件を表示しています。