Skip to main content

このリポジトリの skills

Undermybelt/hermes-skills - 17ページ

SkillsMP は Undermybelt/hermes-skills から 1,242 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

Undermybelt/hermes-skills

収集済み skill 1,242 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories,…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Performs entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows. Activates…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization's external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and NER, data mapping, response templating per Article 15 requirements, deadline tracking, and audit logging.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

原文の言語: 英語

更新
収集済み skill 1,242 件中 40 件を表示しています。