Skip to main content

このリポジトリの skills

Undermybelt/hermes-skills - 23ページ

SkillsMP は Undermybelt/hermes-skills から 1,242 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

Undermybelt/hermes-skills

収集済み skill 1,242 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis, URL/attachment…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag

原文の言語: 英語

更新
職業分類
その他の保護サービス従事者
説明

Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses…

原文の言語: 英語

更新
職業分類
ネットワーク・コンピュータシステム管理者
説明

Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in…

原文の言語: 英語

更新
職業分類
ネットワーク・コンピュータシステム管理者
説明

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.

原文の言語: 英語

更新
職業分類
その他のビジネスオペレーション専門家
説明

Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

原文の言語: 英語

更新
職業分類
ネットワーク・コンピュータシステム管理者
説明

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

原文の言語: 英語

更新
収集済み skill 1,242 件中 40 件を表示しています。