Skip to main content

このリポジトリの skills

yanacuti1121/Yana-AI - 5ページ

SkillsMP は yanacuti1121/Yana-AI から 1,566 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

yanacuti1121/Yana-AI

収集済み skill 1,566 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identify ransomware network indicators including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange via Zeek conn.log and NetFlow analysis

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Generates Angular code and provides architectural guidance. Trigger when creating projects, components, or services, or for best practices on reactivity (signals, linkedSignal, resource), forms, dependency injection, routing, SSR, accessibility (ARIA),…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Design and implement API rate limiting — algorithm selection (token bucket, sliding window, fixed window), Redis-based distributed limiting, per-user and per-IP limits, rate limit headers, retry-after, and burst handling. Use when asked to "add rate…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Use when asked to check an iOS/macOS app before App Store submission, scan for App Store rejection patterns, validate app metadata/privacy manifest/subscription compliance, or run pre-submission Apple Review guidelines checks. Triggers on: 'app store…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Merkle-tree-backed append-only log for distributed audit trails. Hypercore feed creation, append entries, replicate over network, sparse access, and integration with L0 audit hash-chain. Sources: holepunchto/hypercore.

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Streaming ZIP and TAR archive creation for agent release packaging. node-archiver streaming API, append files/directories, compression levels, progress events, and integrity verification. Sources: archiverjs/node-archiver.

原文の言語: 英語

更新
職業分類
ネットワーク・コンピュータシステム管理者
説明

Argo CD GitOps reconciliation loop for agent infrastructure. App-of-Apps pattern, sync policies, drift detection, progressive rollouts, and automated self-healing from Git as single source of truth. Sources: argoproj/argo-cd (Apache-2.0).

原文の言語: 英語

更新
職業分類
その他の高等教育教員
説明

Use when asked to search for academic papers, find related work, look up research on a topic, or retrieve papers from arXiv. Triggers on: 'search papers', 'find papers about', 'arxiv search', 'academic search', 'find related work', 'research papers on',…

原文の言語: ベトナム語

更新
職業分類
データサイエンティスト
説明

Kho tổng hợp 500+ project AI/ML/DL/CV/NLP kèm code — reference nhanh khi cần implementation mẫu. Bao gồm CV, NLP, healthcare ML, time series, production ML.

原文の言語: ベトナム語

更新
職業分類
ソフトウェア開発者
説明

Statically scan agent-generated JavaScript and shell scripts for dangerous patterns using AST analysis (acorn/swc). Detect eval(), process.env access, dynamic require(), child_process usage, and path traversal before code execution.

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Async key-value storage with automatic driver selection. localForage API patterns, IndexedDB/WebSQL/localStorage fallback chain, binary data storage, expiry patterns, and offline-first agent state persistence. Sources: localForage/localForage.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Design authentication and authorization systems — JWT lifecycle, OAuth 2.0 / OIDC flows, token storage, refresh strategy, RBAC and ABAC permission models. Use when asked about "login flow", "JWT", "OAuth", "refresh token", "access control", "permissions",…

原文の言語: 英語

更新
収集済み skill 1,566 件中 40 件を表示しています。