Skip to main content

nexuslinkproductions/yuri-os

SkillsMP는 nexuslinkproductions/yuri-os에서 1,033개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
1,033
GitHub 스타
2
GitHub 포크
0

수집된 skill 1,033개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Extract DPAPI-protected secrets such as credentials and browser data offline and online.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

>- Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

>- Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated…

원문 언어: 영어

업데이트
수집된 skill 1,033개 중 40개를 표시합니다.