Skip to main content

이 저장소의 skills

nexuslinkproductions/yuri-os - 10페이지

SkillsMP는 nexuslinkproductions/yuri-os에서 1,033개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

nexuslinkproductions/yuri-os

수집된 skill 1,033개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

>- Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS data, and IP enrichment to map and monitor threat actor command-and-control networks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Architect redirectors with nginx and Apache, malleable profiles, and OPSEC for resilient C2.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation, role mining, access request workflows, periodic recertification, and orphaned account remediation using IGA platforms. Activates for requests…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing and distribute them in STIX format through TAXII feeds and threat intelligence platforms.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp…

원문 언어: 영어

업데이트
수집된 skill 1,033개 중 40개를 표시합니다.