Skip to main content

OWASP/openshield

SkillsMP는 OWASP/openshield에서 14개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
14
GitHub 스타
56
GitHub 포크
68

이 저장소의 skills

분류 대기 중

수집된 skill 14개 중 14개를 표시합니다.

직업 분류
미분류
설명

Identifies and remediates non-quantum-safe cryptographic configurations in Azure including classical TLS key exchange, RSA and ECC keys in Key Vault, and classical certificate algorithms. Maps findings to NIST PQC standards FIPS 203, FIPS 204, and FIPS 205.…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Queries Azure Monitor activity logs and sign-in logs to detect suspicious administrative operations, impossible travel, and privilege escalation.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Detect abnormal access patterns in Azure Blob Storage by analyzing Storage Analytics and diagnostic logs. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetBlob spikes), and potential data exfiltration.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, and guest user risks.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Conduct cloud security audits using Center for Internet Security (CIS) benchmarks for Azure. Covers interpreting CIS Foundations Benchmark controls, running automated assessments, and maintaining continuous compliance monitoring.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for Azure. Covers configuring data connectors (Entra ID, Azure Activity), writing KQL detection queries, and building automated response playbooks.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Establish SAML 2.0 identity federation between on-premises Active Directory and Microsoft Entra ID (Azure AD) for seamless cross-domain authentication and SSO.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Builds comprehensive identity governance and lifecycle management processes in Azure Entra ID, including JML (Joiner-Mover-Leaver) automation and periodic access reviews.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Offensive methodology for Hybrid Active Directory and Entra ID (Azure AD). Covers pivots from on-premises to cloud (AAD Connect, Golden SAML) and cloud-to-on-prem (DCSync).

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Azure-specific offensive security testing methodology. Covers credential harvesting (IMDS, managed identities), enumeration, privilege escalation, and data exfiltration within Azure subscriptions and Entra ID tenants.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Insecure Direct Object Reference (IDOR) testing skill focused on Azure resource identifiers and API endpoints. Covers GUID enumeration, horizontal/vertical privilege escalation, and Azure-specific object reference vulnerabilities.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, and blind SQLi with Azure SQL specific attack paths. Use when performing web application SQL injection testing, database enumeration, or…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Server-Side Request Forgery (SSRF) testing skill with focus on Azure metadata services and internal network pivots. Covers discovery, bypass techniques, and Azure-specific exploitation (IMDS, Managed Identities).

원문 언어: 영어

업데이트
직업 분류
미분류
설명

WAF bypass techniques checklist for Azure Front Door and Application Gateway. Covers encoding bypass, header manipulation, and Azure-specific evasion strategies.

원문 언어: 영어

업데이트
수집된 skill 14개 중 14개를 표시합니다.