Skip to main content

이 저장소의 skills

oyi77/1ai-skills - 15페이지

SkillsMP는 oyi77/1ai-skills에서 1,311개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

oyi77/1ai-skills

수집된 skill 1,311개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis. Use when detecting rdp brute force…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers. . Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns. Use when detecting abuse of service accounts through anomalous interactive logons, privilege.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms. Use when working with detecting shadow api endpoints.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification. Use when detecting unauthorized saas and cloud service usage…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,. Use when working with detecting spearphishing with email…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks. Use when detecting risky oauth application consent grants in azure ad /.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion. Use when detecting suspicious powershell execution patterns including encoded commands, download…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation. Use when detecting os credential dumping techniques…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns. Use when detecting…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships. Use when detecting abuse of…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation. Use when detecting wmi event subscription persistence by analyzing sysmon event ids.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection. Use when working with eradicating malware from infected systems.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins. Use when working with executing red team engagement…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments. Use when exploiting misconfigured active directory…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac. Use when working with exploiting active directory with…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure. . Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker. Use when working with exploiting broken link hijacking.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation. Use when exploiting kerberos constrained delegation…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers. Use when working with exploiting http request smuggling.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs. Use when working with exploiting idor vulnerabilities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests. Use when working with exploiting insecure deserialization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses. . Use when working with…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts. Use when performing kerberoasting attacks using impacket's getuserspns to extract and crack.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests. Use when working with exploiting mass assignment in rest…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it. Use when working with exploiting ms17 010 eternalblue…

원문 언어: 영어

업데이트
수집된 skill 1,311개 중 40개를 표시합니다.