Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 12페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based on business impact, data sensitivity, and operational importance.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with SSH and SMB credentials for comprehensive host-level assessment.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security sett

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.