Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 14페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Activates for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based policy design, device compliance requirements, risk-based authentication, named l

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Enforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous capability assignments, and host path mounts using the kubernetes Python client. Identifies CVE-2022-0492 style escapes via cgroup abuse. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scan container images for known vulnerabilities using Anchore Grype with SBOM-based matching and configurable severity thresholds.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.