Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 25페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools…

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and…

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Apply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.