Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 26페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational…

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response…

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Plan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access. Unlike broad phishing campaigns, spearphishing uses OSINT-derived intelligence to craf

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring, renewing, and revoking X.509 certificates. Poor certificate management is a leading

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169.254.169.254), internal port scanning…

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.