Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 28페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
기타 비즈니스 운영 전문가
설명

Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Analyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for…

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.

원문 언어: 영어

업데이트
직업 분류
기타 비즈니스 운영 전문가
설명

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source…

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.