Skip to main content

이 저장소의 skills

Undermybelt/hermes-skills - 29페이지

SkillsMP는 Undermybelt/hermes-skills에서 1,242개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Undermybelt/hermes-skills

수집된 skill 1,242개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and device posture, and integrating with IdPs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when auditing bounty scope CSVs, public source repos, or no-account bounty surfaces such as exposed RPC/API services; also use for HackerOne-style reports, weakness classification, and PoC zip attachments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Jailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Class-level umbrella for sub.hdd.sb puzzle platform reverse engineering, Tampermonkey/userscript automation, solver hotfixes, and game-specific debugging across puzzle15, 2048, memory, sudoku, and tile-style games. Use when working on the sub.hdd.sb platform…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

AI engineering curriculum reference.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Real-time search engine supporting web search, vertical domain search, parallel batch search, and URL content extraction.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Gap-driven arXiv research: identify gaps in project docs, search arXiv API for papers, extract key sections via ar5iv HTML fallback, write structured synthesis md, convert best paper to Python. Trigger when user asks to 'find papers', 'research papers for X',…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Autonomous experiment/evaluate/iterate loop for code, prompts, skills, or workflows. Use when optimizing a measurable metric with repeated keep/discard decisions and resumable state.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Monitor blogs and RSS/Atom feeds via blogwatcher-cli tool.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Use the reviewed local bpc-fetch source as an optional article discovery, supported-site lookup, and authorized article-export CLI wrapper. Activate when the user mentions bpc-fetch, Bypass Paywalls Clean, paywall article discovery, supported paywall sites,…

원문 언어: 영어

업데이트
수집된 skill 1,242개 중 40개를 표시합니다.