Skip to main content

이 저장소의 skills

xalgord/xalgorix - 21페이지

SkillsMP는 xalgord/xalgorix에서 855개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

xalgord/xalgorix

수집된 skill 855개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing web applications for CRLF (Carriage Return / Line Feed) injection where unsanitized %0d%0a sequences in user input let an attacker inject HTTP headers, split responses, poison caches, plant cookies, or pivot to XSS and request smuggling. Activates…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing web applications for Regular Expression Denial of Service (ReDoS), where crafted input forces a backtracking regex engine into super-linear (polynomial or exponential) processing time, hanging worker threads and causing denial of service. Also covers…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting weaknesses in password reset flows including weak reset tokens, host header poisoning, IDOR on the identification parameter, missing session invalidation, and account enumeration.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting weaknesses in account registration including duplicate/overwrite registration, weak password policy, missing email verification, disposable email acceptance, route-clobbering usernames, pre-account-takeover, and role mass-assignment.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting weaknesses in session handling including fixation, weak token entropy, missing cookie flags, improper invalidation on logout/password change, and client-side session tampering.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and device posture, and integrating with IdPs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for VPN replacement.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and Chrome Enterprise Premium for VPN-less secure application access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance before granting resource access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce identity and posture-based access to GCP resources and internal…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS Foundations…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

원문 언어: 영어

업데이트
수집된 skill 855개 중 40개를 표시합니다.