Skip to main content

이 저장소의 skills

xalgord/xalgorix - 3페이지

SkillsMP는 xalgord/xalgorix에서 855개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

xalgord/xalgorix

수집된 skill 855개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud DLP API to discover, classify, and protect sensitive data across cloud storage, databases, and data pipelines.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Cloud Security Posture Management (CSPM) to continuously monitor multi-cloud environments for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Azure Defender, and GCP Security Command…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks. It details configuring managed rule sets, creating custom rules for business logic…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing and auditing GCP VPC firewall rules to enforce network segmentation, restrict ingress and egress traffic, apply hierarchical firewall policies across the organization, and monitor firewall rule effectiveness using VPC Flow Logs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform GCP security testing using GCPBucketBrute for storage bucket enumeration, gcloud IAM privilege escalation path analysis, and service account permission auditing

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage permissions, and compliance against CIS GCP Foundations…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate permissions, and enforcing role scoping through SCPs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses cloud-specific…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

원문 언어: 영어

업데이트
수집된 skill 855개 중 40개를 표시합니다.