AWS security configuration scanning and hardening using Prowler, Security Hub, and AWS Config
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 2.079 skills de a5c-ai/babysitter. Abra uma skill para revisar a origem e os detalhes.
a5c-ai/babysitterMostrando 40 de 2.079 skills coletadas.
AWS security configuration scanning and hardening using Prowler, Security Hub, and AWS Config
Idioma do texto original: inglês
Azure security configuration scanning and hardening using Azure Security Center, Azure Policy, and ScoutSuite
Idioma do texto original: inglês
Automated evidence collection across compliance frameworks from cloud providers, identity systems, and security tools
Idioma do texto original: inglês
Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance
Idioma do texto original: inglês
Cryptographic implementation analysis and validation for encryption algorithms, key sizes, and certificate management
Idioma do texto original: inglês
Dynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope, correlate findings with SAST results, and generate comprehensive vulnerability reports.
Idioma do texto original: inglês
GCP security configuration scanning and hardening using Security Command Center, Forseti, and ScoutSuite
Idioma do texto original: inglês
GDPR compliance assessment and automation for data mapping, consent management, DSAR handling, and privacy impact assessments
Idioma do texto original: inglês
Git diff forensics for surfacing and classifying code changes for trojan detection
Idioma do texto original: inglês
HIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation
Idioma do texto original: inglês
Byte-level Unicode homoglyph detection for identifying invisible character substitutions in code
Idioma do texto original: inglês
Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi
Idioma do texto original: inglês
Cryptographic key lifecycle management orchestration including generation, rotation, and destruction across key management systems
Idioma do texto original: inglês
Unified cloud security posture management across AWS, Azure, and GCP with normalized metrics and CIS benchmark comparison
Idioma do texto original: inglês
Automated OWASP Top 10 vulnerability detection and assessment. Run OWASP ZAP automated scans, detect injection vulnerabilities, identify broken authentication patterns, check for sensitive data exposure, analyze security misconfigurations, and generate…
Idioma do texto original: inglês
PCI DSS compliance assessment and reporting for cardholder data protection, SAQ automation, and ASV scan orchestration
Idioma do texto original: inglês
Phishing simulation campaign execution and analysis for security awareness assessment
Idioma do texto original: inglês
Detect secrets, credentials, and sensitive data in code and configurations. Scan git history for secrets, detect API keys, tokens, passwords, check environment files, monitor CI/CD logs for exposure, generate remediation steps, and track secret rotation…
Idioma do texto original: inglês
Developer security training and assessment for secure coding practices and vulnerability prevention
Idioma do texto original: inglês
LLM-powered semantic analysis of code diffs to detect business-logic trojans
Idioma do texto original: inglês
SOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation
Idioma do texto original: inglês
Continuous vendor security monitoring for security ratings, breach notifications, and risk change detection
Idioma do texto original: inglês
Automated vendor security assessment through questionnaire generation, response parsing, and risk scoring
Idioma do texto original: inglês
AI/ML model security testing and adversarial research capabilities. Generate adversarial examples, test model robustness, perform model extraction attacks, test for data poisoning, analyze model fairness, and support ART framework integration.
Idioma do texto original: inglês
Advanced binary exploitation and mitigation bypass
Idioma do texto original: inglês
Web application security testing with Burp Suite integration
Idioma do texto original: inglês
Multi-cloud security assessment and penetration testing capabilities. Execute Prowler/ScoutSuite assessments, analyze IAM policies, identify cloud misconfigurations, test permissions, and enumerate cloud resources across AWS/GCP/Azure.
Idioma do texto original: inglês
CVE and CWE database querying and management
Idioma do texto original: inglês
Advanced debugging integration for vulnerability research
Idioma do texto original: inglês
Comprehensive fuzzing operations with AFL++, libFuzzer, and OSS-Fuzz integration
Idioma do texto original: inglês
Deep integration with Ghidra and IDA Pro for binary analysis and reverse engineering
Idioma do texto original: inglês
Hardware and embedded security research capabilities. Interface with JTAG debuggers, analyze SPI/I2C communications, dump and analyze firmware, support fault injection, side-channel analysis, and hardware exploitation research.
Idioma do texto original: inglês
Digital forensics and incident response capabilities. Analyze memory dumps with Volatility, parse filesystem artifacts, extract browser forensics, analyze Windows event logs, create forensic timelines, recover deleted files, and generate forensic reports.
Idioma do texto original: inglês
MITRE ATT&CK framework mapping and analysis
Idioma do texto original: inglês
Android and iOS application security testing
Idioma do texto original: inglês
Offensive security tools and techniques integration
Idioma do texto original: inglês
Network protocol capture, analysis, and fuzzing capabilities
Idioma do texto original: inglês
Exploit development automation using pwntools framework
Idioma do texto original: inglês
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and process changes.
Idioma do texto original: inglês
Ethereum and blockchain smart contract security analysis
Idioma do texto original: inglês