Skip to main content

Skills neste repositório

autohandai/community-skills - Página 23

O SkillsMP coletou 1.040 skills de autohandai/community-skills. Abra uma skill para revisar a origem e os detalhes.

autohandai/community-skills

Mostrando 40 de 1.040 skills coletadas.

ocupação
Administradores de redes e sistemas de computador
descrição

This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, and credential…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate permissions, and enforcing role scoping through SCPs.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned…

Idioma do texto original: inglês

atualizado
ocupação
Administradores de redes e sistemas de computador
descrição

This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses cloud-specific…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Integrate security scanning into CI/CD pipelines using tools like Semgrep, Trivy, and Gitleaks. Covers SAST, SCA, container scanning, and secret detection with structured JSON output for pipeline gates.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability bugs. The tester…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server,…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 1.040 skills coletadas.