Skip to main content

Skills neste repositório

Undermybelt/hermes-skills - Página 21

O SkillsMP coletou 1.242 skills de Undermybelt/hermes-skills. Abra uma skill para revisar a origem e os detalhes.

Undermybelt/hermes-skills

Mostrando 40 de 1.242 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks. Use when hardening endpoints against…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. Validates certificate chains, checks expiration, and audits mTLS deployment status. Use when…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Performs advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 1.242 skills coletadas.