Skip to main content

EvilFreelancer/secs

SkillsMP 已收集 EvilFreelancer/secs 中的 33 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
33
GitHub 星标
9
GitHub Forks
2

这个仓库中的 skills

1 个职业分类 · 已分类 100%

已展示 33 / 33 个已收集 Skill。

职业分类
信息安全分析师
描述

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O file, firmware image, or stripped binary, recovering an…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Use when handed a suspicious file, hash, or sample, when triaging an alert artifact, or when…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction from memory-resident data. Use when examining a memory capture…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze a reported or suspected phishing email safely — parse the Received chain and Return-Path, validate SPF/DKIM/DMARC alignment, extract and defang URLs and attachments, detonate payloads in a sandbox, and pivot on sender infrastructure to produce IOCs…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Attack and enumerate Active Directory environments using Kerberos attacks (Kerberoasting, ASREPRoasting), credential dumping (DCSync, Mimikatz), lateral movement (PtH, PtT), and BloodHound analysis. Use when pentesting Windows domains or exploiting AD…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Attack WiFi networks using WPA/WPA2 cracking, WPS exploitation, Evil Twin attacks, deauthentication, and wireless reconnaissance. Use when pentesting wireless networks or performing WiFi security assessments.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. Use when reviewing a codebase or diff for security bugs, performing a security audit, hunting for vulnerabilities in a…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit a Model Context Protocol server's own implementation for how it can subvert or exfiltrate from the agent that connects to it — tool-description injection (tool poisoning), tool shadowing and rug pulls, per-tool authorization and input schemas, SSRF via…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit software supply chain risk — dependency and transitive package review, typosquatting and dependency confusion, lockfile and SBOM analysis, CI/CD pipeline and GitHub Actions security, build provenance, and secrets exposure. Use when assessing third-party…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Enumerate and exploit network services including SMB, FTP, SSH, RDP, HTTP, databases (MySQL, MSSQL, PostgreSQL, MongoDB), LDAP, NFS, DNS, and SNMP. Use when testing network service security or performing port-based exploitation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Escalate privileges on Linux systems using SUID/SGID binaries, capabilities, sudo misconfigurations, cron jobs, kernel exploits, and container escapes. Use when performing Linux post-exploitation or privilege escalation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Escalate privileges on Windows systems using service misconfigurations, DLL hijacking, token manipulation, UAC bypasses, registry exploits, and credential dumping. Use when performing Windows post-exploitation or privilege escalation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Maintain authorized access across reboots and credential changes during red-team post-exploitation — Windows autostart (Run keys, services, scheduled tasks, WMI subscriptions), Linux (cron, systemd, shell profiles, SSH keys), Active Directory (accounts,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit AWS, Azure, and GCP cloud misconfigurations including S3 buckets, IAM roles, metadata services, serverless functions, and cloud-specific privilege escalation. Use when pentesting cloud environments or assessing cloud security.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data),…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Hunt for planted webshells and server-side backdoors on web infrastructure — recently-changed files in web roots, dangerous-callable content signatures (eval/system/base64), YARA scans, web-server log anomalies (POST to static-looking paths, rare user…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate a suspected AWS compromise from the control plane — CloudTrail management and data events (queried with Athena or CloudTrail Lake), GuardDuty findings, VPC Flow Logs, and CloudWatch — to reconstruct IAM/STS abuse, persistence, data access, and log…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate a suspected Azure and Entra ID compromise from the control plane — Azure Activity Log, Entra sign-in and audit logs, and the Microsoft 365 unified audit log, queried with KQL in Log Analytics/Sentinel — to reconstruct identity abuse, MFA and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate a suspected Google Cloud compromise from the control plane — Cloud Audit Logs (Admin Activity, Data Access, System Event, Policy Denied), Cloud Logging, and VPC Flow Logs — to reconstruct IAM and service-account abuse, key creation, data access,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate a live or triaged Windows host for intrusion evidence using disk and registry artifacts — MFT/$UsnJrnl, registry hives, AmCache/ShimCache, Prefetch, LNK/JumpLists, ShellBags, and event logs — parsed with the Eric Zimmerman suite and consolidated…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Run authorized social-engineering assessments — pretext development from OSINT, phishing and spearphishing campaigns (Gophish), vishing and smishing, and physical pretexting — to measure the human attack surface and produce awareness-driving metrics. Use when…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Turn raw observations, extracted IOCs, and open sources into finished threat intelligence — running the intelligence cycle (direction, collection, processing, analysis, dissemination, feedback), enriching and grading indicators, pivoting on TTPs over atomic…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test REST and GraphQL APIs for authentication bypasses, authorization flaws, IDOR, mass assignment, injection attacks, and rate limiting issues. Use when pentesting APIs or testing microservices security.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Safely assess industrial control system and OT networks and their protocols (Modbus, DNP3, S7comm, EtherNet/IP-CIP, OPC UA, IEC 60870-5-104, BACnet) using a passive-first, safety-gated methodology aligned to the Purdue model and IEC 62443. Use when mapping an…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test Android and iOS applications for security flaws following OWASP MASVS/MASTG — insecure data storage, weak transport security and certificate pinning, broken authentication and session handling, cryptography misuse, exported-component and deep-link abuse,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test web applications for security vulnerabilities including SQLi, XSS, command injection, JWT attacks, SSRF, file uploads, XXE, and API flaws. Use when pentesting web apps, analyzing authentication, or exploiting OWASP Top 10 vulnerabilities.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is loaded into a model's context and its config can run on startup. Use when reviewing a skill pack, Claude Code / Cursor / Cline plugin, or MCP…

原文语言:英语

更新
已展示 33 / 33 个已收集 Skill。