Skip to main content

这个仓库中的 skills

oyi77/1ai-skills - 第 20 页

SkillsMP 已收集 oyi77/1ai-skills 中的 1,311 个 Skill。打开任一 Skill 可查看来源和详情。

oyi77/1ai-skills

已展示 40 / 1,311 个已收集 Skill。

职业分类
软件开发工程师
描述

Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps. Use when implementing software supply chain integrity verification for…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making. Use when implementing a structured threat…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments. Use when deploying and configure velociraptor…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol. Use when deploying and operate greenbone/openvas vulnerability management…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs. Use when working with implementing vulnerability…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati. Use when working with implementing zero knowledge proof…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls. Use when deploying cyberark secure cloud access to eliminate standing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints. Use when implementing nextdns as a zero trust dns filtering layer…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services. . Use…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration. Use when implementing hashicorp boundary for identity-aware zero trust infrastructure…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options. Use when working with investigating ransomware attack artifacts.

原文语言:英语

更新
职业分类
信息安全分析师
描述

IoT and embedded device security testing — firmware analysis, hardware interfaces, protocol exploitation. Use when testing IoT devices, extracting firmware, analyzing embedded systems, or finding hardware vulnerabilities. Use when working with iot hunter.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Linux and Windows kernel exploitation for privilege escalation. Use when finding kernel vulnerabilities, exploiting kernel drivers, or escalating privileges from user to root/system.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Trace and analyze blockchain transactions to investigate illicit fund flows, identify wallet clusters, and map transaction graphs across multiple blockchains. Use when investigating stolen funds, following money trails on-chain, analyzing suspicious…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Orchestrate 35 specialized Claude Code subagents for offensive security. Use when planning a pentest, routing tasks to specialist agents, or conducting multi-phase security assessments.

原文语言:英语

更新
职业分类
信息安全分析师
描述

AI-powered pentesting terminal UI with 4 modes (Assist, Agent, Crew, Interact) and RAG knowledge system. Use when running interactive pentests, multi-agent security assessments, or.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA. Use when configureing and execute access recertification…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin. Use when working with performing active directory bloodhound analysis.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths. Use when working with performing active directory…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment. Use when working with performing active…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise. Use when conducting a focused active…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors. Use when working with performing active directory vulnerability assessment.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens. Use when detecting and respond to adversary-in-the-middle (aitm) phishing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents. Use when configureing and execute agentless vulnerability scanning using…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email lookups, social media profiles, domain records, breach databases, and dark-web mentions—into unified intelligence profiles with confidence scoring…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations. Use when performing systematic alert triage in elastic security siem to rapidly.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability bugs. The…

原文语言:英语

更新
已展示 40 / 1,311 个已收集 Skill。