Skip to main content

这个仓库中的 skills

oyi77/1ai-skills - 第 4 页

SkillsMP 已收集 oyi77/1ai-skills 中的 1,311 个 Skill。打开任一 Skill 可查看来源和详情。

oyi77/1ai-skills

已展示 40 / 1,311 个已收集 Skill。

职业分类
信息安全分析师
描述

Use when deploying FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use when this skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when deploying CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when implementing privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when implementing SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when implementing automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when creating, validating, and sharing STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when implementing security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when automating phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when implementing automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when configuring rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when deploying and configuring an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when building automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when configuring ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tuning rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use when this skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when this skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with their roles. This skill covers review campaign design, reviewer selection, risk-based p

原文语言:英语

更新
职业分类
软件质量保证分析师与测试员
描述

Use when using Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when deploying and operating CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when performing comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when analyzing binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when hunting for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use when this skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when performing entitlement review and access certification campaigns using SailPoint IdentityIQ including manager certifications, targeted entitlement reviews, role-based access validation, SOD violation remediation, and automated revocation workflows.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when performing firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when analyzing firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when performing coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when auditing Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when performing rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use when automating network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files

原文语言:英语

更新
已展示 40 / 1,311 个已收集 Skill。