Skip to main content

这个仓库中的 skills

xalgord/xalgorix - 第 5 页

SkillsMP 已收集 xalgord/xalgorix 中的 855 个 Skill。打开任一 Skill 可查看来源和详情。

xalgord/xalgorix

已展示 40 / 855 个已收集 Skill。

职业分类
信息安全分析师
描述

Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools,…

原文语言:英语

更新
职业分类
软件质量保证分析师与测试员
描述

Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts…

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in…

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment

原文语言:英语

更新
职业分类
软件开发工程师
描述

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

原文语言:英语

更新
职业分类
软件质量保证分析师与测试员
描述

This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and…

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure production-ready images.

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in…

原文语言:英语

更新
职业分类
软件开发工程师
描述

This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

原文语言:英语

更新
已展示 40 / 855 个已收集 Skill。