performing-mobile-app-certificate-pinning-bypass

Use this skill when: Mobile app refuses connections through a proxy due to certificate pinning Performing authorized sec...

github

performing-memory-forensics-with-volatility3

When analyzing a RAM dump from a compromised or suspect system During incident response to identify running malware, inj...

github

performing-memory-forensics-with-volatility3-plugins

Volatility3 (v2.26.0+, feature parity release May 2025) is the standard framework for memory forensics, replacing the de...

github

performing-malware-triage-with-yara

Rapidly classifying a large batch of malware samples against known family signatures Writing detection rules for a newly...

github

performing-malware-ioc-extraction

Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise in...

github

performing-log-source-onboarding-in-siem

Log source onboarding is the systematic process of integrating new data sources into a SIEM platform to enable security ...

github

performing-kubernetes-penetration-testing

Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the A...

github

performing-kerberoasting-attack

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against syst...

github

performing-insider-threat-investigation

DLP (Data Loss Prevention) alerts on large data transfers to personal cloud storage or USB devices User behavior analyti...

github

performing-initial-access-with-evilginx3

EvilGinx3 is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, enabli...

github

performing-indicator-lifecycle-management

Indicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring...

github

performing-ics-asset-discovery-with-claroty

When gaining initial visibility into an OT environment with unknown or poorly documented assets When preparing for an IE...

github

performing-http-parameter-pollution-attack

When testing web applications for input validation bypass vulnerabilities During WAF evasion testing to split attack pay...

github

performing-graphql-security-assessment

During authorized penetration tests when the target application uses a GraphQL API When assessing single-page applicatio...

github

performing-graphql-introspection-attack

Testing GraphQL endpoints for exposed introspection that reveals the complete API schema Mapping the attack surface of a...

github

performing-graphql-depth-limit-attack

GraphQL depth limit attacks exploit the recursive nature of GraphQL schemas to craft deeply nested queries that consume ...

github

performing-gcp-security-assessment-with-forseti

When conducting periodic security assessments of GCP organizations and projects When onboarding new GCP projects and est...

github

performing-gcp-penetration-testing-with-gcpbucketbrute

This skill covers Google Cloud Platform security testing using GCPBucketBrute for storage bucket enumeration and access ...

github

performing-fuzzing-with-aflplusplus

AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided fuzzing for compiled bina...

github

performing-firmware-malware-analysis

A compromised IoT device or router needs firmware analysis to identify implanted backdoors Investigating UEFI/BIOS rootk...

github

performing-firmware-extraction-with-binwalk

Analyzing IoT device firmware downloaded from vendor sites or extracted from flash chips Reverse engineering router, cam...

github

performing-file-carving-with-foremost

When recovering files from unallocated disk space or corrupted file systems For extracting evidence from formatted or wi...

github

performing-false-positive-reduction-in-siem

False positive alerts are non-malicious events that trigger security rules, overwhelming SOC analysts with noise. Studie...

github

performing-external-network-penetration-test

An external network penetration test simulates a real-world attacker targeting an organization's internet-facing assets ...

github