implementing-saml-sso-with-okta

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configur...

github

implementing-runtime-security-with-tetragon

Tetragon is a CNCF project under Cilium that provides flexible Kubernetes-aware security observability and runtime enfor...

github

implementing-rsa-key-pair-management

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures,...

github

implementing-rbac-hardening-for-kubernetes

Kubernetes RBAC regulates access to cluster resources based on roles assigned to users, groups, and service accounts. De...

github

implementing-rapid7-insightvm-for-scanning

Rapid7 InsightVM (formerly Nexpose) is an enterprise vulnerability management platform that combines on-premises scannin...

github

implementing-proofpoint-email-security-gateway

Proofpoint Email Protection is a cloud-native secure email gateway (SEG) that acts as a security checkpoint where all in...

github

implementing-privileged-session-monitoring

Deploying or configuring session recording for all privileged access to critical servers and databases Meeting complianc...

github

implementing-pod-security-admission-controller

Pod Security Admission (PSA) is a built-in Kubernetes admission controller (stable since v1.25) that enforces Pod Securi...

github

implementing-pci-dss-compliance-controls

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit...

github

implementing-pam-for-database-access

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers ses...

github

implementing-next-generation-firewall-with-palo-alto

Palo Alto Networks Next-Generation Firewalls (NGFWs) move beyond traditional port-based rule enforcement to application-...

github

implementing-network-traffic-baselining

Network traffic baselining establishes normal communication patterns by analyzing historical NetFlow/IPFIX data to creat...

github

implementing-network-policies-for-kubernetes

Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traf...

github

implementing-network-intrusion-prevention-with-suricata

Suricata is a high-performance, open-source network threat detection engine developed by the Open Information Security F...

github

implementing-network-deception-with-honeypots

When deploying deception technology to detect lateral movement To create early warning indicators for network intrusion ...

github

implementing-memory-protection-with-dep-aslr

Use this skill when hardening endpoints against memory-based exploits by configuring DEP, ASLR, CFG, and Windows Exploit...

github

implementing-log-integrity-with-blockchain

When deploying or configuring implementing log integrity with blockchain capabilities in your environment When establish...

github

implementing-log-forwarding-with-fluentd

This skill covers configuring Fluentd and Fluent Bit for centralized log collection, routing, and enrichment. Fluent Bit...

github

implementing-llm-guardrails-for-security

Deploying a new LLM-powered application that processes user input and needs input/output safety controls Adding content ...

github

implementing-kubernetes-pod-security-standards

Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforce...

github

implementing-kubernetes-network-policy-with-calico

Calico is an open-source CNI plugin that provides fine-grained network policy enforcement for Kubernetes clusters. It im...

github

implementing-jwt-signing-and-verification

JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization in web ...

github

implementing-just-in-time-access-provisioning

Implement Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound acce...

github

implementing-immutable-backup-with-restic

Establishing ransomware-resistant backup infrastructure with cryptographic integrity verification Implementing 3-2-1-1-0...

github