implementing-vulnerability-remediation-sla

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based o...

github

analyzing-sbom-for-supply-chain-vulnerabilities

A new regulatory requirement (EO 14028, EU CRA) mandates SBOM analysis for software deliveries Security team needs to as...

github

implementing-sigstore-for-software-signing

Signing container images and software artifacts without managing long-lived cryptographic keys Establishing verifiable p...

github

analyzing-mft-for-deleted-file-recovery

The NTFS Master File Table ($MFT) is the central metadata repository for every file and directory on an NTFS volume. Eac...

github

detecting-modbus-command-injection-attacks

When deploying intrusion detection for environments using Modbus TCP (port 502) or Modbus RTU When investigating suspect...

github

testing-for-business-logic-vulnerabilities

During authorized penetration tests when automated scanners have found few technical vulnerabilities When assessing e-co...

github

performing-mobile-device-forensics-with-cellebrite

When extracting evidence from smartphones or tablets during an investigation For recovering deleted messages, call logs,...

github

detecting-typosquatting-packages-in-npm-pypi

Auditing project dependencies to identify packages whose names are suspiciously similar to popular libraries Proactively...

github

detecting-privilege-escalation-in-kubernetes-pods

Privilege escalation in Kubernetes occurs when a pod or container gains elevated permissions beyond its intended scope. ...

github

implementing-patch-management-for-ot-systems

When establishing a formal OT patch management program for the first time When responding to critical ICS-CERT advisorie...

github

generating-threat-intelligence-reports

Use this skill when: Producing weekly, monthly, or quarterly threat intelligence summaries for security leadership Creat...

github

implementing-opa-gatekeeper-for-policy-enforcement

OPA Gatekeeper is a Kubernetes admission controller that enforces policies written in Rego. It uses ConstraintTemplates ...

github

implementing-end-to-end-encryption-for-messaging

End-to-end encryption (E2EE) ensures that only the communicating parties can read messages, with no intermediary (includ...

github

implementing-api-gateway-security-controls

Deploying a centralized authentication and authorization layer for microservice APIs Implementing rate limiting, throttl...

github

implementing-infrastructure-as-code-security-scanning

When provisioning cloud infrastructure with Terraform, CloudFormation, or Pulumi and needing automated security validati...

github

performing-privileged-account-access-review

Privileged Account Access Review is a critical identity governance process that validates whether users with elevated pe...

github

exploiting-insecure-data-storage-in-mobile

Use this skill when: Assessing whether mobile applications store sensitive data securely on the device filesystem Testin...

github

implementing-cloud-dlp-for-data-protection

When compliance frameworks (GDPR, HIPAA, PCI DSS) require automated sensitive data discovery and protection When buildin...

github

detecting-service-account-abuse

When proactively hunting for indicators of detecting service account abuse in the environment After threat intelligence ...

github

testing-jwt-token-security

During authorized penetration tests when the application uses JWT for authentication or authorization When assessing API...

github

analyzing-threat-actor-ttps-with-mitre-navigator

The MITRE ATT&CK Navigator is a web application for annotating and visualizing ATT&CK matrices. Combined with the attack...

github

implementing-nerc-cip-compliance-controls

When a registered entity must achieve or maintain NERC CIP compliance for BES cyber systems When preparing for a NERC CI...

github

implementing-velociraptor-for-ir-collection

Velociraptor is an advanced open-source endpoint monitoring, digital forensics, and incident response platform developed...

github

performing-phishing-simulation-with-gophish

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness ...

github