implementing-deception-based-detection-with-canarytoken

Canary Tokens are lightweight tripwire mechanisms that alert when an attacker accesses a resource. This skill uses the T...

github

performing-web-cache-deception-attack

When testing applications behind CDNs or reverse proxies (Cloudflare, Akamai, Varnish, Nginx) During assessment of authe...

github

implementing-zero-standing-privilege-with-cyberark

Zero Standing Privileges (ZSP) is a security model where no user or identity retains persistent privileged access. Inste...

github

analyzing-active-directory-acl-abuse

Active Directory Access Control Lists (ACLs) define permissions on AD objects through Discretionary Access Control Lists...

github

configuring-identity-aware-proxy-with-google-iap

When protecting Google Cloud applications (App Engine, Cloud Run, GKE, Compute Engine) with identity-based access When i...

github

implementing-conditional-access-policies-azure-ad

Configure Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control. Covers signal-based p...

github

performing-hardware-security-module-integration

Hardware Security Modules (HSMs) provide tamper-resistant cryptographic key storage and operations. This skill covers in...

github

performing-endpoint-forensics-investigation

Use this skill when: Investigating a confirmed or suspected endpoint compromise requiring forensic analysis Collecting v...

github

performing-sqlite-database-forensics

SQLite is the most widely deployed database engine in the world, used by virtually every mobile application, web browser...

github

performing-vlan-hopping-attack

Testing the effectiveness of VLAN-based network segmentation during authorized penetration tests Validating that switch ...

github

detecting-azure-service-principal-abuse

Azure service principals are identity objects used by applications, services, and automation tools to access Azure resou...

github

implementing-ot-incident-response-playbook

When building OT-specific incident response procedures for the first time When existing IT IR playbooks do not address I...

github

implementing-ransomware-kill-switch-detection

Analyzing a ransomware sample to determine if it contains a kill switch mechanism (mutex, domain, registry) Deploying pr...

github

implementing-canary-tokens-for-network-intrusion

When deploying deception-based tripwires across network infrastructure to detect intrusions When building early warning ...

github

detecting-supply-chain-attacks-in-ci-cd

When investigating security incidents that require detecting supply chain attacks in ci cd When building detection rules...

github

implementing-aws-config-rules-for-compliance

When establishing continuous compliance monitoring for AWS resources against regulatory standards When implementing auto...

github

detecting-modbus-protocol-anomalies

When deploying Modbus-specific intrusion detection in an OT environment When building baseline models for deterministic ...

github

implementing-azure-ad-privileged-identity-management

Microsoft Entra Privileged Identity Management (PIM) provides time-based and approval-based role activation to mitigate ...

github

performing-content-security-policy-bypass

When XSS is found but execution is blocked by Content Security Policy During web application security assessments to eva...

github

detecting-stuxnet-style-attacks

When implementing advanced threat detection for high-value OT targets (nuclear, chemical, critical infrastructure) When ...

github

performing-ip-reputation-analysis-with-shodan

Shodan is the world's first search engine for internet-connected devices, continuously scanning the IPv4 and IPv6 addres...

github

analyzing-windows-lnk-files-for-artifacts

When reconstructing user file access history from Windows shortcut files For tracking accessed files, network shares, an...

github

hunting-for-shadow-copy-deletion

When proactively hunting for indicators of hunting for shadow copy deletion in the environment After threat intelligence...

github

correlating-threat-campaigns

Use this skill when: Multiple unrelated-appearing incidents share IOCs (same C2 IP, same malware hash, similar TTPs) An ...

github