Search Skills
Search across 54932 indexed skills
testing-for-xxe-injection-vulnerabilities
During authorized penetration tests when the application processes XML input (SOAP APIs, file uploads, RSS feeds) When testing APIs that accept Conten...
testing-websocket-api-security
Assessing real-time communication APIs that use WebSocket (ws://) or Secure WebSocket (wss://) protocols Testing for Cross-Site WebSocket Hijacking (C...
triaging-security-incident
A SIEM or EDR alert fires and requires human classification before escalation Multiple concurrent alerts arrive and the SOC must prioritize response o...
performing-web-application-firewall-bypass
When confirmed vulnerabilities are blocked by WAF signature-based detection During penetration testing where WAF prevents exploitation of known issues...
scanning-kubernetes-manifests-with-kubesec
Kubesec is an open-source security risk analysis tool developed by ControlPlane that inspects Kubernetes resource manifests for common exploitable ris...
securing-container-registry-images
When establishing security controls for container image registries (ECR, ACR, GCR, Docker Hub) When building CI/CD pipelines that enforce vulnerabilit...
securing-historian-server-in-ot-environment
When deploying a new historian server in an OT environment and configuring it securely from the start When hardening an existing historian after a sec...
securing-remote-access-to-ot-environment
When implementing or upgrading remote access architecture for OT environments When onboarding vendors who require remote access to OT systems for supp...
testing-for-sensitive-data-exposure
During authorized penetration tests when assessing data protection controls When evaluating applications for GDPR, PCI DSS, HIPAA, or other data prote...
testing-mobile-api-authentication
Use this skill when: Assessing mobile app backend API authentication during penetration tests Testing JWT token implementation for common vulnerabilit...
testing-for-xml-injection-vulnerabilities
When testing applications that process XML input (SOAP APIs, XML-RPC, file uploads) During penetration testing of applications with XML parsers When a...
testing-for-xss-vulnerabilities
Testing web applications for client-side injection vulnerabilities as part of OWASP WSTG testing Evaluating the effectiveness of input sanitization an...