Debugging
Debugging utilities
building adversary infrastructure tracking system
GitHubBuild an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS
building automated malware submission pipeline
GitHub'Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and
building cloud siem with sentinel
GitHub'This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security
building ioc defanging and sharing pipeline
GitHubBuild an automated pipeline to defang indicators of compromise (URLs, IPs, domains, emails) for safe sharing
building ioc enrichment pipeline with opencti
GitHubOpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its
building threat actor profile from osint
GitHubBuild comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary
building vulnerability aging and sla tracking
GitHubImplement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against
building vulnerability exception tracking system
GitHubBuild a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls
collecting open source intelligence
GitHub'Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and
collecting threat intelligence with misp
GitHubMISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing,
collecting volatile evidence from compromised host
GitHubCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory,
conducting cloud incident response
GitHub'Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
conducting post incident lessons learned
GitHubFacilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce
configuring windows event logging for detection
GitHub'Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
containing active breach
GitHub'Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed
deobfuscating javascript malware
GitHub'Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing
detecting anomalous authentication patterns
GitHub'Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
detecting api enumeration attacks
GitHubDetect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
detecting arp poisoning in network traffic
GitHubDetect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom
detecting attacks on historian servers
GitHub'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT
detecting attacks on scada systems
GitHub'This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems
detecting aws cloudtrail anomalies
GitHubDetect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis
detecting azure lateral movement
GitHubDetect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel
detecting cloud threats with guardduty
GitHub'This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection