Development
Development tools and utilities
analyzing threat actor ttps with mitre navigator
GitHub'Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework
analyzing threat intelligence feeds
GitHub'Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics,
analyzing windows prefetch with python
GitHubParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history,
automating ioc enrichment
GitHub'Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using
building identity governance lifecycle process
GitHub'Builds comprehensive identity governance and lifecycle management processes including joiner-mover-leaver automation,
building soc metrics and kpi tracking
GitHub'Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to
building threat intelligence feed integration
GitHub'Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat
correlating threat campaigns
GitHub'Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify
deploying palo alto prisma access zero trust
GitHub'Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents,
detecting anomalies in industrial control systems
GitHub'This skill covers deploying anomaly detection systems for industrial control environments using machine learning
detecting dll sideloading attacks
GitHubDetect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack
detecting exfiltration over dns with zeek
GitHubDetect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query
eradicating malware from infected systems
GitHubSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring
hunting for anomalous powershell execution
GitHub'Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event
implementing aws security hub compliance
GitHub'Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards
implementing cloud dlp for data protection
GitHub'Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azure Information Protection, and Google Cloud
implementing conduit security for ot remote access
GitHub'Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying
implementing device posture assessment in zero trust
GitHub'Implementing device posture assessment as a zero trust access control by integrating endpoint health signals
implementing ics firewall with tofino
GitHub'Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using
implementing network traffic baselining
GitHubBuild network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score
implementing privileged access workstation
GitHubDesign and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration
implementing secrets management with vault
GitHub'This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including
implementing secrets scanning in ci cd
GitHubIntegrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment
implementing siem use case tuning
GitHubTune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting