AI-Augmented Cybersecurity

Capabilities

817 executable cybersecurity skills across 29 domains — from threat hunting and red teaming to AI governance and compliance frameworks. Each skill is mapped to MITRE ATT&CK, NIST CSF, and D3FEND.

817

Total Skills

29

Domains

12+

Frameworks Mapped

5

Capability Areas

Showing 29 domains · 817 skills

Cloud Security

66 skills · CIS Benchmarks, NIST 800-53, CSA CCM

  • Analyzing Cloud Storage Access Patterns
  • Analyzing Office365 Audit Logs For Compromise
  • Auditing Aws S3 Bucket Permissions
  • Auditing Azure Active Directory Configuration
  • Auditing Cloud With Cis Benchmarks
  • Auditing Gcp Iam Permissions
  • Auditing Kubernetes Cluster Rbac
  • Building Cloud Siem With Sentinel
  • Conducting Cloud Penetration Testing
  • Container Security Pipeline
  • Detecting Aws Cloudtrail Anomalies
  • Detecting Aws Guardduty Findings Automation
  • Detecting Aws Iam Privilege Escalation
  • Detecting Azure Lateral Movement
  • Detecting Azure Service Principal Abuse
  • Detecting Azure Storage Account Misconfigurations
  • Detecting Cloud Threats With Guardduty
  • Detecting Compromised Cloud Credentials
  • Detecting Cryptomining In Cloud
  • Detecting Misconfigured Azure Storage
  • Detecting Oauth Token Theft
  • Detecting S3 Data Exfiltration Attempts
  • Detecting Serverless Function Injection
  • Detecting Shadow It Cloud Usage
  • Detecting Suspicious Oauth Application Consent
  • Emulating Cloud Attacks With Stratus Red Team
  • Enumerating Cloud With Cloudfox
  • Exploiting Aws With Pacu
  • Implementing Aws Config Rules For Compliance
  • Implementing Aws Macie For Data Classification
  • Implementing Aws Nitro Enclave Security
  • Implementing Aws Security Hub
  • Implementing Aws Security Hub Compliance
  • Implementing Azure Defender For Cloud
  • Implementing Cloud Dlp For Data Protection
  • Implementing Cloud Security Posture Management
  • Implementing Cloud Trail Log Analysis
  • Implementing Cloud Waf Rules
  • Implementing Cloud Workload Protection
  • Implementing Gcp Binary Authorization
  • Implementing Gcp Vpc Firewall Rules
  • Implementing Secrets Management With Vault
  • Implementing Zero Trust In Cloud
  • Implementing Zero Trust Network Access
  • Lambda Security Scan
  • Managing Cloud Identity With Okta
  • Organizations/Organization_Id/Customconstraints/Custom.Disablegkeautoupgrade
  • Performing Aws Account Enumeration With Scout Suite
  • Performing Aws Privilege Escalation Assessment
  • Performing Cloud Asset Inventory With Cartography
  • Performing Cloud Forensics With Aws Cloudtrail
  • Performing Cloud Log Forensics With Athena
  • Performing Cloud Native Forensics With Falco
  • Performing Cloud Native Threat Hunting With Aws Detective
  • Performing Cloud Penetration Testing With Pacu
  • Performing Gcp Penetration Testing With Gcpbucketbrute
  • Performing Gcp Security Assessment With Forseti
  • Performing Serverless Function Security Review
  • Remediating S3 Bucket Misconfiguration
  • Secrets Scan
  • Securing Api Gateway With Aws Waf
  • Securing Aws Iam Permissions
  • Securing Aws Lambda Execution Roles
  • Securing Azure With Microsoft Defender
  • Securing Kubernetes On Cloud
  • Terraform Security Scan

Threat Hunting

58 skills · MITRE ATT&CK, NIST CSF

  • Analyzing Persistence Mechanisms In Linux
  • Analyzing Powershell Empire Artifacts
  • Analyzing Ransomware Network Indicators
  • Building Threat Hunt Hypothesis Framework
  • Custom.Hunt.Suspiciouspowershell
  • Detecting Dcsync Attack In Active Directory
  • Detecting Dll Sideloading Attacks
  • Detecting Email Forwarding Rules Attack
  • Detecting Golden Ticket Attacks In Kerberos Logs
  • Detecting Insider Threat Behaviors
  • Detecting Kerberoasting Attacks
  • Detecting Lateral Movement With Splunk
  • Detecting Malicious Scheduled Tasks With Sysmon
  • Detecting Mimikatz Execution Patterns
  • Detecting Ntlm Relay With Event Correlation
  • Detecting Pass The Hash Attacks
  • Detecting Privilege Escalation Attempts
  • Detecting Process Hollowing Technique
  • Detecting Service Account Abuse
  • Detecting Suspicious Powershell Execution
  • Detecting T1003 Credential Dumping With Edr
  • Detecting T1055 Process Injection With Sysmon
  • Detecting T1548 Abuse Elevation Control Mechanism
  • Detecting Wmi Persistence
  • Hunting Evtx With Chainsaw
  • Hunting For Anomalous Powershell Execution
  • Hunting For Beaconing With Frequency Analysis
  • Hunting For Cobalt Strike Beacons
  • Hunting For Command And Control Beaconing
  • Hunting For Data Exfiltration Indicators
  • Hunting For Data Staging Before Exfiltration
  • Hunting For Dcom Lateral Movement
  • Hunting For Dcsync Attacks
  • Hunting For Defense Evasion Via Timestomping
  • Hunting For Dns Based Persistence
  • Hunting For Dns Tunneling With Zeek
  • Hunting For Domain Fronting C2 Traffic
  • Hunting For Lateral Movement Via Wmi
  • Hunting For Living Off The Cloud Techniques
  • Hunting For Living Off The Land Binaries
  • Hunting For Lolbins Execution In Endpoint Logs
  • Hunting For Ntlm Relay Attacks
  • Hunting For Persistence Mechanisms In Windows
  • Hunting For Persistence Via Wmi Subscriptions
  • Hunting For Process Injection Techniques
  • Hunting For Registry Persistence Mechanisms
  • Hunting For Registry Run Key Persistence
  • Hunting For Scheduled Task Persistence
  • Hunting For Shadow Copy Deletion
  • Hunting For Spearphishing Indicators
  • Hunting For Startup Folder Persistence
  • Hunting For Supply Chain Compromise
  • Hunting For Suspicious Scheduled Tasks
  • Hunting For T1098 Account Manipulation
  • Hunting For Unusual Network Connections
  • Hunting For Unusual Service Installations
  • Hunting For Webshell Activity
  • Performing Threat Hunting With Yara Rules

Threat Intelligence

52 skills · MITRE ATT&CK, STIX/TAXII, Diamond Model

  • Analyzing Apt Group With Mitre Navigator
  • Analyzing Campaign Attribution Evidence
  • Analyzing Certificate Transparency For Phishing
  • Analyzing Cyber Kill Chain
  • Analyzing Indicators Of Compromise
  • Analyzing Malware Family Relationships With Malpedia
  • Analyzing Ransomware Leak Site Intelligence
  • Analyzing Threat Actor Ttps With Mitre Attack
  • Analyzing Threat Actor Ttps With Mitre Navigator
  • Analyzing Threat Intelligence Feeds
  • Analyzing Threat Landscape With Misp
  • Analyzing Typosquatting Domains With Dnstwist
  • Auditing Tls Certificate Transparency Logs
  • Automating Ioc Enrichment
  • Building Adversary Infrastructure Tracking System
  • Building Attack Pattern Library From Cti Reports
  • Building Ioc Defanging And Sharing Pipeline
  • Building Ioc Enrichment Pipeline With Opencti
  • Building Threat Actor Profile From Osint
  • Building Threat Feed Aggregation With Misp
  • Building Threat Intelligence Platform
  • Collecting Open Source Intelligence
  • Collecting Threat Intelligence With Misp
  • Correlating Threat Campaigns
  • Evaluating Threat Intelligence Platforms
  • Generating Threat Intelligence Reports
  • Hunting Advanced Persistent Threats
  • Implementing Diamond Model Analysis
  • Implementing Security Information Sharing With Stix2
  • Implementing Stix Taxii Feed Integration
  • Implementing Taxii Server With Opentaxii
  • Implementing Threat Intelligence Lifecycle Management
  • Managing Intelligence Lifecycle
  • Mapping Mitre Attack Techniques
  • Modeling Threats With Opencti
  • Monitoring Darkweb Sources
  • Operationalizing Misp Threat Feeds
  • Performing Ai Driven Osint Correlation
  • Performing Brand Monitoring For Impersonation
  • Performing Dark Web Monitoring For Threats
  • Performing Indicator Lifecycle Management
  • Performing Ip Reputation Analysis With Shodan
  • Performing Malware Hash Enrichment With Virustotal
  • Performing Malware Ioc Extraction
  • Performing Osint With Spiderfoot
  • Performing Paste Site Monitoring For Credentials
  • Performing Threat Emulation With Atomic Red Team
  • Performing Threat Intelligence Sharing With Misp
  • Performing Threat Landscape Assessment For Sector
  • Processing Stix Taxii Feeds
  • Profiling Threat Actor Groups
  • Tracking Threat Actor Infrastructure

Web Application Security

46 skills · OWASP Top 10, OWASP ASVS, CWE

  • Bypassing Authentication With Forced Browsing
  • Devsecops Security Pipeline
  • Exploiting Broken Link Hijacking
  • Exploiting Http Request Smuggling
  • Exploiting Idor Vulnerabilities
  • Exploiting Insecure Deserialization
  • Exploiting Mass Assignment In Rest Apis
  • Exploiting Nosql Injection Vulnerabilities
  • Exploiting Oauth Misconfiguration
  • Exploiting Prototype Pollution In Javascript
  • Exploiting Race Condition Vulnerabilities
  • Exploiting Server Side Request Forgery
  • Exploiting Sql Injection With Sqlmap
  • Exploiting Template Injection Vulnerabilities
  • Exploiting Type Juggling Vulnerabilities
  • Exploiting Websocket Vulnerabilities
  • Implementing Runtime Application Self Protection
  • Implementing Web Application Logging With Modsecurity
  • Performing Blind Ssrf Exploitation
  • Performing Clickjacking Attack Test
  • Performing Content Security Policy Bypass
  • Performing Csrf Attack Simulation
  • Performing Directory Traversal Testing
  • Performing Fuzzing With Aflplusplus
  • Performing Graphql Security Assessment
  • Performing Http Parameter Pollution Attack
  • Performing Second Order Sql Injection
  • Performing Security Headers Audit
  • Performing Subdomain Enumeration With Subfinder
  • Performing Supply Chain Attack Simulation
  • Performing Web Application Firewall Bypass
  • Performing Web Cache Deception Attack
  • Performing Web Cache Poisoning Attack
  • Testing Api Security With Owasp Top 10
  • Testing Cors Misconfiguration
  • Testing For Broken Access Control
  • Testing For Business Logic Vulnerabilities
  • Testing For Email Header Injection
  • Testing For Host Header Injection
  • Testing For Json Web Token Vulnerabilities
  • Testing For Open Redirect Vulnerabilities
  • Testing For Sensitive Data Exposure
  • Testing For Xml Injection Vulnerabilities
  • Testing For Xss Vulnerabilities With Burpsuite
  • Testing For Xxe Injection Vulnerabilities
  • Testing Jwt Token Security

Network Security

45 skills · NIST 800-53, CIS Controls

  • Analyzing Network Flow Data With Netflow
  • Analyzing Network Packets With Scapy
  • Analyzing Network Traffic With Wireshark
  • Bgp Hijack Lab
  • Conducting Man In The Middle Attack Simulation
  • Configuring Network Segmentation With Vlans
  • Configuring Pfsense Firewall Rules
  • Configuring Snort Ids For Intrusion Detection
  • Configuring Suricata For Network Monitoring
  • Detecting Arp Poisoning In Network Traffic
  • Detecting Bluetooth Low Energy Attacks
  • Detecting Command And Control Over Dns
  • Detecting Dns Exfiltration With Dns Query Analysis
  • Detecting Exfiltration Over Dns With Zeek
  • Detecting Lateral Movement In Network
  • Detecting Lateral Movement With Zeek
  • Detecting Network Anomalies With Zeek
  • Detecting Network Scanning With Ids Signatures
  • Detecting Port Scanning With Fail2Ban
  • Exploiting Ipv6 Vulnerabilities
  • Exploiting Smb Vulnerabilities With Metasploit
  • Implementing Bgp Security With Rpki
  • Implementing Browser Isolation For Zero Trust
  • Implementing Ddos Mitigation With Cloudflare
  • Implementing Network Access Control
  • Implementing Network Access Control With Cisco Ise
  • Implementing Network Intrusion Prevention With Suricata
  • Implementing Network Segmentation With Firewall Zones
  • Implementing Network Traffic Analysis With Arkime
  • Implementing Network Traffic Baselining
  • Implementing Next Generation Firewall With Palo Alto
  • Performing Arp Spoofing Attack Simulation
  • Performing Bandwidth Throttling Attack Simulation
  • Performing Bluetooth Security Assessment
  • Performing Dns Enumeration And Zone Transfer
  • Performing Network Traffic Analysis With Tshark
  • Performing Network Traffic Analysis With Zeek
  • Performing Packet Injection Attack
  • Performing Ssl Stripping Attack
  • Performing Ssl Tls Inspection Configuration
  • Performing Ssl Tls Security Assessment
  • Performing Vlan Hopping Attack
  • Performing Wifi Password Cracking With Aircrack
  • Performing Wireless Security Assessment With Kismet
  • Scanning Network With Nmap Advanced

Digital Forensics

41 skills · NIST 800-86, ACPO Guidelines

  • Acquiring Disk Image With Dd And Dcfldd
  • Analyzing Browser Forensics With Hindsight
  • Analyzing Disk Image With Autopsy
  • Analyzing Docker Container Forensics
  • Analyzing Email Headers For Phishing Investigation
  • Analyzing Linux Kernel Rootkits
  • Analyzing Linux System Artifacts
  • Analyzing Lnk File And Jump List Artifacts
  • Analyzing Mft For Deleted File Recovery
  • Analyzing Outlook Pst For Email Forensics
  • Analyzing Prefetch Files For Execution History
  • Analyzing Slack Space And File System Artifacts
  • Analyzing Usb Device Connection History
  • Analyzing Windows Amcache Artifacts
  • Analyzing Windows Lnk Files For Artifacts
  • Analyzing Windows Prefetch With Python
  • Analyzing Windows Registry For Artifacts
  • Analyzing Windows Shellbag Artifacts
  • Building Super Timelines With Plaso
  • Extracting Browser History Artifacts
  • Extracting Credentials From Memory Dump
  • Extracting Windows Event Logs Artifacts
  • Generating Forensic Timelines With Hayabusa
  • Investigating Ransomware Attack Artifacts
  • Parsing Artifacts With Eric Zimmerman Tools
  • Performing Cloud Forensics Investigation
  • Performing Cloud Storage Forensic Acquisition
  • Performing File Carving With Foremost
  • Performing Linux Log Forensics Investigation
  • Performing Log Analysis For Forensic Investigation
  • Performing Malware Persistence Investigation
  • Performing Memory Forensics With Volatility3
  • Performing Mobile Device Forensics With Cellebrite
  • Performing Network Forensics With Wireshark
  • Performing Network Packet Capture Analysis
  • Performing Sqlite Database Forensics
  • Performing Steganography Detection
  • Performing Timeline Reconstruction With Plaso
  • Performing Windows Artifact Analysis With Eric Zimmerman Tools
  • Recovering Deleted Files With Photorec
  • Triaging Windows With Kape

Identity & Access Management

40 skills · NIST 800-63, CIS Controls, CRI Profile

  • Analyzing Active Directory Acl Abuse
  • Attacking Entra Id With Roadtools
  • Attacking Oauth With Device Code Phishing
  • Auditing Entra Id With Aadinternals
  • Building Identity Federation With Saml Azure Ad
  • Building Identity Governance Lifecycle Process
  • Building Role Mining For Rbac Optimization
  • Configuring Active Directory Tiered Model
  • Configuring Ldap Security Hardening
  • Configuring Multi Factor Authentication With Duo
  • Configuring Oauth2 Authorization Flow
  • Detecting Anomalous Authentication Patterns
  • Implementing Aws Iam Permission Boundaries
  • Implementing Azure Ad Privileged Identity Management
  • Implementing Conditional Access Policies Azure Ad
  • Implementing Delinea Secret Server For Pam
  • Implementing Google Workspace Admin Security
  • Implementing Google Workspace Sso Configuration
  • Implementing Hardware Security Key Authentication
  • Implementing Hashicorp Vault Dynamic Secrets
  • Implementing Identity Governance With Sailpoint
  • Implementing Just In Time Access Provisioning
  • Implementing Pam For Database Access
  • Implementing Passwordless Auth With Microsoft Entra
  • Implementing Passwordless Authentication With Fido2
  • Implementing Privileged Access Management With Cyberark
  • Implementing Privileged Access Workstation
  • Implementing Privileged Session Monitoring
  • Implementing Saml Sso With Okta
  • Implementing Scim Provisioning With Okta
  • Implementing Zero Standing Privilege With Cyberark
  • Performing Access Recertification With Saviynt
  • Performing Access Review And Certification
  • Performing Entitlement Review With Sailpoint Iiq
  • Performing Oauth Scope Minimization Review
  • Performing Privileged Account Access Review
  • Performing Privileged Account Discovery
  • Performing Service Account Audit
  • Performing Service Account Credential Rotation
  • Post Exploiting Microsoft Graph With Graphrunner

Malware Analysis

39 skills · MITRE ATT&CK, YARA, D3FEND

  • Analyzing Android Malware With Apktool
  • Analyzing Bootkit And Rootkit Samples
  • Analyzing Cobalt Strike Beacon Configuration
  • Analyzing Cobaltstrike Malleable C2 Profiles
  • Analyzing Command And Control Communication
  • Analyzing Golang Malware With Ghidra
  • Analyzing Heap Spray Exploitation
  • Analyzing Linux Elf Malware
  • Analyzing Macro Malware In Office Documents
  • Analyzing Malicious Pdf With Peepdf
  • Analyzing Malware Behavior With Cuckoo Sandbox
  • Analyzing Malware Persistence With Autoruns
  • Analyzing Malware Sandbox Evasion Techniques
  • Analyzing Memory Dumps With Volatility
  • Analyzing Network Covert Channels In Malware
  • Analyzing Network Traffic Of Malware
  • Analyzing Packed Malware With Upx Unpacker
  • Analyzing Pdf Malware With Pdfid
  • Analyzing Ransomware Encryption Mechanisms
  • Analyzing Supply Chain Malware Artifacts
  • Deobfuscating Javascript Malware
  • Deobfuscating Powershell Obfuscated Malware
  • Detecting Fileless Malware Techniques
  • Detecting Process Injection Techniques
  • Detecting Rootkit Activity
  • Extracting Config From Agent Tesla Rat
  • Extracting Iocs From Malware Samples
  • Performing Automated Malware Analysis With Cape
  • Performing Dynamic Analysis With Any Run
  • Performing Firmware Malware Analysis
  • Performing Malware Triage With Yara
  • Performing Memory Forensics With Volatility3 Plugins
  • Performing Static Malware Analysis With Pe Studio
  • Performing Yara Rule Development For Detection
  • Reverse Engineering Android Malware With Jadx
  • Reverse Engineering Dotnet Malware With Dnspy
  • Reverse Engineering Malware With Ghidra
  • Reverse Engineering Ransomware Encryption Routine
  • Reverse Engineering Rust Malware

Red Teaming & Offensive Security

37 skills · MITRE ATT&CK, PTES, CBEST

  • Abusing Dpapi For Credential Access
  • Abusing Shadow Credentials For Privesc
  • Building C2 Infrastructure With Sliver Framework
  • Building C2 Redirector Infrastructure
  • Building Red Team C2 Infrastructure With Havoc
  • Coercing Authentication With Coercer Petitpotam
  • Conducting Domain Persistence With Dcsync
  • Conducting Full Scope Red Team Engagement
  • Conducting Internal Reconnaissance With Bloodhound Ce
  • Conducting Pass The Ticket Attack
  • Conducting Social Engineering Pretext Call
  • Conducting Spearphishing Simulation Campaign
  • Executing Red Team Engagement Planning
  • Exploiting Active Directory Certificate Services Esc1
  • Exploiting Active Directory With Bloodhound
  • Exploiting Adcs With Certipy
  • Exploiting Constrained Delegation Abuse
  • Exploiting Kerberoasting With Impacket
  • Exploiting Ms17 010 Eternalblue Vulnerability
  • Exploiting Nopac Cve 2021 42278 42287
  • Exploiting Zerologon Vulnerability Cve 2020 1472
  • Implementing Attack Surface Management
  • Mapping Attack Paths With Bloodhound Ce
  • Operating Havoc C2
  • Operating Sliver C2
  • Performing Active Directory Bloodhound Analysis
  • Performing Active Directory Forest Trust Attack
  • Performing Binary Exploitation Analysis
  • Performing Credential Access With Lazagne
  • Performing Initial Access With Evilginx3
  • Performing Kerberoasting Attack
  • Performing Lateral Movement With Wmiexec
  • Performing Open Source Intelligence Gathering
  • Performing Physical Intrusion Assessment
  • Performing Privilege Escalation On Linux
  • Performing Red Team With Covenant
  • Relaying Ntlm For Adcs Esc8

SOC Operations

35 skills · NIST CSF, MITRE ATT&CK, ITIL

  • Analyzing Dns Logs For Exfiltration
  • Analyzing Windows Event Logs In Splunk
  • Building Automated Malware Submission Pipeline
  • Building Detection Rule With Splunk Spl
  • Building Incident Response Dashboard
  • Building Soc Escalation Matrix
  • Building Soc Metrics And Kpi Tracking
  • Building Soc Playbook For Ransomware
  • Building Threat Intelligence Enrichment In Splunk
  • Building Threat Intelligence Feed Integration
  • Building Vulnerability Scanning Workflow
  • Correlating Security Events In Qradar
  • Credential Dumping Via Lsass Access
  • Detecting Entra Offensive Tools In Graph Logs
  • Hunting Saas Sso Token Abuse
  • Implementing Alert Fatigue Reduction
  • Implementing Mitre Attack Coverage Mapping
  • Implementing Soar Automation With Phantom
  • Implementing Threat Modeling With Mitre Attack
  • Implementing Ticketing System For Incidents
  • Investigating Insider Threat Indicators
  • Investigating Phishing Email Incident
  • Performing Alert Triage With Elastic Siem
  • Performing Deception Technology Deployment
  • Performing False Positive Reduction In Siem
  • Performing Ioc Enrichment Automation
  • Performing Lateral Movement Detection
  • Performing Log Source Onboarding In Siem
  • Performing Purple Team Exercise
  • Performing Soc Tabletop Exercise
  • Performing Threat Hunting With Elastic Siem
  • Performing User Behavior Analytics
  • Phishing Investigation Full
  • Sigma Rule Ci
  • Triaging Security Alerts In Splunk

Container Security

33 skills · CIS Kubernetes Benchmark, NIST 800-190

  • Analyzing Kubernetes Audit Logs
  • Auditing Kubernetes Rbac Privilege Escalation
  • Benchmarking Kubernetes With Kube Bench
  • Cis Benchmark
  • Detecting Container Drift At Runtime
  • Detecting Container Escape Attempts
  • Detecting Container Escape With Falco Rules
  • Detecting Container Runtime Threats With Falco
  • Detecting Privilege Escalation In Kubernetes Pods
  • Escaping Containers To Host
  • Hardening Docker Containers For Production
  • Hardening Docker Daemon Configuration
  • Helm Chart Security
  • Implementing Container Image Minimal Base With Distroless
  • Implementing Container Network Policies With Calico
  • Implementing Kubernetes Network Policy With Calico
  • Implementing Kubernetes Pod Security Standards
  • Implementing Network Policies For Kubernetes
  • Implementing Opa Gatekeeper For Policy Enforcement
  • Implementing Pod Security Admission Controller
  • Implementing Rbac Hardening For Kubernetes
  • Implementing Runtime Security With Tetragon
  • Implementing Supply Chain Security With In Toto
  • Kubesec Scan
  • Performing Container Escape Detection
  • Performing Container Security Scanning With Trivy
  • Performing Docker Bench Security Assessment
  • Performing Kubernetes Etcd Security Assessment
  • Performing Kubernetes Penetration Testing
  • Scanning Container Images With Grype
  • Securing Container Registry With Harbor
  • Sign And Publish
  • Trivy Container Scan

OT/ICS Security

29 skills · IEC 62443, NIST 800-82, MITRE ICS

  • Detecting Anomalies In Industrial Control Systems
  • Detecting Attacks On Historian Servers
  • Detecting Attacks On Scada Systems
  • Detecting Dnp3 Protocol Anomalies
  • Detecting Modbus Command Injection Attacks
  • Detecting Modbus Protocol Anomalies
  • Detecting Stuxnet Style Attacks
  • Implementing Conduit Security For Ot Remote Access
  • Implementing Dragos Platform For Ot Monitoring
  • Implementing Ics Firewall With Tofino
  • Implementing Iec 62443 Security Zones
  • Implementing Nerc Cip Compliance Controls
  • Implementing Network Segmentation For Ot
  • Implementing Ot Incident Response Playbook
  • Implementing Ot Network Traffic Analysis With Nozomi
  • Implementing Patch Management For Ot Systems
  • Implementing Purdue Model Network Segmentation
  • Monitoring Scada Modbus Traffic Anomalies
  • Performing Ics Asset Discovery With Claroty
  • Performing Oil Gas Cybersecurity Assessment
  • Performing Ot Network Security Assessment
  • Performing Ot Vulnerability Assessment With Claroty
  • Performing Ot Vulnerability Scanning Safely
  • Performing Plc Firmware Security Analysis
  • Performing Power Grid Cybersecurity Assessment
  • Performing S7Comm Protocol Security Analysis
  • Performing Scada Hmi Security Assessment
  • Securing Historian Server In Ot Environment
  • Securing Remote Access To Ot Environment

Security Operations

28 skills · NIST CSF, MITRE D3FEND

  • Analyzing Api Gateway Access Logs
  • Analyzing Azure Activity Logs For Threats
  • Analyzing Memory Forensics With Lime And Volatility
  • Analyzing Powershell Script Block Logging
  • Analyzing Tls Certificate Transparency Logs
  • Analyzing Web Server Logs For Intrusion
  • Detecting Beaconing Patterns With Zeek
  • Detecting Insider Data Exfiltration Via Dlp
  • Detecting Sql Injection Via Waf Logs
  • Detecting Supply Chain Attacks In Ci Cd
  • Extracting Memory Artifacts With Rekall
  • Hunting Credential Stuffing Attacks
  • Implementing Canary Tokens For Network Intrusion
  • Implementing Ebpf Security Monitoring
  • Implementing Endpoint Detection With Wazuh
  • Implementing Honeytokens For Breach Detection
  • Implementing Log Forwarding With Fluentd
  • Implementing Log Integrity With Blockchain
  • Implementing Mtls For Zero Trust Services
  • Implementing Security Chaos Engineering
  • Implementing Security Monitoring With Datadog
  • Implementing Siem Correlation Rules For Apt
  • Implementing Siem Use Case Tuning
  • Implementing Soar Playbook For Phishing
  • Implementing Syslog Centralization With Rsyslog
  • Performing Dns Tunneling Detection
  • Performing Red Team Phishing With Gophish
  • Performing Ssrf Vulnerability Exploitation

API Security

28 skills · OWASP API Top 10, OpenAPI

  • Api Schema Security Check
  • Api Security Testing
  • Api Security Tests
  • Detecting Api Enumeration Attacks
  • Detecting Broken Object Property Level Authorization
  • Detecting Shadow Api Endpoints
  • Exploiting Api Injection Vulnerabilities
  • Exploiting Broken Function Level Authorization
  • Exploiting Excessive Data Exposure In Api
  • Exploiting Jwt Algorithm Confusion Attack
  • Implementing Api Abuse Detection With Rate Limiting
  • Implementing Api Gateway Security Controls
  • Implementing Api Key Security Controls
  • Implementing Api Rate Limiting And Throttling
  • Implementing Api Security Posture Management
  • Implementing Api Threat Protection With Apigee
  • Performing Api Fuzzing With Restler
  • Performing Api Inventory And Discovery
  • Performing Api Rate Limiting Bypass
  • Performing Graphql Depth Limit Attack
  • Performing Graphql Introspection Attack
  • Performing Jwt None Algorithm Attack
  • Performing Soap Web Service Security Testing
  • Testing Api Authentication Weaknesses
  • Testing Api For Broken Object Level Authorization
  • Testing Api For Mass Assignment Vulnerability
  • Testing Oauth2 Implementation Flaws
  • Testing Websocket Api Security

Incident Response

26 skills · NIST 800-61, SANS IR, MITRE ATT&CK

  • Analyzing Linux Audit Logs For Intrusion
  • Analyzing Network Traffic For Incidents
  • Analyzing Security Logs With Splunk
  • Building Incident Response Playbook
  • Building Incident Timeline With Timesketch
  • Building Malware Incident Communication Template
  • Collecting Indicators Of Compromise
  • Collecting Volatile Evidence From Compromised Host
  • Conducting Cloud Incident Response
  • Conducting Malware Incident Response
  • Conducting Memory Forensics With Volatility
  • Conducting Phishing Incident Response
  • Conducting Post Incident Lessons Learned
  • Containing Active Breach
  • Detecting Email Account Compromise
  • Eradicating Malware From Infected Systems
  • Implementing Velociraptor For Ir Collection
  • Performing Active Directory Compromise Investigation
  • Performing Cloud Incident Containment Procedures
  • Performing Disk Forensics Investigation
  • Performing Insider Threat Investigation
  • Performing Ransomware Response
  • Testing Ransomware Recovery Procedures
  • Triaging Security Incident
  • Triaging Security Incident With Ir Playbook
  • Validating Backup Integrity For Recovery

Vulnerability Management

25 skills · CVSS, NIST 800-40, CIS Controls

  • Building Patch Tuesday Response Process
  • Building Vulnerability Aging And Sla Tracking
  • Building Vulnerability Exception Tracking System
  • Exploiting Vulnerabilities With Metasploit Framework
  • Implementing Attack Path Analysis With Xm Cyber
  • Implementing Cloud Vulnerability Posture Management
  • Implementing Continuous Security Validation With Bas
  • Implementing Epss Score For Vulnerability Prioritization
  • Implementing Patch Management Workflow
  • Implementing Rapid7 Insightvm For Scanning
  • Implementing Vulnerability Management With Greenbone
  • Implementing Vulnerability Remediation Sla
  • Implementing Vulnerability Sla Breach Alerting
  • Performing Active Directory Vulnerability Assessment
  • Performing Agentless Vulnerability Scanning
  • Performing Asset Criticality Scoring For Vulns
  • Performing Authenticated Scan With Openvas
  • Performing Authenticated Vulnerability Scan
  • Performing Cve Prioritization With Kev Catalog
  • Performing Web Application Scanning With Nikto
  • Performing Web Application Vulnerability Triage
  • Prioritizing Vulnerabilities With Cvss Scoring
  • Scanning Infrastructure With Nessus
  • Security Scan
  • Triaging Vulnerabilities With Ssvc Framework

Penetration Testing

21 skills · PTES, OWASP, NIST 800-115

  • Conducting Api Security Testing
  • Conducting External Reconnaissance With Osint
  • Conducting Internal Network Penetration Test
  • Conducting Mobile App Penetration Test
  • Conducting Network Penetration Test
  • Conducting Social Engineering Penetration Test
  • Conducting Wireless Network Penetration Test
  • Executing Active Directory Attack Simulation
  • Executing Phishing Simulation Campaign
  • Executing Red Team Exercise
  • Exploiting Sql Injection Vulnerabilities
  • Moving Laterally With Netexec
  • Performing Active Directory Penetration Test
  • Performing External Network Penetration Test
  • Performing Iot Security Assessment
  • Performing Privilege Escalation Assessment
  • Performing Thick Client Application Penetration Test
  • Performing Vulnerability Scanning With Nessus
  • Performing Web Application Penetration Test
  • Performing Wireless Network Penetration Test
  • Testing For Xss Vulnerabilities

DevSecOps

18 skills · OWASP SAMM, NIST SSDF

  • Build And Sign
  • Building Devsecops Pipeline With Gitlab Ci
  • Ci Pipeline
  • Codeql Analysis
  • Container Security Scan
  • Container Security Scan
  • Custom Codeql Config
  • Dast Security Scan
  • Dependency Security Scan
  • Fuzz Testing
  • Iac Security Scan
  • Implementing Secrets Scanning In Ci Cd
  • Performing Container Image Hardening
  • Performing Threat Modeling With Owasp Threat Dragon
  • Policy Validation
  • Scanning Iac And Images With Trivy
  • Secret Scanning
  • Semgrep Sast

Zero Trust Architecture

18 skills · NIST 800-207, CISA ZTA

  • Configuring Aws Verified Access For Ztna
  • Configuring Identity Aware Proxy With Google Iap
  • Configuring Microsegmentation For Zero Trust
  • Configuring Zscaler Private Access For Ztna
  • Deploying Cloudflare Access For Zero Trust
  • Deploying Palo Alto Prisma Access Zero Trust
  • Deploying Software Defined Perimeter
  • Deploying Tailscale For Zero Trust Vpn
  • Implementing Beyondcorp Zero Trust Access Model
  • Implementing Cisa Zero Trust Maturity Model
  • Implementing Device Posture Assessment In Zero Trust
  • Implementing Identity Verification For Zero Trust
  • Implementing Microsegmentation With Guardicore
  • Implementing Zero Trust Dns With Nextdns
  • Implementing Zero Trust For Saas Applications
  • Implementing Zero Trust Network Access With Zscaler
  • Implementing Zero Trust With Beyondcorp
  • Implementing Zero Trust With Hashicorp Boundary

Endpoint Security

17 skills · CIS Benchmarks, MITRE ATT&CK

  • Configuring Host Based Intrusion Detection
  • Configuring Windows Defender Advanced Settings
  • Configuring Windows Event Logging For Detection
  • Deploying Edr Agent With Crowdstrike
  • Deploying Osquery For Endpoint Monitoring
  • Detecting Evasion Techniques In Endpoint Logs
  • Detecting Fileless Attacks On Endpoints
  • Hardening Linux Endpoint With Cis Benchmark
  • Hardening Windows Endpoint With Cis Benchmark
  • Implementing Application Whitelisting With Applocker
  • Implementing Disk Encryption With Bitlocker
  • Implementing Endpoint Dlp Controls
  • Implementing File Integrity Monitoring With Aide
  • Implementing Memory Protection With Dep Aslr
  • Implementing Usb Device Control Policy
  • Performing Endpoint Forensics Investigation
  • Performing Endpoint Vulnerability Remediation

Cryptography

18 skills · NIST 800-57, FIPS 140-3

  • Analyzing Ethereum Smart Contract Vulnerabilities
  • Auditing Foundry Smart Contract Security
  • Configuring Certificate Authority With Openssl
  • Configuring Hsm For Key Storage
  • Configuring Tls 1 3 For Secure Communications
  • Implementing Aes Encryption For Data At Rest
  • Implementing Digital Signatures With Ed25519
  • Implementing End To End Encryption For Messaging
  • Implementing Envelope Encryption With Aws Kms
  • Implementing Jwt Signing And Verification
  • Implementing Rsa Key Pair Management
  • Implementing Zero Knowledge Proof For Authentication
  • Migrating To Post Quantum Cryptography
  • Performing Cryptographic Audit Of Application
  • Performing Hardware Security Module Integration
  • Performing Hash Cracking With Hashcat
  • Performing Post Quantum Cryptography Migration
  • Performing Ssl Certificate Lifecycle Management

Phishing & Social Engineering Defense

16 skills · MITRE ATT&CK, NIST CSF

  • Analyzing Malicious Url With Urlscan
  • Building Phishing Reporting Button Workflow
  • Detecting Business Email Compromise
  • Detecting Business Email Compromise With Ai
  • Detecting Deepfake Audio In Vishing Attacks
  • Detecting Qr Code Phishing With Email Security
  • Detecting Spearphishing With Email Gateway
  • Implementing Anti Phishing Training Program
  • Implementing Dmarc Dkim Spf Email Security
  • Implementing Email Sandboxing With Proofpoint
  • Implementing Google Workspace Phishing Protection
  • Implementing Mimecast Targeted Attack Protection
  • Implementing Proofpoint Email Security Gateway
  • Performing Adversary In The Middle Phishing Detection
  • Performing Dmarc Policy Enforcement Rollout
  • Performing Phishing Simulation With Gophish

AI Security

14 skills · NIST AI RMF, OWASP LLM Top 10, ISO 42001

  • Assessing Vector And Embedding Weaknesses
  • Auditing Mcp Servers For Tool Poisoning
  • Defending Llms With Guardrails
  • Detecting Ai Model Prompt Injection Attacks
  • Detecting Data And Model Poisoning
  • Detecting Indirect Prompt Injection
  • Detecting Model Extraction Attacks
  • Implementing Llm Guardrails For Security
  • Llm Red Team
  • Orchestrating Llm Attacks With Pyrit
  • Red Teaming Llms With Garak
  • Securing Agentic Ai Tool Invocation
  • Testing For System Prompt Leakage
  • Testing Prompt Injection In Rag Pipelines

Ransomware Defense

13 skills · CISA, MITRE ATT&CK, NIST CSF

  • Analyzing Ransomware Payment Wallets
  • Building Ransomware Playbook With Cisa Framework
  • Deploying Decoy Files For Ransomware Detection
  • Deploying Ransomware Canary Files
  • Detecting Ransomware Encryption Behavior
  • Detecting Ransomware Precursors In Network
  • Implementing Anti Ransomware Group Policy
  • Implementing Honeypot For Ransomware Detection
  • Implementing Immutable Backup With Restic
  • Implementing Ransomware Backup Strategy
  • Implementing Ransomware Kill Switch Detection
  • Performing Ransomware Tabletop Exercise
  • Recovering From Ransomware Attack

Mobile Security

13 skills · OWASP MASVS, MITRE ATT&CK Mobile

  • Analyzing Ios App Security With Objection
  • Detecting Mobile Malware Behavior
  • Exploiting Deeplink Vulnerabilities
  • Exploiting Insecure Data Storage In Mobile
  • Implementing Mobile Application Management
  • Intercepting Mobile Traffic With Burpsuite
  • Performing Android App Static Analysis With Mobsf
  • Performing Dynamic Analysis Of Android App
  • Performing Ios App Security Assessment
  • Performing Mobile App Certificate Pinning Bypass
  • Reverse Engineering Ios App With Frida
  • Testing Android Intents For Vulnerabilities
  • Testing Mobile Api Authentication

Compliance & Governance

13 skills · NIST 800-30, CMMC, NIST RMF, GDPR

  • Achieving Cmmc Level 2 Compliance
  • Conducting Cyber Risk Assessment With Nist 800 30
  • Executing Nist Rmf Authorization To Operate
  • Implementing Data Loss Prevention With Microsoft Purview
  • Implementing Gdpr Data Protection Controls
  • Implementing Gdpr Data Subject Access Request
  • Implementing Hipaa Security Rule Safeguards
  • Implementing Iso 27001 Information Security Management
  • Implementing Pci Dss Compliance Controls
  • Managing Third Party Vendor Risk
  • Performing Nist Csf Maturity Assessment
  • Performing Privacy Impact Assessment
  • Performing Soc2 Type2 Audit Preparation

Supply Chain Security

8 skills · NIST SSDF, SLSA, CycloneDX

  • Analyzing Sbom For Supply Chain Vulnerabilities
  • Dependency Confusion
  • Detecting Malicious Npm Packages
  • Detecting Typosquatting Packages In Npm Pypi
  • Generating And Analyzing Sboms
  • Implementing Sigstore For Software Signing
  • Typosquat Gate
  • Verifying Build Provenance With Slsa Sigstore

Threat Detection & Deception

14 skills · MITRE ATT&CK, MITRE D3FEND, MITRE Engage

  • Deploying Active Directory Honeytokens
  • Deploying Cloud Deception With Decoy Resources
  • Deploying Honeytokens And Canarytokens
  • Designing Adversary Engagement With Mitre Engage
  • Detecting Credential Dumping Techniques
  • Detecting Golden Ticket Forgery
  • Detecting Insider Threat With Ueba
  • Detecting Living Off The Land Attacks
  • Detecting Living Off The Land With Lolbas
  • Detecting Pass The Ticket Attacks
  • Detecting Rdp Brute Force Attacks
  • Implementing Deception Based Detection With Canarytoken
  • Implementing Network Deception With Honeypots
  • Performing Purple Team Atomic Testing

Hardware & Firmware Security

6 skills · NIST 800-193, TCG

  • Analyzing Uefi Bootkit Persistence
  • Auditing Uefi Firmware With Chipsec
  • Detecting Secure Boot Bypass
  • Hunting Bootkits In Efi System Partition
  • Performing Firmware Extraction With Binwalk
  • Validating Tpm Measured Boot Attestation

Framework Coverage

Every skill is mapped to industry-standard frameworks for traceability and audit evidence.

MITRE ATT&CK

Technique-level mapping across tactics

NIST CSF 2.0

Function and category alignment

MITRE D3FEND

Defensive technique countermeasures

OWASP Top 10

Web and API vulnerability coverage

CIS Controls

Implementation group mapping

NIST 800-53

Security control family alignment

CRI Profile

Financial services control coverage

ISO 42001

AI management system requirements

From Skills to Outcomes

These capabilities power threat-informed risk assessments, AI governance programs, and compliance audits for financial services. See them in action.