Recently Added

Fresh skills just added to the collection. Be the first to try them out!

Showing 145-168 of 196 skills
mukul975

analyzing-network-traffic-for-incidents

by mukul975

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.

API Dev 31.3K 6mo ago
mukul975

analyzing-slack-space-and-file-system-artifacts

by mukul975

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

Code Review 31.3K 6mo ago
mukul975

analyzing-pdf-malware-with-pdfid

by mukul975

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.

Processing 31.3K 6mo ago
mukul975

analyzing-bootkit-and-rootkit-samples

by mukul975

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.

Code Review 31.3K 6mo ago
mukul975

analyzing-malware-persistence-with-autoruns

by mukul975

Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry

Automation 31.3K 5mo ago
mukul975

analyzing-cobalt-strike-beacon-configuration

by mukul975

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,

Analytics 31.3K 5mo ago
mukul975

analyzing-windows-lnk-files-for-artifacts

by mukul975

Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

CLI Tools 31.3K 6mo ago
mukul975

analyzing-security-logs-with-splunk

by mukul975

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.

File Ops 31.3K 6mo ago
mukul975

analyzing-threat-intelligence-feeds

by mukul975

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.

API Dev 31.3K 6mo ago
mukul975

analyzing-docker-container-forensics

by mukul975

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to

Debugging 31.3K 5mo ago
mukul975

auditing-aws-s3-bucket-permissions

by mukul975

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

Cloud 31.3K 6mo ago
mukul975

analyzing-packed-malware-with-upx-unpacker

by mukul975

'Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for

Debugging 31.3K 5mo ago
mukul975

analyzing-linux-system-artifacts

by mukul975

Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover

File Ops 31.3K 5mo ago
mukul975

analyzing-indicators-of-compromise

by mukul975

Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.

Code Review 31.3K 6mo ago
mukul975

analyzing-malicious-url-with-urlscan

by mukul975

URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content,

Automation 31.3K 5mo ago
mukul975

auditing-azure-active-directory-configuration

by mukul975

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.

Analytics 31.3K 6mo ago
mukul975

analyzing-certificate-transparency-for-phishing

by mukul975

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates,

Analytics 31.3K 5mo ago
mukul975

analyzing-apt-group-with-mitre-navigator

by mukul975

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps

Analytics 31.3K 5mo ago
mukul975

analyzing-network-covert-channels-in-malware

by mukul975

Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration,

Debugging 31.3K 5mo ago
mukul975

analyzing-ransomware-leak-site-intelligence

by mukul975

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

Analytics 31.3K 6mo ago
mukul975

analyzing-dns-logs-for-exfiltration

by mukul975

'Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert

Docs Gen 31.3K 5mo ago
mukul975

analyzing-malware-family-relationships-with-malpedia

by mukul975

Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.

API Dev 31.3K 6mo ago
mukul975

analyzing-outlook-pst-for-email-forensics

by mukul975

Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments,

Processing 31.3K 5mo ago
mukul975

analyzing-campaign-attribution-evidence

by mukul975

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or

Analytics 31.3K 5mo ago