热门技能

当前社区里最受关注、增长最快的技能。

显示 49-72 / 共 196 个技能
mukul975

analyzing-linux-kernel-rootkits

mukul975

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules),

代码评审 3.1万 5个月前
mukul975

analyzing-malware-family-relationships-with-malpedia

mukul975

Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.

API 开发 3.1万 6个月前
mukul975

analyzing-office365-audit-logs-for-compromise

mukul975

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation,

分析 3.1万 5个月前
mukul975

analyzing-cloud-storage-access-patterns

mukul975

Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS

云服务 3.1万 5个月前
mukul975

analyzing-network-flow-data-with-netflow

mukul975

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing

数据处理 3.1万 5个月前
mukul975

analyzing-docker-container-forensics

mukul975

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to

调试 3.1万 5个月前
mukul975

analyzing-linux-audit-logs-for-intrusion

mukul975

'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized

代码评审 3.1万 5个月前
mukul975

analyzing-cyber-kill-chain

mukul975

'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases

分析 3.1万 5个月前
mukul975

analyzing-pdf-malware-with-pdfid

mukul975

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.

数据处理 3.1万 6个月前
mukul975

analyzing-ransomware-leak-site-intelligence

mukul975

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

分析 3.1万 6个月前
mukul975

analyzing-malicious-pdf-with-peepdf

mukul975

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,

数据处理 3.1万 5个月前
mukul975

analyzing-heap-spray-exploitation

mukul975

Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns,

代码评审 3.1万 5个月前
mukul975

analyzing-typosquatting-domains-with-dnstwist

mukul975

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

代码生成 3.1万 6个月前
mukul975

analyzing-network-traffic-for-incidents

mukul975

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.

API 开发 3.1万 6个月前
mukul975

analyzing-disk-image-with-autopsy

mukul975

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and

数据库 3.1万 5个月前
mukul975

analyzing-security-logs-with-splunk

mukul975

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.

文件操作 3.1万 6个月前
mukul975

analyzing-network-traffic-with-wireshark

mukul975

'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,

智能体 3.1万 5个月前
mukul975

analyzing-indicators-of-compromise

mukul975

Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.

代码评审 3.1万 6个月前
mukul975

analyzing-network-packets-with-scapy

mukul975

Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and

数据处理 3.1万 5个月前
mukul975

analyzing-active-directory-acl-abuse

mukul975

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and

代码评审 3.1万 5个月前
mukul975

analyzing-email-headers-for-phishing-investigation

mukul975

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify

调试 3.1万 5个月前
mukul975

analyzing-cobalt-strike-beacon-configuration

mukul975

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,

分析 3.1万 5个月前
mukul975

analyzing-malware-behavior-with-cuckoo-sandbox

mukul975

Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.

分析 3.1万 6个月前
mukul975

analyzing-cobaltstrike-malleable-c2-profiles

mukul975

Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract

API 开发 3.1万 5个月前