Search
Data & Analytics · By mukul975
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. | mukul975/ | 34k | — | ~581 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 2 | Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and… | mukul975/ | 34k | — | ~599 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 3 | Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for high-throughput, protocol-aware traffic inspection (HTTP, TLS, DNS, SMB) and SIEM… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 4 | Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. | mukul975/ | 34k | — | ~662 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Identify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger reconstruction), Cleanlab… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | Detect AI-generated deepfake audio used in voice phishing (vishing) by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 7 | Detect anomalies in DNP3 communications used in SCADA/ICS systems by monitoring unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 8 | Detect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and… | mukul975/ | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. | mukul975/ | 34k | — | ~623 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Detect anomalies in Modbus/TCP and Modbus RTU industrial traffic via function code monitoring, register range validation, timing analysis, and deep packet inspection, using Zeek's Modbus analyzer… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Detects sophisticated cyber-physical attacks that follow the Stuxnet pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation, using PLC logic integrity monitoring… | mukul975/ | 34k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. | mukul975/ | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. | mukul975/ | 34k | — | ~578 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis, providing asset visibility, behavioral anomaly detection, protocol-aware monitoring, and vulnerability assessment… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Conducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Query a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdowns, threat actor galaxy clusters, and tag trends, and generate threat landscape… | mukul975/ | 34k | — | ~597 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including… | mukul975/ | 34k | — | ~7.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. | mukul975/ | 34k | — | ~543 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. | mukul975/ | 34k | — | ~626 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Detect unauthorized SaaS and cloud service usage (shadow IT) by parsing proxy access logs, DNS query logs, and firewall/netflow data with Python pandas to aggregate traffic by domain, classify… | mukul975/ | 34k | — | ~637 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python pandas, computing hourly/daily volume distributions, per-host and protocol/port statistics, and top-talker… | mukul975/ | 34k | — | ~652 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying… | mukul975/ | 34k | — | ~7.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command… | mukul975/ | 34k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. | mukul975/ | 34k | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 28 | Implements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring. | mukul975/ | 301 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 29 | Implements data classification labels and tagging systems including metadata tagging, DLP integration, automated label propagation, user-applied labels, and label inheritance rules. | mukul975/ | 301 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 30 | Build automated PII detection and redaction pipelines using spaCy NER, Microsoft Presidio, and AWS Macie integration. | mukul975/ | 301 | — | ~5.6k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 31 | Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. | mukul975/ | 301 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 32 | Implements data lineage tracking for privacy compliance including origin tracking, transformation logging, access auditing, deletion verification, and cross-system lineage graphs. | mukul975/ | 301 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 33 | Creates executive reporting and visualization from RoPA data including processing activity counts, risk heatmaps, compliance scores, trend analysis, and supervisory authority readiness indicators. | mukul975/ | 301 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |