Search

Security · trilwu/secskills

36 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

trilwu/secskills157—~3.2kAutomated safety check: PassMIT1 mo ago
2

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills157—~3.1kAutomated safety check: NotesMIT1 mo ago
3

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
4

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
5

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
6

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
7

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills157—~4.3kAutomated safety check: PassMIT1 mo ago
8

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
9

Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections…

trilwu/secskills157—~3.1kAutomated safety check: PassMIT1 mo ago
10

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
11

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills157—~2.4kAutomated safety check: PassMIT1 mo ago
12

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices.

trilwu/secskills157—~3.3kAutomated safety check: PassMIT1 mo ago
13

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

trilwu/secskills157—~1.9kAutomated safety check: PassMIT1 mo ago
14

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
15

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills157—~4.8kAutomated safety check: PassMIT1 mo ago
16

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
17

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills157—~4.7kAutomated safety check: PassMIT1 mo ago
18

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
19

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
20

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
21

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

trilwu/secskills157—~4.4kAutomated safety check: PassMIT1 mo ago
22

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

trilwu/secskills157—~2.7kAutomated safety check: PassMIT1 mo ago
23

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills157—~3.4kAutomated safety check: PassMIT1 mo ago
24

Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline.

trilwu/secskills157—~2.3kAutomated safety check: PassMIT1 mo ago
25

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…

trilwu/secskills157—~2.7kAutomated safety check: PassMIT1 mo ago
26

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
27

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
28

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
29

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…

trilwu/secskills157—~4.1kAutomated safety check: PassMIT1 mo ago
30

Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…

trilwu/secskills157—~5.3kAutomated safety check: PassMIT1 mo ago
31

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…

trilwu/secskills157—~5.3kAutomated safety check: PassMIT1 mo ago
32

Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF…

trilwu/secskills157—~1.8kAutomated safety check: PassMIT1 mo ago
33

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

trilwu/secskills157—~1.6kAutomated safety check: PassMIT1 mo ago
34

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

trilwu/secskills157—~3.9kAutomated safety check: NotesMIT1 mo ago
35

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…

trilwu/secskills157—~1.4kAutomated safety check: PassMIT1 mo ago
36

Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…

trilwu/secskills157—~2.3kAutomated safety check: PassMIT1 mo ago