Search
By briiirussell
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency… | briiirussell/ | 413 | — | ~3.7k | Automated safety check: Notes | MIT | 4 mo ago |
| 2 | Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023). | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 3 | Learn from public breach disclosures — extract the audit question each one implies and check your own stack. | briiirussell/ | 413 | — | ~3.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. | briiirussell/ | 413 | — | ~1.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 5 | Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. | briiirussell/ | 413 | — | ~2.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 6 | Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 7 | Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). | briiirussell/ | 413 | — | ~3k | Automated safety check: Notes | MIT | 4 mo ago |
| 8 | Analyze disk images, file systems, and memory captures for digital evidence recovery in forensic investigations and CTF challenges. | briiirussell/ | 413 | — | ~1.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 9 | Triage a single security finding — from a scanner, audit, advisory, or report — to a defensible disposition with a mitigation plan, false-positive justification, or accepted-risk writeup. | briiirussell/ | 413 | — | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 10 | 10.Hipaa Audit Audit applications and infrastructure handling Protected Health Information against HIPAA — Security Rule (administrative, physical, technical safeguards), Privacy Rule, Breach Notification Rule… | briiirussell/ | 413 | — | ~4.4k | Automated safety check: Notes | MIT | 4 mo ago |
| 11 | Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 12 | 12.Iam Audit Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization… | briiirussell/ | 413 | — | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 13 | Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. | briiirussell/ | 413 | — | ~1.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 14 | 14.Osint Recon Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. | briiirussell/ | 413 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 15 | 15.Pci Audit Audit applications and infrastructure handling payment card data against PCI DSS v4.0. | briiirussell/ | 413 | — | ~3.7k | Automated safety check: Notes | MIT | 4 mo ago |
| 16 | Implement and audit privacy controls in product and infrastructure — GDPR, CCPA / CPRA, LGPD, PIPEDA. | briiirussell/ | 413 | — | ~4.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 17 | 17.Recon Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs. | briiirussell/ | 413 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 18 | Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 19 | Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. | briiirussell/ | 413 | — | ~3.8k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 21 | Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst… | briiirussell/ | 413 | — | ~2.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 22 | Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. | briiirussell/ | 413 | — | ~2.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 23 | Run a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases. | briiirussell/ | 413 | — | ~2.7k | Automated safety check: Notes | MIT | 4 mo ago |
| 24 | 24.Owasp Audit Audit application source code against the OWASP Top 10 (2021) vulnerability categories — broken access control, cryptographic failures, injection, insecure design, security misconfiguration… | briiirussell/ | 413 | — | ~8.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 25 | 25.Mobile Audit Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Warn | MIT | 4 mo ago |