Search

trilwu/secskills

50 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

trilwu/secskills157—~3.2kAutomated safety check: PassMIT1 mo ago
2

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills157—~3.1kAutomated safety check: NotesMIT1 mo ago
3

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
4

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
5

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
6

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
7

Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

trilwu/secskills157—~3.6kAutomated safety check: PassMIT1 mo ago
8

Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction…

trilwu/secskills157—~4kAutomated safety check: NotesMIT1 mo ago
9

Triage and forensically analyze reported phishing safely — extract the raw message, read the Received chain, verify SPF/DKIM/DMARC, detect display-name and lookalike spoofing, unwrap redirects and…

trilwu/secskills157—~4.2kAutomated safety check: PassMIT1 mo ago
10

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills157—~4.3kAutomated safety check: PassMIT1 mo ago
11

Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of…

trilwu/secskills157—~2.3kAutomated safety check: PassMIT1 mo ago
12

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
13

Attack SAML single sign-on by decoding and tampering with signed XML assertions — XML signature wrapping (XSW1-XSW8), signature stripping, assertion and attribute tampering, NameID comment…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
14

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
15

Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections…

trilwu/secskills157—~3.1kAutomated safety check: PassMIT1 mo ago
16

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
17

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills157—~2.4kAutomated safety check: PassMIT1 mo ago
18

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
19

Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora, or ghidriff to find the changed functions, reading the added checks to recover…

trilwu/secskills157—~1.9kAutomated safety check: PassMIT1 mo ago
20

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices.

trilwu/secskills157—~3.3kAutomated safety check: PassMIT1 mo ago
21

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

trilwu/secskills157—~1.9kAutomated safety check: PassMIT1 mo ago
22

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
23

Hunt planted webshells and backdoors across a web source tree — PHP first (also JSP, ASP, Node) — triaging a directory at scale, statically decoding obfuscation layers without ever executing the…

trilwu/secskills157—~3kAutomated safety check: PassMIT1 mo ago
24

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills157—~4.8kAutomated safety check: PassMIT1 mo ago
25

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
26

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

trilwu/secskills157—~4.1kAutomated safety check: PassMIT1 mo ago
27

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills157—~4.7kAutomated safety check: PassMIT1 mo ago
28

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
29

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
30

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
31

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

trilwu/secskills157—~4.4kAutomated safety check: PassMIT1 mo ago
32

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

trilwu/secskills157—~2.7kAutomated safety check: PassMIT1 mo ago
33

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills157—~3.4kAutomated safety check: PassMIT1 mo ago
34

Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline.

trilwu/secskills157—~2.3kAutomated safety check: PassMIT1 mo ago
35

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…

trilwu/secskills157—~2.7kAutomated safety check: PassMIT1 mo ago
36

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
37

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
38

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
39

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…

trilwu/secskills157—~2.1kAutomated safety check: PassMIT1 mo ago
40

Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…

trilwu/secskills157—~4kAutomated safety check: PassMIT1 mo ago
41

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…

trilwu/secskills157—~4.1kAutomated safety check: PassMIT1 mo ago
42

Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules…

trilwu/secskills157—~4.4kAutomated safety check: PassMIT1 mo ago
43

Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…

trilwu/secskills157—~5.3kAutomated safety check: PassMIT1 mo ago
44

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…

trilwu/secskills157—~5.3kAutomated safety check: PassMIT1 mo ago
45

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…

trilwu/secskills157—~1.7kAutomated safety check: PassMIT1 mo ago
46

Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF…

trilwu/secskills157—~1.8kAutomated safety check: PassMIT1 mo ago
47

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

trilwu/secskills157—~1.6kAutomated safety check: PassMIT1 mo ago
48

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

trilwu/secskills157—~3.9kAutomated safety check: NotesMIT1 mo ago