explainx.ainewsletter3.4k
trending🔥loopsskills
pricing
workshops ↗
explainx.ai

Learn to lead teams that combine humans and agents. Platform access, live workshops, bootcamps, and 50+ courses — plus skills, tools, and MCP to practice what you learn.

follow us

custom AI agents

[email protected]

get started

Join · $29/mo

learn

start for freepathwaysworkshopsbootcampscoursescertificationscertification testsexplainx universitycorporate trainingfacilitatorshackathonslearn skills & mcp

discover

skillstoolsagentsmcp serversdesignsllmsagiranks

content

releasesvisionmissionaboutcommunityteamcareersresourcespromptsgenerators hubgenerator SEO hubprompt templatesprompt guidesblogfor LLMsdemo

Sister Products

Infloq

Infloq

Influencer marketing

BgBlur

BgBlur

Privacy-first blur

Olly Social

Olly Social

Social AI copilot

Ceptory

Ceptory

Video intelligence

BgRemover

BgRemover

Background removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

contactsupportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 1 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
performing-kubernetes-etcd-security-assessment
performing-kubernetes-etcd-security-assessment

Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillimplementing-continuous-security-validation-with-bas
    implementing-continuous-security-validation-with-bas

    Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques across the kill chain.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-lateral-movement-via-wmi
    hunting-for-lateral-movement-via-wmi

    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-subdomain-enumeration-with-subfinder
    performing-subdomain-enumeration-with-subfinder

    Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-gcp-binary-authorization
    implementing-gcp-binary-authorization

    Implement GCP Binary Authorization to enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-pass-the-ticket-attacks
    detecting-pass-the-ticket-attacks

    Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-android-malware-with-apktool
    analyzing-android-malware-with-apktool

    Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-cloud-penetration-testing
    conducting-cloud-penetration-testing

    This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-passwordless-authentication-with-fido2
    implementing-passwordless-authentication-with-fido2

    Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillintercepting-mobile-traffic-with-burpsuite
    intercepting-mobile-traffic-with-burpsuite

    Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performin…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-dynamic-analysis-with-any-run
    performing-dynamic-analysis-with-any-run

    Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activ…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-linux-elf-malware
    analyzing-linux-elf-malware

    Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dyn…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-threat-modeling-with-owasp-threat-dragon
    performing-threat-modeling-with-owasp-threat-dragon

    Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-shadow-api-endpoints
    detecting-shadow-api-endpoints

    Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-snort-ids-for-intrusion-detection
    configuring-snort-ids-for-intrusion-detection

    Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network seg…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-knowledge-proof-for-authentication
    implementing-zero-knowledge-proof-for-authentication

    Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-epss-score-for-vulnerability-prioritization
    implementing-epss-score-for-vulnerability-prioritization

    Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-soar-playbook-for-phishing
    implementing-soar-playbook-for-phishing

    Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-remote-access-to-ot-environment
    securing-remote-access-to-ot-environment

    This skill covers implementing secure remote access to OT/ICS environments for operators, engineers, and vendors while preventing unauthorized access that could compromise industrial operations. It addresses jump server…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-anomalous-authentication-patterns
    detecting-anomalous-authentication-patterns

    Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised acco…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-slack-space-and-file-system-artifacts
    analyzing-slack-space-and-file-system-artifacts

    Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillgenerating-threat-intelligence-reports
    generating-threat-intelligence-reports

    Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when prod…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-vulnerabilities-with-metasploit-framework
    exploiting-vulnerabilities-with-metasploit-framework

    The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-persistence-via-wmi-subscriptions
    hunting-for-persistence-via-wmi-subscriptions

    Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-disk-image-with-autopsy
    analyzing-disk-image-with-autopsy

    Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillreverse-engineering-rust-malware
    reverse-engineering-rust-malware

    Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated strings, crate dependency extraction, and Rust-specific control flow analysis.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillextracting-browser-history-artifacts
    extracting-browser-history-artifacts

    Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-api-key-security-controls
    implementing-api-key-security-controls

    Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entro…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-data-loss-prevention-with-microsoft-purview
    implementing-data-loss-prevention-with-microsoft-purview

    Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity l…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-dcsync-attack-in-active-directory
    detecting-dcsync-attack-in-active-directory

    Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-active-directory-vulnerability-assessment
    performing-active-directory-vulnerability-assessment

    Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-conduit-security-for-ot-remote-access
    implementing-conduit-security-for-ot-remote-access

    Implement secure conduit architecture for OT remote access following IEC 62443 zones and conduits model, deploying jump servers, MFA-enabled gateways, session recording, and approval-based workflows to control vendor an…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-attack-pattern-library-from-cti-reports
    building-attack-pattern-library-from-cti-reports

    Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-windows-shellbag-artifacts
    analyzing-windows-shellbag-artifacts

    Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-unusual-network-connections
    hunting-for-unusual-network-connections

    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-secrets-management-with-vault
    implementing-secrets-management-with-vault

    This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate manage…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-zscaler-private-access-for-ztna
    configuring-zscaler-private-access-for-ztna

    Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring access policies based on user identity and devic…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-kubernetes-audit-logs
    analyzing-kubernetes-audit-logs

    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-alert-triage-with-elastic-siem
    performing-alert-triage-with-elastic-siem

    Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security alerts for SOC operations.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-active-directory-forest-trust-attack
    performing-active-directory-forest-trust-attack

    Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-container-escape-with-falco-rules
    detecting-container-escape-with-falco-rules

    Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldeploying-tailscale-for-zero-trust-vpn
    deploying-tailscale-for-zero-trust-vpn

    Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-sigstore-for-software-signing
    implementing-sigstore-for-software-signing

    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for conta…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-honeytokens-for-breach-detection
    implementing-honeytokens-for-breach-detection

    Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations fo…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-process-injection-techniques
    detecting-process-injection-techniques

    Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and b…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-automated-malware-submission-pipeline
    building-automated-malware-submission-pipeline

    Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ip-reputation-analysis-with-shodan
    performing-ip-reputation-analysis-with-shodan

    Analyze IP address reputation using the Shodan API to identify open ports, running services, known vulnerabilities, and hosting context for threat intelligence enrichment and incident triage.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-trust-dns-with-nextdns
    implementing-zero-trust-dns-with-nextdns

    Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-threat-hunting-with-elastic-siem
    performing-threat-hunting-with-elastic-siem

    Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for speci…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-mobile-app-certificate-pinning-bypass
    performing-mobile-app-certificate-pinning-bypass

    Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinn…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    123…11
    next →