explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 10 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
exploiting-smb-vulnerabilities-with-metasploit
exploiting-smb-vulnerabilities-with-metasploit

Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in e…

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillanalyzing-linux-audit-logs-for-intrusion
    analyzing-linux-audit-logs-for-intrusion

    Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldeobfuscating-javascript-malware
    deobfuscating-javascript-malware

    Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original m…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-network-intrusion-prevention-with-suricata
    implementing-network-intrusion-prevention-with-suricata

    Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-incident-response-dashboard
    building-incident-response-dashboard

    Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-container-security-scanning-with-trivy
    performing-container-security-scanning-with-trivy

    Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-living-off-the-land-with-lolbas
    detecting-living-off-the-land-with-lolbas

    Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-vulnerability-scanning-workflow
    building-vulnerability-scanning-workflow

    Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-excessive-data-exposure-in-api
    exploiting-excessive-data-exposure-in-api

    Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for le…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillprocessing-stix-taxii-feeds
    processing-stix-taxii-feeds

    Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collectio…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-identity-federation-with-saml-azure-ad
    building-identity-federation-with-saml-azure-ad

    Establish SAML 2.0 identity federation between on-premises Active Directory and Azure AD (Microsoft Entra ID) for seamless cross-domain authentication and SSO to cloud applications.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-suspicious-scheduled-tasks
    hunting-for-suspicious-scheduled-tasks

    Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-ioc-enrichment-pipeline-with-opencti
    building-ioc-enrichment-pipeline-with-opencti

    OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-log-source-onboarding-in-siem
    performing-log-source-onboarding-in-siem

    Perform structured log source onboarding into SIEM platforms by configuring collectors, parsers, normalization, and validation for complete security visibility.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-deception-based-detection-with-canarytoken
    implementing-deception-based-detection-with-canarytoken

    Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug tokens, DNS tokens, document tokens, and AWS key tokens.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-credential-dumping-techniques
    detecting-credential-dumping-techniques

    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-dcom-lateral-movement
    hunting-for-dcom-lateral-movement

    Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-kubernetes-penetration-testing
    performing-kubernetes-penetration-testing

    Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-container-escape-attempts
    detecting-container-escape-attempts

    Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-identity-verification-for-zero-trust
    implementing-identity-verification-for-zero-trust

    Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-historian-server-in-ot-environment
    securing-historian-server-in-ot-environment

    This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for his…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-opa-gatekeeper-for-policy-enforcement
    implementing-opa-gatekeeper-for-policy-enforcement

    Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-for-email-header-injection
    testing-for-email-header-injection

    Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-rbac-hardening-for-kubernetes
    implementing-rbac-hardening-for-kubernetes

    Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-network-traffic-with-wireshark
    analyzing-network-traffic-with-wireshark

    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized networ…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-api-gateway-security-controls
    implementing-api-gateway-security-controls

    Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateway…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-malware-ioc-extraction
    performing-malware-ioc-extraction

    Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-network-traffic-analysis-with-arkime
    implementing-network-traffic-analysis-with-arkime

    Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze connection patterns, detect beaconing behavior, and identify…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillrecovering-from-ransomware-attack
    recovering-from-ransomware-attack

    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration f…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillintegrating-dast-with-owasp-zap-in-pipeline
    integrating-dast-with-owasp-zap-in-pipeline

    This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting Z…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-malicious-scheduled-tasks-with-sysmon
    detecting-malicious-scheduled-tasks-with-sysmon

    Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task crea…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-jwt-signing-and-verification
    implementing-jwt-signing-and-verification

    JSON Web Tokens (JWT) defined in RFC 7519 are compact, URL-safe tokens used for authentication and authorization in web applications. This skill covers implementing secure JWT signing with HMAC-SHA256

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-tls-1-3-for-secure-communications
    configuring-tls-1-3-for-secure-communications

    TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillprioritizing-vulnerabilities-with-cvss-scoring
    prioritizing-vulnerabilities-with-cvss-scoring

    The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-cors-misconfiguration
    testing-cors-misconfiguration

    Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-digital-signatures-with-ed25519
    implementing-digital-signatures-with-ed25519

    Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-startup-folder-persistence
    hunting-for-startup-folder-persistence

    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-oauth-scope-minimization-review
    performing-oauth-scope-minimization-review

    Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-windows-event-logs-in-splunk
    analyzing-windows-event-logs-in-splunk

    Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-sca-dependency-scanning-with-snyk
    performing-sca-dependency-scanning-with-snyk

    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull r…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-device-posture-assessment-in-zero-trust
    implementing-device-posture-assessment-in-zero-trust

    Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that enforce compliance befo…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-living-off-the-land-binaries
    hunting-for-living-off-the-land-binaries

    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-mitre-attack-coverage-mapping
    implementing-mitre-attack-coverage-mapping

    Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbypassing-authentication-with-forced-browsing
    bypassing-authentication-with-forced-browsing

    Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-kubernetes-pod-security-standards
    implementing-kubernetes-pod-security-standards

    Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-cloud-penetration-testing-with-pacu
    performing-cloud-penetration-testing-with-pacu

    Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate securi…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-ntlm-relay-attacks
    hunting-for-ntlm-relay-attacks

    Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillauditing-cloud-with-cis-benchmarks
    auditing-cloud-with-cis-benchmarks

    This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments wit…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-malware-triage-with-yara
    performing-malware-triage-with-yara

    Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule wri…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-ics-firewall-with-tofino
    implementing-ics-firewall-with-tofino

    Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    1…891011
    next →