explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 2 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
testing-mobile-api-authentication
testing-mobile-api-authentication

Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when perfo…

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillperforming-endpoint-forensics-investigation
    performing-endpoint-forensics-investigation

    Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidenc…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-api-injection-vulnerabilities
    exploiting-api-injection-vulnerabilities

    Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The te…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-webshell-activity
    hunting-for-webshell-activity

    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ssl-tls-inspection-configuration
    performing-ssl-tls-inspection-configuration

    Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-anomalous-powershell-execution
    hunting-for-anomalous-powershell-execution

    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated comma…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-malware-behavior-with-cuckoo-sandbox
    analyzing-malware-behavior-with-cuckoo-sandbox

    Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral r…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-fileless-attacks-on-endpoints
    detecting-fileless-attacks-on-endpoints

    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-initial-access-with-evilginx3
    performing-initial-access-with-evilginx3

    Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-bandwidth-throttling-attack-simulation
    performing-bandwidth-throttling-attack-simulation

    Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments to test quality-of-service controls, application resilience, and network monitoring detection of traf…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-deeplink-vulnerabilities
    exploiting-deeplink-vulnerabilities

    Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assess…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-post-incident-lessons-learned
    conducting-post-incident-lessons-learned

    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-service-account-abuse
    detecting-service-account-abuse

    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-api-for-mass-assignment-vulnerability
    testing-api-for-mass-assignment-vulnerability

    Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-cloud-log-forensics-with-athena
    performing-cloud-log-forensics-with-athena

    Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, dat…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-malware-incident-communication-template
    building-malware-incident-communication-template

    Build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-constrained-delegation-abuse
    exploiting-constrained-delegation-abuse

    Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconfiguring-windows-defender-advanced-settings
    configuring-windows-defender-advanced-settings

    Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows en…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-defense-evasion-via-timestomping
    hunting-for-defense-evasion-via-timestomping

    Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-network-flow-data-with-netflow
    analyzing-network-flow-data-with-netflow

    Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and appli…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-network-traffic-baselining
    implementing-network-traffic-baselining

    Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-cloud-vulnerability-posture-management
    implementing-cloud-vulnerability-posture-management

    Implement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-bootkit-and-rootkit-samples
    analyzing-bootkit-and-rootkit-samples

    Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI modul…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-incident-timeline-with-timesketch
    building-incident-timeline-with-timesketch

    Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-modbus-command-injection-attacks
    detecting-modbus-command-injection-attacks

    Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communica…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-usb-device-connection-history
    analyzing-usb-device-connection-history

    Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-active-directory-bloodhound-analysis
    performing-active-directory-bloodhound-analysis

    Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised users to Domain Admin.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldeploying-decoy-files-for-ransomware-detection
    deploying-decoy-files-for-ransomware-detection

    Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to tr…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-prefetch-files-for-execution-history
    analyzing-prefetch-files-for-execution-history

    Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-soc-tabletop-exercise
    performing-soc-tabletop-exercise

    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impact…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-supply-chain-compromise
    hunting-for-supply-chain-compromise

    Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-ransomware-leak-site-intelligence
    analyzing-ransomware-leak-site-intelligence

    Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-golden-ticket-attacks-in-kerberos-logs
    detecting-golden-ticket-attacks-in-kerberos-logs

    Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain control…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-devsecops-security-scanning
    implementing-devsecops-security-scanning

    Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy fo…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-siem-correlation-rules-for-apt
    implementing-siem-correlation-rules-for-apt

    Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule forma…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-scheduled-task-persistence
    hunting-for-scheduled-task-persistence

    Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-active-directory-compromise-investigation
    performing-active-directory-compromise-investigation

    Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-dns-tunneling-detection
    performing-dns-tunneling-detection

    Detects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality. Uses scapy for packet capture anal…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-diamond-model-analysis
    implementing-diamond-model-analysis

    The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-cloud-storage-forensic-acquisition
    performing-cloud-storage-forensic-acquisition

    Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-linux-system-artifacts
    analyzing-linux-system-artifacts

    Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-mobile-device-forensics-with-cellebrite
    performing-mobile-device-forensics-with-cellebrite

    Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-for-xxe-injection-vulnerabilities
    testing-for-xxe-injection-vulnerabilities

    Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-active-directory-acl-abuse
    analyzing-active-directory-acl-abuse

    Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-persistence-mechanisms-in-linux
    analyzing-persistence-mechanisms-in-linux

    Detect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-sbom-for-supply-chain-vulnerabilities
    analyzing-sbom-for-supply-chain-vulnerabilities

    Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs,…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-cloud-siem-with-sentinel
    building-cloud-siem-with-sentinel

    This skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection qu…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillmonitoring-scada-modbus-traffic-anomalies
    monitoring-scada-modbus-traffic-anomalies

    Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus,…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-powershell-empire-artifacts
    analyzing-powershell-empire-artifacts

    Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-malware-hash-enrichment-with-virustotal
    performing-malware-hash-enrichment-with-virustotal

    Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    1234…11
    next →