explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 4 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
building-detection-rule-with-splunk-spl
building-detection-rule-with-splunk-spl

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillsecuring-container-registry-with-harbor
    securing-container-registry-with-harbor

    Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-security-headers-audit
    performing-security-headers-audit

    Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-canary-tokens-for-network-intrusion
    implementing-canary-tokens-for-network-intrusion

    Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intru…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-kerberoasting-with-impacket
    exploiting-kerberoasting-with-impacket

    Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ssl-tls-security-assessment
    performing-ssl-tls-security-assessment

    Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillauditing-azure-active-directory-configuration
    auditing-azure-active-directory-configuration

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using Azure…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-man-in-the-middle-attack-simulation
    conducting-man-in-the-middle-attack-simulation

    Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and d…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-red-team-with-covenant
    performing-red-team-with-covenant

    Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-living-off-the-land-attacks
    detecting-living-off-the-land-attacks

    Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patte…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-threat-hunting-with-yara-rules
    performing-threat-hunting-with-yara-rules

    Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel fee…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-soar-playbook-with-palo-alto-xsoar
    implementing-soar-playbook-with-palo-alto-xsoar

    Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-lnk-file-and-jump-list-artifacts
    analyzing-lnk-file-and-jump-list-artifacts

    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-soc-escalation-matrix
    building-soc-escalation-matrix

    Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillconducting-pass-the-ticket-attack
    conducting-pass-the-ticket-attack

    Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-http-request-smuggling
    exploiting-http-request-smuggling

    Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-user-behavior-analytics
    performing-user-behavior-analytics

    Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-memory-forensics-with-volatility3
    performing-memory-forensics-with-volatility3

    Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-cryptomining-in-cloud
    detecting-cryptomining-in-cloud

    This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-network-traffic-analysis-with-tshark
    performing-network-traffic-analysis-with-tshark

    Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-active-directory-penetration-test
    performing-active-directory-penetration-test

    Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound, exploit Kerberos weaknesses, escalate privileges via ADCS/DCSync, and demonstrate domain compromise.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-insider-data-exfiltration-via-dlp
    detecting-insider-data-exfiltration-via-dlp

    Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistica…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-azure-storage-account-misconfigurations
    detecting-azure-storage-account-misconfigurations

    Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Pytho…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-api-security-testing-with-42crunch
    implementing-api-security-testing-with-42crunch

    Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-authenticated-vulnerability-scan
    performing-authenticated-vulnerability-scan

    Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security sett

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-anti-ransomware-group-policy
    implementing-anti-ransomware-group-policy

    Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, an…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-lateral-movement-detection
    performing-lateral-movement-detection

    Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-alert-fatigue-reduction
    implementing-alert-fatigue-reduction

    Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and pr…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillcorrelating-threat-campaigns
    correlating-threat-campaigns

    Correlates disparate security incidents, IOCs, and adversary behaviors across time and organizations to identify unified threat campaigns, attribute them to common threat actors, and extract shared indicators for improv…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-web-application-logging-with-modsecurity
    implementing-web-application-logging-with-modsecurity

    Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-insider-threat-with-ueba
    detecting-insider-threat-with-ueba

    Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltr…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-dmarc-dkim-spf-email-security
    implementing-dmarc-dkim-spf-email-security

    SPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-aws-account-enumeration-with-scout-suite
    performing-aws-account-enumeration-with-scout-suite

    Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-siem-use-case-tuning
    implementing-siem-use-case-tuning

    Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-kubernetes-network-policy-with-calico
    implementing-kubernetes-network-policy-with-calico

    Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillreverse-engineering-malware-with-ghidra
    reverse-engineering-malware-with-ghidra

    Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-cve-prioritization-with-kev-catalog
    performing-cve-prioritization-with-kev-catalog

    Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-privileged-access-management-with-cyberark
    implementing-privileged-access-management-with-cyberark

    Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-dns-enumeration-and-zone-transfer
    performing-dns-enumeration-and-zone-transfer

    Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-pass-the-hash-attacks
    detecting-pass-the-hash-attacks

    Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-memory-dumps-with-volatility
    analyzing-memory-dumps-with-volatility

    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux,…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-pod-security-admission-controller
    implementing-pod-security-admission-controller

    Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-scada-hmi-security-assessment
    performing-scada-hmi-security-assessment

    Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI an…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-dark-web-monitoring-for-threats
    performing-dark-web-monitoring-for-threats

    Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-t1098-account-manipulation
    hunting-for-t1098-account-manipulation

    Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-gdpr-data-protection-controls
    implementing-gdpr-data-protection-controls

    The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-command-and-control-communication
    analyzing-command-and-control-communication

    Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detect…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillvalidating-backup-integrity-for-recovery
    validating-backup-integrity-for-recovery

    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-aws-nitro-enclave-security
    implementing-aws-nitro-enclave-security

    Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner bui…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-standing-privilege-with-cyberark
    implementing-zero-standing-privilege-with-cyberark

    Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using just-in-time access with time, entitlement, and approval controls.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    123456…11
    next →