Bulletin · UTC

Merged timeline: 501 items (blog publish time and listing createdAt in UTC). Page 5 of 11. For registry-only weekly slices, use /new.

  1. Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

    by Yash @ Explainxdetecting-wmi-persistence0 comments
  2. Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business envi…

    by Yash @ Explainxconfiguring-pfsense-firewall-rules0 comments
  3. Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident R…

    by Yash @ Explainxtriaging-security-alerts-in-splunk0 comments
  4. Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Lev…

    by Yash @ Explainximplementing-purdue-model-network-segmentation0 comments
  5. Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified securit…

    by Yash @ Explainxdeploying-palo-alto-prisma-access-zero-trust0 comments
  6. Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for fo…

    by Yash @ Explainxanalyzing-browser-forensics-with-hindsight0 comments
  7. Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account sp…

    by Yash @ Explainxdetecting-lateral-movement-with-zeek0 comments
  8. Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.

    by Yash @ Explainxanalyzing-network-covert-channels-in-malware0 comments
  9. Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile appli…

    by Yash @ Explainxdetecting-mobile-malware-behavior0 comments
  10. Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

    by Yash @ Explainxtriaging-vulnerabilities-with-ssvc-framework0 comments
  11. Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify…

    by Yash @ Explainxperforming-dynamic-analysis-of-android-app0 comments
  12. Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

    by Yash @ Explainxtesting-jwt-token-security0 comments
  13. Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized acc…

    by Yash @ Explainxdetecting-aws-credential-exposure-with-trufflehog0 comments
  14. Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use w…

    by Yash @ Explainxreverse-engineering-ios-app-with-frida0 comments
  15. Deploys remote browser isolation (RBI) as a core component of a Zero Trust architecture. Implements isolation policies with URL categorization and risk-based routing, content disarming and reconstruction (CDR) for file…

    by Yash @ Explainximplementing-browser-isolation-for-zero-trust0 comments
  16. Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find securi…

    by Yash @ Explainxperforming-api-fuzzing-with-restler0 comments
  17. Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT…

    by Yash @ Explainxauditing-tls-certificate-transparency-logs0 comments
  18. Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.

    by Yash @ Explainxdetecting-email-account-compromise0 comments
  19. Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection…

    by Yash @ Explainxdetecting-rootkit-activity0 comments
  20. Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized s…

    by Yash @ Explainxperforming-binary-exploitation-analysis0 comments
  21. Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

    by Yash @ Explainxtesting-for-host-header-injection0 comments
  22. This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentati…

    by Yash @ Explainximplementing-zero-trust-in-cloud0 comments
  23. Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security f…

    by Yash @ Explainxperforming-android-app-static-analysis-with-mobsf0 comments
  24. Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embed…

    by Yash @ Explainxanalyzing-pdf-malware-with-pdfid0 comments
  25. Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.

    by Yash @ Explainxperforming-network-forensics-with-wireshark0 comments
  26. Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege esca…

    by Yash @ Explainximplementing-cloud-trail-log-analysis0 comments
  27. Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user be…

    by Yash @ Explainxperforming-insider-threat-investigation0 comments
  28. Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

    by Yash @ Explainxanalyzing-campaign-attribution-evidence0 comments
  29. Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enfor…

    by Yash @ Explainxauditing-aws-s3-bucket-permissions0 comments
  30. Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential ana…

    by Yash @ Explainxperforming-ios-app-security-assessment0 comments
  31. This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets…

    by Yash @ Explainxsecuring-serverless-functions0 comments
  32. Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-base…

    by Yash @ Explainximplementing-zero-trust-network-access0 comments
  33. Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.

    by Yash @ Explainximplementing-mimecast-targeted-attack-protection0 comments
  34. Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral mo…

    by Yash @ Explainxperforming-cloud-incident-containment-procedures0 comments
  35. Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API…

    by Yash @ Explainxtesting-api-for-broken-object-level-authorization0 comments
  36. Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

    by Yash @ Explainxanalyzing-typosquatting-domains-with-dnstwist0 comments
  37. Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypa…

    by Yash @ Explainxperforming-vlan-hopping-attack0 comments
  38. Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.

    by Yash @ Explainxsecuring-helm-chart-deployments0 comments
  39. Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and potential decryption opportunities using static and dynamic analysis.

    by Yash @ Explainxreverse-engineering-ransomware-encryption-routine0 comments
  40. Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.

    by Yash @ Explainximplementing-azure-ad-privileged-identity-management0 comments
  41. Detects container escape attempts by analyzing namespace configurations, privileged container checks, dangerous capability assignments, and host path mounts using the kubernetes Python client. Identifies CVE-2022-0492 s…

    by Yash @ Explainxperforming-container-escape-detection0 comments
  42. Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The…

    by Yash @ Explainxperforming-disk-forensics-investigation0 comments
  43. Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credentia

    by Yash @ Explainximplementing-pam-for-database-access0 comments
  44. Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security graph of infrastructure assets, IAM permissions, and attack paths across AWS, GCP, and Azure.

    by Yash @ Explainxperforming-cloud-asset-inventory-with-cartography0 comments
  45. Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand de…

    by Yash @ Explainximplementing-siem-use-cases-for-detection0 comments
  46. Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust access to self-hosted and private applications, configuring identity-aware access policies, device posture checks, and WARP client enrollment for…

    by Yash @ Explainxdeploying-cloudflare-access-for-zero-trust0 comments
  47. Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.

    by Yash @ Explainxextracting-config-from-agent-tesla-rat0 comments
  48. This skill covers implementing Open Policy Agent (OPA) and Gatekeeper for policy-as-code enforcement in Kubernetes and CI/CD pipelines. It addresses writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admiss…

    by Yash @ Explainximplementing-policy-as-code-with-open-policy-agent0 comments
  49. Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

    by Yash @ Explainximplementing-proofpoint-email-security-gateway0 comments
  50. Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.

    by Yash @ Explainxrecovering-deleted-files-with-photorec0 comments