explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 6 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
recovering-deleted-files-with-photorec
recovering-deleted-files-with-photorec

Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skilldetecting-evasion-techniques-in-endpoint-logs
    detecting-evasion-techniques-in-endpoint-logs

    Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, buildin…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-physical-intrusion-assessment
    performing-physical-intrusion-assessment

    Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillauditing-gcp-iam-permissions
    auditing-gcp-iam-permissions

    Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM R…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-aes-encryption-for-data-at-rest
    implementing-aes-encryption-for-data-at-rest

    AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-for-xml-injection-vulnerabilities
    testing-for-xml-injection-vulnerabilities

    Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-ransomware-playbook-with-cisa-framework
    building-ransomware-playbook-with-cisa-framework

    Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework. Covers preparation, detection, containment, eradication, recovery, and post-incident…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-golang-malware-with-ghidra
    analyzing-golang-malware-with-ghidra

    Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-fuzz-testing-in-cicd-with-aflplusplus
    implementing-fuzz-testing-in-cicd-with-aflplusplus

    Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines to discover memory corruption, input handling, and logic vulnerabilities in C/C++ and compiled applications.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-network-traffic-analysis-with-zeek
    performing-network-traffic-analysis-with-zeek

    Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-mimikatz-execution-patterns
    detecting-mimikatz-execution-patterns

    Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-oauth-misconfiguration
    exploiting-oauth-misconfiguration

    Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-plc-firmware-security-analysis
    performing-plc-firmware-security-analysis

    This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocum…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-vulnerability-remediation-sla
    implementing-vulnerability-remediation-sla

    Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-google-workspace-phishing-protection
    implementing-google-workspace-phishing-protection

    Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-api-abuse-detection-with-rate-limiting
    implementing-api-abuse-detection-with-rate-limiting

    Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-github-actions-workflows
    securing-github-actions-workflows

    This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-open-source-intelligence-gathering
    performing-open-source-intelligence-gathering

    Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillsecuring-aws-iam-permissions
    securing-aws-iam-permissions

    This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access An…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltriaging-security-incident-with-ir-playbook
    triaging-security-incident-with-ir-playbook

    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-stix-taxii-feed-integration
    implementing-stix-taxii-feed-integration

    STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-hash-cracking-with-hashcat
    performing-hash-cracking-with-hashcat

    Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-api-enumeration-attacks
    detecting-api-enumeration-attacks

    Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-exfiltration-over-dns-with-zeek
    detecting-exfiltration-over-dns-with-zeek

    Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillscanning-network-with-nmap-advanced
    scanning-network-with-nmap-advanced

    Performs advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating sy…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-purple-team-atomic-testing
    performing-purple-team-atomic-testing

    Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the ATT&CK matrix, and runs detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-c2-infrastructure-with-sliver-framework
    building-c2-infrastructure-with-sliver-framework

    Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with redirectors, HTTPS listeners, and multi-operator support for authorized red team engagements.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-threat-hunt-hypothesis-framework
    building-threat-hunt-hypothesis-framework

    Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldeploying-edr-agent-with-crowdstrike
    deploying-edr-agent-with-crowdstrike

    Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configur…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-threat-actor-ttps-with-mitre-navigator
    analyzing-threat-actor-ttps-with-mitre-navigator

    Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-threat-feed-aggregation-with-misp
    building-threat-feed-aggregation-with-misp

    Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-t1548-abuse-elevation-control-mechanism
    detecting-t1548-abuse-elevation-control-mechanism

    Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relati…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-delinea-secret-server-for-pam
    implementing-delinea-secret-server-for-pam

    Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Direc…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-broken-object-property-level-authorization
    detecting-broken-object-property-level-authorization

    Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-bgp-hijacking-vulnerabilities
    exploiting-bgp-hijacking-vulnerabilities

    Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet r…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-command-and-control-over-dns
    detecting-command-and-control-over-dns

    Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload deliv…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-syslog-centralization-with-rsyslog
    implementing-syslog-centralization-with-rsyslog

    Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-rsa-key-pair-management
    implementing-rsa-key-pair-management

    RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. This skill covers generating, storing, rotating,

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-steganography-detection
    performing-steganography-detection

    Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-windows-prefetch-with-python
    analyzing-windows-prefetch-with-python

    Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-anomalies-in-industrial-control-systems
    detecting-anomalies-in-industrial-control-systems

    This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industria…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-malicious-pdf-with-peepdf
    analyzing-malicious-pdf-with-peepdf

    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-red-team-phishing-with-gophish
    performing-red-team-phishing-with-gophish

    Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and ana…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-misconfigured-azure-storage
    detecting-misconfigured-azure-storage

    Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, P…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-patch-management-for-ot-systems
    implementing-patch-management-for-ot-systems

    This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility tes…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-ms17-010-eternalblue-vulnerability
    exploiting-ms17-010-eternalblue-vulnerability

    MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-thick-client-application-penetration-test
    performing-thick-client-application-penetration-test

    Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Proc…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-pci-dss-compliance-controls
    implementing-pci-dss-compliance-controls

    PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-web-application-firewall-bypass
    performing-web-application-firewall-bypass

    Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection r…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-zero-trust-with-hashicorp-boundary
    implementing-zero-trust-with-hashicorp-boundary

    Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    1…45678…11
    next →