explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

custom AI agents

[email protected]

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource librarydemofor LLMs

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

More from us

InfloqInfluencer marketingBgBlurPrivacy-first blurOlly SocialSocial AI copilotCeptoryVideo intelligenceBgRemoverBackground removal

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightssubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

catch up on ai/2026-05-25

Monday, May 25, 2026

Merged timeline of 501 items — blog publish times and listing timestamps, cut at midnight UTC. Page 8 of 11.

← 2026-05-242026-05-26 →Calendar
Skill
hunting-for-cobalt-strike-beacons
hunting-for-cobalt-strike-beacons

Detect Cobalt Strike beacon network activity using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP C2 profile pattern matching, beacon jitter analysis, and named pipe detection via…

by Yash @ Explainx0 comments
listed May 25, 11:27 UTC
  • Skillanalyzing-ransomware-payment-wallets
    analyzing-ransomware-payment-wallets

    Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and ex…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-mft-for-deleted-file-recovery
    analyzing-mft-for-deleted-file-recovery

    Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillevaluating-threat-intelligence-platforms
    evaluating-threat-intelligence-platforms

    Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-file-carving-with-foremost
    performing-file-carving-with-foremost

    Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillprofiling-threat-actor-groups
    profiling-threat-actor-groups

    Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicator…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-osint-with-spiderfoot
    performing-osint-with-spiderfoot

    Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance, and structured result analysis across 200+ data sources

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-web-cache-deception-attack
    performing-web-cache-deception-attack

    Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-fuzzing-with-aflplusplus
    performing-fuzzing-with-aflplusplus

    Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/af…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-runtime-application-self-protection
    implementing-runtime-application-self-protection

    Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java a…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-powershell-script-block-logging
    analyzing-powershell-script-block-logging

    Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scr…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-docker-bench-security-assessment
    performing-docker-bench-security-assessment

    Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying Docker containers in production. Based on the CIS Docker Benchmark, it audits host confi

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-kerberoasting-attacks
    detecting-kerberoasting-attacks

    Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-bluetooth-low-energy-attacks
    detecting-bluetooth-low-energy-attacks

    Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet captur…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-for-persistence-mechanisms-in-windows
    hunting-for-persistence-mechanisms-in-windows

    Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-soc-playbook-for-ransomware
    building-soc-playbook-for-ransomware

    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-serverless-function-security-review
    performing-serverless-function-security-review

    Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, a…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-ticketing-system-for-incidents
    implementing-ticketing-system-for-incidents

    Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SO…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-dll-sideloading-attacks
    detecting-dll-sideloading-attacks

    Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-credential-access-with-lazagne
    performing-credential-access-with-lazagne

    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-jwt-algorithm-confusion-attack
    exploiting-jwt-algorithm-confusion-attack

    Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg he…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-threat-landscape-assessment-for-sector
    performing-threat-landscape-assessment-for-sector

    Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-code-signing-for-artifacts
    implementing-code-signing-for-artifacts

    This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-process-hollowing-technique
    detecting-process-hollowing-technique

    Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-packed-malware-with-upx-unpacker
    analyzing-packed-malware-with-upx-unpacker

    Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-ot-vulnerability-assessment-with-claroty
    performing-ot-vulnerability-assessment-with-claroty

    This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It a…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-external-network-penetration-test
    performing-external-network-penetration-test

    Conduct a comprehensive external network penetration test to identify vulnerabilities in internet-facing infrastructure using PTES methodology, reconnaissance, scanning, exploitation, and reporting.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-soc-metrics-and-kpi-tracking
    building-soc-metrics-and-kpi-tracking

    Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-for-open-redirect-vulnerabilities
    testing-for-open-redirect-vulnerabilities

    Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-dnp3-protocol-anomalies
    detecting-dnp3-protocol-anomalies

    Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring for unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-network-anomalies-with-zeek
    detecting-network-anomalies-with-zeek

    Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and i…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-vulnerability-sla-breach-alerting
    implementing-vulnerability-sla-breach-alerting

    Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-gcp-organization-policy-constraints
    implementing-gcp-organization-policy-constraints

    Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-security-information-sharing-with-stix2
    implementing-security-information-sharing-with-stix2

    Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillanalyzing-cloud-storage-access-patterns
    analyzing-cloud-storage-access-patterns

    Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresse…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-network-policies-for-kubernetes
    implementing-network-policies-for-kubernetes

    Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-attack-surface-management
    implementing-attack-surface-management

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring.…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-privileged-account-access-review
    performing-privileged-account-access-review

    Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-second-order-sql-injection
    performing-second-order-sql-injection

    Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilltesting-api-security-with-owasp-top-10
    testing-api-security-with-owasp-top-10

    Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillhunting-credential-stuffing-attacks
    hunting-credential-stuffing-attacks

    Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses statistical analysis on Splun…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-brand-monitoring-for-impersonation
    performing-brand-monitoring-for-impersonation

    Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthorized brand usage targeting your organization.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillinvestigating-insider-threat-indicators
    investigating-insider-threat-indicators

    Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use wh…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillcorrelating-security-events-in-qradar
    correlating-security-events-in-qradar

    Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources.…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillperforming-service-account-audit
    performing-service-account-audit

    Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillimplementing-bgp-security-with-rpki
    implementing-bgp-security-with-rpki

    Implement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillexploiting-active-directory-with-bloodhound
    exploiting-active-directory-with-bloodhound

    BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skilldetecting-azure-service-principal-abuse
    detecting-azure-service-principal-abuse

    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillmanaging-intelligence-lifecycle
    managing-intelligence-lifecycle

    Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • Skillbuilding-incident-response-playbook
    building-incident-response-playbook

    Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision…

    by Yash @ Explainx0 comments
    listed May 25, 11:27 UTC
  • ← prev
    1…67891011
    next →