Bulletin · UTC

Merged timeline: 501 items (blog publish time and listing createdAt in UTC). Page 9 of 11. For registry-only weekly slices, use /new.

  1. Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.

    by Yash @ Explainxexploiting-active-directory-certificate-services-esc10 comments
  2. Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructiv…

    by Yash @ Explainxtesting-ransomware-recovery-procedures0 comments
  3. Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports

    by Yash @ Explainxanalyzing-malware-sandbox-evasion-techniques0 comments
  4. This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security sta…

    by Yash @ Explainximplementing-aws-security-hub0 comments
  5. Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create…

    by Yash @ Explainximplementing-aws-security-hub-compliance0 comments
  6. Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

    by Yash @ Explainxconducting-domain-persistence-with-dcsync0 comments
  7. Deploy and configure the Dragos Platform for OT network monitoring, leveraging its 600+ industrial protocol parsers, intelligence-driven threat detection analytics, and asset visibility capabilities to protect ICS envir…

    by Yash @ Explainximplementing-dragos-platform-for-ot-monitoring0 comments
  8. Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

    by Yash @ Explainximplementing-saml-sso-with-okta0 comments
  9. Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks.…

    by Yash @ Explainximplementing-memory-protection-with-dep-aslr0 comments
  10. Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC2, and HIPAA.

    by Yash @ Explainxperforming-access-recertification-with-saviynt0 comments
  11. Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and…

    by Yash @ Explainxdetecting-ransomware-encryption-behavior0 comments
  12. Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

    by Yash @ Explainxdetecting-aws-iam-privilege-escalation0 comments
  13. Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.

    by Yash @ Explainxperforming-malware-persistence-investigation0 comments
  14. Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs…

    by Yash @ Explainxanalyzing-indicators-of-compromise0 comments
  15. ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete

    by Yash @ Explainximplementing-iso-27001-information-security-management0 comments
  16. Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.

    by Yash @ Explainximplementing-threat-intelligence-lifecycle-management0 comments
  17. Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring.…

    by Yash @ Explainxcollecting-open-source-intelligence0 comments
  18. Configure Fluentd and Fluent Bit for centralized log aggregation, routing, filtering, and enrichment across distributed infrastructure

    by Yash @ Explainximplementing-log-forwarding-with-fluentd0 comments
  19. Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app sec…

    by Yash @ Explainxanalyzing-ios-app-security-with-objection0 comments
  20. Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM…

    by Yash @ Explainxperforming-aws-privilege-escalation-assessment0 comments
  21. Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.

    by Yash @ Explainxperforming-directory-traversal-testing0 comments
  22. Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between…

    by Yash @ Explainximplementing-microsegmentation-with-guardicore0 comments
  23. Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC…

    by Yash @ Explainxperforming-cloud-native-forensics-with-falco0 comments
  24. Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The test…

    by Yash @ Explainxtesting-oauth2-implementation-flaws0 comments
  25. Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known b…

    by Yash @ Explainxanalyzing-uefi-bootkit-persistence0 comments
  26. This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitor…

    by Yash @ Explainxdetecting-cloud-threats-with-guardduty0 comments
  27. Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based at…

    by Yash @ Explainximplementing-passwordless-auth-with-microsoft-entra0 comments
  28. Analyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal i…

    by Yash @ Explainxanalyzing-outlook-pst-for-email-forensics0 comments
  29. Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), eval…

    by Yash @ Explainxperforming-post-quantum-cryptography-migration0 comments
  30. Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.

    by Yash @ Explainxbuilding-threat-actor-profile-from-osint0 comments
  31. Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.

    by Yash @ Explainxconducting-full-scope-red-team-engagement0 comments
  32. Deploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.

    by Yash @ Explainxdeploying-software-defined-perimeter0 comments
  33. Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate networ…

    by Yash @ Explainxconducting-internal-network-penetration-test0 comments
  34. Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.

    by Yash @ Explainxanalyzing-windows-lnk-files-for-artifacts0 comments
  35. Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitor…

    by Yash @ Explainxconfiguring-host-based-intrusion-detection0 comments
  36. Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account

    by Yash @ Explainxperforming-privileged-account-discovery0 comments
  37. This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categoriz…

    by Yash @ Explainximplementing-nerc-cip-compliance-controls0 comments
  38. Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security…

    by Yash @ Explainximplementing-azure-defender-for-cloud0 comments
  39. Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attack…

    by Yash @ Explainxperforming-ssl-stripping-attack0 comments
  40. Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

    by Yash @ Explainxanalyzing-office365-audit-logs-for-compromise0 comments
  41. Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse e…

    by Yash @ Explainxperforming-firmware-malware-analysis0 comments
  42. Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump,…

    by Yash @ Explainxanalyzing-macro-malware-in-office-documents0 comments
  43. Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.

    by Yash @ Explainxanalyzing-cobaltstrike-malleable-c2-profiles0 comments
  44. URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat

    by Yash @ Explainxanalyzing-malicious-url-with-urlscan0 comments
  45. Deploy Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points. This skill covers Duo integration methods, adaptive authentication policies, device trust

    by Yash @ Explainxconfiguring-multi-factor-authentication-with-duo0 comments
  46. This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses detecting misconfigurations in Terraform, CloudFormation, Kub…

    by Yash @ Explainximplementing-infrastructure-as-code-security-scanning0 comments
  47. Deploy XM Cyber's continuous exposure management platform to map attack paths, identify choke points, and prioritize the 2% of exposures that threaten critical assets.

    by Yash @ Explainximplementing-attack-path-analysis-with-xm-cyber0 comments
  48. This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and…

    by Yash @ Explainxremediating-s3-bucket-misconfiguration0 comments
  49. Deploy SailPoint IdentityNow or IdentityIQ for identity governance and administration. Covers identity lifecycle management, access request workflows, certification campaigns, role mining, SOD policy

    by Yash @ Explainximplementing-identity-governance-with-sailpoint0 comments
  50. Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

    by Yash @ Explainxdetecting-aws-guardduty-findings-automation0 comments