balsm-health
Official@balsm-health
The first open-source unified healthcare ecosystem for the MENA region. Connecting hospitals, clinics, and labs. Technology in the service of healing.
Agent Skills by balsm-health
Showing 50 vetted skills indexed across 1 GitHub repositories.
exploiting-broken-function-level-authorization
Detect and test Broken Function Level Authorization vulnerabilities in APIs.
analyzing-linux-system-artifacts
Analyze Linux system artifacts for signs of compromise or unauthorized activity.
conducting-cloud-incident-response
Automate AWS, Azure, and GCP incident response workflows including containment and evidence collection.
domain-driven-design-planner
Assess DDD suitability and guide strategic modeling and implementation.
analyzing-indicators-of-compromise
Analyze and enrich indicators of compromise using VirusTotal, AbuseIPDB, and MISP.
extracting-iocs-from-malware-samples
Extract file hashes, network indicators, and host artifacts from malware samples.
exploiting-insecure-data-storage-in-mobile
Identify and exploit insecure data storage vulnerabilities in Android and iOS mobile applications.
detecting-s3-data-exfiltration-attempts
Detect AWS S3 data exfiltration attempts by analyzing CloudTrail logs.
detecting-supply-chain-attacks-in-ci-cd
Detect supply chain attack vectors in GitHub Actions CI/CD workflows.
hunting-for-unusual-network-connections
Analyze EDR, SIEM, and Sysmon logs for unusual network connections.
implementing-cloud-security-posture-management
Automate continuous security posture monitoring across AWS, Azure, and GCP.
exploiting-sql-injection-with-sqlmap
Automate SQL injection detection and data extraction with sqlmap.
exploiting-mass-assignment-in-rest-apis
Detect mass assignment vulnerabilities in REST APIs by injecting unexpected parameters.
analyzing-memory-dumps-with-volatility
Automate RAM memory dump analysis with Volatility 3 for malware detection.
hunting-for-webshell-activity
Detect webshell deployments by analyzing process creation, network, and web access logs.
testing-oauth2-implementation-flaws
Assess OAuth 2.0 and OpenID Connect implementations for security flaws.
exploiting-http-request-smuggling
Detect and exploit HTTP request smuggling via front-end and back-end parsing discrepancies.
exploiting-nosql-injection-vulnerabilities
Detect and exploit NoSQL injection vulnerabilities in MongoDB and CouchDB endpoints.
implementing-secrets-management-with-vault
Manage secrets lifecycle with HashiCorp Vault and hvac.
exploiting-sql-injection-vulnerabilities
Detect and exploit SQL injection vulnerabilities in web applications during penetration tests.
testing-for-sensitive-data-exposure
Scan applications for hardcoded secrets and insecure data transmission.
detecting-credential-dumping-techniques
Detect credential dumping techniques in Sysmon and Windows Security logs.
implementing-hashicorp-vault-dynamic-secrets
Automate generation, management, and rotation of dynamic secrets with HashiCorp Vault.
exploiting-deeplink-vulnerabilities
Test Android and iOS deep links for injection and redirect vulnerabilities.
Frequently Asked Questions About balsm-health
FAQPage SchemaWhat specific security tasks are enabled by these capabilities?▼
These capabilities enable comprehensive penetration testing, cloud infrastructure hardening, and incident response. Users can perform vulnerability scanning for injection flaws, audit cloud IAM configurations, analyze malware artifacts, and implement secrets management using HashiCorp Vault.
Which technical personas benefit from these security modules?▼
Security engineers, penetration testers, and cloud infrastructure architects are the primary users. These modules support professionals tasked with securing enterprise environments, auditing CI/CD pipelines, and responding to unauthorized system activity or data exfiltration attempts.
What are the prerequisites for deploying these security assessments?▼
Deployment requires authorized access to the target environment, such as cloud provider credentials, administrative access to endpoints, or permission to perform penetration testing on specific applications. Users must also have the relevant security software installed, such as Volatility 3, HashiCorp Vault, or Frida.