Sanjeev Jaiswal
Community@jassics · Bangalore, India
A Seasoned security professional with 15+ years of experience. #ApplicationSecurity #CloudSecurity #Python #DevSecOps #ContainerSecurity #Pentest
Agent Skills by Sanjeev Jaiswal
Showing 96 vetted skills indexed across 1 GitHub repositories.
secure-pipeline
Review and secure CI/CD pipelines with automated security scanning gates.
alert-triage
Automate SIEM/EDR alert triage with validation, enrichment, and verdict decisions.
security-investigation
Correlate EDR, auth, network, and app logs into a security investigation timeline.
k8s-rbac-review
Audit Kubernetes RBAC configurations for excessive permissions and cluster-admin escalation paths.
k8s-workload-hardening
Review and apply Pod Security Standards to harden Kubernetes workloads.
k8s-cluster-review
Audit Kubernetes clusters against the CIS Kubernetes Benchmark and 4Cs model.
threat-hunting
Formulate and test hypotheses on system and network logs to detect adversary activity.
detection-coverage-review
Analyze detection coverage against the MITRE ATT&CK matrix to identify gaps.
detection-rule-development
Develop and review detection rules mapped to MITRE ATT&CK with test cases.
forensic-triage
Automate forensic triage by collecting disk, memory, and log evidence to build an incident timeline.
incident-response
Orchestrate security incident response using NIST SP 800-61 and SANS PICERL.
ioc-development
Extract and validate atomic, computed, and behavioral indicators from incident data.
adversary-emulation
Simulate cyber attacks using ATT&CK framework-based scenarios for red team exercises.
recon
Coordinates passive and active enumeration of authorized attack surfaces for penetration testing.
artifact-provenance-verification
Verify build artifact provenance and integrity using SLSA guidelines.
dependency-supply-chain-review
Review third-party dependencies for typosquatting, dependency confusion, and malicious scripts.
pipeline-integrity-review
Reviews CI/CD pipelines for supply-chain tampering risks and prioritizes fixes.
risk-assessment
Automate ISO 27005 / NIST SP 800-30 risk assessments with a structured risk register.
compliance-assessment
Map controls to evidence and prioritize remediation actions for compliance frameworks.
policy-management
Develop and review security governance documents aligned with frameworks and risk assessments.
framework-mapping
Map security findings across compliance frameworks like CWE and NIST CSF.
attack-lookup
Map observed behaviors to MITRE ATT&CK technique IDs and references.
owasp-reference
Map security findings to OWASP category IDs and names.
threat-actor-profiling
Profile threat actors and campaigns with TTPs mapped to MITRE ATT&CK.