Agent Skills by YukiIto1999
Showing 169 vetted skills indexed across 1 GitHub repositories.
analyzing-cobaltstrike-malleable-c2-profiles
Extract Cobalt Strike Malleable C2 profile configurations and indicators.
analyzing-uefi-bootkit-persistence
Analyze UEFI bootkit persistence via CHIPSEC SPI dumps and ESP inspection.
analyzing-dns-logs-for-exfiltration
Detect DNS exfiltration and tunneling patterns using entropy and subdomain-length analysis.
extracting-credentials-from-memory-dump
Extract credentials from memory dumps using Volatility 3 and pypykatz.
analyzing-linux-system-artifacts
Analyze Linux system artifacts to reveal evidence of compromise.
hunting-for-dns-tunneling-with-zeek
Detect DNS tunneling by analyzing Zeek dns.log for high-entropy queries.
performing-jwt-none-algorithm-attack
Test JWT endpoints for signature verification gaps using the none algorithm.
client-side
...
securing-api-gateway-with-aws-waf
Configure AWS WAF Web ACLs to protect API Gateway endpoints from web attacks.
analyzing-api-gateway-access-logs
Analyze API gateway access logs to surface security threats.
exploiting-kerberoasting-with-impacket
Extracts Kerberos TGS ticket-hashes from Active Directory service accounts via Impacket's GetUserSPNs.py for offline cracking with Hashcat or John the Ripper.
performing-kerberoasting-attack
Enumerate Kerberoastable SPN accounts and collect TGS ticket hashes for offline cracking.
analyzing-azure-activity-logs-for-threats
Query Azure Monitor activity and sign-in logs to surface suspicious operations.
analyzing-packed-malware-with-upx-unpacker
Identify UPX-packed malware and restore original executables for static analysis.
performing-endpoint-forensics-investigation
Identify and document endpoint compromises through Windows digital forensics investigations.
network-analyzer
Analyze network traffic from pcaps or live captures to identify security threats.
analyzing-windows-lnk-files-for-artifacts
Extract forensic artifacts from Windows LNK shortcut files.
android-logic-mapper
Map Android app logic from JADX output into architecture and data-flow diagrams.
extracting-memory-artifacts-with-rekall
Analyze memory dumps with Rekall to identify indicators of compromise.
analyzing-certificate-transparency-for-phishing
Analyze certificate transparency data to detect phishing domains and lookalike certificates.
performing-cloud-forensics-with-aws-cloudtrail
Reconstruct attacker activity from AWS CloudTrail logs to identify compromised credentials.
extracting-iocs-from-malware-samples
Extract IOCs from malware samples and export STIX 2.1 and CSV artifacts.
performing-kubernetes-cis-benchmark-with-kube-bench
Run kube-bench checks to identify Kubernetes CIS Benchmark compliance issues.
dfir
Analyzes Windows event logs, PCAPs, and filesystem artifacts to detect security incidents.