Source

trilwu/secskills

92 skills · 2.8K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
abusing-adcs Enumerate and abuse Active Directory Certificate Services with Certipy and Certify — the ESC1 through ESC16 escalatio…
trilwu/secskills
20
2
analyzing-linux-persistence Systematically identify and analyze persistence mechanisms on Linux systems during DFIR investigations -- sweep syste…
trilwu/secskills
20
3
analyzing-memory-images Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credent…
trilwu/secskills
20
4
attacking-bluetooth-nfc Attack Bluetooth Classic, BLE, and NFC targets -- device enumeration, GATT characteristic exploitation, BLE MITM and …
trilwu/secskills
20
5
attacking-eks-gke-aks Assess managed Kubernetes clusters on EKS, GKE, and AKS by exploiting the seams between cloud IAM and Kubernetes RBAC…
trilwu/secskills
20
6
attacking-entra-id Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, …
trilwu/secskills
20
7
attacking-kerberos-delegation Identify and abuse Active Directory Kerberos delegation — unconstrained delegation with printer-bug coercion, constra…
trilwu/secskills
20
8
attacking-saml Attack SAML single sign-on by decoding and tampering with signed XML assertions — XML signature wrapping (XSW1-XSW8),…
trilwu/secskills
20
9
attacking-serverless Attack serverless compute — AWS Lambda, Azure Functions, GCP Cloud Functions, and edge runtimes like Cloudflare Worke…
trilwu/secskills
20
10
auditing-mcp-servers Audit Model Context Protocol servers for injection surfaces, excessive tool scope, authorization gaps, resource over-…
trilwu/secskills
20
11
auditing-supply-chain Audit software supply chain risk — dependency and transitive package review, typosquatting and dependency confusion, …
trilwu/secskills
20
12
authoring-security-skills Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that trigge…
trilwu/secskills
20
13
bypassing-root-jailbreak-detection Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules,…
trilwu/secskills
20
14
engineering-detections Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with e…
trilwu/secskills
20
15
escaping-hardened-containers Escape containers that drop capabilities, enforce seccomp profiles, and run behind AppArmor or SELinux — enumerating …
trilwu/secskills
20
16
hardening-cloud-posture Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over check…
trilwu/secskills
20
17
hunting-threats Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outl…
trilwu/secskills
20
18
managing-vulnerabilities Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with expl…
trilwu/secskills
20
19
reversing-xamarin-maui Reverse engineer Xamarin and .NET MAUI mobile apps by extracting assemblies.blob and XALZ-compressed DLLs with pyxams…
trilwu/secskills
20
20
reviewing-cryptography Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key mana…
trilwu/secskills
20
21
securing-ai-systems Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memor…
trilwu/secskills
20
22
testing-ics-ot-protocols Test Industrial Control Systems and Operational Technology protocols — Modbus, DNP3, OPC UA, BACnet, EtherNet/IP, S7c…
trilwu/secskills
20
23
testing-mobile-ipc Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receive…
trilwu/secskills
20
24
triaging-security-alerts Work a security alert queue to a defensible disposition — separating true positives from false positives and benign t…
trilwu/secskills
20
25
analyzing-phishing-emails Triage and forensically analyze reported phishing safely — extract the raw message, read the Received chain, verify S…
trilwu/secskills
19
26
defending-kubernetes Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalatio…
trilwu/secskills
19
27
devirtualizing-vm-protected-code Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code V…
trilwu/secskills
19
28
investigating-aws-incidents Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs…
trilwu/secskills
19
29
investigating-azure-incidents Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker a…
trilwu/secskills
19
30
investigating-gcp-incidents Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, recon…
trilwu/secskills
19
31
investigating-m365-entra Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate si…
trilwu/secskills
19
32
investigating-windows-endpoints Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of executi…
trilwu/secskills
19
33
writing-sigma-rules Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-posi…
trilwu/secskills
19
34
writing-yara-rules Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditio…
trilwu/secskills
19
35
diffing-binary-patches Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora…
trilwu/secskills
17
36
vetting-agent-extensions Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is…
trilwu/secskills
17
37
analyzing-macos-binaries Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering…
trilwu/secskills
16
38
exploiting-memory-corruption Develop working exploits from memory-corruption bugs in native binaries — turning a stack/heap overflow, use-after-fr…
trilwu/secskills
15
39
reversing-browser-extensions Reverse engineer and security-review Chrome/Firefox browser extensions — unpacking the CRX/XPI, reading the manifest …
trilwu/secskills
15
40
attacking-hardware-interfaces Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C…
trilwu/secskills
14
41
reversing-network-protocols Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recover…
trilwu/secskills
14
42
testing-thick-clients Security-test desktop thick-client applications (.NET/WPF, Java, Electron, native Win32) against their local and netw…
trilwu/secskills
14
Page 2 · 92 total Previous