Browse Skills
Building Attack Pattern Library From Cti Reports
v1.0.0Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.
Building Cloud Security Posture Management
v1.0.0>
Building Detection Rule With Splunk Spl
v1.0.0Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
Building Devsecops Pipeline With Gitlab Ci
v1.0.0Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
Building Incident Response Dashboard
v1.0.0>
Building Incident Response Playbook
v1.0.0>
Building Incident Timeline With Timesketch
v1.0.0Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
Building Malware Incident Communication Template
v1.0.0Build structured communication templates for malware incidents including stakeholder notifications, executive briefings, technical advisories, and regulatory disclosures with severity-based escalation procedures.
Building Patch Tuesday Response Process
v1.0.0Establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs.
Building Red Team C2 Infrastructure With Havoc
v1.0.0Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
Building Soc Escalation Matrix
v1.0.0Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
Building Threat Feed Aggregation With Misp
v1.0.0Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.