S

securityskills

GitHub 资料 · @securityskills

Run a STRIDE-based threat modeling workshop — diagram the system, enumerate threats per element, rank them, and drive mitigations into the backlog. Use during design reviews and new feature planning.
securityskills/stride-threat-modeling
Find and exploit Server-Side Request Forgery across URL-fetching features, including cloud metadata bypasses and blind SSRF techniques. Use during web assessments and bug bounty hunting.
securityskills/ssrf-hunting
Prepare an organization for a SOC 2 Type I or II audit — trust services criteria mapping, evidence collection, control implementation, and remediation planning. Use when starting a SOC 2 journey or preparing for an audit window.
securityskills/soc2-readiness
Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.
securityskills/secure-code-review
Execute an authorized penetration test end-to-end, from scoping and rules of engagement through reconnaissance, exploitation, post-exploitation, and reporting. Use when planning or running an offensive security engagement.
securityskills/pentest-engagement-methodology
Scope a PCI DSS environment correctly — cardholder data flows, segmentation validation, and requirements mapping for compliance. Use when preparing for PCI DSS v4.0 assessments.
securityskills/pci-dss-scoping
Systematically review a web application against the OWASP Top 10 vulnerability classes with concrete test cases per category. Use for web app assessments and security gate reviews.
securityskills/owasp-top10-analysis
Review network segmentation designs and verify enforcement — VLANs, firewalls, cloud security groups, and zero-trust boundaries. Use when assessing internal network architecture.
securityskills/network-segmentation-review
Safely triage unknown malware samples — static indicators, sandbox execution, behavior extraction, and reporting. Use when analyzing suspicious files during investigations.
securityskills/malware-triage
Audit Kubernetes clusters for RBAC excesses, pod security gaps, network policy holes, and supply-chain risks. Use when reviewing cluster configuration or hardening deployments.
securityskills/kubernetes-security-audit
Audit JSON Web Token implementations for algorithm confusion, weak secrets, missing validation, and token lifecycle flaws. Use when a codebase or API uses JWTs for auth.
securityskills/jwt-security-review
Perform digital forensics during incident response — evidence preservation, volatile data collection, artifact analysis, and timeline construction. Use when investigating a suspected compromise.
securityskills/incident-response-forensics
Build a GDPR-compliant data inventory — record of processing activities, lawful basis mapping, data subject rights readiness, and breach response procedures. Use for GDPR audits and privacy programs.
securityskills/gdpr-data-mapping
Harden Dockerfiles and container images — multi-stage builds, non-root users, minimal base images, and vulnerability gates. Use when building production containers or reviewing Dockerfiles.
securityskills/container-image-hardening
Write bug bounty reports that get triaged quickly and rated accurately — clear impact statements, minimal reproduction steps, and professional tone. Use before submitting any vulnerability report.
securityskills/bug-bounty-report-writing
Build an automated, continuously-running reconnaissance pipeline for bug bounty programs — subdomain enumeration, service fingerprinting, and change detection. Use when starting or scaling bug bounty recon.
securityskills/bug-bounty-recon-pipeline
Audit AWS environments for IAM privilege escalation, exposed resources, logging gaps, and misconfigurations across accounts. Use for cloud security assessments and hardening reviews.
securityskills/aws-security-review
Map an organization's external attack surface — domains, subdomains, exposed services, leaked credentials, and brand abuse. Use at the start of assessments or for continuous monitoring.
securityskills/attack-surface-recon
Turn changes authored by AI coding agents into evidence an auditor accepts — provenance, authorization, and mapping to change-management controls. Use when agents contribute to code that falls under SOC 2, ISO 27001, PCI DSS or similar.
securityskills/ai-change-evidence
Review a development pipeline where AI coding agents write, commit and deploy — permission boundaries, approval gates on irreversible actions, credential scope, and what must never be delegated. Use when agents have write access to a repository or an environment.
securityskills/agentic-sdlc-controls
Enumerate and exploit common Active Directory misconfigurations such as Kerberoasting, AS-REP roasting, delegation abuse, and ACL attacks. Use during authorized internal network assessments.
securityskills/active-directory-attack-paths