Cybersecurity Skills Bundle

Security auditing, vulnerability assessment, compliance frameworks, secure coding practices, and incident response skills.

Included Skills (80)

  1. Senior Secops — Senior SecOps engineers conduct SAST and DAST scans, remediate CVEs, and audit dependencies to secure applications and automate compliance for SOC2, PCI‑DSS, HIPAA, and GDPR. They harden infrastructure with secure coding practices and streamline CI/CD pipelines, ensuring robust protection throughout development cycles. Their expertise enables development teams to perform thorough security reviews, prepare for penetration tests, and strengthen incident response and pipeline hardening.
  2. ISO 27001 Compliance Manager — This skill assists security professionals in implementing an ISO/IEC 27001:2022 ISMS by streamlining gap analysis, risk assessment, and mandatory documentation for certification readiness.
  3. Security Incident Triage — Automates the classification and prioritization of security alerts for SOC analysts using structured incident response playbooks and integrated SIEM data sources.
  4. ModSecurity Logging Configuration — Configures ModSecurity WAF and OWASP Core Rule Sets to enable robust audit logging and threat detection for web application security professionals.
  5. Cloud SIEM Architect — This skill assists security engineers in deploying Microsoft Sentinel to centralize multi-cloud threat detection, automated incident response, and large-scale security telemetry analysis.
  6. Vulnerability Exception Manager — This tool automates vulnerability exception workflows, risk acceptance documentation, and expiration tracking to help security teams maintain compliance with major industry frameworks.
  7. Cloud Incident Responder — This skill assists security teams in rapidly containing cloud-native threats by isolating compromised resources and gathering forensic evidence across AWS, Azure, and GCP environments.
  8. SOC 2 Auditor — Automates SOC 2 Type II audit preparation, evidence collection, and continuous compliance monitoring to help security teams streamline their certification and remediation processes.
  9. Security Risk Auditor — This tool performs rigorous security threat modeling and compliance assessments to help engineers identify vulnerabilities before deploying sensitive data or production changes.
  10. TLS 1.3 Configuration — This skill helps security engineers configure and validate TLS 1.3 protocols on servers to ensure robust encryption and compliance with modern security standards.
  11. Cloud Compliance Orchestrator — This tool automates AWS Security Hub deployment and compliance monitoring to help security engineers centralize posture management across multi-account AWS organizational environments.
  12. Cloud WAF Orchestrator — Deploys and optimizes cloud-native Web Application Firewall rules to protect web applications against injection attacks, bot traffic, and unauthorized access for security engineers.
  13. Elastic SIEM Triage — This skill assists SOC analysts in systematically classifying, prioritizing, and investigating security alerts within the Elastic SIEM environment to streamline incident response workflows.
  14. Vulnerability SLA Tracker — This tool implements vulnerability aging dashboards and SLA tracking systems to help security teams monitor remediation timelines and ensure compliance with severity-based deadlines.
  15. ISMS Audit Assistant — This skill helps security professionals conduct ISO 27001 ISMS audits, assess controls, and prepare for certification.
  16. Splunk Threat Enrichment — This skill automates IOC enrichment pipelines in Splunk Enterprise Security to help SOC analysts correlate threat intelligence data and accelerate incident triage.
  17. Security Incident Responder — This skill classifies, triages, and manages declared security incidents, determining severity, escalation paths, and initiating forensic evidence collection for security teams.
  18. Datadog Security Monitor — Configures Datadog Cloud SIEM and workload protection to help security engineers detect threats, enforce compliance, and automate incident response across cloud infrastructure.
  19. CISO Strategic Advisor — Provides growth-stage companies with risk-based security strategies, compliance roadmaps, and financial quantification to align cybersecurity investments with critical business objectives.
  20. Phishing Incident Responder — This skill assists cybersecurity analysts by automating the analysis, containment, and remediation of phishing emails and compromised accounts within an organization.
  21. Incident Ticketing Integrator — Automates incident lifecycle management by connecting SIEM alerts to ticketing platforms, helping SOC teams streamline tracking, escalation, and compliance documentation.
  22. SaaS Zero Trust — This skill helps security engineers secure SaaS environments by deploying CASB, configuring conditional access policies, and governing OAuth permissions for enterprise applications.
  23. Malware Hash Enricher — This tool enriches malware file hashes via VirusTotal API to provide security analysts with critical detection verdicts and contextual threat intelligence.
  24. Malware Incident Responder — This skill assists cybersecurity analysts in managing malware infections by guiding them through structured identification, containment, eradication, and recovery procedures aligned with MITRE ATT&CK.
  25. Privilege Escalation Detector — This skill identifies privilege escalation attempts on Windows and Linux systems to assist security analysts in threat hunting, incident response, and detection validation.
  26. Windows Persistence Hunter — This tool systematically identifies adversary persistence mechanisms across Windows endpoints to assist security analysts during incident response and proactive threat hunting operations.
  27. Insider Threat Detector — This tool identifies malicious or negligent insider activity by analyzing behavioral indicators to assist security analysts in proactive threat hunting and incident investigations.
  28. Phishing Response Automator — This skill automates phishing incident response by integrating with Splunk SOAR to streamline container creation, artifact management, and playbook execution for security analysts.
  29. Scheduled Task Hunter — This tool facilitates proactive threat hunting for Windows Scheduled Task persistence by guiding security analysts through targeted SIEM and EDR query execution.
  30. Threat Intelligence Reporter — This tool generates structured cyber threat intelligence reports for executives and security teams to facilitate informed decision-making and incident response.
  31. SQL Injection Analyzer — This tool parses WAF logs to identify SQL injection patterns and generate incident reports, assisting security analysts in detecting and tracking malicious attack campaigns.
  32. SSL TLS Security Auditor — This tool utilizes the sslyze library to evaluate server TLS configurations, identifying protocol weaknesses, cipher vulnerabilities, and certificate issues for cybersecurity professionals.
  33. SIEM Log Onboarding — This skill assists security analysts in systematically integrating, normalizing, and validating new log sources into SIEM platforms to enhance threat detection capabilities.
  34. YARA Threat Hunter — This tool enables security analysts to proactively identify malware and indicators of compromise by scanning files and memory dumps using custom YARA rules.
  35. Malware IOC Extractor — Automates the extraction and defanging of malware indicators to help security analysts generate threat intelligence and build effective detection content for defense.
  36. Ransomware Incident Responder — This tool guides cybersecurity professionals through structured ransomware containment, forensic analysis, and recovery processes to mitigate impact and ensure regulatory compliance.
  37. Threat Indicator Manager — This tool systematically collects, categorizes, and distributes security indicators to help incident responders improve threat detection, blocking, and intelligence sharing capabilities.
  38. Phishing Incident Investigator — This tool assists security analysts by automating the investigation, analysis, and containment of reported phishing emails using integrated SOC platforms and sandbox tools.
  39. NERC CIP Compliance — This tool assists power grid entities in implementing and maintaining NERC CIP cybersecurity standards to ensure regulatory compliance and audit readiness for BES systems.
  40. Zero Trust Posture Integrator — This tool helps security engineers enforce endpoint compliance by integrating device health signals into conditional access policies for robust zero trust architecture.
  41. Linux Audit Investigator — This tool assists security professionals by analyzing Linux audit logs to detect unauthorized access, privilege escalation, and suspicious system activity for incident response.
  42. Vulnerability SLA Monitor — This tool automates vulnerability remediation tracking, breach detection, and escalation notifications to help security teams maintain compliance with established severity-based SLA timelines.
  43. Malware Analysis Assistant — Analyzes malware binaries using Ghidra to help security researchers decode internal logic, cryptographic routines, and command-and-control protocols for effective threat detection.
  44. Threat Modeling Assistant — This tool helps security professionals and developers build data flow diagrams and generate comprehensive threat model reports using industry-standard methodologies like STRIDE.
  45. Zero Trust Identity — This skill assists security architects in implementing continuous, risk-adaptive identity verification and phishing-resistant MFA aligned with NIST and CISA zero trust standards.
  46. Network Anomaly Hunter — This skill performs hypothesis-driven threat hunting by analyzing SIEM and EDR telemetry to identify suspicious command-and-control traffic for cybersecurity professionals and incident responders.
  47. Access Certification Manager — This tool automates access review campaigns and remediation tracking to ensure user permissions align with compliance standards for security and identity governance.
  48. Threat Hunt Framework — This skill assists security analysts in transforming threat intelligence into actionable, testable hypotheses for proactive hunting and validation across EDR and SIEM platforms.
  49. SIEM Detection Optimizer — This skill helps security operations teams reduce alert fatigue by systematically tuning SIEM detection rules and optimizing thresholds to improve incident response precision.
  50. Kerberos Attack Detector — This skill identifies Kerberos Pass-the-Ticket attacks by analyzing Windows event logs to assist security analysts in threat hunting and incident response activities.
  51. Endpoint Vulnerability Remediation — This skill assists security professionals in prioritizing CVEs and executing automated patch management to maintain endpoint compliance and mitigate critical security risks.
  52. JWT Vulnerability Tester — This tool helps security professionals identify and validate JWT algorithm confusion, signature forgery, and authentication bypass vulnerabilities within API authentication implementations.
  53. TLS Inspection Configurator — This skill assists network security engineers in configuring SSL/TLS decryption on firewalls and proxies to eliminate blind spots and detect malicious encrypted traffic.
  54. Velociraptor IR Deployment — This skill assists incident responders in deploying and configuring Velociraptor to perform scalable forensic artifact collection and threat hunting across enterprise endpoints.
  55. SOC Tabletop Facilitator — This tool guides security teams through simulated incident scenarios to validate response playbooks, improve decision-making, and ensure compliance with industry standards.
  56. Advanced Network Reconnaissance — This tool performs sophisticated network scanning and vulnerability enumeration to assist security professionals in conducting authorized penetration tests and enterprise asset discovery.
  57. MISP Threat Automation — This skill automates MISP instance management, threat feed ingestion, and detection rule generation to help security teams streamline intelligence-driven threat detection workflows.
  58. Malware Incident Communicator — This tool generates structured communication templates for malware incidents, assisting cybersecurity teams in streamlining stakeholder notifications, executive briefings, and essential regulatory disclosures.
  59. Hardware Security Authentication — This skill assists developers in building FIDO2/WebAuthn relying party servers to implement phishing-resistant MFA and passkey authentication for secure user identity management.
  60. Shodan IP Analyst — This tool leverages the Shodan API to provide security analysts with comprehensive IP reputation data, service identification, and vulnerability insights for incident triage.
  61. Timesketch Timeline Analyzer — This tool enables incident responders to collaboratively ingest, normalize, and analyze multi-source forensic data to reconstruct attack chains and document investigation findings effectively.
  62. LLM Security Guardrails — This skill implements robust input and output validation guardrails for LLM applications to ensure safety, compliance, and protection against malicious prompt injections.
  63. Incident Response Dashboard — Creates real-time incident response dashboards in SIEM platforms to provide SOC analysts and leadership with critical situational awareness during active security incidents.
  64. AI Pentesting Agent — Automate security testing with PentAGI, an AI-powered penetration testing agent that helps users deploy autonomous vulnerability scanners and self-hosted security platforms.
  65. Vulnerability Prioritization Assistant — This tool helps security professionals calculate and interpret CVSS scores to effectively prioritize vulnerability remediation efforts based on industry-standard risk assessment frameworks.
  66. Proofpoint Sandbox Implementation — This skill guides security professionals through configuring Proofpoint Targeted Attack Protection to detect zero-day malware and evasive phishing threats within email environments.
  67. SDP Deployment Assistant — Deploys CSA-compliant Software-Defined Perimeters to help security engineers implement zero-trust network access through mutual TLS and Single Packet Authorization for hardened infrastructure.
  68. Wireless Penetration Tester — This tool helps cybersecurity professionals assess WiFi infrastructure security by identifying vulnerabilities in encryption, authentication protocols, and network segmentation configurations.
  69. PowerShell Threat Hunter — This tool enables security analysts to identify malicious PowerShell activity by analyzing EDR and SIEM telemetry for common execution-based attack techniques.
  70. Proofpoint Gateway Deployment — This skill assists security engineers in deploying and configuring Proofpoint Email Protection to effectively block phishing, malware, and spam threats.
  71. Phishing Triage Automation — This workflow automates the triage, classification, and remediation of user-reported phishing emails to assist security teams in streamlining incident response processes.
  72. Cryptographic Audit Assistant — This tool systematically reviews application code and configurations to identify cryptographic vulnerabilities, helping developers and security engineers ensure robust data protection standards.
  73. MISP Threat Analyst — This tool queries MISP instances to generate comprehensive threat intelligence reports, helping cybersecurity professionals identify trends, threat actors, and malware families effectively.
  74. mTLS Security Automator — Automates mutual TLS configuration and certificate management for microservices to help security engineers establish robust zero-trust authentication across distributed service architectures.
  75. Entra ID Policy Architect — Configures Microsoft Entra ID Conditional Access policies to enforce zero trust security, device compliance, and risk-based authentication for identity and access management professionals.
  76. Office365 Compromise Analyzer — This tool parses Microsoft Graph API audit logs to help security analysts detect email forwarding, unauthorized delegation, and suspicious OAuth application grants.
  77. LDAP Security Hardener — This tool secures LDAP and Active Directory environments against common vulnerabilities by enforcing robust signing, encryption, and access control configurations for administrators.
  78. Zero Trust Browser Isolation — Deploys remote browser isolation to harden web access against zero-day exploits and phishing for security engineers building robust Zero Trust architectures.
  79. JWT None Attack — This tool helps security professionals test authentication systems by crafting JWTs with the none algorithm to identify and validate signature verification vulnerabilities.
  80. Disk Forensics Investigator — This tool assists cybersecurity professionals in performing forensic imaging, file system analysis, and evidence recovery to support incident response and legal investigations.