47+AI
ZH

Mukul975 Anthropic Cybersecurity Skills

合集
@mukul9753.3万+开源协议: Apache-2.0

为国防承包商环境准备 CMMC 二级认证:界定 CUI 与 FCI 范围,在 14 个控制族中落实 NIST SP 800-171 Rev 2 的 110 项安…

GitHub

orchestrating-llm-attacks-with-pyrit

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用 Microsoft PyRIT 的 RedTeamingOrchestrator、CrescendoOrchestrator(渐进式升级)以及 TreeO…
 */

parsing-artifacts-with-eric-zimmerman-tools

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 Eric Zimmerman 的 EZ Tools 将 Windows 取证工件——$MFT/$J(MFTECmd)、预取(Prefetch,PECmd)…
 */

performing-access-recertification-with-saviynt

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 在 Saviynt Enterprise Identity Cloud 中配置并执行访问权限再认证活动,以验证用户授权、撤销过度访问,并保持对 SOX、SOC …
 */

performing-access-review-and-certification

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 设计与执行访问审查与认证活动——范围界定、审查人选择、基于风险的优先级划分、微型认证以及整改跟踪——以验证用户访问权限与岗位职责相符,满足 SOX、HIPAA …
 */

performing-active-directory-bloodhound-analysis

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用 BloodHound 和 SharpHound(或 AzureHound)枚举 Active Directory 关系并绘制从已被攻陷的用户到 Domai…
 */

performing-active-directory-compromise-investigation

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 通过分析身份认证日志、复制元数据、组策略更改以及 Kerberos 票据异常来调查
 */

performing-active-directory-forest-trust-attack

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 Impacket 对 Active Directory 林信任关系进行枚举与审计,用于 SID 过滤分析、信任密钥提取、跨林 SID 历史滥用检测以及跨域…
 */

performing-active-directory-penetration-test

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 BloodHound、Impacket、Certipy、Rubeus 和 NetExec 开展有针对性的 Active Directory
 */

performing-active-directory-vulnerability-assessment

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 PingCastle、BloodHound 和 Purple Knight 评估 Active Directory 的安全态势,以识别错误配置、权限提升路…
 */

performing-adversary-in-the-middle-phishing-detection

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 检测并响应使用 EvilProxy、Evilginx 和 Tycoon 2FA 等反向代理套件的中间人(AiTM)钓鱼攻击,这些攻击能够绕过 MFA 并窃取会话…
 */

performing-agentless-vulnerability-scanning

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用网络协议、云快照分析和基于 API 的发现来配置和执行无代理漏洞扫描,
 */

performing-ai-driven-osint-correlation

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用基于 AI/LLM 的推理结合 Sherlock、theHarvester 和 SpiderFoot,将 OSINT
 */

performing-alert-triage-with-elastic-siem

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 在 Elastic Security SIEM 中执行系统化的告警分诊——使用 Kibana、ES|QL 查询
 */

performing-android-app-static-analysis-with-mobsf

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用 Mobile Security Framework(MobSF)对 Android 应用执行自动化静态分析,以识别硬编码密钥、不安全的权限、存在漏洞的组件…
 */

performing-api-fuzzing-with-restler

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用 Microsoft RESTler 执行有状态的 REST API 模糊测试:将 OpenAPI/Swagger
 */

performing-api-inventory-and-discovery

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 执行 API 清单与发现,识别组织环境中所有的 API 端点,包括已记录的、未记录的、影子、僵尸以及已弃用的 API。测试人员使用被动流量分析、主动扫描、DNS…
 */

performing-api-rate-limiting-bypass

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 Python (requests/aiohttp) 和 Burp Suite Turbo Intruder 测试 API 速率限制的绕过漏洞,通过操纵请求…
 */

performing-api-security-testing-with-postman

@mukul975

流程自动化开源协议: Apache-2.0
/**
 * 使用 Postman 构建结构化的 API 安全测试集合,覆盖 OWASP API 安全 Top 10——认证绕过、授权缺陷、注入和数据泄露——具备多角色环境、…
 */

performing-arp-spoofing-attack-simulation

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 在获得授权的实验室或渗透测试环境中,使用 arpspoof、Ettercap 和 Scapy 模拟 ARP 欺骗/缓存投毒攻击,以演示中间人攻击风险,并验证 D…
 */

performing-asset-criticality-scoring-for-vulns

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 构建多因素资产关键性评分模型——整合数据敏感性、业务功能依赖性、监管范围、网络暴露程度以及可恢复性——以生成1-5级关键性层级,用于对漏洞优先级和修复SLA进行…
 */

performing-authenticated-scan-with-openvas

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 OpenVAS/Greenbone Vulnerability Management (GVM) 配置并执行基于凭证认证的漏洞扫描,
 */

performing-authenticated-vulnerability-scan

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 使用 Nessus、Qualys、OpenVAS 或 Rapid7 InsightVM 等扫描器,通过 SSH、SMB、WinRM 或 SNMPv3
 */

performing-automated-malware-analysis-with-cape

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 部署并运维 CAPEv2 恶意软件沙箱(Cuckoo 的衍生版本),在受监控的 Windows 客户机虚拟机中运行样本,
 */

performing-aws-account-enumeration-with-scout-suite

@mukul975

编程协作开源协议: Apache-2.0
/**
 * 运行无代理的开源 ScoutSuite 工具(通过 pip install 和 `scout` CLI)针对 AWS 账户进行枚举,跨服务识别资源配置、发现错误…
 */