16 skills
analyzing-api-gateway-access-logs
Passed all 3 security checks'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
·0↓18
acquiring-disk-image-with-dd-and-dcfldd
Passed all 3 security checksCreate forensically sound bit-for-bit disk images using dd and dcfldd
·0↓18
testing-api-for-broken-object-level-authorization
Passed all 3 security checks'Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated
·0↓16
testing-jwt-token-security
Passed all 3 security checksAssessing JSON Web Token implementations for cryptographic weaknesses,
·0↓14
testing-api-for-mass-assignment-vulnerability
Passed all 3 security checks'Tests APIs for mass assignment (auto-binding) vulnerabilities where
·0↓13
analyzing-cyber-kill-chain
Passed all 3 security checks'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
·0↓13
testing-api-authentication-weaknesses
Passed all 3 security checks'Tests API authentication mechanisms for weaknesses including broken
·0↓13
analyzing-ios-app-security-with-objection
Passed all 3 security checks>-
·0↓13
testing-api-security-with-owasp-top-10
Passed all 3 security checksSystematically assessing REST and GraphQL API endpoints against the OWASP
·0↓13
analyzing-cloud-storage-access-patterns
Passed all 3 security checksDetect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage
·0↓13
analyzing-docker-container-forensics
Passed all 3 security checksInvestigate compromised Docker containers by analyzing images, layers,
·0↓12
analyzing-dns-logs-for-exfiltration
Passed all 3 security checks'Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
·0↓12
analyzing-android-malware-with-apktool
Passed all 3 security checksPerform static analysis of Android APK malware samples using apktool
·0↓12
analyzing-email-headers-for-phishing-investigation
Passed all 3 security checksParse and analyze email headers to trace the origin of phishing emails,
·0↓11
analyzing-command-and-control-communication
Passed all 3 security checks'Analyzes malware command-and-control (C2) communication protocols to
·0↓11
analyzing-certificate-transparency-for-phishing
Passed all 3 security checksMonitor Certificate Transparency logs using crt.sh and Certstream to
·0↓11