Back to authors
autohandai

autohandai

798 Skills published on GitHub.

configuring-suricata-for-network-monitoring

>

UncategorizedView skill →

configuring-tls-1-3-for-secure-communications

TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R

UncategorizedView skill →

configuring-windows-defender-advanced-settings

>

UncategorizedView skill →

configuring-windows-event-logging-for-detection

>

UncategorizedView skill →

configuring-zscaler-private-access-for-ztna

>

UncategorizedView skill →

containing-active-breach

>

UncategorizedView skill →

containing-active-security-breach

Rapidly contain an active security breach by isolating compromised systems, blocking attacker communications, and preserving evidence while minimizing business disruption.

UncategorizedView skill →

context7

|

UncategorizedView skill →

copilot-coding-agent

GitHub Copilot Coding Agent automation. Apply the ai-copilot label to an issue → GitHub Actions auto-assigns Copilot via GraphQL → Copilot creates a Draft PR. One-click issue-to-PR pipeline.

copilotcopilotviewgithub-actionsissue-to-prdraft-prgraphqlautomationai-agent
UncategorizedView skill →

copy-editing

When the user wants to edit, review, or improve existing marketing copy. Also use when the user mentions 'edit this copy,' 'review my copy,' 'copy feedback,' 'proofread,' 'polish this,' 'make this better,' 'copy sweep,' 'tighten this up,' 'this reads awkwardly,' 'clean up this text,' 'too wordy,' or 'sharpen the messaging.' Use this when the user already has copy and wants it improved rather than rewritten from scratch. For writing new copy, see copywriting.

UncategorizedView skill →

copywriting

When the user wants to write, rewrite, or improve marketing copy for any page — including homepage, landing pages, pricing pages, feature pages, about pages, or product pages. Also use when the user says "write copy for," "improve this copy," "rewrite this page," "marketing copy," "headline help," "CTA copy," "value proposition," "tagline," "subheadline," "hero section copy," "above the fold," "this copy is weak," "make this more compelling," or "help me describe my product." Use this whenever someone is working on website text that needs to persuade or convert. For email copy, see email-sequence. For popup copy, see popup-cro. For editing existing copy, see copy-editing.

UncategorizedView skill →

correlating-security-events-in-qradar

>

UncategorizedView skill →

correlating-threat-campaigns

>

UncategorizedView skill →

data-analysis

Analyze datasets to extract insights, identify patterns, and generate reports. Use when exploring data, creating visualizations, or performing statistical analysis. Handles CSV, JSON, SQL queries, and Python pandas operations.

dataanalysispandasstatisticsvisualizationcsvsql
UncategorizedView skill →

deobfuscating-javascript-malware

>

UncategorizedView skill →

deobfuscating-powershell-obfuscated-malware

Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.

UncategorizedView skill →

deploying-cloudflare-access-for-zero-trust

>

UncategorizedView skill →

deploying-edr-agent-with-crowdstrike

>

UncategorizedView skill →

deploying-osquery-for-endpoint-monitoring

>

UncategorizedView skill →

deploying-palo-alto-prisma-access-zero-trust

>

UncategorizedView skill →

deploying-ransomware-canary-files

>

UncategorizedView skill →

deploying-software-defined-perimeter

Deploying Software Defined Perimeter

UncategorizedView skill →

deploying-tailscale-for-zero-trust-vpn

Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.

UncategorizedView skill →

deployment-automation

Automate application deployment to cloud platforms and servers. Use when setting up CI/CD pipelines, deploying to Docker/Kubernetes, or configuring cloud infrastructure. Handles GitHub Actions, Docker, Kubernetes, AWS, Vercel, and deployment best practices.

deploymentCI/CDDockerKubernetesAWSGitHub-Actionsautomation
UncategorizedView skill →

detecting-anomalies-in-industrial-control-systems

>

UncategorizedView skill →

detecting-anomalous-authentication-patterns

>

UncategorizedView skill →

detecting-api-enumeration-attacks

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.

UncategorizedView skill →

detecting-arp-poisoning-in-network-traffic

Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.

UncategorizedView skill →

detecting-attacks-on-historian-servers

>

UncategorizedView skill →

detecting-attacks-on-scada-systems

>

UncategorizedView skill →

detecting-aws-cloudtrail-anomalies

Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.

UncategorizedView skill →

detecting-aws-credential-exposure-with-trufflehog

>

UncategorizedView skill →

detecting-aws-guardduty-findings-automation

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

UncategorizedView skill →

detecting-aws-iam-privilege-escalation

Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations

UncategorizedView skill →

detecting-azure-lateral-movement

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

UncategorizedView skill →

detecting-azure-service-principal-abuse

Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.

UncategorizedView skill →

detecting-azure-storage-account-misconfigurations

Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions using the azure-mgmt-storage Python SDK.

UncategorizedView skill →

detecting-beaconing-patterns-with-zeek

>

UncategorizedView skill →

detecting-broken-object-property-level-authorization

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

UncategorizedView skill →

detecting-business-email-compromise-with-ai

Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.

UncategorizedView skill →

detecting-business-email-compromise

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,

UncategorizedView skill →

detecting-cloud-cryptomining-activity

>

UncategorizedView skill →

detecting-cloud-threats-with-guardduty

>

UncategorizedView skill →

detecting-compromised-cloud-credentials

>

UncategorizedView skill →

detecting-container-drift-at-runtime

Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.

UncategorizedView skill →

detecting-container-escape-attempts

Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators

UncategorizedView skill →

detecting-container-escape-with-falco-rules

Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.

UncategorizedView skill →

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

UncategorizedView skill →

detecting-credential-dumping-with-edr

Detect OS credential dumping techniques including LSASS access, SAM extraction, and DCSync using EDR telemetry and Sysmon logs.

UncategorizedView skill →

detecting-cryptomining-in-cloud

>

UncategorizedView skill →

Page 5 of 16 · 798 results