Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
日本語の概要は準備中です。原文の説明を表示しています。
Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Shadow IT refers to unauthorized SaaS applications and cloud services used without IT approval. This skill analyzes proxy logs, DNS query logs, and firewall/netflow data to identify unauthorized cloud service usage, classify discovered domains against known SaaS categories, measure data transfer volumes, and flag high-risk services based on security posture and compliance requirements.
pandas, tldextractまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
日本語の概要は準備中です。原文の説明を表示しています。
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths
日本語の概要は準備中です。原文の説明を表示しています。
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
日本語の概要は準備中です。原文の説明を表示しています。
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
日本語の概要は準備中です。原文の説明を表示しています。
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
日本語の概要は準備中です。原文の説明を表示しています。