askill
autohandai

autohandai

Publisher on askill

0 total stars
Skills90
Updated 3/18/2026
GitHub
conducting-post-incident-lessons-learned
conducting-post-incident-lessons-learned
autohandai3/18/2026

Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

0
AI 94
hunting-for-persistence-mechanisms-in-windows
hunting-for-persistence-mechanisms-in-windows
autohandai3/18/2026

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

0
AI 93
hunting-for-dns-tunneling-with-zeek
hunting-for-dns-tunneling-with-zeek
autohandai3/18/2026

Detect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert chan...

0
AI 92
analyzing-ios-app-security-with-objection
analyzing-ios-app-security-with-objection
autohandai3/18/2026

Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when as...

0
AI 92
analyzing-threat-intelligence-feeds
analyzing-threat-intelligence-feeds
autohandai3/18/2026

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evalua...

0
AI 91
detecting-qr-code-phishing-with-email-security
detecting-qr-code-phishing-with-email-security
autohandai3/18/2026

Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.

0
AI 90
markdown-url
markdown-url
autohandai3/9/2026

Route any website you need to visit through markdown.new by prefixing the URL. **WHEN TO USE:** - You would normally open a website link to read content (docs, blog posts, changelogs, GitHub issues,...

0
AI 90
detecting-wmi-persistence
detecting-wmi-persistence
autohandai3/18/2026

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

0
AI 89
performing-false-positive-reduction-in-siem
performing-false-positive-reduction-in-siem
autohandai3/18/2026

Perform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.

0
AI 88
azure-resource-lookup
azure-resource-lookup
autohandai3/18/2026

List, find, and show Azure resources. Answers "list my VMs", "show my storage accounts", "list websites", "find container apps", "what resources do I have", and similar queries for any Azure resource...

0
AI 88
performing-kubernetes-etcd-security-assessment
performing-kubernetes-etcd-security-assessment
autohandai3/18/2026

Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.

0
AI 88
detecting-dcsync-attack-in-active-directory
detecting-dcsync-attack-in-active-directory
autohandai3/18/2026

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via D...

0
AI 88
implementing-endpoint-dlp-controls
implementing-endpoint-dlp-controls
autohandai3/18/2026

Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating conte...

0
AI 88
hunting-for-shadow-copy-deletion
hunting-for-shadow-copy-deletion
autohandai3/18/2026

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.

0
AI 88
standup-meeting
standup-meeting
autohandai3/18/2026

Conduct effective daily standup meetings for agile teams. Use when facilitating standups, tracking blockers, or improving team synchronization. Handles standup format, time management, and blocker res...

0
AI 88
detecting-t1548-abuse-elevation-control-mechanism
detecting-t1548-abuse-elevation-control-mechanism
autohandai3/18/2026

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-c...

0
AI 88
securing-helm-chart-deployments
securing-helm-chart-deployments
autohandai3/18/2026

Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.

0
AI 88
web-design-guidelines
web-design-guidelines
autohandai3/9/2026

Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices". Fetches latest...

0
AI 88

Showing 18 of 90