ZooWork
ZooWork Market

发现 Skills

为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。

◇

cpp-testing

mturac

Use only when creating, updating, or modifying C++ tests, configuring GoogleTest/CTest, diagnosing failing or flaky tests, or adding coverage/sanitizers.

◇

everything-openai-codex

mturac

Development conventions and patterns for Everything OpenAI Codex. JavaScript project with conventional commits.

◇

security-bounty-hunter

mturac

Find exploitable, bounty-eligible security issues within a repository. Focuses on remotely reachable vulnerabilities suitable for real reports rather than noisy, local-only findings.

◇

analyze-fasta

MubasherMohammed

Analyze a single FASTA file (nucleotide or protein), compute sequence-level metrics (GC, ORFs, MW, pI, GRAVY, secondary-structure fractions) with Biopython, and write a Markdown report plus structured JSON for downstream chaining.

◇

hla-typing

MubasherMohammed

HLA allele typing from WGS/WES VCF data

alleletypingfrom
◇

detecting-business-email-compromise

mukkuul976

Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,

phishingemail-securitysocial-engineeringdmarc
◇

hunting-for-command-and-control-beaconing

mukkuul976

Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.

threat-huntingmitre-attackc2beaconing
◇

implementing-zero-knowledge-proof-for-authentication

mukkuul976

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identification protocol.

cryptographyzero-knowledge-proofauthenticationprivacy
◇

investigating-ransomware-attack-artifacts

mukkuul976

Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.

forensicsransomwaremalware-analysisincident-response
◇

performing-user-behavior-analytics

mukkuul976

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.

socuebauser-behaviorinsider-threat
◇

analyzing-active-directory-acl-abuse

mukul975

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

active-directoryacl-abuseldapprivilege-escalation
◇

analyzing-cobalt-strike-beacon-configuration

mukul975

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.

cobalt-strikebeaconc2malware-analysis
◇

analyzing-macro-malware-in-office-documents

mukul975

Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.

malwaremacroOfficeVBA
◇

building-phishing-reporting-button-workflow

mukul975

Implement a phishing report button in email clients with automated triage workflow that analyzes user-reported suspicious emails and provides feedback to reporters.

phishing-reportingemail-securityincident-responsesecurity-awareness
◇

building-threat-actor-profile-from-osint

mukul975

Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.

osintthreat-actorprofilingmaltego
◇

conducting-social-engineering-penetration-test

mukul975

Design and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.

social-engineeringphishingvishingpretexting
◇

exploiting-websocket-vulnerabilities

mukul975

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.

penetration-testingwebsocketweb-securityowasp
◇

hunting-for-persistence-mechanisms-in-windows

mukul975

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

threat-huntingmitre-attackpersistencewindows
◇

implementing-azure-ad-privileged-identity-management

mukul975

Configure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.

azure-adpimentra-idjust-in-time
◇

implementing-cisa-zero-trust-maturity-model

mukul975

Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.

zero-trustcisamaturity-modelfederal-compliance
◇

implementing-data-loss-prevention-with-microsoft-purview

mukul975

Implements data loss prevention policies using Microsoft Purview to protect sensitive information across Exchange Online, SharePoint, OneDrive, Teams, endpoint devices, and Power BI. The analyst configures sensitivity labels with encryption and content marking, creates DLP policies using built-in and custom sensitive information types with regex patterns, deploys endpoint DLP rules to control file operations on Windows and macOS devices, and monitors policy effectiveness through Activity Explorer and DLP alert management. Uses PowerShell cmdlets and the Microsoft Graph API for programmatic policy management. Activates for requests involving DLP policy creation, sensitivity label configuration, data classification, endpoint data protection, or Microsoft Purview compliance administration.

DLPMicrosoft-Purviewsensitivity-labelsendpoint-DLP
◇

implementing-delinea-secret-server-for-pam

mukul975

Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation.

PAMDelineaSecret-Serverprivileged-access
◇

implementing-kubernetes-network-policy-with-calico

mukul975

Implement Kubernetes network segmentation using Calico NetworkPolicy and GlobalNetworkPolicy for zero-trust pod-to-pod communication.

calicokubernetesnetwork-policynetwork-segmentation
◇

implementing-ot-incident-response-playbook

mukul975

Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.

ot-securityicsincident-responseplaybook
上一页第 697 / 1466 页下一页