All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 169–192 of 26,873 skills
- Secure Auth PatternsAuthentication and session implementation patterns: password hashing, session cookie settings, JWT validation and its pitfalls, and access control checks, with language-specific examples. Use when building or reviewing login, sessions, tokens, or authorization code.Votes: 0GitHub stars: 4
- Vault PatternsSecret storage platform reference for HashiCorp Vault, AWS Secrets Manager, and GCP Secret Manager: architecture, platform comparison, the bootstrap problem, and access patterns. Use when choosing or configuring a vault or wiring applications to it.Votes: 0GitHub stars: 4
- Secret DetectionSecret detection reference: pattern, entropy, and verification approaches, formats of common credentials, gitleaks and trufflehog configuration, and false positive management. Use when setting up secret scanning or tuning its rules.Votes: 0GitHub stars: 4
- Mitre Attack FrameworkMITRE ATT&CK Enterprise reference: tactics, key techniques with procedures, data sources, detection guidance, and mitigations. Use when mapping behavior to technique IDs, building detections, or planning authorized emulation.Votes: 0GitHub stars: 4
- Adversary EmulationMethodology for threat-intelligence-based adversary emulation within written rules of engagement: lifecycle, TIBER-EU and MITRE emulation plans, safety controls, phased scenarios, and atomic testing with benign indicators. Use when designing an authorized emulation or purple team exercise.Votes: 0GitHub stars: 4
- Privacy By DesignThe seven Privacy by Design principles with software engineering practices for each, such as privacy requirements in specs, privacy-protective defaults, and separating identity from behavioral data. Use when designing features that handle personal data.Votes: 0GitHub stars: 4
- Data Protection PatternsTechnical patterns for anonymization, pseudonymization, field-level encryption, data minimization, consent management, and data subject request automation, with the difference between anonymous and pseudonymous data. Use when implementing privacy controls in code or data pipelines.Votes: 0GitHub stars: 4
- Pentest MethodologyReference for PTES phases, the OWASP Testing Guide, and testing patterns by technology and vulnerability class, starting from pre-engagement authorization and rules of engagement. Use when planning or running an authorized penetration test and structuring its report.Votes: 0GitHub stars: 4
- Network SegmentationNetwork segmentation strategies: trust zones, VLAN and DMZ design, micro-segmentation, and lateral movement prevention. Use when designing segmentation or assessing how far a compromise could spread inside a network.Votes: 0GitHub stars: 4
- Firewall PatternsFirewall design reference with iptables and nftables rulesets, cloud security group patterns, stateful versus stateless processing, and common rule mistakes. Use when writing or reviewing host or cloud firewall rules.Votes: 0GitHub stars: 4
- Owasp MasvsOWASP MASVS v2.0 reference covering every control group (storage, crypto, auth, network, platform, code, resilience) and how each maps to MASTG test cases. Use when scoping, testing, or reporting against the mobile verification standard.Votes: 0GitHub stars: 4
- Mobile Crypto PatternsMobile cryptography patterns for Android Keystore and iOS Secure Enclave, Keychain, and CryptoKit: key storage, data-at-rest encryption, password key derivation, TLS and certificate pinning, and secure randomness. Use when implementing or reviewing crypto in a mobile app.Votes: 0GitHub stars: 4
- Malware Analysis MethodologyDefensive malware analysis workflow from safe handling in an isolated lab through triage, static analysis, dynamic analysis, and reporting with ATT&CK mapping and YARA, Snort/Suricata, or Sigma signatures. Use when planning or running an analysis of a suspected sample for incident response.Votes: 0GitHub stars: 4
- Ioc PatternsIndicator of compromise taxonomy ranked by the Pyramid of Pain, extraction and defanging patterns, quality assessment, and structured formats such as STIX 2.1 for sharing. Use when extracting, prioritizing, or formatting IOCs from an investigation.Votes: 0GitHub stars: 4
- K8s Security PoliciesPod Security Standards and Pod Security Admission, NetworkPolicy fundamentals with default-deny and service-to-service patterns, restricted-profile pod security contexts, and Kyverno examples. Use when hardening workloads or writing NetworkPolicy and admission rules.Votes: 0GitHub stars: 4
- K8s Rbac PatternsKubernetes RBAC reference: the Role and ClusterRole binding model, evaluation logic, escalation paths, least-privilege patterns for developers, CI/CD, monitoring, and break-glass access, plus common misconfigurations. Use when writing RBAC manifests or reviewing who can do what in a cluster.Votes: 0GitHub stars: 4
- Ir PlaybooksStep-by-step incident response playbooks (indicators, validation, containment, eradication and recovery, post-incident) for malware infection, account compromise, data breach, ransomware, DDoS, and insider threat. Use when responding to one of these incidents or writing its runbook.Votes: 0GitHub stars: 4
- Mfa ImplementationMFA reference covering factor types, NIST AAL levels, WebAuthn/FIDO2 registration, TOTP implementation, enforcement middleware with step-up auth, and bypass risks such as SMS SIM swap and prompt bombing. Use when adding or hardening multi-factor authentication.Votes: 0GitHub stars: 4
- Access Control ModelsRBAC, ABAC, and ReBAC (Zanzibar-style) reference with a decision framework, implementation patterns, a segregation-of-duties matrix, and anti-patterns such as role explosion and hard-coded authorization. Use when choosing or implementing an authorization model or fixing IDOR-style ambient authority.Votes: 0GitHub stars: 4
- Memory ForensicsMemory forensics reference: acquisition tools (WinPMem, DumpIt, FTK Imager, LiME, AVML), Volatility 3 architecture, and triage patterns for processes, hidden processes, and injected code. Use when acquiring or analyzing a memory image during incident response.Votes: 0GitHub stars: 4
- Forensic MethodologyForensic methodology following NIST SP 800-86 and ISO 27037: the forensic process, order of volatility (RFC 3227), evidence integrity, KAPE triage collection, and disk imaging with dc3dd and ewfacquire. Use when collecting or preserving evidence during an investigation.Votes: 0GitHub stars: 4
- Security GatesSecurity gate reference: gate types, severity matrices, risk-based gating with CVSS, EPSS, and KEV, differential gating for new code, application-tiered gates, and an override process. Use when deciding when a finding should break the build.Votes: 0GitHub stars: 4
- Ci Security PatternsReference pipelines for security scanning in GitHub Actions, GitLab CI, and Jenkins, plus pre-commit hooks, with stage ordering and design decisions. Use when adding or reviewing security stages in CI.Votes: 0GitHub stars: 4
- Key ManagementKey management reference: key lifecycle and types, storage security hierarchy, rotation strategy, envelope encryption, crypto-shredding, KMS access control, and anti-patterns such as keys in source code. Use when designing how keys are stored, rotated, or destroyed.Votes: 0GitHub stars: 4