.
├── backup
│   ├── checkin_git.config_2026-04-01T22:45:51Z.backup
│   ├── checkin_git.config_2026-04-02T04:39:08Z.backup
│   ├── checkin_git.config_2026-04-02T06:57:08Z.backup
│   ├── checkin_git.sh_2026-04-01T22:45:51Z.backup
│   ├── checkin_git.sh_2026-04-02T04:39:08Z.backup
│   └── checkin_git.sh_2026-04-02T06:57:08Z.backup
├── bandit.yml
├── Cargo.toml
├── checkin_git.config
├── checkin_git.sh
├── CLAUDE.md
├── clippy.toml
├── CODE_OF_CONDUCT_DE.md
├── CODE_OF_CONDUCT_DE.txt
├── CODE_OF_CONDUCT.md
├── CODE_OF_CONDUCT.txt
├── content_long_list.txt
├── content_summary.txt
├── dep
├── documentation
│   ├── hadolint
│   ├── html
│   ├── javascript_typescript
│   │   ├── fta
│   │   │   ├── fta-report-2026-04-01T22:57:38Z.json
│   │   │   ├── fta-report-2026-04-01T22:57:38Z.txt
│   │   │   ├── fta-report-2026-04-02T05:24:39Z.json
│   │   │   ├── fta-report-2026-04-02T05:24:39Z.txt
│   │   │   ├── fta-report-2026-04-02T08:32:46Z.json
│   │   │   └── fta-report-2026-04-02T08:32:46Z.txt
│   │   └── oxlint
│   │       ├── oxlint-autofix-2026-04-01T22:57:37Z.log
│   │       ├── oxlint-autofix-2026-04-02T05:24:36Z.log
│   │       ├── oxlint-autofix-2026-04-02T08:32:42Z.log
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.github
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.json
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.junit.xml
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.stylish
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.unix
│   │       ├── oxlint-report-2026-04-01T22:57:37Z.xml
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.github
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.json
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.junit.xml
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.stylish
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.unix
│   │       ├── oxlint-report-2026-04-02T05:24:36Z.xml
│   │       ├── oxlint-report-2026-04-02T08:32:42Z.github
│   │       ├── oxlint-report-2026-04-02T08:32:42Z.json
│   │       ├── oxlint-report-2026-04-02T08:32:42Z.junit.xml
│   │       ├── oxlint-report-2026-04-02T08:32:42Z.stylish
│   │       ├── oxlint-report-2026-04-02T08:32:42Z.unix
│   │       └── oxlint-report-2026-04-02T08:32:42Z.xml
│   ├── markdownlint
│   │   ├── markdownlint-autofix-2026-04-01T22:58:12Z.log
│   │   ├── markdownlint-autofix-2026-04-02T05:24:55Z.log
│   │   ├── markdownlint-autofix-2026-04-02T08:33:12Z.log
│   │   ├── markdownlint-report-2026-04-01T22:58:12Z.json
│   │   ├── markdownlint-report-2026-04-01T22:58:12Z.txt
│   │   ├── markdownlint-report-2026-04-02T05:24:55Z.json
│   │   ├── markdownlint-report-2026-04-02T05:24:55Z.txt
│   │   ├── markdownlint-report-2026-04-02T08:33:12Z.json
│   │   └── markdownlint-report-2026-04-02T08:33:12Z.txt
│   ├── python
│   │   ├── ruff-autofix-2026-04-02T04:57:17Z.log
│   │   ├── ruff-autofix-2026-04-02T07:36:51Z.log
│   │   ├── ruff-report-2026-04-02T04:57:17Z.azure.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.full.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.github.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.gitlab.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.grouped.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.json
│   │   ├── ruff-report-2026-04-02T04:57:17Z.jsonl
│   │   ├── ruff-report-2026-04-02T04:57:17Z.junit.xml
│   │   ├── ruff-report-2026-04-02T04:57:17Z.pylint.txt
│   │   ├── ruff-report-2026-04-02T04:57:17Z.rdjson
│   │   ├── ruff-report-2026-04-02T04:57:17Z.sarif
│   │   ├── ruff-report-2026-04-02T04:57:17Z.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.azure.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.full.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.github.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.gitlab.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.grouped.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.json
│   │   ├── ruff-report-2026-04-02T07:36:51Z.jsonl
│   │   ├── ruff-report-2026-04-02T07:36:51Z.junit.xml
│   │   ├── ruff-report-2026-04-02T07:36:51Z.pylint.txt
│   │   ├── ruff-report-2026-04-02T07:36:51Z.rdjson
│   │   ├── ruff-report-2026-04-02T07:36:51Z.sarif
│   │   └── ruff-report-2026-04-02T07:36:51Z.txt
│   ├── robots.txt
│   ├── rumdl
│   │   ├── rumdl-autofix-2026-04-01T23:06:03Z.log
│   │   ├── rumdl-autofix-2026-04-02T05:33:15Z.log
│   │   ├── rumdl-autofix-2026-04-02T08:40:07Z.log
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.azure.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.concise.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.full.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.github.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.gitlab.json
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.grouped.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.json
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.jsonl
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.junit.xml
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.pylint.txt
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.sarif
│   │   ├── rumdl-report-2026-04-01T23:06:03Z.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.azure.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.concise.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.full.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.github.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.gitlab.json
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.grouped.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.json
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.jsonl
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.junit.xml
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.pylint.txt
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.sarif
│   │   ├── rumdl-report-2026-04-02T05:33:15Z.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.azure.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.concise.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.full.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.github.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.gitlab.json
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.grouped.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.json
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.jsonl
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.junit.xml
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.pylint.txt
│   │   ├── rumdl-report-2026-04-02T08:40:07Z.sarif
│   │   └── rumdl-report-2026-04-02T08:40:07Z.txt
│   ├── ryl
│   │   ├── ryl-report-2026-04-01T23:05:44Z.colored.txt
│   │   ├── ryl-report-2026-04-01T23:05:44Z.github.txt
│   │   ├── ryl-report-2026-04-01T23:05:44Z.parsable.txt
│   │   ├── ryl-report-2026-04-01T23:05:44Z.txt
│   │   ├── ryl-report-2026-04-02T05:32:58Z.colored.txt
│   │   ├── ryl-report-2026-04-02T05:32:58Z.github.txt
│   │   ├── ryl-report-2026-04-02T05:32:58Z.parsable.txt
│   │   ├── ryl-report-2026-04-02T05:32:58Z.txt
│   │   ├── ryl-report-2026-04-02T08:39:50Z.colored.txt
│   │   ├── ryl-report-2026-04-02T08:39:50Z.github.txt
│   │   ├── ryl-report-2026-04-02T08:39:50Z.parsable.txt
│   │   └── ryl-report-2026-04-02T08:39:50Z.txt
│   ├── scorecard
│   ├── security
│   │   └── bandit
│   │       ├── bandit-report-2026-04-02T05:03:50Z.csv
│   │       ├── bandit-report-2026-04-02T05:03:50Z.custom.txt
│   │       ├── bandit-report-2026-04-02T05:03:50Z.html
│   │       ├── bandit-report-2026-04-02T05:03:50Z.json
│   │       ├── bandit-report-2026-04-02T05:03:50Z.screen.txt
│   │       ├── bandit-report-2026-04-02T05:03:50Z.xml
│   │       ├── bandit-report-2026-04-02T05:03:50Z.yaml
│   │       ├── bandit-report-2026-04-02T07:56:04Z.csv
│   │       ├── bandit-report-2026-04-02T07:56:04Z.custom.txt
│   │       ├── bandit-report-2026-04-02T07:56:04Z.html
│   │       ├── bandit-report-2026-04-02T07:56:04Z.json
│   │       ├── bandit-report-2026-04-02T07:56:04Z.screen.txt
│   │       ├── bandit-report-2026-04-02T07:56:04Z.xml
│   │       └── bandit-report-2026-04-02T07:56:04Z.yaml
│   ├── shellcheck
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.diff
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.gcc
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.json
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.tty
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.txt
│   │   ├── shellcheck-report-2026-04-01T22:46:12Z.xml
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.diff
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.gcc
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.json
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.tty
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.txt
│   │   ├── shellcheck-report-2026-04-02T04:45:32Z.xml
│   │   ├── shellcheck-report-2026-04-02T07:08:10Z.diff
│   │   ├── shellcheck-report-2026-04-02T07:08:10Z.gcc
│   │   ├── shellcheck-report-2026-04-02T07:08:10Z.json
│   │   ├── shellcheck-report-2026-04-02T07:08:10Z.tty
│   │   ├── shellcheck-report-2026-04-02T07:08:10Z.txt
│   │   └── shellcheck-report-2026-04-02T07:08:10Z.xml
│   ├── shfmt
│   │   ├── shfmt_report_2026-04-02T04:57:06Z.txt
│   │   ├── shfmt_report_2026-04-02T07:36:41Z.txt
│   │   ├── shfmt-report_diff_2026-04-02T04:57:06Z.txt
│   │   ├── shfmt-report_diff_2026-04-02T07:36:41Z.txt
│   │   ├── shfmtreport_2026-04-02T04:57:06Z.json
│   │   └── shfmtreport_2026-04-02T07:36:41Z.json
│   └── yamllint
│       ├── yamllint-report_2026-04-01T22:46:01Z.json
│       ├── yamllint-report_2026-04-01T22:46:01Z.txt
│       ├── yamllint-report_2026-04-02T04:39:17Z.json
│       ├── yamllint-report_2026-04-02T04:39:17Z.txt
│       ├── yamllint-report_2026-04-02T06:57:22Z.json
│       ├── yamllint-report_2026-04-02T06:57:22Z.txt
│       ├── yamllint-report_colored_2026-04-01T22:46:01Z.txt
│       ├── yamllint-report_colored_2026-04-02T04:39:17Z.txt
│       ├── yamllint-report_colored_2026-04-02T06:57:22Z.txt
│       ├── yamllint-report_config_2026-04-01T22:46:01Z.txt
│       ├── yamllint-report_config_2026-04-02T04:39:17Z.txt
│       ├── yamllint-report_config_2026-04-02T06:57:22Z.txt
│       ├── yamllint-report_parsable_2026-04-01T22:46:01Z.txt
│       ├── yamllint-report_parsable_2026-04-02T04:39:17Z.txt
│       └── yamllint-report_parsable_2026-04-02T06:57:22Z.txt
├── eslint.config.js
├── example
├── fta.json
├── LICENSE
├── mega-linter.yml
├── mypy.ini
├── proxy.config.json
├── pyproject.toml
├── pytest.ini
├── README.md
├── references
│   ├── aisvs-00-frontispiece.md
│   ├── aisvs-00-preface.md
│   ├── aisvs-00-using-aisvs.md
│   ├── aisvs-appendix-a-glossary.md
│   ├── aisvs-appendix-b-references.md
│   ├── aisvs-appendix-c-ai-code-generation.md
│   ├── aisvs-appendix-d-controls-inventory.md
│   ├── aisvs-C01-training-data-integrity.md
│   ├── aisvs-C02-user-input-validation.md
│   ├── aisvs-C03-model-lifecycle.md
│   ├── aisvs-C04-infrastructure.md
│   ├── aisvs-C05-access-control.md
│   ├── aisvs-C06-supply-chain.md
│   ├── aisvs-C07-model-behavior.md
│   ├── aisvs-C08-memory-embeddings-vectordb.md
│   ├── aisvs-C09-orchestration-agentic.md
│   ├── aisvs-C10-mcp-security.md
│   ├── aisvs-C11-adversarial-robustness.md
│   ├── aisvs-C12-privacy.md
│   ├── aisvs-C13-monitoring-logging.md
│   ├── aisvs-C14-human-oversight.md
│   ├── asvs-5-0-0.md
│   ├── rust-doctor-rules-reference.md
│   ├── rust-doctor-score-interpretation.md
│   └── rust-doctor-suppression-syntax.md
├── renovate.json
├── renovate.json.license
├── res
├── robots.txt
├── rustfmt.toml
├── SECURITY.md
├── security.txt
├── skills
│   ├── access-control.md
│   ├── accessibility.md
│   ├── aisvs-skills.md
│   ├── api-documentation-openapi.md
│   ├── api-security-best-practices.md
│   ├── architecture-decision-records.md
│   ├── assessment-workflow.md
│   ├── asvs-skills.md
│   ├── authentication-failures.md
│   ├── authentication.md
│   ├── broken-access-control.md
│   ├── cryptographic-failures.md
│   ├── cybersecurity-skills
│   │   ├── assets
│   │   │   └── banner.png
│   │   ├── CODE_OF_CONDUCT.md
│   │   ├── CONTRIBUTING.md
│   │   ├── index.json
│   │   ├── mappings
│   │   │   ├── attack-navigator-layer.json
│   │   │   ├── mitre-attack
│   │   │   │   ├── coverage-summary.md
│   │   │   │   └── README.md
│   │   │   ├── nist-csf
│   │   │   │   ├── csf-alignment.md
│   │   │   │   └── README.md
│   │   │   ├── owasp
│   │   │   │   └── README.md
│   │   │   └── README.md
│   │   ├── README.md
│   │   ├── SECURITY.md
│   │   └── skills
│   │       ├── acquiring-disk-image-with-dd-and-dcfldd
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-active-directory-acl-abuse
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-android-malware-with-apktool
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-api-gateway-access-logs
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-apt-group-with-mitre-navigator
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-azure-activity-logs-for-threats
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-bootkit-and-rootkit-samples
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-browser-forensics-with-hindsight
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-campaign-attribution-evidence
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-certificate-transparency-for-phishing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-cloud-storage-access-patterns
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-cobalt-strike-beacon-configuration
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-cobalt-strike-malleable-profiles
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-cobaltstrike-malleable-c2-profiles
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-command-and-control-communication
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-cyber-kill-chain
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-disk-image-with-autopsy
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-dns-logs-for-exfiltration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-docker-container-forensics
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-email-headers-for-phishing-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-ethereum-smart-contract-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-golang-malware-with-ghidra
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-heap-spray-exploitation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-indicators-of-compromise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-ios-app-security-with-objection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-kubernetes-audit-logs
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-linux-audit-logs-for-intrusion
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-linux-elf-malware
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-linux-kernel-rootkits
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-linux-system-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-lnk-file-and-jump-list-artifacts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-macro-malware-in-office-documents
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malicious-pdf-with-peepdf
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malicious-url-with-urlscan
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malware-behavior-with-cuckoo-sandbox
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malware-family-relationships-with-malpedia
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malware-persistence-with-autoruns
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-malware-sandbox-evasion-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-memory-dumps-with-volatility
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-memory-forensics-with-lime-and-volatility
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-mft-for-deleted-file-recovery
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-covert-channels-in-malware
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-flow-data-with-netflow
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-packets-with-scapy
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-traffic-for-incidents
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-traffic-of-malware
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-network-traffic-with-wireshark
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-office365-audit-logs-for-compromise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-outlook-pst-for-email-forensics
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-packed-malware-with-upx-unpacker
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-pdf-malware-with-pdfid
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-persistence-mechanisms-in-linux
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-phishing-email-headers
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-powershell-empire-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-powershell-script-block-logging
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-prefetch-files-for-execution-history
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-ransomware-encryption-mechanisms
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-ransomware-leak-site-intelligence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-ransomware-network-indicators
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-security-logs-with-splunk
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-slack-space-and-file-system-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-supply-chain-malware-artifacts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-threat-actor-ttps-with-mitre-attack
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-threat-actor-ttps-with-mitre-navigator
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-threat-intelligence-feeds
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-threat-landscape-with-misp
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-tls-certificate-transparency-logs
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-typosquatting-domains-with-dnstwist
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-usb-device-connection-history
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-web-server-logs-for-intrusion
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-amcache-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-event-logs-in-splunk
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-lnk-files-for-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-prefetch-with-python
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-registry-for-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── analyzing-windows-shellbag-artifacts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── auditing-aws-s3-bucket-permissions
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── auditing-azure-active-directory-configuration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── auditing-cloud-with-cis-benchmarks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── auditing-gcp-iam-permissions
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── auditing-kubernetes-cluster-rbac
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── auditing-kubernetes-rbac-permissions
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── auditing-terraform-infrastructure-for-security
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── automating-ioc-enrichment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-adversary-infrastructure-tracking-system
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-attack-pattern-library-from-cti-reports
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-automated-malware-submission-pipeline
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-c2-infrastructure-with-sliver-framework
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-cloud-security-posture-management
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-cloud-siem-with-sentinel
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-detection-rule-with-splunk-spl
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-detection-rules-with-sigma
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-devsecops-pipeline-with-gitlab-ci
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-identity-federation-with-saml-azure-ad
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-identity-governance-lifecycle-process
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-incident-response-dashboard
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-incident-response-playbook
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-incident-timeline-with-timesketch
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-ioc-defanging-and-sharing-pipeline
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-ioc-enrichment-pipeline-with-opencti
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-malware-incident-communication-template
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-patch-tuesday-response-process
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-phishing-reporting-button-workflow
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-red-team-c2-infrastructure-with-havoc
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-role-mining-for-rbac-optimization
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-soc-escalation-matrix
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-soc-metrics-and-kpi-tracking
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-soc-playbook-for-ransomware
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-actor-profile-from-osint
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-feed-aggregation-with-misp
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-hunt-hypothesis-framework
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-intelligence-enrichment-in-splunk
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-intelligence-feed-integration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── building-threat-intelligence-platform
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-vulnerability-aging-and-sla-tracking
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-vulnerability-dashboard-with-defectdojo
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-vulnerability-exception-tracking-system
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── building-vulnerability-scanning-workflow
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── bypassing-authentication-with-forced-browsing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── collecting-indicators-of-compromise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── collecting-open-source-intelligence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── collecting-threat-intelligence-with-misp
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── collecting-volatile-evidence-from-compromised-host
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-api-security-testing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-cloud-incident-response
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-cloud-infrastructure-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-cloud-penetration-testing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-domain-persistence-with-dcsync
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-external-reconnaissance-with-osint
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-full-scope-red-team-engagement
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-internal-network-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-internal-reconnaissance-with-bloodhound-ce
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-malware-incident-response
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-man-in-the-middle-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-memory-forensics-with-volatility
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-mobile-app-penetration-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-mobile-application-penetration-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-network-penetration-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-pass-the-ticket-attack
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-phishing-incident-response
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── conducting-post-incident-lessons-learned
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-social-engineering-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-social-engineering-pretext-call
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-spearphishing-simulation-campaign
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── conducting-wireless-network-penetration-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-active-directory-tiered-model
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-aws-verified-access-for-ztna
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-certificate-authority-with-openssl
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-host-based-intrusion-detection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-hsm-for-key-storage
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-identity-aware-proxy-with-google-iap
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-ldap-security-hardening
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-microsegmentation-for-zero-trust
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-multi-factor-authentication-with-duo
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-network-segmentation-with-vlans
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-oauth2-authorization-flow
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-pfsense-firewall-rules
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-snort-ids-for-intrusion-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-suricata-for-network-monitoring
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── configuring-tls-1-3-for-secure-communications
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-windows-defender-advanced-settings
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-windows-event-logging-for-detection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── configuring-zscaler-private-access-for-ztna
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── containing-active-breach
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── containing-active-security-breach
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── correlating-security-events-in-qradar
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── correlating-threat-campaigns
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── deobfuscating-javascript-malware
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── deobfuscating-powershell-obfuscated-malware
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── deploying-cloudflare-access-for-zero-trust
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── deploying-edr-agent-with-crowdstrike
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── deploying-osquery-for-endpoint-monitoring
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── deploying-palo-alto-prisma-access-zero-trust
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── deploying-ransomware-canary-files
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── deploying-software-defined-perimeter
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── deploying-tailscale-for-zero-trust-vpn
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-anomalies-in-industrial-control-systems
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-anomalous-authentication-patterns
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-api-enumeration-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-arp-poisoning-in-network-traffic
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-attacks-on-historian-servers
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-attacks-on-scada-systems
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-aws-cloudtrail-anomalies
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-aws-credential-exposure-with-trufflehog
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-aws-guardduty-findings-automation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-aws-iam-privilege-escalation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-azure-lateral-movement
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-azure-service-principal-abuse
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-azure-storage-account-misconfigurations
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-beaconing-patterns-with-zeek
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-broken-object-property-level-authorization
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-business-email-compromise
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-business-email-compromise-with-ai
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-cloud-cryptomining-activity
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-cloud-threats-with-guardduty
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-compromised-cloud-credentials
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-container-drift-at-runtime
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-container-escape-attempts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-container-escape-with-falco-rules
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-credential-dumping-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-credential-dumping-with-edr
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-cryptomining-in-cloud
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-dcsync-attack-in-active-directory
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-dll-sideloading-attacks
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-dnp3-protocol-anomalies
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-dns-exfiltration-with-dns-query-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-email-account-compromise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-email-forwarding-rules-attack
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-evasion-techniques-in-endpoint-logs
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-exfiltration-over-dns-with-zeek
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-fileless-attacks-on-endpoints
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-fileless-malware-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-golden-ticket-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-golden-ticket-attacks-in-kerberos-logs
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-golden-ticket-forgery
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-insider-data-exfiltration-via-dlp
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-insider-threat-behaviors
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-insider-threat-with-ueba
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-kerberoasting-attacks
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-lateral-movement-in-network
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-lateral-movement-with-splunk
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-living-off-the-land-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-living-off-the-land-with-lolbas
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-malicious-scheduled-tasks-with-sysmon
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-mimikatz-execution-patterns
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-misconfigured-azure-storage
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-mobile-malware-behavior
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-modbus-command-injection-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-modbus-protocol-anomalies
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-network-anomalies-with-zeek
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-network-scanning-with-ids-signatures
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-oauth-token-theft
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-pass-the-hash-attacks
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-pass-the-ticket-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-port-scanning-with-fail2ban
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-privilege-escalation-attempts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-privilege-escalation-in-kubernetes-pods
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-process-hollowing-technique
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-process-injection-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-qr-code-phishing-with-email-security
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-ransomware-precursors-in-network
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-rdp-brute-force-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-rootkit-activity
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-s3-data-exfiltration-attempts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-service-account-abuse
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-shadow-api-endpoints
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-shadow-it-cloud-usage
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-spearphishing-with-email-gateway
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-sql-injection-via-waf-logs
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-stuxnet-style-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-supply-chain-attacks-in-ci-cd
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-suspicious-oauth-application-consent
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── detecting-suspicious-powershell-execution
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-t1003-credential-dumping-with-edr
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-t1055-process-injection-with-sysmon
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-t1548-abuse-elevation-control-mechanism
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── detecting-wmi-persistence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── eradicating-malware-from-infected-systems
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── evaluating-threat-intelligence-platforms
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── executing-active-directory-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── executing-diamond-model-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── executing-phishing-simulation-campaign
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── executing-red-team-engagement-planning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── executing-red-team-exercise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-active-directory-certificate-services-esc1
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-active-directory-with-bloodhound
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-api-injection-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-bgp-hijacking-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-broken-function-level-authorization
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-broken-link-hijacking
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-constrained-delegation-abuse
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-deeplink-vulnerabilities
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-excessive-data-exposure-in-api
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-http-request-smuggling
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-idor-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-insecure-data-storage-in-mobile
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-insecure-deserialization
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-ipv6-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-jwt-algorithm-confusion-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-kerberoasting-with-impacket
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-mass-assignment-in-rest-apis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-ms17-010-eternalblue-vulnerability
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-nopac-cve-2021-42278-42287
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-nosql-injection-vulnerabilities
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-oauth-misconfiguration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-prototype-pollution-in-javascript
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-race-condition-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-server-side-request-forgery
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-smb-vulnerabilities-with-metasploit
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-sql-injection-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-sql-injection-with-sqlmap
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-template-injection-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-type-juggling-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-vulnerabilities-with-metasploit-framework
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-websocket-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── exploiting-zerologon-vulnerability-cve-2020-1472
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── extracting-browser-history-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── extracting-config-from-agent-tesla-rat
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── extracting-credentials-from-memory-dump
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── extracting-iocs-from-malware-samples
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── extracting-memory-artifacts-with-rekall
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── extracting-windows-event-logs-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── generating-threat-intelligence-reports
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hardening-docker-containers-for-production
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hardening-docker-daemon-configuration
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hardening-linux-endpoint-with-cis-benchmark
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hardening-windows-endpoint-with-cis-benchmark
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-advanced-persistent-threats
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-credential-stuffing-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-anomalous-powershell-execution
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-beaconing-with-frequency-analysis
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-cobalt-strike-beacons
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-command-and-control-beaconing
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-data-exfiltration-indicators
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-data-staging-before-exfiltration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-dcsync-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-defense-evasion-via-timestomping
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-dns-based-persistence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-dns-tunneling-with-zeek
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-domain-fronting-c2-traffic
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-lateral-movement-via-wmi
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-living-off-the-cloud-techniques
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-living-off-the-land-binaries
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-lolbins-execution-in-endpoint-logs
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-ntlm-relay-attacks
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-persistence-mechanisms-in-windows
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-persistence-via-wmi-subscriptions
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-process-injection-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-registry-persistence-mechanisms
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-registry-run-key-persistence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-scheduled-task-persistence
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-shadow-copy-deletion
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-spearphishing-indicators
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-startup-folder-persistence
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-supply-chain-compromise
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-suspicious-scheduled-tasks
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-t1098-account-manipulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-unusual-network-connections
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-unusual-service-installations
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-webshell-activity
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── hunting-for-webshells-in-web-servers
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── hunting-living-off-the-land-binaries
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aes-encryption-for-data-at-rest
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-alert-fatigue-reduction
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-anti-phishing-training-program
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-abuse-detection-with-rate-limiting
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-gateway-security-controls
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-key-security-controls
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-rate-limiting-and-throttling
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-schema-validation-security
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-security-posture-management
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-security-testing-with-42crunch
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-api-threat-protection-with-apigee
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-application-whitelisting-with-applocker
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aqua-security-for-container-scanning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-attack-path-analysis-with-xm-cyber
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aws-config-rules-for-compliance
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aws-iam-permission-boundaries
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aws-macie-for-data-classification
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aws-security-hub
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-aws-security-hub-compliance
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-azure-ad-privileged-identity-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-azure-defender-for-cloud
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-beyondcorp-zero-trust-access-model
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-bgp-security-with-rpki
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cisa-zero-trust-maturity-model
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-dlp-for-data-protection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-security-posture-management
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-trail-log-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-vulnerability-posture-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-waf-rules
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-cloud-workload-protection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-code-signing-for-artifacts
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-conditional-access-policies-azure-ad
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-conduit-security-for-ot-remote-access
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-container-image-minimal-base-with-distroless
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-container-network-policies-with-calico
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-continuous-security-validation-with-bas
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ddos-mitigation-with-cloudflare
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-deception-based-detection-with-canarytoken
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-delinea-secret-server-for-pam
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-device-posture-assessment-in-zero-trust
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-devsecops-security-scanning
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-diamond-model-analysis
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-digital-signatures-with-ed25519
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-disk-encryption-with-bitlocker
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-dmarc-dkim-spf-email-security
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-dragos-platform-for-ot-monitoring
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-email-sandboxing-with-proofpoint
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-email-security-with-dmarc-dkim-spf
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-end-to-end-encryption-for-messaging
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-endpoint-detection-with-wazuh
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-endpoint-dlp-controls
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-envelope-encryption-with-aws-kms
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-epss-score-for-vulnerability-prioritization
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-file-integrity-monitoring-with-aide
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-fuzz-testing-in-cicd-with-aflplusplus
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-gcp-binary-authorization
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-gcp-organization-policy-constraints
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-gcp-vpc-firewall-rules
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-gdpr-data-protection-controls
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-github-advanced-security-for-code-scanning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-google-workspace-admin-security
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-google-workspace-phishing-protection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-google-workspace-sso-configuration
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-hashicorp-vault-dynamic-secrets
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-honeypot-for-ransomware-detection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-honeytokens-for-breach-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ics-firewall-with-tofino
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-identity-governance-with-sailpoint
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-identity-verification-for-zero-trust
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-iec-62443-security-zones
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-image-provenance-verification-with-cosign
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-immutable-backup-with-restic
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-infrastructure-as-code-security-scanning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-iso-27001-information-security-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-just-in-time-access-provisioning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-jwt-signing-and-verification
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-kubernetes-network-policy-with-calico
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-kubernetes-pod-security-standards
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-log-forwarding-with-fluentd
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-log-integrity-with-blockchain
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-memory-protection-with-dep-aslr
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-microsegmentation-with-guardicore
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-mimecast-targeted-attack-protection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-mitre-attack-coverage-mapping
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-mobile-application-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-mtls-for-zero-trust-services
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-nerc-cip-compliance-controls
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-access-control
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-access-control-with-cisco-ise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-deception-with-honeypots
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-intrusion-prevention-with-suricata
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-policies-for-kubernetes
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-segmentation-for-ot
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-segmentation-with-firewall-zones
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-traffic-analysis-with-arkime
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-network-traffic-baselining
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-next-generation-firewall-with-palo-alto
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-opa-gatekeeper-for-policy-enforcement
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-osquery-for-endpoint-monitoring
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ot-incident-response-playbook
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ot-network-traffic-analysis-with-nozomi
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-pam-for-database-access
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-passwordless-auth-with-microsoft-entra
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-passwordless-authentication-with-fido2
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-patch-management-for-ot-systems
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-patch-management-workflow
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-pci-dss-compliance-controls
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-pod-security-admission-controller
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-policy-as-code-with-open-policy-agent
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-privileged-access-management-with-cyberark
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-privileged-access-workstation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-privileged-identity-management-with-azure
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-privileged-session-monitoring
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-proofpoint-email-security-gateway
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-purdue-model-network-segmentation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ransomware-backup-strategy
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-rapid7-insightvm-for-scanning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-rbac-for-kubernetes-cluster
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-rbac-hardening-for-kubernetes
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-rsa-key-pair-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-runtime-application-self-protection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-runtime-security-with-tetragon
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-saml-sso-with-okta
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-scim-provisioning-with-okta
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-secret-scanning-with-gitleaks
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-secrets-management-with-vault
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-secrets-scanning-in-ci-cd
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-security-chaos-engineering
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-security-information-sharing-with-stix2
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-security-monitoring-with-datadog
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-semgrep-for-custom-sast-rules
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   └── standards.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-siem-correlation-rules-for-apt
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-siem-use-case-tuning
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-siem-use-cases-for-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-soar-automation-with-phantom
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-soar-playbook-for-phishing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-soar-playbook-with-palo-alto-xsoar
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-stix-taxii-feed-integration
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-supply-chain-security-with-in-toto
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-syslog-centralization-with-rsyslog
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-taxii-server-with-opentaxii
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-threat-intelligence-lifecycle-management
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-threat-intelligence-platform
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-threat-modeling-with-mitre-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-ticketing-system-for-incidents
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-usb-device-control-policy
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-velociraptor-for-ir-collection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-vulnerability-management-with-greenbone
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-vulnerability-remediation-sla
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-vulnerability-sla-breach-alerting
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-web-application-logging-with-modsecurity
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-knowledge-proof-for-authentication
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-standing-privilege-with-cyberark
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-dns-with-nextdns
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-for-saas-applications
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-in-cloud
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-network-access
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-network-access-with-zscaler
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-with-beyondcorp
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── implementing-zero-trust-with-hashicorp-boundary
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── integrating-dast-with-owasp-zap-in-pipeline
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── integrating-sast-into-github-actions-pipeline
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── intercepting-mobile-traffic-with-burpsuite
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── investigating-insider-threat-indicators
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── investigating-phishing-email-incident
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── investigating-ransomware-attack-artifacts
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── managing-cloud-identity-with-okta
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── managing-intelligence-lifecycle
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── mapping-mitre-attack-techniques
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── monitoring-darkweb-sources
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-access-recertification-with-saviynt
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-access-review-and-certification
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-active-directory-bloodhound-analysis
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-active-directory-compromise-investigation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-active-directory-forest-trust-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-active-directory-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-active-directory-vulnerability-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-adversary-in-the-middle-phishing-detection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-agentless-vulnerability-scanning
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-alert-triage-with-elastic-siem
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-android-app-static-analysis-with-mobsf
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-api-fuzzing-with-restler
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-api-inventory-and-discovery
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-api-rate-limiting-bypass
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-api-security-testing-with-postman
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-arp-spoofing-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-asset-criticality-scoring-for-vulns
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-authenticated-scan-with-openvas
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-authenticated-vulnerability-scan
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-automated-malware-analysis-with-cape
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-aws-account-enumeration-with-scout-suite
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-aws-privilege-escalation-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-bandwidth-throttling-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-binary-exploitation-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-blind-ssrf-exploitation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-bluetooth-security-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-brand-monitoring-for-impersonation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-clickjacking-attack-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-asset-inventory-with-cartography
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-forensics-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-forensics-with-aws-cloudtrail
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-incident-containment-procedures
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-native-forensics-with-falco
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-penetration-testing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-penetration-testing-with-pacu
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cloud-storage-forensic-acquisition
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-container-escape-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-container-image-hardening
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-container-security-scanning-with-trivy
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-content-security-policy-bypass
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-credential-access-with-lazagne
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-cryptographic-audit-of-application
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-csrf-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-cve-prioritization-with-kev-catalog
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-dark-web-monitoring-for-threats
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-deception-technology-deployment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-directory-traversal-testing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-disk-forensics-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-dmarc-policy-enforcement-rollout
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-dns-enumeration-and-zone-transfer
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-dns-tunneling-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-docker-bench-security-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-dynamic-analysis-of-android-app
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-dynamic-analysis-with-any-run
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-endpoint-forensics-investigation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-endpoint-vulnerability-remediation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-entitlement-review-with-sailpoint-iiq
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-external-network-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-false-positive-reduction-in-siem
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-file-carving-with-foremost
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-firmware-malware-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-fuzzing-with-aflplusplus
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-gcp-penetration-testing-with-gcpbucketbrute
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-gcp-security-assessment-with-forseti
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-graphql-depth-limit-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-graphql-introspection-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-graphql-security-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-hardware-security-module-integration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-hash-cracking-with-hashcat
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-http-parameter-pollution-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ics-asset-discovery-with-claroty
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-indicator-lifecycle-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-initial-access-with-evilginx3
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-insider-threat-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ioc-enrichment-automation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-iot-security-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ip-reputation-analysis-with-shodan
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-jwt-none-algorithm-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-kerberoasting-attack
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-kubernetes-cis-benchmark-with-kube-bench
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-kubernetes-etcd-security-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-kubernetes-penetration-testing
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-lateral-movement-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-lateral-movement-with-wmiexec
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-linux-log-forensics-investigation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-log-analysis-for-forensic-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-log-source-onboarding-in-siem
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-malware-hash-enrichment-with-virustotal
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-malware-ioc-extraction
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-malware-persistence-investigation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-malware-triage-with-yara
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-memory-forensics-with-volatility3
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-memory-forensics-with-volatility3-plugins
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-mobile-app-certificate-pinning-bypass
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-mobile-device-forensics-with-cellebrite
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-network-forensics-with-wireshark
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-network-packet-capture-analysis
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-network-traffic-analysis-with-tshark
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-network-traffic-analysis-with-zeek
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-nist-csf-maturity-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-oauth-scope-minimization-review
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-oil-gas-cybersecurity-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-open-source-intelligence-gathering
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-osint-with-spiderfoot
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ot-network-security-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-ot-vulnerability-assessment-with-claroty
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ot-vulnerability-scanning-safely
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-packet-injection-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-paste-site-monitoring-for-credentials
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-phishing-simulation-with-gophish
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-physical-intrusion-assessment
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-plc-firmware-security-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-power-grid-cybersecurity-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-privilege-escalation-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-privilege-escalation-on-linux
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-privileged-account-access-review
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-privileged-account-discovery
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-purple-team-exercise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ransomware-incident-response
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-ransomware-response
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ransomware-tabletop-exercise
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-red-team-phishing-with-gophish
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-red-team-with-covenant
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-s7comm-protocol-security-analysis
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-sca-dependency-scanning-with-snyk
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-scada-hmi-security-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-second-order-sql-injection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-security-headers-audit
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-serverless-function-security-review
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-service-account-audit
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-service-account-credential-rotation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-soap-web-service-security-testing
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-soc-tabletop-exercise
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-soc2-type2-audit-preparation
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-sqlite-database-forensics
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-ssl-certificate-lifecycle-management
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-ssl-stripping-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ssl-tls-inspection-configuration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ssl-tls-security-assessment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-ssrf-vulnerability-exploitation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-static-malware-analysis-with-pe-studio
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-steganography-detection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-subdomain-enumeration-with-subfinder
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-supply-chain-attack-simulation
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-thick-client-application-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-emulation-with-atomic-red-team
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-hunting-with-elastic-siem
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-hunting-with-yara-rules
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-intelligence-sharing-with-misp
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-landscape-assessment-for-sector
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-threat-modeling-with-owasp-threat-dragon
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-timeline-reconstruction-with-plaso
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-user-behavior-analytics
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-vlan-hopping-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-vulnerability-scanning-with-nessus
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-application-firewall-bypass
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-application-penetration-test
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-application-scanning-with-nikto
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-application-vulnerability-triage
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-cache-deception-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-web-cache-poisoning-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-wifi-password-cracking-with-aircrack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-windows-artifact-analysis-with-eric-zimmerman-tools
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-wireless-network-penetration-test
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── performing-wireless-security-assessment-with-kismet
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── performing-yara-rule-development-for-detection
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── prioritizing-vulnerabilities-with-cvss-scoring
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── processing-stix-taxii-feeds
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── profiling-threat-actor-groups
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── recovering-deleted-files-with-photorec
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── recovering-from-ransomware-attack
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── remediating-s3-bucket-misconfiguration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-android-malware-with-jadx
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-dotnet-malware-with-dnspy
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-ios-app-with-frida
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-malware-with-ghidra
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-ransomware-encryption-routine
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── reverse-engineering-rust-malware
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── scanning-container-images-with-grype
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── scanning-containers-with-trivy-in-cicd
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── scanning-docker-images-with-trivy
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── scanning-infrastructure-with-nessus
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── scanning-kubernetes-manifests-with-kubesec
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── scanning-network-with-nmap-advanced
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-api-gateway-with-aws-waf
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-aws-iam-permissions
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-aws-lambda-execution-roles
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-azure-with-microsoft-defender
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-container-registry-images
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-container-registry-with-harbor
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── securing-github-actions-workflows
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── securing-helm-chart-deployments
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── securing-historian-server-in-ot-environment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-kubernetes-on-cloud
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-remote-access-to-ot-environment
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── securing-serverless-functions
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-android-intents-for-vulnerabilities
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── testing-api-authentication-weaknesses
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-api-for-broken-object-level-authorization
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-api-for-mass-assignment-vulnerability
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-api-security-with-owasp-top-10
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-cors-misconfiguration
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-broken-access-control
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-business-logic-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-email-header-injection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-host-header-injection
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-json-web-token-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-open-redirect-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-sensitive-data-exposure
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-xml-injection-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-xss-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-xss-vulnerabilities-with-burpsuite
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-for-xxe-injection-vulnerabilities
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-jwt-token-security
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-mobile-api-authentication
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── testing-oauth2-implementation-flaws
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── testing-websocket-api-security
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── tracking-threat-actor-infrastructure
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       ├── triaging-security-alerts-in-splunk
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── triaging-security-incident
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   └── api-reference.md
│   │       │   ├── scripts
│   │       │   │   └── agent.py
│   │       │   └── SKILL.md
│   │       ├── triaging-security-incident-with-ir-playbook
│   │       │   ├── assets
│   │       │   │   └── template.md
│   │       │   ├── LICENSE
│   │       │   ├── references
│   │       │   │   ├── api-reference.md
│   │       │   │   ├── standards.md
│   │       │   │   └── workflows.md
│   │       │   ├── scripts
│   │       │   │   ├── agent.py
│   │       │   │   └── process.py
│   │       │   └── SKILL.md
│   │       └── triaging-vulnerabilities-with-ssvc-framework
│   │           ├── LICENSE
│   │           ├── references
│   │           │   ├── api-reference.md
│   │           │   ├── standards.md
│   │           │   └── workflows.md
│   │           ├── scripts
│   │           │   ├── agent.py
│   │           │   └── process.py
│   │           └── SKILL.md
│   ├── dependency-security.md
│   ├── dispatching-parallel-agents.md
│   ├── file-uploads.md
│   ├── firecrawl-scraper.md
│   ├── frontend-security-coder.md
│   ├── gdpr-data-handling-implementation-playbook.md
│   ├── gdpr-data-handling.md
│   ├── gitlab-automation.md
│   ├── helm-chart-scaffolding
│   │   ├── assets
│   │   │   ├── Chart.yaml.template
│   │   │   └── values.yaml.template
│   │   ├── helm-chart-scaffolding.md
│   │   ├── references
│   │   │   └── chart-structure.md
│   │   ├── resources
│   │   │   └── implementation-playbook.md
│   │   └── scripts
│   │       ├── validate-chart.sh
│   │       └── validate-chart.sh.backup
│   ├── incident-responder.md
│   ├── incident-response-smart-fix-implementation-playbook.md
│   ├── incident-response-smart-fix.md
│   ├── incident-runbook-templates.md
│   ├── injection-prevention.md
│   ├── injection.md
│   ├── input-validation.md
│   ├── insecure-design.md
│   ├── integrity-failures.md
│   ├── keyword-extractor.md
│   ├── lessons.md
│   ├── logging-monitoring.md
│   ├── mcp-builder
│   │   ├── reference
│   │   │   ├── evaluation.md
│   │   │   ├── mcp_best_practices.md
│   │   │   ├── node_mcp_server.md
│   │   │   └── python_mcp_server.md
│   │   └── scripts
│   │       ├── connections.py
│   │       ├── evaluation.py
│   │       ├── example_evaluation.xml
│   │       └── requirements.txt
│   ├── mcp-builder.md
│   ├── owasp-aisvs-appdev.md
│   ├── pci-compliance.md
│   ├── pentest-checklist.md
│   ├── pentest-commands.md
│   ├── postgresql-optimization.md
│   ├── postgresql.md
│   ├── powershell-windows.md
│   ├── prevention-strategies.md
│   ├── privacy-by-design.md
│   ├── privilege-escalation-methods.md
│   ├── python-packaging-implementation-playbook.md
│   ├── python-packaging.md
│   ├── python-patterns.md
│   ├── python-performance-optimization-implementation-playbook.md
│   ├── python-performance-optimization.md
│   ├── python-testing-patterns.md
│   ├── readme.md
│   ├── red-team-tactics.md
│   ├── red-team-tools.md
│   ├── reference-guide.md
│   ├── rust-doctor.md
│   ├── rust-pro.md
│   ├── rust.md
│   ├── sbom-implementation-playbook.md
│   ├── scanning-tools.md
│   ├── secrets-management.md
│   ├── security-api.md
│   ├── security-context.md
│   ├── security-headers.md
│   ├── security-misconfiguration.md
│   ├── security-owasp.md
│   ├── security-scanning-security-dependencies.md
│   ├── security-secrets.md
│   ├── sql-injection-testing.md
│   ├── sql-optimization-patterns .md
│   ├── sql-optimization-patterns-implementation-playbook.md
│   ├── sqlmap-database-pentesting.md
│   ├── ssrf.md
│   ├── terraform-infrastructure.md
│   ├── terraform-skill.md
│   ├── test-driven-development.md
│   ├── timestamp.md
│   ├── vulnerable-components.md
│   ├── wiki-architect.md
│   ├── wiki-researcher.md
│   └── xss-csrf.md
├── src
│   ├── build.rs
│   ├── fuzz_ext.rs
│   ├── fuzz_file_bytes.rs
│   ├── fuzz_mime.rs
│   ├── integration.rs
│   ├── lib.rs
│   └── main.rs
├── structure.txt
├── target
│   └── flycheck0
│       ├── stderr
│       └── stdout
├── test
├── tools
│   ├── git_config.sh
│   ├── git_config.sh.backup
│   ├── git_credential.sh
│   └── git_credential.sh.backup
├── tsconfig.json
└── Vulnerability_Disclosure_Policy.md

2530 directories, 4435 files
