Offline evidence-linked attack-path analysis of user-supplied exports.
6 skillscybersecuritygraphattack-pathOffline authorized-scope reconciliation and passive attack surface test planning.
9 skillscybersecurityoffensive-securityattack-surfaceEvaluate detection rule quality, dependencies, schema drift, and regression baselines for Sentinel KQL and Splunk SPL.
1 skillcybersecurityregression-testingdetection-engineeringModel, analyze, and review Entra ID and AI Agent identity graphs, privilege boundaries, and exposure paths offline.
1 skillazurecybersecurityidentityAuthor adversarial scenarios and evaluate Microsoft Foundry and Semantic Kernel agents against deterministic mock sandboxes.
1 skillcybersecurityprompt-injectionfoundryOffline incident action planning and fixture-only sandbox execution.
1 skillcybersecurityincident-responsesandboxBounded offline security review of an immutable Git commit pair.
1 skillappsecvulnerability-managementpatch-reviewReview repository signals and produce cost-aware security logging recommendations.
3 skillsauditcybersecuritytelemetryAuthor and stress-test defensive Microsoft hunting workflows with deterministic offline evidence.
6 skillscybersecuritykqlsentinelPlan and review local evidence-backed SOC investigations; external hunt integration remains pending.
2 skillscybersecurityinvestigationdetectionTrace synthetic test markers across Cribl Stream routing, Splunk and Sentinel indexing, and detection evaluation to prove pipeline health.
1 skillcybersecuritytelemetrydetection-engineeringRead-only source-specific threat intelligence lookups with explicit privacy approval and bounded requests.
1 skillcybersecurityenrichmentmicrosoft
