Total 52,033 skills, Security & Compliance has 2053 skills
Showing 12 of 2053 skills
Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis (Received chain, Message-ID, SPF/DKIM/DMARC). Use for email OSINT, verifying whether an address exists, finding accounts registered to an address, guessing a company's email format, or tracing where a message actually came from.
Enumerate a username across hundreds of platforms with sherlock, maigret, and WhatsMyName, then correlate and confirm which accounts belong to the same person. Use for username OSINT, handle enumeration, "find all accounts for this username", cross-platform account correlation, nickname or screen-name pivots, or turning a handle into a real name.
Investigate a phone number — E.164 normalisation with libphonenumber, phoneinfoga scanning, carrier and line-type identification, VoIP and burner detection, messaging-app registration checks, and reverse-lookup and caller-ID sources. Use for phone OSINT, reverse phone lookup, "who owns this number", identifying a burner or VoIP number, or checking whether a number is on WhatsApp, Telegram, or Signal.
Mine GitHub, GitLab, and git history for identities, infrastructure, and leaked credentials using commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe, and full-ref history scans. Use when investigating a developer or organisation on GitHub, finding leaked API keys, AWS access keys or tokens in code, enumerating org members and their personal repos, recovering secrets deleted from HEAD but present in history or forks, or checking exposed .git directories, gists, and CI logs.
Deep-dive a subject's social media presence — profile metadata, follower and mutual network, content analysis, and posting-time pattern of life across Instagram, Facebook, X/Twitter, TikTok, LinkedIn, Reddit, Telegram and Discord. Use when profiling a social account, mapping someone's friends and family, inferring a target's timezone, routine, home or workplace from their posts, or archiving a profile before it's deleted.
Find internet-exposed hosts, ports, services and devices using third-party internet-scan data. Use when searching Shodan or Censys, writing Shodan filter queries, reading service banners, checking open ports on an IP or netblock, pivoting on favicon hashes or TLS certificate fingerprints, hunting origin IPs behind Cloudflare or a CDN, or looking for exposed databases, dashboards, cameras and ICS devices without scanning the target.
Enumerate an organization's subdomains and sibling domains from Certificate Transparency logs and passive DNS. Use when looking for hidden, staging, dev, or VPN hosts, querying crt.sh or CT logs, reading certificate SAN fields, running subfinder or amass, doing subdomain enumeration or DNS brute-forcing, checking newly issued TLS certificates, or mapping the full hostname footprint of a domain.
Build an entity-relationship link-analysis graph of an investigation — nodes, typed edges with source and confidence, aliases, and temporal validity — to expose shared infrastructure, bridging nodes, and the real principal behind a frontman. Use for link analysis, network mapping, Maltego graphs, Neo4j/Cypher or Gephi work, centrality and community detection, entity resolution and deduplication, or visualising how selectors and pivots connect.
End-to-end passive reconnaissance workflow for a domain, website, or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending traffic to the target.
Craft advanced search-engine queries and Google dorks to surface hidden files, documents, and mentions. Use when building a Google dork, using search operators (site:, filetype:, inurl:, intitle:, intext:, before:/after:), forcing verbatim/exact-match search, finding exposed directory listings, config files, backups, or open S3 buckets, searching paste sites and document repositories for a name, email, or leaked selector, or comparing Google against Bing, DuckDuckGo, and Yandex operators.
Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP, and adverse media. Use for vendor and counterparty risk, KYC/KYB, M&A diligence, investor checks, or shell-company assessment.
Plans migrations from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE stacks to Cloudflare One. Use for migration assessments, policy mapping, rollout plans, and parity/gap analysis.