Initial commit - 611 cybersecurity skills across all subdomains

This commit is contained in:
mukul975
2026-02-25 10:47:44 +01:00
commit 22a7ab1462
1765 changed files with 280648 additions and 0 deletions
@@ -0,0 +1,23 @@
# Standards and References - Agentless Vulnerability Scanning
## Tools and Platforms
- Vuls (Open Source): https://vuls.io/
- Microsoft Defender for Cloud Agentless: https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-agentless-data-collection
- Tenable Agentless Discovery: https://www.tenable.com/cloud-security/capabilities/agentless-asset-vulnerability-discovery
- Wiz Agentless VM: https://www.wiz.io/solutions/vulnerability-management
- Datadog Agentless Scanning: https://www.datadoghq.com/blog/agentless-scanning/
## Industry Standards
- **NIST SP 800-115**: Technical Guide to Information Security Testing and Assessment
- **CIS Controls v8.1 Control 7.5**: Perform Automated Vulnerability Scans of Internal Assets
- **PCI DSS v4.0 Req 11.3**: External and internal vulnerability scanning
- **ISO 27001:2022 A.8.8**: Management of technical vulnerabilities
## Protocol Requirements
| Protocol | Port | Auth Method | Use Case |
|----------|------|-------------|----------|
| SSH | 22 | Key-based or password | Linux/Unix scanning |
| WinRM | 5985/5986 | NTLM/Kerberos | Windows scanning |
| WMI | 135 + dynamic | NTLM | Windows legacy |
| SNMP v3 | 161 | AuthPriv | Network devices |
| Cloud APIs | 443 | IAM roles/keys | Cloud VMs |
@@ -0,0 +1,52 @@
# Workflows - Agentless Vulnerability Scanning
## Workflow 1: Multi-Protocol Scanning Pipeline
```
┌──────────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ Asset Discovery │────>│ Classify by │────>│ Select Scanning │
│ (CMDB/Network) │ │ OS / Platform │ │ Protocol │
└──────────────────┘ └──────────────────┘ └──────────────────┘
┌──────────────┬──────────────┬─────────────────┘
v v v
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ SSH Scan │ │ WinRM Scan │ │ Cloud API │
│ (Linux) │ │ (Windows) │ │ Snapshot Scan│
└──────────────┘ └──────────────┘ └──────────────┘
│ │ │
└──────────────┴──────────────┘
v
┌──────────────────┐
│ Normalize & │
│ Correlate Results│
└──────────────────┘
```
## Workflow 2: Cloud Snapshot Scan Process
```
For each cloud VM:
1. Identify attached volumes (root + data)
2. Create snapshot of root volume via cloud API
3. Mount snapshot in isolated analysis environment
4. Extract OS metadata (packages, configs, users)
5. Compare against vulnerability databases (NVD, vendor)
6. Generate findings with CVE mappings
7. Delete temporary snapshot
8. Report findings to central dashboard
```
## Workflow 3: Credential Validation Before Scan
```
Pre-Scan Credential Check:
For each target:
1. Test SSH/WinRM connectivity (TCP handshake)
2. Authenticate with stored credentials
3. Execute lightweight test command
4. Verify sudo/admin privileges if required
5. Log result: Success / Auth Failure / Network Error
6. Only proceed with scan if credential test passes
```