Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Casky was already ahead
This CVE exploits attack patterns that Casky's 439matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-16353 is a critical use-after-free vulnerability (CVSS 9.8) in Firefox and Thunderbird's DOM Bindings (WebIDL) implementation that allows attackers to corrupt memory through invalid pointer manipulation. The vulnerability affects the fundamental JavaScript-to-C++ interface layer that handles all DOM interactions, making it broadly exploitable across any Firefox-based browser activity. This impacts all Firefox users running versions prior to 153, Firefox ESR users below 115.38 or 140.13, and Thunderbird users below 153 or 140.13—affecting millions of endpoints globally and presenting immediate risk for arbitrary code execution and data theft.
Casky's 439 mapped skills detect exploitation chains targeting this vulnerability by analyzing patterns across multiple MITRE ATT&CK phases: Initial Access (TA0001) through malicious web content delivery, Execution (TA0002) via JavaScript-triggered memory corruption, Persistence (TA0003) through code execution, Privilege Escalation (TA0004), and Exfiltration (TA0010) of sensitive data. Practitioners using Casky's Claude-powered analysis would identify suspicious DOM manipulation sequences, unusual memory access patterns during WebIDL binding operations, and behavioral indicators like unexpected process elevation or browser sandbox escapes. The platform's extended reasoning capability correlates seemingly benign DOM operations with their potential to trigger the pointer corruption pathway, flagging attack chains that traditional signature-based detection misses—enabling security teams to catch exploitation attempts before successful compromise.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
These skills use Claude AI's reasoning model to surface findings in the same attack categories as CVE-2026-16353.
Casky has 439 skills that investigate the attack patterns behind CVE-2026-16353. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →Account Takeover
red teaming · high
Account Takeover
incident response · low
Account Takeover
red teaming · high
Account Takeover: Exposed API Key
digital forensics · low
Account Takeover: Exposed Login Credential
soc operations · low
Account Takeover: Exposed Login Credential
incident response · low
Account Takeover: Exposed Login Credential
threat hunting · low
Account Takeover: Exposed Login Credential
red teaming · high
acquiring-disk-image-with-dd-and-dcfldd
digital forensics · low
Adversary-in-the-Browser: Malicious JavaScript Injection
network security · medium
analyzing-android-malware-with-apktool
malware analysis · medium
analyzing-apt-group-with-mitre-navigator
threat intelligence · low
analyzing-bootkit-and-rootkit-samples
malware analysis · medium
analyzing-browser-forensics-with-hindsight
digital forensics · low
analyzing-campaign-attribution-evidence
threat intelligence · low
analyzing-cobalt-strike-beacon-configuration
malware analysis · medium
analyzing-cobaltstrike-malleable-c2-profiles
malware analysis · medium
analyzing-command-and-control-communication
malware analysis · medium
analyzing-cyber-kill-chain
threat intelligence · low
analyzing-disk-image-with-autopsy
digital forensics · low
analyzing-dns-logs-for-exfiltration
soc operations · low
analyzing-docker-container-forensics
digital forensics · low
analyzing-golang-malware-with-ghidra
malware analysis · medium
analyzing-heap-spray-exploitation
malware analysis · medium
analyzing-kubernetes-audit-logs
container security · low
analyzing-linux-audit-logs-for-intrusion
incident response · low
analyzing-linux-kernel-rootkits
digital forensics · low
analyzing-linux-system-artifacts
digital forensics · low
analyzing-lnk-file-and-jump-list-artifacts
digital forensics · low
analyzing-macro-malware-in-office-documents
malware analysis · medium
analyzing-malicious-pdf-with-peepdf
malware analysis · medium
analyzing-malware-behavior-with-cuckoo-sandbox
malware analysis · medium
analyzing-malware-family-relationships-with-malpedia
threat intelligence · low
analyzing-malware-persistence-with-autoruns
malware analysis · medium
analyzing-malware-sandbox-evasion-techniques
malware analysis · medium
analyzing-memory-dumps-with-volatility
malware analysis · medium
analyzing-mft-for-deleted-file-recovery
digital forensics · low
analyzing-network-covert-channels-in-malware
malware analysis · medium
analyzing-network-flow-data-with-netflow
network security · medium
analyzing-network-packets-with-scapy
network security · medium
analyzing-network-traffic-for-incidents
incident response · low
analyzing-network-traffic-of-malware
malware analysis · medium
analyzing-network-traffic-with-wireshark
network security · medium
analyzing-outlook-pst-for-email-forensics
digital forensics · low
analyzing-packed-malware-with-upx-unpacker
malware analysis · medium
analyzing-pdf-malware-with-pdfid
malware analysis · medium
analyzing-persistence-mechanisms-in-linux
threat hunting · low
analyzing-powershell-empire-artifacts
threat hunting · low
analyzing-prefetch-files-for-execution-history
digital forensics · low
analyzing-security-logs-with-splunk
incident response · low
analyzing-slack-space-and-file-system-artifacts
digital forensics · low
analyzing-supply-chain-malware-artifacts
malware analysis · medium
analyzing-threat-actor-ttps-with-mitre-attack
threat intelligence · low
analyzing-threat-actor-ttps-with-mitre-navigator
threat intelligence · low
analyzing-threat-intelligence-feeds
threat intelligence · low
analyzing-threat-landscape-with-misp
threat intelligence · low
analyzing-usb-device-connection-history
digital forensics · low
analyzing-windows-amcache-artifacts
digital forensics · low
analyzing-windows-event-logs-in-splunk
soc operations · low
analyzing-windows-lnk-files-for-artifacts
digital forensics · low
analyzing-windows-prefetch-with-python
digital forensics · low
analyzing-windows-registry-for-artifacts
digital forensics · low
analyzing-windows-shellbag-artifacts
digital forensics · low
auditing-kubernetes-rbac-privilege-escalation
container security · low
auditing-tls-certificate-transparency-logs
threat intelligence · low
automating-ioc-enrichment
threat intelligence · low
benchmarking-kubernetes-with-kube-bench
container security · low
Brute Force: Credential Stuffing
threat intelligence · low
building-adversary-infrastructure-tracking-system
threat intelligence · low
building-attack-pattern-library-from-cti-reports
threat intelligence · low
building-automated-malware-submission-pipeline
soc operations · low
building-c2-infrastructure-with-sliver-framework
red teaming · high
building-c2-redirector-infrastructure
red teaming · high
building-detection-rule-with-splunk-spl
soc operations · low
building-detection-rules-with-sigma
soc operations · low
building-incident-response-dashboard
soc operations · low
building-incident-response-playbook
incident response · low
building-incident-timeline-with-timesketch
incident response · low
building-ioc-defanging-and-sharing-pipeline
threat intelligence · low
building-ioc-enrichment-pipeline-with-opencti
threat intelligence · low
building-malware-incident-communication-template
incident response · low
building-red-team-c2-infrastructure-with-havoc
red teaming · high
building-soc-escalation-matrix
soc operations · low
building-soc-metrics-and-kpi-tracking
soc operations · low
building-super-timelines-with-plaso
digital forensics · low
building-threat-actor-profile-from-osint
threat intelligence · low
building-threat-feed-aggregation-with-misp
threat intelligence · low
building-threat-hunt-hypothesis-framework
threat hunting · low
building-threat-intelligence-enrichment-in-splunk
soc operations · low
building-threat-intelligence-feed-integration
soc operations · low
building-threat-intelligence-platform
threat intelligence · low
building-vulnerability-scanning-workflow
soc operations · low
coercing-authentication-with-coercer-petitpotam
red teaming · high
collecting-indicators-of-compromise
incident response · low
collecting-open-source-intelligence
threat intelligence · low
collecting-threat-intelligence-with-misp
threat intelligence · low
collecting-volatile-evidence-from-compromised-host
incident response · low
conducting-api-security-testing
penetration testing · medium
conducting-cloud-incident-response
incident response · low
conducting-domain-persistence-with-dcsync
red teaming · high
conducting-external-reconnaissance-with-osint
penetration testing · medium
conducting-full-scope-red-team-engagement
red teaming · high
conducting-internal-network-penetration-test
penetration testing · medium
conducting-internal-reconnaissance-with-bloodhound-ce
red teaming · high
conducting-malware-incident-response
incident response · low
conducting-man-in-the-middle-attack-simulation
network security · medium
conducting-memory-forensics-with-volatility
incident response · low
conducting-mobile-app-penetration-test
penetration testing · medium
conducting-network-penetration-test
penetration testing · medium
conducting-pass-the-ticket-attack
red teaming · high
conducting-post-incident-lessons-learned
incident response · low
conducting-wireless-network-penetration-test
penetration testing · medium
configuring-host-based-intrusion-detection
endpoint security · low
configuring-network-segmentation-with-vlans
network security · medium
configuring-pfsense-firewall-rules
network security · medium
configuring-snort-ids-for-intrusion-detection
network security · medium
configuring-suricata-for-network-monitoring
network security · medium
configuring-windows-defender-advanced-settings
endpoint security · low
configuring-windows-event-logging-for-detection
endpoint security · low
containing-active-breach
incident response · low
Conversion to Physical Monetary Instruments: Cash
ransomware defense · medium
Conversion to Physical Monetary Instruments: Cash
incident response · low
Conversion to Physical Monetary Instruments: Cash
incident response · low
Conversion to Physical Monetary Instruments: Cash
ransomware defense · medium
Conversion to Physical Monetary Instruments: Cash
digital forensics · low
Convert to Cryptocurrency
ransomware defense · medium
Convert to Cryptocurrency
ransomware defense · medium
correlating-security-events-in-qradar
soc operations · low
correlating-threat-campaigns
threat intelligence · low
Create Fake Materials: Fake Website
penetration testing · medium
Create Fake Materials: Fake Website
threat intelligence · low
Create Fake Materials: Fake Website
digital forensics · low
Create Fake Materials: Fake Website
threat hunting · low
deobfuscating-javascript-malware
malware analysis · medium
deobfuscating-powershell-obfuscated-malware
malware analysis · medium
deploying-edr-agent-with-crowdstrike
endpoint security · low
deploying-osquery-for-endpoint-monitoring
endpoint security · low
detecting-anomalies-in-industrial-control-systems
ot ics security · medium
detecting-arp-poisoning-in-network-traffic
network security · medium
detecting-attacks-on-historian-servers
ot ics security · medium
detecting-attacks-on-scada-systems
ot ics security · medium
detecting-command-and-control-over-dns
network security · medium
detecting-container-drift-at-runtime
container security · low
detecting-container-escape-attempts
container security · low
detecting-container-escape-with-falco-rules
container security · low
detecting-container-runtime-threats-with-falco
container security · low
detecting-dcsync-attack-in-active-directory
threat hunting · low
detecting-dll-sideloading-attacks
threat hunting · low
detecting-dnp3-protocol-anomalies
ot ics security · medium
detecting-dns-exfiltration-with-dns-query-analysis
network security · medium
detecting-email-account-compromise
incident response · low
detecting-email-forwarding-rules-attack
threat hunting · low
detecting-entra-offensive-tools-in-graph-logs
soc operations · low
detecting-evasion-techniques-in-endpoint-logs
endpoint security · low
detecting-exfiltration-over-dns-with-zeek
network security · medium
detecting-fileless-attacks-on-endpoints
endpoint security · low
detecting-fileless-malware-techniques
malware analysis · medium
detecting-golden-ticket-attacks-in-kerberos-logs
threat hunting · low
detecting-insider-threat-behaviors
threat hunting · low
detecting-kerberoasting-attacks
threat hunting · low
detecting-lateral-movement-in-network
network security · medium
detecting-lateral-movement-with-splunk
threat hunting · low
detecting-lateral-movement-with-zeek
network security · medium
detecting-malicious-scheduled-tasks-with-sysmon
threat hunting · low
detecting-mimikatz-execution-patterns
threat hunting · low
detecting-modbus-command-injection-attacks
ot ics security · medium
detecting-modbus-protocol-anomalies
ot ics security · medium
detecting-network-anomalies-with-zeek
network security · medium
detecting-network-scanning-with-ids-signatures
network security · medium
detecting-ntlm-relay-with-event-correlation
threat hunting · low
detecting-pass-the-hash-attacks
threat hunting · low
detecting-port-scanning-with-fail2ban
network security · medium
detecting-privilege-escalation-attempts
threat hunting · low
detecting-privilege-escalation-in-kubernetes-pods
container security · low
detecting-process-hollowing-technique
threat hunting · low
detecting-process-injection-techniques
malware analysis · medium
detecting-rootkit-activity
malware analysis · medium
detecting-service-account-abuse
threat hunting · low
detecting-stuxnet-style-attacks
ot ics security · medium
detecting-suspicious-powershell-execution
threat hunting · low
detecting-t1055-process-injection-with-sysmon
threat hunting · low
detecting-t1548-abuse-elevation-control-mechanism
threat hunting · low
detecting-wmi-persistence
threat hunting · low
Electronic Funds Transfer: Wire Transfer
ransomware defense · medium
Electronic Funds Transfer: Wire Transfer
threat intelligence · low
Email Spoofing
threat intelligence · low
eradicating-malware-from-infected-systems
incident response · low
escaping-containers-to-host
container security · low
evaluating-threat-intelligence-platforms
threat intelligence · low
executing-active-directory-attack-simulation
penetration testing · medium
executing-red-team-engagement-planning
red teaming · high
executing-red-team-exercise
penetration testing · medium
exploiting-active-directory-certificate-services-esc1
red teaming · high
exploiting-active-directory-with-bloodhound
red teaming · high
exploiting-adcs-with-certipy
red teaming · high
exploiting-bgp-hijacking-vulnerabilities
network security · medium
exploiting-constrained-delegation-abuse
red teaming · high
exploiting-ipv6-vulnerabilities
network security · medium
exploiting-kerberoasting-with-impacket
red teaming · high
exploiting-ms17-010-eternalblue-vulnerability
red teaming · high
exploiting-nopac-cve-2021-42278-42287
red teaming · high
exploiting-smb-vulnerabilities-with-metasploit
network security · medium
exploiting-sql-injection-vulnerabilities
penetration testing · medium
exploiting-zerologon-vulnerability-cve-2020-1472
red teaming · high
extracting-browser-history-artifacts
digital forensics · low
extracting-config-from-agent-tesla-rat
malware analysis · medium
extracting-iocs-from-malware-samples
malware analysis · medium
extracting-windows-event-logs-artifacts
digital forensics · low
fleet-hunting-with-velociraptor
threat hunting · low
Gather Customer Information
threat intelligence · low
generating-forensic-timelines-with-hayabusa
digital forensics · low
generating-threat-intelligence-reports
threat intelligence · low
hardening-docker-containers-for-production
container security · low
hardening-docker-daemon-configuration
container security · low
hardening-linux-endpoint-with-cis-benchmark
endpoint security · low
hardening-windows-endpoint-with-cis-benchmark
endpoint security · low
hunting-advanced-persistent-threats
threat intelligence · low
hunting-evtx-with-chainsaw
threat hunting · low
hunting-for-anomalous-powershell-execution
threat hunting · low
hunting-for-beaconing-with-frequency-analysis
threat hunting · low
hunting-for-cobalt-strike-beacons
threat hunting · low
hunting-for-command-and-control-beaconing
threat hunting · low
hunting-for-data-exfiltration-indicators
threat hunting · low
hunting-for-data-staging-before-exfiltration
threat hunting · low
hunting-for-dcom-lateral-movement
threat hunting · low
hunting-for-dcsync-attacks
threat hunting · low
hunting-for-defense-evasion-via-timestomping
threat hunting · low
hunting-for-dns-based-persistence
threat hunting · low
hunting-for-dns-tunneling-with-zeek
threat hunting · low
hunting-for-domain-fronting-c2-traffic
threat hunting · low
hunting-for-lateral-movement-via-wmi
threat hunting · low
hunting-for-living-off-the-cloud-techniques
threat hunting · low
hunting-for-living-off-the-land-binaries
threat hunting · low
hunting-for-lolbins-execution-in-endpoint-logs
threat hunting · low
hunting-for-ntlm-relay-attacks
threat hunting · low
hunting-for-persistence-mechanisms-in-windows
threat hunting · low
hunting-for-persistence-via-wmi-subscriptions
threat hunting · low
hunting-for-process-injection-techniques
threat hunting · low
hunting-for-registry-persistence-mechanisms
threat hunting · low
hunting-for-registry-run-key-persistence
threat hunting · low
hunting-for-scheduled-task-persistence
threat hunting · low
hunting-for-shadow-copy-deletion
threat hunting · low
hunting-for-startup-folder-persistence
threat hunting · low
hunting-for-supply-chain-compromise
threat hunting · low
hunting-for-suspicious-scheduled-tasks
threat hunting · low
hunting-for-t1098-account-manipulation
threat hunting · low
hunting-for-unusual-network-connections
threat hunting · low
hunting-for-unusual-service-installations
threat hunting · low
hunting-for-webshell-activity
threat hunting · low
hunting-saas-sso-token-abuse
soc operations · low
implementing-alert-fatigue-reduction
soc operations · low
implementing-application-whitelisting-with-applocker
endpoint security · low
implementing-bgp-security-with-rpki
network security · medium
implementing-conduit-security-for-ot-remote-access
ot ics security · medium
implementing-container-image-minimal-base-with-distroless
container security · low
implementing-container-network-policies-with-calico
container security · low
implementing-ddos-mitigation-with-cloudflare
network security · medium
implementing-diamond-model-analysis
threat intelligence · low
implementing-disk-encryption-with-bitlocker
endpoint security · low
implementing-dragos-platform-for-ot-monitoring
ot ics security · medium
implementing-endpoint-dlp-controls
endpoint security · low
implementing-file-integrity-monitoring-with-aide
endpoint security · low
implementing-ics-firewall-with-tofino
ot ics security · medium
implementing-iec-62443-security-zones
ot ics security · medium
implementing-image-provenance-verification-with-cosign
container security · low
implementing-immutable-backup-with-restic
ransomware defense · medium
implementing-kubernetes-network-policy-with-calico
container security · low
implementing-kubernetes-pod-security-standards
container security · low
implementing-memory-protection-with-dep-aslr
endpoint security · low
implementing-mitre-attack-coverage-mapping
soc operations · low
implementing-nerc-cip-compliance-controls
ot ics security · medium
implementing-network-access-control
network security · medium
implementing-network-access-control-with-cisco-ise
network security · medium
implementing-network-intrusion-prevention-with-suricata
network security · medium
implementing-network-policies-for-kubernetes
container security · low
implementing-network-segmentation-for-ot
ot ics security · medium
implementing-network-segmentation-with-firewall-zones
network security · medium
implementing-network-traffic-analysis-with-arkime
network security · medium
implementing-network-traffic-baselining
network security · medium
implementing-next-generation-firewall-with-palo-alto
network security · medium
implementing-opa-gatekeeper-for-policy-enforcement
container security · low
implementing-ot-incident-response-playbook
ot ics security · medium
implementing-ot-network-traffic-analysis-with-nozomi
ot ics security · medium
implementing-patch-management-for-ot-systems
ot ics security · medium
implementing-pod-security-admission-controller
container security · low
implementing-purdue-model-network-segmentation
ot ics security · medium
implementing-rbac-hardening-for-kubernetes
container security · low
implementing-runtime-security-with-tetragon
container security · low
implementing-security-information-sharing-with-stix2
threat intelligence · low
implementing-siem-use-cases-for-detection
soc operations · low
implementing-soar-automation-with-phantom
soc operations · low
implementing-soar-playbook-with-palo-alto-xsoar
soc operations · low
implementing-stix-taxii-feed-integration
threat intelligence · low
implementing-supply-chain-security-with-in-toto
container security · low
implementing-taxii-server-with-opentaxii
threat intelligence · low
implementing-threat-intelligence-lifecycle-management
threat intelligence · low
implementing-threat-modeling-with-mitre-attack
soc operations · low
implementing-ticketing-system-for-incidents
soc operations · low
implementing-usb-device-control-policy
endpoint security · low
implementing-velociraptor-for-ir-collection
incident response · low
Indicator Removal
ransomware defense · medium
Indicator Removal
ransomware defense · medium
Insider Access Abuse
ransomware defense · medium
investigating-insider-threat-indicators
soc operations · low
managing-intelligence-lifecycle
threat intelligence · low
mapping-attack-paths-with-bloodhound-ce
red teaming · high
mapping-mitre-attack-techniques
threat intelligence · low
modeling-threats-with-opencti
threat intelligence · low
moving-laterally-with-netexec
penetration testing · medium
operating-havoc-c2
red teaming · high
operating-sliver-c2
red teaming · high
operationalizing-misp-threat-feeds
threat intelligence · low
parsing-artifacts-with-eric-zimmerman-tools
digital forensics · low
performing-active-directory-bloodhound-analysis
red teaming · high
performing-active-directory-compromise-investigation
incident response · low
performing-active-directory-penetration-test
penetration testing · medium
performing-ai-driven-osint-correlation
threat intelligence · low
performing-alert-triage-with-elastic-siem
soc operations · low
performing-arp-spoofing-attack-simulation
network security · medium
performing-automated-malware-analysis-with-cape
malware analysis · medium
performing-bandwidth-throttling-attack-simulation
network security · medium
performing-cloud-forensics-investigation
digital forensics · low
performing-cloud-incident-containment-procedures
incident response · low
performing-cloud-storage-forensic-acquisition
digital forensics · low
performing-container-escape-detection
container security · low
performing-container-security-scanning-with-trivy
container security · low
performing-dark-web-monitoring-for-threats
threat intelligence · low
performing-deception-technology-deployment
soc operations · low
performing-disk-forensics-investigation
incident response · low
performing-dns-enumeration-and-zone-transfer
network security · medium
performing-docker-bench-security-assessment
container security · low
performing-dynamic-analysis-with-any-run
malware analysis · medium
performing-endpoint-forensics-investigation
endpoint security · low
performing-endpoint-vulnerability-remediation
endpoint security · low
performing-external-network-penetration-test
penetration testing · medium
performing-false-positive-reduction-in-siem
soc operations · low
performing-file-carving-with-foremost
digital forensics · low
performing-firmware-malware-analysis
malware analysis · medium
performing-ics-asset-discovery-with-claroty
ot ics security · medium
performing-indicator-lifecycle-management
threat intelligence · low
performing-insider-threat-investigation
incident response · low
performing-ioc-enrichment-automation
soc operations · low
performing-iot-security-assessment
penetration testing · medium
performing-ip-reputation-analysis-with-shodan
threat intelligence · low
performing-kerberoasting-attack
red teaming · high
performing-kubernetes-cis-benchmark-with-kube-bench
container security · low
performing-kubernetes-etcd-security-assessment
container security · low
performing-kubernetes-penetration-testing
container security · low
performing-lateral-movement-detection
soc operations · low
performing-lateral-movement-with-wmiexec
red teaming · high
performing-linux-log-forensics-investigation
digital forensics · low
performing-log-analysis-for-forensic-investigation
digital forensics · low
performing-log-source-onboarding-in-siem
soc operations · low
performing-malware-hash-enrichment-with-virustotal
threat intelligence · low
performing-malware-ioc-extraction
threat intelligence · low
performing-malware-persistence-investigation
digital forensics · low
performing-malware-triage-with-yara
malware analysis · medium
performing-memory-forensics-with-volatility3
digital forensics · low
performing-memory-forensics-with-volatility3-plugins
malware analysis · medium
performing-mobile-device-forensics-with-cellebrite
digital forensics · low
performing-network-forensics-with-wireshark
digital forensics · low
performing-network-packet-capture-analysis
digital forensics · low
performing-network-traffic-analysis-with-tshark
network security · medium
performing-network-traffic-analysis-with-zeek
network security · medium
performing-oil-gas-cybersecurity-assessment
ot ics security · medium
performing-open-source-intelligence-gathering
red teaming · high
performing-osint-with-spiderfoot
threat intelligence · low
performing-ot-network-security-assessment
ot ics security · medium
performing-ot-vulnerability-assessment-with-claroty
ot ics security · medium
performing-ot-vulnerability-scanning-safely
ot ics security · medium
performing-packet-injection-attack
network security · medium
performing-physical-intrusion-assessment
red teaming · high
performing-plc-firmware-security-analysis
ot ics security · medium
performing-power-grid-cybersecurity-assessment
ot ics security · medium
performing-privilege-escalation-assessment
penetration testing · medium
performing-privilege-escalation-on-linux
red teaming · high
performing-purple-team-exercise
soc operations · low
performing-s7comm-protocol-security-analysis
ot ics security · medium
performing-scada-hmi-security-assessment
ot ics security · medium
performing-soc-tabletop-exercise
soc operations · low
performing-sqlite-database-forensics
digital forensics · low
performing-ssl-stripping-attack
network security · medium
performing-ssl-tls-inspection-configuration
network security · medium
performing-ssl-tls-security-assessment
network security · medium
performing-static-malware-analysis-with-pe-studio
malware analysis · medium
performing-steganography-detection
digital forensics · low
performing-thick-client-application-penetration-test
penetration testing · medium
performing-threat-emulation-with-atomic-red-team
threat intelligence · low
performing-threat-hunting-with-elastic-siem
soc operations · low
performing-threat-hunting-with-yara-rules
threat hunting · low
performing-threat-intelligence-sharing-with-misp
threat intelligence · low
performing-threat-landscape-assessment-for-sector
threat intelligence · low
performing-timeline-reconstruction-with-plaso
digital forensics · low
performing-user-behavior-analytics
soc operations · low
performing-vlan-hopping-attack
network security · medium
performing-vulnerability-scanning-with-nessus
penetration testing · medium
performing-web-application-penetration-test
penetration testing · medium
performing-wifi-password-cracking-with-aircrack
network security · medium
performing-windows-artifact-analysis-with-eric-zimmerman-tools
digital forensics · low
performing-wireless-network-penetration-test
penetration testing · medium
performing-wireless-security-assessment-with-kismet
network security · medium
performing-yara-rule-development-for-detection
malware analysis · medium
Phishing
threat intelligence · low
Phishing
threat intelligence · low
Phone Number Spoofing: Official Phone Number Spoofing
red teaming · high
processing-stix-taxii-feeds
threat intelligence · low
profiling-threat-actor-groups
threat intelligence · low
recovering-deleted-files-with-photorec
digital forensics · low
relaying-ntlm-for-adcs-esc8
red teaming · high
Remote Access Tools
malware analysis · medium
Remote Access Tools
malware analysis · medium
Remote Access Tools
ransomware defense · medium
reverse-engineering-android-malware-with-jadx
malware analysis · medium
reverse-engineering-dotnet-malware-with-dnspy
malware analysis · medium
reverse-engineering-malware-with-ghidra
malware analysis · medium
reverse-engineering-rust-malware
malware analysis · medium
scanning-container-images-with-grype
container security · low
scanning-docker-images-with-trivy
container security · low
scanning-kubernetes-manifests-with-kubesec
container security · low
scanning-network-with-nmap-advanced
network security · medium
securing-container-registry-with-harbor
container security · low
securing-helm-chart-deployments
container security · low
securing-historian-server-in-ot-environment
ot ics security · medium
securing-remote-access-to-ot-environment
ot ics security · medium
Stage Capabilities: SEO Poisoning
threat intelligence · low
Structuring
ransomware defense · medium
testing-for-xss-vulnerabilities
penetration testing · medium
Transfer of funds
threat hunting · low
Transfer of funds
ransomware defense · medium
Transfer of funds
malware analysis · medium
Transfer of funds
soc operations · low
Transfer of funds
ransomware defense · medium
triaging-security-alerts-in-splunk
soc operations · low
triaging-security-incident
incident response · low
triaging-security-incident-with-ir-playbook
incident response · low
triaging-windows-with-kape
digital forensics · low
© 2026 Casky.AI, Inc. · AI Security Investigation