Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة
az0307
ملف منشئ GitHub

az0307

عرض على مستوى المستودعات لـ 23 skills مجمعة عبر 2 مستودعات GitHub.

skills مجمعة
23
مستودعات
2
محدث
2026-06-25
مستكشف المستودعات

المستودعات و skills الممثلة

active-directory
محللو أمن المعلومات

Active Directory and Windows domain attack techniques including domain enumeration, Kerberos attacks, credential relay, lateral movement, and domain privilege escalation for internal penetration testing engagements. Use this skill whenever the user mentions Active Directory, AD attacks, domain enumeration, BloodHound, Kerberoasting, AS-REP roasting, pass the hash, pass the ticket, overpass the hash, golden ticket, silver ticket, DCSync, DCShadow, NTDS.dit extraction, LDAP enumeration, domain controller, Group Policy abuse, ACL abuse, delegation abuse, constrained delegation, unconstrained delegation, resource-based constrained delegation, ADCS attacks, certificate abuse, LAPS, gMSA, domain trust attacks, forest trust, or any Windows domain-focused penetration testing activity. Also trigger for: impacket, crackmapexec, evil-winrm, bloodhound-python, kerbrute, responder, ntlmrelayx, petitpotam, certipy, rubeus, mimikatz, powerview, sharphound, enum4linux, smbclient, rpcclient, "enumerate the domain", "dump doma

2026-06-25
audit-logger
محللو أمن المعلومات

Security engagement audit logging, evidence chain management, and compliance trail for penetration testing. Use this skill whenever the user mentions audit log, audit trail, engagement logging, evidence collection, chain of custody, compliance logging, pentest logging, tool execution logging, JSONL log, activity log, forensic evidence, engagement timeline, or any request to log, track, or document security testing activities. Also trigger for: "log this action", "create audit trail", "evidence chain", "what did we do", "engagement timeline", "export activity log", or when any other security skill needs to record its actions for compliance. This skill is called BY other skills — it is the universal logging layer.

2026-06-25
credential-attack
محللو أمن المعلومات

Password cracking, credential brute force, hash analysis, and authentication testing for penetration testing engagements. Use this skill whenever the user mentions password cracking, hash cracking, brute force attack, credential spraying, password spray, dictionary attack, hashcat, john the ripper, hydra, medusa, credential stuffing, NTLM hash, NTHash, NetNTLMv2, Kerberos ticket cracking, AS-REP roasting, Kerberoasting, hash identification, rainbow tables, wordlist generation, custom wordlists, CeWL, crunch, cupp, password policy analysis, or any request to crack, guess, or test credentials. Also trigger for: "crack these hashes", "brute force this login", "test default credentials", "generate a wordlist", "what hash type is this", "password audit", or any credential-related testing activity. Expert tools: hashcat (GPU), john (CPU), hydra (online brute force), crackmapexec (network cred testing), medusa (parallel brute force).

2026-06-25
ctf-walkthrough
معلمو التعليم العالي، جميع الآخرون

Generate structured CTF walkthrough writeups from engagement data, findings, and attack paths. Use this skill whenever the user mentions CTF writeup, walkthrough, write-up, CTF solution, box writeup, challenge writeup, HackTheBox writeup, TryHackMe writeup, "write up this box", "document how I solved", "create a walkthrough for", or any request to document a CTF/lab solution in educational format. Also trigger for: "writeup for HTB", "THM walkthrough", "document the attack path", "how did we solve this", or when red-team-report is called with engagement type CTF. Produces clean Markdown writeups with technique explanations, command output, and learning notes — suitable for blog posts or portfolio.

2026-06-25
exploit-dev
محللو أمن المعلومات

Exploit research, proof-of-concept development, controlled exploitation, and initial access verification for penetration testing engagements. Use this skill whenever the user mentions exploit development, PoC creation, Metasploit module execution, searchsploit, payload generation, msfvenom, exploit testing, vulnerability exploitation, initial access, shell access, reverse shell, bind shell, exploit chain, privilege escalation exploits, buffer overflow, web shell upload, or "can we exploit this finding". Also trigger for: ExploitDB search, Metasploit framework usage, custom exploit writing, payload encoding, exploit adaptation, weaponization, or any request to move from identified vulnerability to confirmed access. This is phase three of a pentest — trigger after vuln-analysis confirms exploitable findings, or standalone when the operator has a specific CVE. CRITICAL: All exploitation requires human approval before execution. The AI prepares commands and payloads but the operator confirms each run.

2026-06-25
network-forensics
محللو أمن المعلومات

Network traffic capture, packet analysis, protocol dissection, and digital evidence preservation for security engagements. Use this skill whenever the user mentions packet capture, pcap analysis, Wireshark, tshark, tcpdump, network forensics, traffic analysis, protocol analysis, packet inspection, network evidence, DNS analysis from captures, HTTP traffic extraction, credential sniffing from pcap, malware traffic analysis, C2 detection, network timeline reconstruction, or any task involving captured network data. Also trigger for: "capture traffic", "analyze this pcap", "what's in this capture", "extract files from pcap", "find credentials in traffic", "reconstruct network session", or any network evidence analysis task. Expert tools: tshark (CLI analysis), tcpdump (capture), Wireshark (GUI), NetworkMiner (artifact extraction), zeek (protocol logging).

2026-06-25
payload-craft
محللو أمن المعلومات

Custom payload generation, encoding, obfuscation, and delivery mechanism design for authorized penetration testing. Use this skill when the user mentions payload generation, msfvenom, reverse shell, bind shell, web shell, shellcode, payload encoding, AV evasion, payload obfuscation, custom exploit payload, stager, stageless, meterpreter payload, shell payload, PowerShell payload, Python payload, macro payload, HTA payload, or any request to generate code that establishes remote access on an authorized target. Also trigger for: "generate a reverse shell", "create a payload for", "encode this payload", "bypass AV", "craft a dropper", "listener setup", or any payload engineering task during an authorized engagement. Expert tools: msfvenom (Metasploit payloads), custom Python/Bash generators. CRITICAL: All payloads are for authorized testing only. Operator confirms target and scope before any payload is deployed.

2026-06-25
pentest-cheatsheet
محللو أمن المعلومات

Quick reference cheatsheet for penetration testing commands, techniques, and one-liners organized by phase and tool. Use this skill whenever the user asks for a cheatsheet, quick reference, one-liner, command syntax, "how do I use nmap/sqlmap/hashcat", "give me the command for", pentesting shortcuts, reverse shell one-liners, nmap flags, sqlmap syntax, hashcat modes, hydra syntax, ffuf usage, nuclei commands, or any request for a quick pentest command reference. Also trigger for: "remind me how to", "what's the flag for", "cheatsheet for", "quick reference", or when a user needs a specific command during an active engagement without wanting a full skill execution. This is a REFERENCE skill — it provides commands, not execution.

2026-06-25
عرض أهم 8 من أصل 17 skills مجمعة في هذا المستودع.
عرض 2 من أصل 2 مستودعات
تم تحميل كل المستودعات