macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
لغة النص الأصلي: الإنجليزية
القائمة
جمع SkillsMP عدد ٧٬٤٤٢ من skills من CyberStrikeus/CyberStrike. افتح أي skill لمراجعة مصدره وتفاصيله.
عرض ٤٠ من أصل ٧٬٤٤٢ skills مجمعة.
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
لغة النص الأصلي: الإنجليزية
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
لغة النص الأصلي: الإنجليزية
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
لغة النص الأصلي: الإنجليزية
READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
لغة النص الأصلي: الإنجليزية
READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
لغة النص الأصلي: الإنجليزية
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
لغة النص الأصلي: الإنجليزية
Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
لغة النص الأصلي: الإنجليزية
GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
لغة النص الأصلي: الإنجليزية
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
لغة النص الأصلي: الإنجليزية
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
لغة النص الأصلي: الإنجليزية
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
لغة النص الأصلي: الإنجليزية
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
لغة النص الأصلي: الإنجليزية
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
لغة النص الأصلي: الإنجليزية
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
لغة النص الأصلي: الإنجليزية
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
لغة النص الأصلي: الإنجليزية
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
لغة النص الأصلي: الإنجليزية
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
لغة النص الأصلي: الإنجليزية
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
لغة النص الأصلي: الإنجليزية
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
لغة النص الأصلي: الإنجليزية
Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
لغة النص الأصلي: الإنجليزية
Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
لغة النص الأصلي: الإنجليزية
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
لغة النص الأصلي: الإنجليزية
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
لغة النص الأصلي: الإنجليزية
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
لغة النص الأصلي: الإنجليزية
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
لغة النص الأصلي: الإنجليزية
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
لغة النص الأصلي: الإنجليزية
XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
لغة النص الأصلي: الإنجليزية
Active Directory security testing and attack techniques
لغة النص الأصلي: الإنجليزية
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
لغة النص الأصلي: الإنجليزية
Kerberos protocol attack techniques and exploitation
لغة النص الأصلي: الإنجليزية
Bug bounty and pentest reconnaissance methodology
لغة النص الأصلي: الإنجليزية
API Testing Overview
لغة النص الأصلي: الإنجليزية
API Reconnaissance
لغة النص الأصلي: الإنجليزية
Testing for Broken Object Level Authorization (BOLA)
لغة النص الأصلي: الإنجليزية
Testing GraphQL
لغة النص الأصلي: الإنجليزية
Testing for Credentials Transported over an Encrypted Channel
لغة النص الأصلي: الإنجليزية
Testing for Default Credentials
لغة النص الأصلي: الإنجليزية
Testing for Weak Lock Out Mechanism
لغة النص الأصلي: الإنجليزية
Testing for Bypassing Authentication Schema
لغة النص الأصلي: الإنجليزية
Testing for Vulnerable Remember Password
لغة النص الأصلي: الإنجليزية