Skip to main content
elementalsouls
ملف منشئ GitHub

elementalsouls

عرض على مستوى المستودعات لـ ٩٧ skills مجمعة عبر ٣ مستودعات GitHub.

skills مجمعة
٩٧
مستودعات
٣
محدث
٢٤ أغسطس ٢٠٢٦
مستكشف المستودعات

المستودعات و skills الممثلة

hunt-cicd
غير مصنف

Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI…

٢٤ أغسطس ٢٠٢٦
hunt-cors
غير مصنف

Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled…

٢٤ أغسطس ٢٠٢٦
hunt-deserialization
غير مصنف

Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NET BinaryFormatter, Ruby Marshal.load, JNDI/Log4Shell. RCE via deserialization is almost always Critical. Use when target runs Java, PHP…

٢٤ أغسطس ٢٠٢٦
hunt-k8s
غير مصنف

Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape…

٢٤ أغسطس ٢٠٢٦
hunt-laravel
غير مصنف

Hunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true exposes full stack trace + env vars), Laravel Telescope/Horizon dashboard unauthorized access, Ignition RCE (CVE-2021-3129), Signed URL manipulation, Queue Worker abuse, mass…

٢٤ أغسطس ٢٠٢٦
hunt-llm-ai
غير مصنف

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…

٢٤ أغسطس ٢٠٢٦
hunt-nextjs
غير مصنف

Hunt Next.js specific vulnerabilities — Server Actions arbitrary function execution, Middleware auth bypass via static asset paths, ISR cache poisoning, Image Optimization SSRF (/_next/image), RSC payload leakage, getServerSideProps injection, source map…

٢٤ أغسطس ٢٠٢٦
hunt-nosqli
غير مصنف

Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.

٢٤ أغسطس ٢٠٢٦
عرض 8 من أصل ٨٣ skills مجمعة.
run-claude-osint
المهن الحاسوبية الأخرى

Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run sync-skill-content.sh, run the smoke test. Use when asked to run, build, test, validate, or smoke-test claude-osint or…

٢٤ أغسطس ٢٠٢٦
cloud-saas-exposure
غير مصنف

Organization-grade cloud and supply-chain attack-surface discovery: S3/GCS/Azure Blob bucket discovery via observed-name mining (CNAME/cert-SAN/Wayback) and bounded two-class permutation (6 prefixes x 15 suffixes on trusted tokens, bounded target-bound…

٢٤ أغسطس ٢٠٢٦
continuous-exposure-monitoring
غير مصنف

Turns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated webhook alert), the scan-to-scan diff engine…

٢٤ أغسطس ٢٠٢٦
email-domain-security
غير مصنف

Rigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the offensive-osint arsenal (§16.14) with the reasoning that…

٢٤ أغسطس ٢٠٢٦
exposure-risk-quantification
غير مصنف

FAIR-aligned exposure quantification: turns a pile of recon findings into a defensible 0-100 + A-F org risk score (Likelihood x Impact, three ownership-aware factors: exposure/threat/impact), an ownership + proof demotion cap so unproven or weakly-owned…

٢٤ أغسطس ٢٠٢٦
identity-provider-recon
غير مصنف

Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf…

٢٤ أغسطس ٢٠٢٦
offensive-osint
غير مصنف

Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths,…

٢٤ أغسطس ٢٠٢٦
org-attack-surface
غير مصنف

Org-grade attack-surface mapping: given a company's legal identity, discover its ENTIRE owned internet footprint — corporate family -> owned domains -> owned netblocks/ASN -> live assets — with attribution discipline, not just DNS breadth. The org-first…

٢٤ أغسطس ٢٠٢٦
عرض 8 من أصل ١٠ skills مجمعة.
عرض ٣ من أصل ٣ مستودعات
تم تحميل كل المستودعات