Guide complet de fuzzing avancé d'API REST/GraphQL — structure-aware fuzzing, grammar-based fuzzing, differential fuzzing, ffuf methodologies, param mining, value tampering, status code analysis, et custom fuzzing scripts
لغة النص الأصلي: الفرنسية
القائمة
Skills في هذا المستودع
جمع SkillsMP عدد ١٬٠٠١ من skills من JohnNuwan/EVA_CORE. افتح أي skill لمراجعة مصدره وتفاصيله.
JohnNuwan/EVA_COREعرض ٤٠ من أصل ١٬٠٠١ skills مجمعة.
Guide complet de fuzzing avancé d'API REST/GraphQL — structure-aware fuzzing, grammar-based fuzzing, differential fuzzing, ffuf methodologies, param mining, value tampering, status code analysis, et custom fuzzing scripts
لغة النص الأصلي: الفرنسية
Guide complet de hacking d'API REST — OWASP API Top 10, fuzzing, rate limiting bypass, IDOR, mass assignment, SSRF, injection
لغة النص الأصلي: الفرنسية
Guide complet d'exploitation de Mass Assignment (API3) et Broken Object Property Level Authorization (BOPLA) — hidden fields, extra properties, prototype pollution, parameter pollution, et contournement de DTO
لغة النص الأصلي: الفرنسية
Guide complet des attaques de pollution de paramètres API — HTTP Parameter Pollution (HPP), type confusion, array injection, charset attacks, content-type switching, Unicode normalization bypass, et mass assignment via paramètres
لغة النص الأصلي: الفرنسية
Techniques avancées de contournement de rate limiting — en-têtes IP, rotation de proxies, timing attacks, distributed brute force, GraphQL batching, burst smuggling, et contournement de WAF
لغة النص الأصلي: الفرنسية
Guide complet de découverte et d'exploitation d'API shadow — endpoints zombies, debug backdoors, versioning attacks, swagger/OpenAPI leaks, staging endpoints, admin panels, et API docs exposées
لغة النص الأصلي: الفرنسية
Guide complet d'exploitation des webhooks API — SSRF inbound via webhooks, exfiltration out-of-band, callback servers, blind SSRF, DNS exfiltration, webhook smuggling, et détournement de notification
لغة النص الأصلي: الفرنسية
Guide complet d'Autopsy et The Sleuth Kit (TSK) — analyse de disque, système de fichiers, ingestion de sources, modules, keyword search, timeline view, et automatisation CLI
لغة النص الأصلي: الفرنسية
Guide complet des certifications AWS liées à la sécurité — AWS Certified Security - Specialty, Solutions Architect, Cloud Practitioner, et parcours de certification AWS.
لغة النص الأصلي: الفرنسية
Guide complet des services de sécurité AWS — GuardDuty, Inspector, Macie, Detective, Firewall Manager, Network Firewall, Security Hub, Config, Artifact, et architecture défensive AWS
لغة النص الأصلي: الفرنسية
Guide complet des services de sécurité Azure — Microsoft Defender for Cloud, Sentinel, Azure Policy, Azure AD Identity Protection, Defender XDR, Azure Security Benchmark, Key Vault, Managed HSM, et architecture défensive Azure
لغة النص الأصلي: الفرنسية
BeEF (Browser Exploitation Framework) — hook navigateur, modules d'exploitation, reconnaissance client, phishing, tunneling, exfiltration, pivoting via navigateur, et scénarios d'attaque complets.
لغة النص الأصلي: الفرنسية
Bettercap — MITM framework, ARP spoofing, DNS spoofing, HTTP/HTTPS interception, credential harvesting, session hijacking, Beacon C2 detection, HID attacks, Bluetooth, WiFi, BLE, et modules avancés.
لغة النص الأصلي: الفرنسية
Binary Exploitation avancé — heap exploitation, format string, use-after-free, type confusion, kernel exploitation, et techniques d'exploitation CTF/monde réel
لغة النص الأصلي: الفرنسية
Guide complet de la cryptographie blockchain — Merkle Trees, BLS signatures, Schnorr, Account Abstraction, Threshold Signatures, zk-Rollups, MEV, et protocoles blockchain.
لغة النص الأصلي: الفرنسية
BloodHound — cartographie et analyse des relations Active Directory, collecteurs (SharpHound, AzureHound), requêtes Cypher personnalisées, attaque des chemins de privilèges, ACL abuse, ACE abusives, et optimisation des attaques AD.
لغة النص الأصلي: الفرنسية
Guide complet de pentest navigateur — DOM clobbering, Service Worker hijacking, extension exploitation, postMessage, sandbox escape, et Web API abuse
لغة النص الأصلي: الفرنسية
Buffer Overflow — exploitation de stack/heap/SEH, ROP chains, canary bypass, egg hunters et développement d'exploits Windows/Linux
لغة النص الأصلي: الفرنسية
Burp Suite Pro — proxy d'interception, scanner automatisé, Intruder avancé, Repeater, Sequencer, Decoder, Comparer, Extensions (BApp Store), workflows OWASP, et automatisation d'audit web.
لغة النص الأصلي: الفرنسية
Bypass AV/EDR — AMSI bypass, ETW patching, DLL sideloading, obfuscation, packing, shellcode encryption, and evasion de Windows Defender, CrowdStrike, SentinelOne
لغة النص الأصلي: الإنجليزية
C2 Frameworks — Cobalt Strike, Sliver, Havoc, Mythic, Nighthawk, Empire, redirection, CDN proxying, et infrastructure de command & control
لغة النص الأصلي: الفرنسية
Guide complet de la certification CEH (Certified Ethical Hacker) v13 AI d'EC-Council — contenu, modules, préparation, ressources, coûts, et conseils d'examen.
لغة النص الأصلي: الفرنسية
Méthodologie de préparation aux certifications cybersécurité — stratégie d'étude, techniques de mémorisation, planification, gestion du stress, et optimisation de l'apprentissage pour maximiser la réussite.
لغة النص الأصلي: الفرنسية
Roadmap des certifications cybersécurité — arbre décisionnel, parcours par rôle (pentester, SOC, management, cloud, OSINT, devsecops), progression débutant → expert, et tableaux comparatifs.
لغة النص الأصلي: الفرنسية
Certipy — exploitation ADCS (Active Directory Certificate Services), ESC1 à ESC8, forger des certificats, authentification par certificat, pass-the-certificate, Shadow Credentials, et attaques PKI.
لغة النص الأصلي: الفرنسية
Chisel — tunnel TCP/HTTP/WebSocket, SOCKS proxy, reverse port forwarding, single-binary client/server, traversée de firewall, HTTP over WebSocket, et scénarios de pivoting avancés.
لغة النص الأصلي: الفرنسية
Guide complet des attaques de pipeline CI/CD — GitHub Actions, GitLab CI, Jenkins, secret extraction, poisoned pipeline execution, Artifact poisoning, outils
لغة النص الأصلي: الفرنسية
Guide complet de la certification CISSP (Certified Information Systems Security Professional) d'ISC2 — 8 domaines, préparation, examen, ressources et conseils.
لغة النص الأصلي: الفرنسية
Guide complet des Cloud Access Security Brokers (CASB) — Microsoft Defender for Cloud Apps, Netskope, Palo Alto Prisma, CASB use cases, Shadow IT discovery, DLP cloud, threat detection SaaS, et bonnes pratiques CASB
لغة النص الأصلي: الفرنسية
Guide complet de la conformité et gouvernance cloud — SOC2, PCI-DSS, HIPAA, GDPR, FedRAMP, ISO 27001, AWS Organizations SCP, GCP Organization Policies, Azure Policy, compliance frameworks, audit logging, et reporting
لغة النص الأصلي: الفرنسية
Guide complet de sécurité des conteneurs cloud — EKS, GKE, AKS, image scanning, admission controllers, runtime security, CIS benchmarks, Pod Security Standards, network policies, secrets management
لغة النص الأصلي: غير محددة
Guide complet du Cloud Security Posture Management (CSPM) — Prowler, ScoutSuite, Checkov, CloudSploit, Security Hub, et automatisation de la posture multi-cloud AWS/GCP/Azure
لغة النص الأصلي: الفرنسية
Guide complet de durcissement et défense cloud — CIS benchmarks, Security Score, hardening AWS/GCP/Azure, least privilege, network segmentation, encryption, logging, et monitoring
لغة النص الأصلي: الفرنسية
Guide complet de détection et réponse aux incidents cloud — GuardDuty, Security Hub, Security Command Center, Defender for Cloud, Sentinel, CloudTrail, Audit Logs, SIEM integration, forensic cloud, playbooks IR
لغة النص الأصلي: الإنجليزية
Guide complet de DevSecOps cloud — CI/CD pipeline security, IaC scanning (Terraform, CloudFormation, ARM), SAST/DAST, secret scanning, SBOM, supply chain security, et Shift Left
لغة النص الأصلي: الإنجليزية
Guide complet de sécurité financière cloud — cost anomalies, resource hijacking, crypto mining detection, budget alerts, orphan resources, license compliance, FinOps security, AWS Budgets, GCP quotas, Azure Cost Management
لغة النص الأصلي: غير محددة
Guide complet de sécurité IAM multi-cloud — AWS IAM, GCP IAM, Azure RBAC/AD, politiques, rôles, fédération d'identité, moindre privilège, analyse des chemins de privesc, et durcissement
لغة النص الأصلي: الفرنسية
Guide complet de sécurité réseau multi-cloud — VPC, security groups, NACL, WAF, CDN, DDoS protection, PrivateLink, VPC peering, Cloud VPN, service mesh, Zero Trust network
لغة النص الأصلي: غير محددة
Guide complet de pentest AWS — S3, IAM, Lambda, EC2, ECS, metadata service, privesc, outils et méthodologie
لغة النص الأصلي: غير محددة
Guide complet de pentest GCP — Cloud Storage, IAM, Compute Engine, Cloud Functions, KMS, privesc, outils
لغة النص الأصلي: الفرنسية