Skip to main content
NoorQureshi
ملف منشئ GitHub

NoorQureshi

عرض على مستوى المستودعات لـ ١٠٠ skills مجمعة عبر ١ مستودعات GitHub.

skills مجمعة
١٠٠
مستودعات
١
محدث
٦ سبتمبر ٢٠٢٦
خريطة المستودعات

أين توجد skills

أهم المستودعات حسب عدد skills المجمعة، مع حصتها من كتالوج هذا المنشئ وانتشارها المهني.

مستكشف المستودعات

المستودعات و skills الممثلة

ad-adcs
غير مصنف

Attack Active Directory Certificate Services (ADCS) — ESC1–ESC8 template/CA misconfigurations to escalate to Domain Admin. Load with a domain foothold/creds where ADCS is present, on "certipy", "ESC1", "certificate template", or a CA server. Signals: Cert…

٦ سبتمبر ٢٠٢٦
ad-dacl-abuse
غير مصنف

Abuse Active Directory object ACLs/DACLs for lateral movement and escalation — GenericAll, WriteDACL, GenericWrite, WriteOwner, AddMember, ForceChangePassword, and DCSync rights. Load with domain creds + BloodHound showing an ACL edge, on "GenericAll",…

٦ سبتمبر ٢٠٢٦
ad-kerberoasting
غير مصنف

Kerberoasting & AS-REP roasting — request/crack Kerberos tickets to recover service/user passwords offline. Load with any domain foothold or valid domain creds, on "kerberoast", "AS-REP", SPNs, service accounts, ports 88/389. Signals: domain creds in hand,…

٦ سبتمبر ٢٠٢٦
tools-ad-pivot
غير مصنف

One line: Active Directory, pivoting/tunneling, and password-cracking arsenal for authorized engagements. Trigger signals: "Active Directory", "domain", "kerberos", "kerberoast", "AS-REP", "BloodHound", "DCSync", "AD/.local domain", holding domain creds or a…

٦ سبتمبر ٢٠٢٦
ai-agent-tool-abuse
غير مصنف

Abuse an LLM agent's tools/functions — coerce it to call tools with attacker-chosen args for SSRF, RCE, data exfil, or privilege abuse. Load when the target is an agent with tools/ function-calling/plugins, MCP servers, code interpreters, or "the assistant…

٦ سبتمبر ٢٠٢٦
ai-insecure-output-handling
غير مصنف

Exploit apps that trust LLM output — pass model text unsanitized into XSS sinks, SQL, shell, code, or downstream calls. Load when LLM output is rendered as HTML/markdown, executed, or fed to another system. Signals: chatbot output shown with…

٦ سبتمبر ٢٠٢٦
ai-jailbreak
غير مصنف

Bypass an LLM's safety/guardrails to make it produce restricted output or ignore its policy. Load when testing an AI product's content controls, "jailbreak", "guardrail bypass", refusal testing, or safety evals. Signals: a chatbot/assistant with a usage…

٦ سبتمبر ٢٠٢٦
ai-llm-dos
غير مصنف

Unbounded-consumption / denial-of-wallet attacks on LLM apps — force runaway tokens, cost, or latency. Load when testing an LLM product's limits/billing, on "LLM DoS", cost amplification, or resource exhaustion. Signals: user-controlled prompts/max_tokens,…

٦ سبتمبر ٢٠٢٦
عرض 8 من أصل ١٠٠ skills مجمعة.
عرض ١ من أصل ١ مستودعات
تم تحميل كل المستودعات