Skip to main content
s0ld13rr
ملف منشئ GitHub

s0ld13rr

عرض على مستوى المستودعات لـ ٢٨ skills مجمعة عبر ١ مستودعات GitHub.

skills مجمعة
٢٨
مستودعات
١
محدث
٢٧ يوليو ٢٠٢٦
خريطة المستودعات

أين توجد skills

أهم المستودعات حسب عدد skills المجمعة، مع حصتها من كتالوج هذا المنشئ وانتشارها المهني.

مستكشف المستودعات

المستودعات و skills الممثلة

svc-pivoting
محللو أمن المعلومات

Turn a foothold into a RELIABLE pivot (SOCKS tunnel + persistent shell) so internal volume never rides a fragile stateless RCE. Use the moment you have code-exec on a dual-homed/edge host and need to reach an internal segment. Triggers - dual-homed host, "not…

٢٧ يوليو ٢٠٢٦
web-deserialization
محللو أمن المعلومات

Insecure deserialization to RCE for web apps. Use when the app deserializes attacker-controlled data - cookies/tokens/hidden fields/params that are serialized blobs, VIEWSTATE, Java/PHP/.NET/Python/Node apps. Triggers - base64 starting rO0AB or hex AC ED 00…

٢٤ يوليو ٢٠٢٦
playbook-ad
محللو أمن المعلومات

Active Directory pentest playbook — Kerberos, LDAP, GPO, ADCS, delegation, lateral movement, DA paths. Load at the START of an AD engagement or when a Windows domain / DC is found. Triggers - domain controller, Kerberos 88, LDAP 389/636, domain SMB,…

٢٤ يوليو ٢٠٢٦
playbook-cloud
محللو أمن المعلومات

Cloud security playbook — AWS/GCP/Azure misconfiguration and attack patterns (IAM, storage, metadata, privesc). Load when the target is a cloud environment or you obtain cloud creds/metadata. Triggers - AWS/GCP/Azure, IAM role/policy, S3/blob bucket,…

٢٤ يوليو ٢٠٢٦
playbook-infra
محللو أمن المعلومات

Infrastructure pentest playbook — PTES-based phase flow for internal networks, servers, and non-web services. Load at the START of an internal/infra engagement or multi-host network assessment. Triggers - internal network, subnet/CIDR scan, infra pentest,…

٢٤ يوليو ٢٠٢٦
playbook-webapp
محللو أمن المعلومات

Web application pentest methodology + ROUTER to the per-vuln-class web skills. Load at the START of systematic web testing to get the phase flow (recon → map → test-by-OWASP-class → prove → report) and pick which web-<class> skill to load for each surface.…

٢٤ يوليو ٢٠٢٦
svc-cicd
محللو أمن المعلومات

CI/CD & dev-infra attack techniques — credential exposure, RCE (script console / build), pipeline abuse, secret stores. Use when a CI/CD or SCM service is exposed. Triggers - Jenkins /job/ or script console, GitLab, ArgoCD, TeamCity, Gitea, Drone, exposed…

٢٤ يوليو ٢٠٢٦
svc-database
محللو أمن المعلومات

Database service attack techniques — auth bypass, UDF/xp_cmdshell/COPY-TO-PROGRAM RCE, file read/write, cred dump. Use when a database service is found or you have DB creds. Triggers - MySQL 3306, PostgreSQL 5432, MSSQL 1433, Oracle 1521, Redis 6379, MongoDB…

٢٤ يوليو ٢٠٢٦
عرض 8 من أصل ٢٨ skills مجمعة.
عرض ١ من أصل ١ مستودعات
تم تحميل كل المستودعات