Skip to main content
SnailSploit
ملف منشئ GitHub

SnailSploit

عرض على مستوى المستودعات لـ ٥٠ skills مجمعة عبر ١ مستودعات GitHub.

skills مجمعة
٥٠
مستودعات
١
محدث
٢٦ أغسطس ٢٠٢٦
خريطة المستودعات

أين توجد skills

أهم المستودعات حسب عدد skills المجمعة، مع حصتها من كتالوج هذا المنشئ وانتشارها المهني.

مستكشف المستودعات

المستودعات و skills الممثلة

offensive-network-attacks
محللو أنظمة الحاسوب

Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC bypass, IPv6 attacks. Tools: Bettercap, Responder, mitm6, Ettercap, Wireshark. MITRE T1557, T1040. Use when conducting…

٢٦ أغسطس ٢٠٢٦
offensive-data-exfiltration
محللو أمن المعلومات

Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob SAS tokens, GCS…

٢٦ أغسطس ٢٠٢٦
offensive-ssti
مطوّرو البرمجيات

Dense description covering Server-Side Template Injection across Jinja2, Twig, Freemarker, Velocity, Pebble, Smarty, Mako, Handlebars, ERB, Thymeleaf, EJS, Pug. Engine fingerprinting, filter bypass, blind exploitation, WAF evasion, SSTI-to-RCE chains. Tools:…

٢٦ أغسطس ٢٠٢٦
offensive-api-abuse
محللو أمن المعلومات

Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific…

٢٥ أغسطس ٢٠٢٦
offensive-persistence
محللو أمن المعلومات

Comprehensive persistence tradecraft for authorized red team engagements covering Windows and Linux mechanisms. Windows techniques include registry Run/RunOnce keys, scheduled tasks, WMI event subscriptions, DLL search order hijacking, COM object hijacking,…

٢٥ أغسطس ٢٠٢٦
offensive-windows-privesc
محللو أمن المعلومات

Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\SYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using…

٢٥ أغسطس ٢٠٢٦
offensive-dependency-confusion
محللو أمن المعلومات

Deep-dive offensive methodology for dependency confusion and namespace attacks across all major package ecosystems. Covers npm scope confusion exploiting the gap between public and private scoped packages and .npmrc misconfigurations where registry mappings…

٢٥ أغسطس ٢٠٢٦
offensive-deserialization
مطوّرو البرمجيات

Insecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/phpggc/ysoserial.net, ObjectInputStream and BinaryFormatter sink identification, pickle __reduce__ RCE, phar:// wrapper…

٢٥ أغسطس ٢٠٢٦
عرض 8 من أصل ٥٠ skills مجمعة.
عرض ١ من أصل ١ مستودعات
تم تحميل كل المستودعات