Skip to main content

Suzu-Testing/metasploit-cursor-harness

جمع SkillsMP عدد ٥٧ من skills من Suzu-Testing/metasploit-cursor-harness. افتح أي skill لمراجعة مصدره وتفاصيله.

آخر نشاط مصدر مسجل
آخر تحديث لفهرس SkillsMP
skills مجمعة
٥٧
نجوم GitHub
٣
تفرعات GitHub
١

Skills في هذا المستودع

التصنيف قيد الانتظار

عرض ٤٠ من أصل ٥٧ skills مجمعة.

المهنة
غير مصنف
الوصف

Guides AI and LLM application security testing including prompt injection, system prompt extraction, tool/function abuse, MCP server testing, and data exfiltration via LLM features. Use for chatbots, agents, and AI-integrated apps.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides binary exploitation including stack overflow, ROP, format strings, heap basics, pwntools, and GDB analysis. Use when engagement ROE explicitly authorizes custom exploit development beyond Metasploit modules.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides blockchain and smart contract security testing with reentrancy, flash loan, and access control analysis using Slither and EVM tooling. Use when auditing Solidity contracts, DeFi protocols, EVM dApps, or Web3 signing workflows in engagement scope.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides cloud penetration testing for AWS, Azure, and GCP enumeration, credential abuse, metadata SSRF, storage misconfigurations, IAM privilege escalation, and cloud lateral movement from web or internal footholds.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides OS command injection testing with shell metacharacter probes, blind exfiltration, filter bypass, and OS-specific syntax. Use when inputs reach shell commands such as ping, nslookup, file conversion, or when shell metacharacters alter application…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides container and DevOps penetration testing for Docker escape, Kubernetes abuse, CI/CD pipeline secrets, package manager poisoning, and secrets enumeration from footholds or exposed services.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides database penetration testing for MSSQL, MySQL, PostgreSQL, MongoDB, Redis, and Elasticsearch. Use when database ports are open, SQL injection yields DB access, or linked-server abuse is suspected.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides insecure deserialization testing with format identification, language-specific gadget chains, and ysoserial/phpggc tooling. Use when Java, .NET, PHP, Python, or Ruby serialized objects appear in cookies, headers, APIs, or base64-encoded parameters…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides DNS name resolution service penetration testing. Use when port 53 is discovered during scanning or when DNS is identified on a target.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides digital forensics methodology for disk images, memory dumps, pcaps, and artifact analysis. Use when analyzing evidence to support incident response, malware triage, or pentest finding validation.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides FTP file transfer service penetration testing. Use when port 21 is discovered during scanning or when FTP is identified on a target.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides GraphQL injection and authorization testing with introspection, field enumeration, batch attacks, and nested query abuse. Use when GraphQL endpoints, introspection, or query syntax are discovered.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides network and service penetration testing after port discovery. Provides port-to-skill routing, per-service quick reference, and general enumeration methodology for services with and without dedicated harness skills.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides hardware and physical access penetration testing with UART/JTAG/SPI analysis, firmware extraction, and logic analyzer techniques. Use when engagement ROE includes firmware extraction, debug interface access, or physical device compromise.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Insecure Direct Object Reference testing with ID manipulation, parameter pollution, and horizontal/vertical privilege escalation techniques. Use when predictable IDs in URLs, sequential numbers, UUIDs, or authorization bypass indicators appear.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides initial access techniques including external attack surface mapping, credential abuse, phishing delivery chains, and client-side payload planning. Use during external engagement phases before exploitation.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Active Directory and internal network penetration testing for AD enumeration, Kerberos abuse, relay attacks, ADCS exploitation, lateral movement, domain dominance, and MSSQL attacks in domain environments.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides JSON Web Token attack testing with algorithm confusion, signature bypass, header injection, and secret brute force techniques. Use when Bearer tokens, Authorization headers with eyJ prefix, or JWT cookies are observed during web or API testing.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides LDAP directory service penetration testing. Use when port 389 or 636 is discovered during scanning or when LDAP/Active Directory is identified.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides local and remote file inclusion testing with traversal payloads, PHP wrappers, log poisoning, and LFI-to-RCE chains. Use when parameters like page, file, include, or path accept filenames or traversal sequences.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Linux penetration testing for privesc, persistence, container host escape, SUID/capabilities abuse, cron, kernel exploits, and post-ex on Linux sessions.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides macOS penetration testing when ROE includes macOS endpoints. Covers privesc, TCC bypass, keychain abuse, sandbox escape, launch daemon abuse, dylib hijacking, and XPC/Mach service abuse on Intel and Apple Silicon.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Memcached in-memory cache penetration testing. Use when port 11211 is discovered during scanning or when Memcached is identified on a target.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Central reference for pentest methodology, cross-cutting cheatsheets, reverse shells, file transfer, hash cracking, network discovery, and common tool syntax. Use during recon, threat modeling, post-exploit, and reporting when any domain skill needs quick…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Android and iOS application penetration testing including static/dynamic analysis, Frida hooking, certificate pinning bypass, and common mobile vulns. Use when ROE includes Android, iOS, or hybrid mobile app testing.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Orchestrates Metasploit Cursor Harness MCP tools through recon, module check, exploit, handler, session, and post-exploitation phases. Use when running msf_search_modules, msf_run_exploit, msf_run_auxiliary_module, payload generation, or session management…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Master guide for using the Metasploit Cursor Harness MCP server. Use when starting an engagement, choosing between MCP and shell, setting up ROE, or understanding the tool surface. Read this first before any Metasploit work.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Post-exploitation workflow using Metasploit MCP. Use when interacting with active sessions, running post modules, harvesting credentials, collecting loot, or cleaning up sessions.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Reconnaissance workflow using Metasploit MCP read tools. Use when mapping targets, searching for exploit modules, correlating services with vulnerabilities, or querying the Metasploit database.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides NFS network file system penetration testing. Use when port 2049 is discovered during scanning or when NFS is identified on a target.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides NoSQL injection testing with operator-based auth bypass, blind extraction, JavaScript injection, and MongoDB-specific payloads. Use when MongoDB backend, JSON body with operators ($gt, $ne, $regex), or NoSQL error messages are observed during web…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Routes pentest tasks to the correct harness skill based on engagement type, target platform, discovered services, or vulnerability class. Use when choosing which skill to load for a specific testing scenario.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Orchestrates PTES-aligned phases, gates, and subgates for pentest engagements. Each subgate links to a skill the agent must load and execute. Use when starting an engagement, advancing phases, completing subgates, or when the user asks about workflow, gates,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides persistence mechanism research and documentation for Windows, Linux, and RDP. Use during post-exploit when ROE authorizes persistence testing, or to document options without deployment.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides network pivoting and tunneling including SSH tunnels, chisel, ligolo-ng, proxychains, Meterpreter routing, and port forwarding during post-exploitation. Use when reaching unreachable in-scope subnets from a foothold host.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides prompt injection testing with direct/indirect injection, jailbreak techniques, tool abuse, and system prompt extraction. Use when LLM chatbot features, AI-powered search, or text generation from user input are discovered.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides Remote Desktop Protocol penetration testing. Use when port 3389 is discovered during scanning or when RDP service is identified on a target.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides OPSEC, EDR evasion, and defensive control bypass including AMSI, AppLocker, ETW patching, process injection, PPID spoofing, and living-off-the-land techniques. Use before noisy actions or when encountering AV/EDR controls.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides vulnerability report writing and finding documentation including severity rating, evidence standards, and report structure. Use during report phase (SG6) and when structuring harness evidence into client deliverables.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Guides HTTP request smuggling testing with CL.TE, TE.CL, TE.TE, and H2 downgrade detection and exploitation. Use when front/back-end proxy chains or HTTP/2 downgrade scenarios are suspected in the target architecture.

لغة النص الأصلي: الإنجليزية

آخر تحديث
عرض ٤٠ من أصل ٥٧ skills مجمعة.