How to pentest RSH (Remote Shell) services on port 514. Use this skill whenever the user mentions RSH, remote shell, port 514, .rhosts files, hosts.equiv, or needs to test legacy remote authentication services. This skill covers reconnaissance, authentication…
Skills in this repository
abelrguezr/hacktricks-skills - Page 14
SkillsMP has collected 908 skills from abelrguezr/hacktricks-skills. Open a skill to review its source and details.
abelrguezr/hacktricks-skillsShowing 40 of 908 collected skills.
How to perform authorized penetration testing on SAP systems. Use this skill whenever the user mentions SAP security testing, SAP penetration testing, SAP vulnerability assessment, SAP GUI testing, SAP web interface testing, SAP configuration review, or needs…
Use this skill whenever you need to fuzz the Linux in-kernel SMB server (ksmbd) with syzkaller, set up SMB2/SMB3 protocol fuzzing, configure ksmbd for maximum attack surface, or build stateful fuzzing harnesses for SMB protocol testing. Make sure to use this…
SMB/NetBIOS pentesting on ports 139/445. Use this skill whenever the user mentions SMB, NetBIOS, file shares, Windows shares, CIFS, port 139, port 445, or needs to enumerate/attack SMB services. This includes share enumeration, credential attacks, command…
Use rpcclient to enumerate Windows systems via SMB/RPC. Use this skill whenever the user needs to enumerate users, groups, domains, or shares on a Windows target, or when they mention rpcclient, SMB enumeration, RID cycling, SID enumeration, or Windows domain…
Perform SMTP security assessments including banner grabbing, user enumeration, MX record analysis, SPF/DKIM/DMARC validation, and open relay detection. Use this skill whenever the user needs to assess email server security, test SMTP configurations, enumerate…
SMTP enumeration and security testing skill. Use this skill whenever you need to test SMTP servers, enumerate email addresses, check SMTP configurations, or perform security assessments on mail servers. This includes tasks like verifying email addresses,…
How to test for and understand SMTP smuggling vulnerabilities. Use this skill when investigating email security, testing SMTP servers for protocol parsing discrepancies, or when you need to understand how attackers can smuggle additional emails through SMTP…
Pentest Cisco network devices using SNMP vulnerabilities. Use this skill whenever the user mentions SNMP, Cisco devices, network pentesting, community strings, or needs to enumerate/dump configurations from network equipment. Trigger for any task involving…
Pentest SNMP services on network devices. Use this skill whenever the user needs to enumerate SNMP (ports 161/162/10161/10162), discover community strings, extract system information from network devices (routers, switches, printers, IoT), or perform…
Exploit SNMP services with write-accessible community strings to achieve remote code execution. Use this skill whenever you need to test SNMP security, enumerate SNMP services, inject commands via NET-SNMP-EXTEND-MIB, or gain shell access through SNMP…
SSH/SFTP penetration testing and security assessment. Use this skill whenever the user needs to enumerate SSH services, test for vulnerabilities, check for weak configurations, attempt credential attacks, or assess SSH server security. Trigger on mentions of…
Pentest Telnet services (port 23) - use this skill whenever the user mentions Telnet, port 23, network service enumeration, credential brute-forcing, or vulnerability assessment of Telnet daemons. This skill covers banner grabbing, option enumeration,…
VNC (Virtual Network Computing) pentesting and exploitation. Use this skill whenever the user mentions VNC, remote desktop, ports 5800/5801/5900/5901, RFB protocol, vncviewer, or needs to enumerate/connect to/attack VNC services. Also trigger for VNC password…
Reference guide for VoIP protocols in pentesting. Use this skill when analyzing VoIP infrastructure, identifying protocols in network traffic, or understanding VoIP attack surfaces. Covers SIP, MGCP, SCCP, H.323, IAX, SDP, RTP, RTCP, SRTP, and ZRTP. Make sure…
Expert assistance for Session Initiation Protocol (SIP) tasks including message construction, protocol analysis, security assessments, and VoIP pentesting. Use this skill whenever the user needs to understand SIP methods, create SIP messages, analyze SIP…
Perform VoIP penetration testing including SIP enumeration, extension scanning, password cracking, vulnerability detection (SIPDigestLeak, RTPBleed), and attack testing. Use this skill whenever the user mentions VoIP, SIP, PBX, Asterisk, FreePBX, Elastix,…
How to audit and test for HTTP 403/401 bypass vulnerabilities. Use this skill whenever the user mentions access control testing, forbidden page bypasses, authentication bypass, 403 errors, 401 errors, HTTP method fuzzing, header manipulation, path traversal…
Pentest Adobe Experience Manager (AEM) instances. Use this skill whenever the user mentions AEM, Adobe Experience Manager, Adobe Experience Cloud, Sling, OSGi, JCR, or needs to assess AEM security. Trigger for AEM fingerprinting, vulnerability scanning,…
Security audit and pentesting guide for Angular applications. Use this skill whenever you need to assess Angular app security, look for XSS vulnerabilities, check for bypassSecurityTrust misuse, audit template injection risks, test for open redirects, or…
Apache web server pentesting and exploitation techniques. Use this skill whenever the user mentions Apache, web server vulnerabilities, .htaccess, mod_rewrite, PHP handlers, CVE-2021-41773, confusion attacks, LFI, RCE, or any Apache-related security testing.…
Security testing and vulnerability assessment for JFrog Artifactory instances. Use this skill whenever the user mentions Artifactory security, wants to test an Artifactory instance, needs to enumerate Artifactory vulnerabilities, or is doing penetration…
How to exploit Bolt CMS for Remote Code Execution (RCE) via Twig template injection. Use this skill when pentesting Bolt CMS installations, when you need to check for SSTI vulnerabilities in Bolt CMS, or when you have admin access to a Bolt CMS instance and…
How to enumerate and abuse AWS S3 buckets during cloud pentesting. Use this skill whenever the user mentions S3 buckets, AWS storage, cloud storage enumeration, bucket access testing, or wants to check for unauthenticated S3 access. Make sure to use this…
How to pentest Firebase Realtime Database and Firestore. Use this skill whenever the user mentions Firebase, Firebase database security, cloud database pentesting, NoSQL injection, Firebase enumeration, or any Firebase-related security assessment. Make sure…
How to test and exploit CGI vulnerabilities in web applications. Use this skill whenever the user mentions CGI scripts, ShellShock, Perl web scripts, .cgi endpoints, Apache CGI modules, or wants to test for command injection in web forms. This includes…
Perform static application security testing (SAST) and source code security reviews. Use this skill whenever the user wants to scan code for vulnerabilities, review source code for security issues, run SAST tools, analyze dependencies for known…
Analyze and exploit custom UDP RPC protocols in games. Use this skill whenever you need to enumerate proprietary game networking protocols, intercept file-transfer RPCs, perform path traversal attacks on game saves, or turn protocol vulnerabilities into code…
Django security testing and exploitation. Use this skill whenever the user mentions Django applications, web app pentesting, SSTI vulnerabilities, pickle deserialization, session cookie attacks, or Django-specific CVEs. Trigger for any Django security…
Exploit .NET SOAP/WSDL client proxy vulnerabilities for NTLM relay, arbitrary file writes, and RCE. Use this skill whenever you need to test for SoapHttpClientProtocol abuse, WSDL import vulnerabilities, or HttpWebClientProtocol scheme-agnostic bugs in .NET…
Pentest DotNetNuke (DNN) installations for vulnerabilities including unauthenticated RCE, SSRF, NTLM hash exposure, and IP filter bypass. Use this skill whenever the user mentions DNN, DotNetNuke, .NET CMS, or needs to assess DNN security, enumerate versions,…
Exploit Drupal vulnerabilities for remote code execution. Use this skill whenever the user mentions Drupal exploitation, Drupal RCE, Drupal pentesting, Drupal security testing, PHP Filter module, Drupal configuration synchronization, Drupal gadget chains, or…
How to perform security assessments and penetration testing on Drupal websites. Use this skill whenever the user mentions Drupal, wants to enumerate a Drupal site, check for Drupal vulnerabilities, test Drupal security, or perform any kind of Drupal…
How to exploit Electron apps with disabled contextIsolation to achieve RCE. Use this skill whenever you're pentesting Electron desktop applications, analyzing Electron security, investigating context isolation bypasses, or need to demonstrate prototype…
How to identify and exploit Electron app vulnerabilities when contextIsolation is disabled or preload scripts expose dangerous IPC endpoints. Use this skill whenever you're testing Electron desktop applications for security vulnerabilities, analyzing IPC…
How to identify and exploit Electron app contextIsolation vulnerabilities for RCE. Use this skill whenever you're pentesting Electron desktop applications, analyzing Electron security, investigating preload script vulnerabilities, or need to test for context…
Security testing for Electron desktop applications. Use this skill whenever the user needs to audit, test, or analyze Electron apps for vulnerabilities like nodeIntegration misconfigurations, contextIsolation bypasses, XSS-to-RCE chains, preload script…
How to exploit Flask web application vulnerabilities including session cookie manipulation, secret key brute-forcing, and SSRF attacks. Use this skill whenever the user mentions Flask applications, session cookies, web pentesting, SSTI vulnerabilities, or…
Security assessment skill for Fortinet FortiWeb appliances. Use this skill when users need to test FortiWeb for authentication bypass vulnerabilities (CVE-2025-64446), SQL injection in Fabric Connector (CVE-2025-25257), SSO signature bypass (CVE-2025-59719),…
How to exploit exposed .git directories in web applications. Use this skill whenever the user mentions .git exposure, git directory dumping, git secrets, git-based pentesting, or wants to extract sensitive data from exposed version control. Make sure to use…