Skip to main content

CyberStrikeus/CyberStrike

SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
7,442
GitHub stars
1,653
GitHub forks
254

Showing 40 of 7,442 collected skills.

occupation
unclassified
description

macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools

updated
occupation
unclassified
description

Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations

updated
occupation
unclassified
description

Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence

updated
occupation
Information Security Analysts
description

READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain

updated
occupation
Information Security Analysts
description

READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl

updated
occupation
unclassified
description

Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation

updated
occupation
Information Security Analysts
description

Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks

updated
occupation
Information Security Analysts
description

GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK

updated
occupation
Information Security Analysts
description

eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux

updated
occupation
Information Security Analysts
description

AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3

updated
occupation
Information Security Analysts
description

CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab

updated
occupation
Information Security Analysts
description

Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users

updated
occupation
Information Security Analysts
description

CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage

updated
occupation
Information Security Analysts
description

GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass

updated
occupation
Information Security Analysts
description

Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host

updated
occupation
Information Security Analysts
description

IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure

updated
occupation
Information Security Analysts
description

JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping

updated
occupation
Information Security Analysts
description

Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains

updated
occupation
Information Security Analysts
description

JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation

updated
occupation
Information Security Analysts
description

Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws

updated
occupation
Information Security Analysts
description

Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation

updated
occupation
Information Security Analysts
description

HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass

updated
occupation
Information Security Analysts
description

Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques

updated
occupation
Information Security Analysts
description

Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines

updated
occupation
Information Security Analysts
description

Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation

updated
occupation
Information Security Analysts
description

WebSocket security testing — CSWSH, message injection, auth bypass, origin validation

updated
occupation
Information Security Analysts
description

XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing

updated
occupation
Information Security Analysts
description

Active Directory security testing and attack techniques

updated
occupation
Software Developers
description

Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.

updated
occupation
Information Security Analysts
description

Kerberos protocol attack techniques and exploitation

updated
occupation
Information Security Analysts
description

Bug bounty and pentest reconnaissance methodology

updated
occupation
Information Security Analysts
description

API Testing Overview

updated
occupation
Information Security Analysts
description

API Reconnaissance

updated
occupation
Information Security Analysts
description

Testing for Broken Object Level Authorization (BOLA)

updated
occupation
Information Security Analysts
description

Testing GraphQL

updated
occupation
Information Security Analysts
description

Testing for Credentials Transported over an Encrypted Channel

updated
occupation
Information Security Analysts
description

Testing for Default Credentials

updated
occupation
Information Security Analysts
description

Testing for Weak Lock Out Mechanism

updated
occupation
Information Security Analysts
description

Testing for Bypassing Authentication Schema

updated
occupation
Information Security Analysts
description

Testing for Vulnerable Remember Password

updated
Showing 40 of 7,442 collected skills.