Sector-specific recon for fire damage restoration, water damage restoration, and disaster cleanup company websites — typically WordPress on shared hosting with emergency service pages, insurance claim assistance, and photo galleries. Common platforms include…
Skills in this repository
EntroVyx/hermes-agent-offsec - Page 4
SkillsMP has collected 146 skills from EntroVyx/hermes-agent-offsec. Open a skill to review its source and details.
EntroVyx/hermes-agent-offsecShowing 26 of 146 collected skills.
Sector-specific recon for gym, fitness center, and health club websites — common platforms include Mindbody, Mariana Tek, ClubReady, Glofox, PushPress, and Wodify for scheduling/booking; typically WordPress or custom PHP on shared hosting with member portals,…
Sector-specific recon for HVAC company websites — heating, cooling, AC repair, furnace installation. Typically WordPress on shared hosting with service booking, emergency contact forms, and seasonal maintenance plan pages.
Sector-specific recon for landscaping company websites — lawn care, tree service, irrigation, hardscaping, snow removal. Typically WordPress on shared hosting with photo galleries, booking tools, and seasonal service pages.
Sector-specific recon for laundromat, dry cleaning, and laundry service company websites — typically WordPress or custom PHP on shared hosting with pricing calculators, service area pages, pickup/delivery booking, and customer account portals. Common…
Sector-specific recon for mattress retailer and bedding store websites — common e-commerce platforms (Shopify, WooCommerce, BigCommerce), financing integration patterns (Affirm, Klarna, Bread, Synchrony), and mattress-in-a-box brand sites. Typically Shopify…
Sector-specific recon for moving company, relocation service, and logistics websites — typically WordPress on shared hosting with online booking, quote request forms, customer account portals, and inventory tracking. Built from an 18-target batch recon across…
Sector-specific recon for pet grooming, pet care, and dog walking company websites — typically WordPress on shared hosting with online booking, service menus, customer portals with pet profiles, and photo galleries. Common platforms include Gingr, PetExec,…
Sector-specific recon for plumbing company websites — plumbing repair, drain cleaning, water heater installation, emergency service. Typically WordPress on shared hosting with emergency booking, estimate request forms, and photo galleries.
Sector-specific recon for pool service and pool construction company websites — pool cleaning, repair, installation, hot tubs. Typically WordPress on shared hosting with booking systems, photo galleries, and seasonal service content.
Sector-specific recon for property management, apartment rental, and real estate management company websites — typically WordPress on shared hosting with rental listings, tenant portals, maintenance request systems, and online rent payment integrations. Built…
Sector-specific recon for roofing company websites — roof repair, replacement, inspection, storm damage. Typically WordPress or custom PHP on shared hosting with project galleries, insurance claim assistance pages, and estimate request forms.
Sector-specific recon for salon, barbershop, nail salon, and spa websites — common booking platforms include Booksy, Vagaro, Square Appointments, Mindbody, Fresha, and StyleSeat. Typically WordPress or custom PHP on shared hosting with online booking, service…
Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+…
Sector-specific recon for small business service provider websites — plumbers, HVAC, electricians, landscapers, roofers, painters, cleaners, contractors. Typically WordPress, Wix, Squarespace, or custom PHP on shared hosting with minimal security. These sites…
Sector-specific recon for tree service company websites — arborist, tree removal, stump grinding, tree trimming. Common platforms include Arborgold, ArborNote, SingleOps, and Jobber for CRM/estimating; typically WordPress on shared hosting with photo…
Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the…
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP…
External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD…
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit…
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep…
Proven attack chain combining CORS credential reflection on WordPress REST API with XMLRPC methods (system.multicall, wp.uploadFile) and open registration for full RCE. Built from field experience across 58-company mass recon where 5/7 deep targets had CORS…
Scripts and workflows to batch-test popular WordPress plugin CVEs across hundreds of domains. Covers automated plugin detection, version extraction from readme.txt, CVE matching against a curated matrix of high-impact plugin vulnerabilities (ElementsKit,…
Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API,…