with one click
Tesserin-pro
Tesserin-pro contains 16 collected skills from Samurai-goose, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Audit Active Directory, LDAP, and enterprise identity infrastructure for misconfigurations, privilege escalation paths, Kerberos weaknesses, trust relationship abuse, and credential exposure.
API-specific security testing for REST, GraphQL, WebSocket, and gRPC endpoints. Covers authentication, authorization, injection, rate limiting, mass assignment, and API-specific attack patterns.
Intake, deduplication, severity assignment, and prioritization of security findings for bug bounty and pentest engagements. Processes raw findings into actionable triaged items.
Audit CI/CD pipelines and software supply chains for poisoning vectors, secret exposure, artifact tampering, dependency confusion, and build environment compromise. Covers GitHub Actions, GitLab CI, Jenkins, and container build pipelines.
Audit cloud infrastructure configuration for security misconfigurations across AWS, Azure, and GCP. Covers IAM, storage, networking, compute, and logging. Reviews IaC templates (Terraform, CloudFormation, Pulumi).
Assess container runtime security including escape paths, kernel exploitation, capability abuse, namespace breakouts, and orchestration runtime issues beyond static configuration review.
Audit third-party dependencies for known vulnerabilities and detect hardcoded secrets, API keys, and credentials in source code, configuration, and git history.
Compile, format, and generate security assessment reports from triaged findings. Produces consistent, professional reports with executive summaries, finding details, remediation guidance, and validation notes.
Develop and execute proof-of-concept exploits to validate suspected vulnerabilities. Confirms exploitability, measures real impact, and produces reproducible evidence for confirmed findings.
Deep reconnaissance review and attack surface mapping. Analyzes gathered recon data to identify exposed services, entry points, technology stacks, and potential attack vectors.
Security assessment of iOS and Android mobile applications. Covers OWASP Mobile Top 10, reverse engineering, runtime manipulation, data storage, network security, certificate pinning bypass, and platform-specific attack patterns.
Network-layer security assessment covering segmentation validation, service enumeration, firewall rule analysis, protocol attacks, and infrastructure exposure testing.
Source-level vulnerability hunting. Systematic review of application source code for injection flaws, auth bypasses, logic bugs, cryptographic weaknesses, and unsafe patterns. Operates on code files within the workspace.
Establishes engagement rules, authorization boundaries, and operational guardrails for all security review skills. Must be invoked before any assessment work begins.
Proactive threat identification using structured frameworks (STRIDE, PASTA). Models data flows, trust boundaries, and threat actors to prioritize security testing and contextualize findings with business risk.
Review web server, application, and infrastructure configuration for security misconfigurations. Covers headers, TLS, CORS, error handling, directory exposure, and deployment hygiene.