Skip to main content

Skills in this repository

Suzu-Testing/metasploit-cursor-harness - Page 2

SkillsMP has collected 57 skills from Suzu-Testing/metasploit-cursor-harness. Open a skill to review its source and details.

Suzu-Testing/metasploit-cursor-harness

Showing 17 of 57 collected skills.

occupation
unclassified
description

Guides binary reverse engineering with static/dynamic analysis, Ghidra, radare2, GDB, .NET decompilation, and checksec workflows. Use when analyzing unknown binaries, malware samples, or supporting exploit development.

Source text: Mixed languages

updated
occupation
unclassified
description

Guides SMB/CIFS service penetration testing. Use when port 445 or 139 is discovered during scanning or when SMB file sharing is identified on a target.

updated
occupation
unclassified
description

Guides SMTP mail transfer service penetration testing. Use when port 25 or 587 is discovered during scanning or when SMTP is identified on a target.

updated
occupation
unclassified
description

Guides SNMP network management service penetration testing. Use when port 161 or 162 is discovered during scanning or when SNMP is identified.

updated
occupation
unclassified
description

Guides SQL injection testing with detection probes, DB-specific payloads, bypass techniques, and sqlmap automation. Use when database errors appear, single quotes break queries, numeric parameters behave oddly, or search/filter endpoints reflect SQL-like…

updated
occupation
unclassified
description

Guides SSH/SFTP service penetration testing. Use when port 22 is discovered during scanning or when Secure Shell service is identified on a target.

updated
occupation
unclassified
description

Guides server-side request forgery testing with internal network probes, cloud metadata abuse, protocol smuggling, and filter bypass techniques. Use when the application fetches URLs, webhooks, PDFs, image proxies, or imports content from user-supplied…

updated
occupation
unclassified
description

Guides server-side template injection testing with engine identification probes, RCE payloads per template engine, and tplmap automation. Use when template delimiters appear in output, template engine errors surface, or user input is rendered inside…

updated
occupation
unclassified
description

Guides Telnet remote terminal service penetration testing. Use when port 23 is discovered during scanning or when Telnet is identified on a target.

updated
occupation
unclassified
description

Guides file upload vulnerability testing with extension bypass, content-type manipulation, magic byte injection, and web shell deployment. Use when file upload forms, avatar/profile uploads, or document import features are in scope.

updated
occupation
unclassified
description

Guides VNC remote desktop service penetration testing. Use when port 5900 is discovered during scanning or when VNC/RFB service is identified.

updated
occupation
unclassified
description

Guides web application penetration testing aligned with OWASP/WSTG methodology. Use for attack surface mapping, vuln class routing, auth testing, and MSF delivery after web-based initial access. Payload details live in tier-3 vuln skills.

updated
occupation
unclassified
description

Guides wireless network penetration testing including monitor mode setup, WPA2 handshake capture, PMKID attacks, hashcat cracking, evil twin, WPS, and WPA-Enterprise testing. Use when wireless networks are explicitly in engagement scope and ROE authorizes RF…

updated
occupation
unclassified
description

Guides Windows host penetration testing for local privesc, credential theft, token abuse, DPAPI, and lateral movement from a Windows foothold or non-domain Windows targets.

updated
occupation
unclassified
description

Guides Windows Remote Management penetration testing. Use when port 5985 or 5986 is discovered during scanning or when WinRM is identified on a target.

updated
occupation
unclassified
description

Guides cross-site scripting testing with context-aware payloads, filter evasion, CSP bypass, and blind XSS techniques. Use when user input appears in HTML, JavaScript, or DOM sinks, or reflected/stored content suggests script injection is possible.

updated
occupation
unclassified
description

Guides XML external entity injection testing with classic, blind OOB, XXE-to-SSRF, and file read payloads. Use when the application accepts XML, SOAP, SVG, DOCX/XLSX, RSS, or other XML-based uploads and parsers may resolve external entities.

updated
Showing 17 of 57 collected skills.