macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Quellsprache: Englisch
Menü
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
Es werden 40 von 7.442 gesammelten Skills angezeigt.
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Quellsprache: Englisch
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Quellsprache: Englisch
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
Quellsprache: Englisch
READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
Quellsprache: Englisch
READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
Quellsprache: Englisch
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
Quellsprache: Englisch
Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
Quellsprache: Englisch
GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
Quellsprache: Englisch
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
Quellsprache: Englisch
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
Quellsprache: Englisch
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
Quellsprache: Englisch
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
Quellsprache: Englisch
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
Quellsprache: Englisch
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
Quellsprache: Englisch
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
Quellsprache: Englisch
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
Quellsprache: Englisch
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
Quellsprache: Englisch
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
Quellsprache: Englisch
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
Quellsprache: Englisch
Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
Quellsprache: Englisch
Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
Quellsprache: Englisch
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
Quellsprache: Englisch
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
Quellsprache: Englisch
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
Quellsprache: Englisch
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
Quellsprache: Englisch
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
Quellsprache: Englisch
XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
Quellsprache: Englisch
Active Directory security testing and attack techniques
Quellsprache: Englisch
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
Quellsprache: Englisch
Kerberos protocol attack techniques and exploitation
Quellsprache: Englisch
Bug bounty and pentest reconnaissance methodology
Quellsprache: Englisch
API Testing Overview
Quellsprache: Englisch
API Reconnaissance
Quellsprache: Englisch
Testing for Broken Object Level Authorization (BOLA)
Quellsprache: Englisch
Testing GraphQL
Quellsprache: Englisch
Testing for Credentials Transported over an Encrypted Channel
Quellsprache: Englisch
Testing for Default Credentials
Quellsprache: Englisch
Testing for Weak Lock Out Mechanism
Quellsprache: Englisch
Testing for Bypassing Authentication Schema
Quellsprache: Englisch
Testing for Vulnerable Remember Password
Quellsprache: Englisch