Skip to main content

CyberStrikeus/CyberStrike

SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.

Letzte erfasste Quellaktivität
SkillsMP-Katalog aktualisiert
gesammelte Skills
7.442
GitHub-Stars
1.653
GitHub-Forks
254

Es werden 40 von 7.442 gesammelten Skills angezeigt.

Beruf
nicht klassifiziert
Beschreibung

macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools

Quellsprache: Englisch

Aktualisiert
Beruf
nicht klassifiziert
Beschreibung

Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations

Quellsprache: Englisch

Aktualisiert
Beruf
nicht klassifiziert
Beschreibung

Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl

Quellsprache: Englisch

Aktualisiert
Beruf
nicht klassifiziert
Beschreibung

Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

WebSocket security testing — CSWSH, message injection, auth bypass, origin validation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Active Directory security testing and attack techniques

Quellsprache: Englisch

Aktualisiert
Beruf
Softwareentwickler
Beschreibung

Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Kerberos protocol attack techniques and exploitation

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Bug bounty and pentest reconnaissance methodology

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

API Testing Overview

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

API Reconnaissance

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Broken Object Level Authorization (BOLA)

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing GraphQL

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Credentials Transported over an Encrypted Channel

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Default Credentials

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Weak Lock Out Mechanism

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Bypassing Authentication Schema

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Testing for Vulnerable Remember Password

Quellsprache: Englisch

Aktualisiert
Es werden 40 von 7.442 gesammelten Skills angezeigt.