Skip to main content

m-sec-org/BreachWeave

SkillsMP hat 22 Skills aus m-sec-org/BreachWeave gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.

Letzte erfasste Quellaktivität
SkillsMP-Katalog aktualisiert
gesammelte Skills
22
GitHub-Stars
517
GitHub-Forks
64

Skills in diesem Repository

Es werden 22 von 22 gesammelten Skills angezeigt.

Beruf
Softwareentwickler
Beschreibung

This skill should be used when working with Bun runtime, bun:sqlite, Bun.serve, bun:test, or when "Bun", "bun:test", or Bun-specific patterns are mentioned.

Quellsprache: Englisch

Aktualisiert
Beruf
Softwareentwickler
Beschreibung

pi-mono agent framework reference (github.com/badlogic/pi-mono). TRIGGER when: writing agent code using pi-ai/pi-agent-core/pi-coding-agent packages, defining tools with TypeBox schemas, implementing TUI or Web UI over an agent core, building extensions that…

Quellsprache: Englisch

Aktualisiert
Beruf
Web- und digitale Schnittstellendesigner
Beschreibung

UI/UX design intelligence. 50 styles, 21 palettes, 50 font pairings, 20 charts, 8 stacks (React, Next.js, Vue, Svelte, SwiftUI, React Native, Flutter, Tailwind). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance,…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Active Directory 域渗透全链路指导技能。基于 GOAD (Game of Active Directory) 靶场实战经验, 涵盖从初始侦察、用户枚举、密码攻击、中继与投毒、ADCS证书攻击、MSSQL利用、提权、 横向移动、凭据提取、ACL滥用、委派攻击、域信任利用到域控拿下的完整渗透链。 当用户提到以下任何关键词时,务必触发此技能: AD渗透、域渗透、Active Directory、域控攻击、内网渗透、kerberoasting、AS-REP roasting、 NTLM…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Softwareentwickler
Beschreibung

Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web apps, or automating any browser task. Triggers include…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Help with ffuf-based Web parameter fuzzing. Use this skill whenever the user wants to fuzz Web request paths, query parameters, headers, POST bodies, JSON fields, or raw HTTP requests with ffuf, or when they ask for an ffuf command, wordlist choice,…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Navigate the fuzzDicts repository and choose the right dictionary or payload list for authorized Web directory scanning, parameter fuzzing, upload bypass testing, subdomain enumeration, API discovery, credential spraying, and vuln-specific fuzzing. Use this…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

CTF/靶场多层内网渗透指导与自动化脚本生成技能。基于 NPS C2 通道,覆盖从初始侦察、网段发现、 服务利用、Windows/Linux 提权、凭据收集与复用、域渗透(ADCS/noPac/Zerologon)、 云原生/K8s/Docker 逃逸到横向移动的完整渗透链,目标是拿到 FLAG 或域控权限。 触发场景:用户提到内网渗透、CTF内网、靶场、多层内网、横向移动、提权、凭据获取、mimikatz、 hash传递、域渗透、域控攻击、云原生渗透、Docker逃逸、K8s渗透、fscan扫描、服务利用、…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Help with authorized JWT assessment using ticarpi/jwt_tool. Use this skill whenever the user mentions `jwt_tool`, wants commands for JWT decoding, verification, secret cracking, claim tampering, playbook scans, `alg:none`, key confusion, JWKS spoofing or…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

通用已知产品/框架漏洞利用专项技能。适用于 fscan/Nuclei/Wappalyzer 识别出目标运行已知产品(OA系统、CMS、中间件、框架)后的标准利用流程。 核心原则:已知产品必须 Nuclei 先行,不走盲测渗透。覆盖 Nuclei 精准扫描、模板分析、手工验证、环境诊断、命令执行方式选择、NPS 收口。 触发场景:fscan…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Help with safe, practical use of ProjectDiscovery Nuclei for authorized scanning. Use this skill whenever the user wants to run `nuclei`, choose templates, filter by tags or severity, scan one host or a target list, validate or run a custom template, tune…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Payload crafting and bypass research for vulnerability verification

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Browse the bundled PayloadsAllTheThings corpus for CTF and web security payloads, bypasses, fuzz strings, exploit ideas, and methodology notes. Use when Agent needs to locate payloads by vulnerability category during CTFs, pentests, or challenge solving, then…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Help with authorized Web pentest, Web fuzzing, and CTF-style vulnerability analysis. Use this skill whenever the user wants payload ideas, fuzz dictionaries, quick probe strings, test methodology, response-difference heuristics, or per-vulnerability…

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

安全构造 PHP payload 的专项技能。解决 bash/shell 转义导致 PHP 代码损坏的问题,提供经过验证的 payload 模板。 触发场景:用户需要通过 bash/shell 写入 PHP 文件(echo、printf、redis-cli -x、curl -d)、 遇到 $_POST/$_GET 变量被 bash 展开、PHP 代码写入后不执行、disable_functions bypass、 构造 webshell、构造诊断页、构造文件下载器、heredoc 写法、base64…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Fast reconnaissance - discover assets, entry points, attack surface, and hypotheses

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Windows/Linux 场景下基于 Redis 未授权访问写入 Web 根并获取稳定命令执行、随后快速收敛到 NPS 的专项技能。只要用户提到 Redis、Redis未授权、6379、fscan 提示 unauthorized file、CONFIG SET dir/dbfilename、写 webshell、写计划任务、写 ssh key,或者已经确认 Redis 能写入 Web 目录,就应优先使用本技能,而不是走泛化 Web 利用或 SMB 分支。尤其在用户已经有上游跳板、NPS 通道、HTTP…

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

Windows/Linux 远程命令执行规范技能。覆盖 NPS execcmd 通用规范、Windows cmd /c 要求与绝对路径、 Linux nohup/后台执行、wmic/setsid 后台启动、工具上传语义、常用命令路径参考。 触发场景:用户通过 NPS execcmd 在受控主机上执行命令、遇到命令不回显、命令超时、 路径错误、找不到命令、工具上传后执行失败、后台进程启动、文件下载传输、 环境变量/PATH 异常时使用。同时适用于 Windows 和 Linux 主机。

Quellsprache: Chinesisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.

Quellsprache: Englisch

Aktualisiert
Beruf
Informationssicherheitsanalysten
Beschreibung

用于 pentest-agent 的 targeted-pentest 子 agent,在已锁定的 hypothesis_id、kind 与 entry_point 上执行单假设定向验证。适用于 Web、API、认证、浏览器端、服务端、Node.js 与 CVE 线索的验证场景;在同一假设内完成基线确认、payload 研究、最小化利用、证据收集、结论判定与 goal 提交。不用于宽泛 recon、不切换到其他假设、也不做与当前假设无关的发散测试。

Quellsprache: Chinesisch

Aktualisiert
Beruf
Softwareentwickler
Beschreibung

Use this skill whenever the user wants to crawl a website with the `tch-headless` or `TCH-EZ-Headless` browser crawler for a quick headless pass, especially for dynamic pages, Chrome-based automation, request capture, sitemap-style output inspection, or…

Quellsprache: Englisch

Aktualisiert
Es werden 22 von 22 gesammelten Skills angezeigt.