Skip to main content
GitHub-Repository

Mingyi-Atlas

Mingyi-Atlas enthält 122 gesammelte Skills von MingyiSecLab, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
122
Stars
9
aktualisiert
2026-06-08
Forks
0
Berufsabdeckung
5 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

benchmark
Sonstige Computerberufe

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

2026-06-08
adcs-esc1
Informationssicherheitsanalysten

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

2026-06-08
bloodhound-query
Informationssicherheitsanalysten

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

2026-06-08
netexec
Informationssicherheitsanalysten

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

2026-06-08
ad
Informationssicherheitsanalysten

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

2026-06-08
engagement-lifecycle
Sonstige Computerberufe

Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.

2026-06-08
engagement-startup
Sonstige Computerberufe

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

2026-06-08
final-report
Sonstige Computerberufe

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

2026-06-08
kill-chain-analysis
Sonstige Computerberufe

Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.

2026-06-08
orchestration
Sonstige Computerberufe

Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.

2026-06-08
atlas
Sonstige Computerberufe

Atlas orchestrator workflow — engagement intake, OPPLAN build, execution loop via task() delegation, final report. Tools=[]; everything ships through sub-agents.

2026-06-08
k8s-pivot
Sonstige Computerberufe

Kubernetes attack playbook — service-account token theft, RBAC abuse, pod escape, hostPath mount abuse, kube-api-server pivoting.

2026-06-08
s3-takeover
Sonstige Computerberufe

Detect and claim dangling S3 buckets referenced by subdomains (CNAME → s3 hostnames where bucket no longer exists).

2026-06-08
cloud
Sonstige Computerberufe

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

2026-06-08
terraform-state-leak
Sonstige Computerberufe

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

2026-06-08
oracle-manipulation
Sonstige Computerberufe

Hunt single-block oracle manipulation — spot-price AMM oracles, manipulable TWAP, dependent calculations, missing staleness checks.

2026-06-08
contracts
Softwareentwickler

Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.

2026-06-08
crypto-decode
Informationssicherheitsanalysten

Cipher detection + automated decryption via Ciphey, Cyberchef recipes, hashcat hash-ID, format conversion, common encoding chains.

2026-06-08
exploit-reporting
Informationssicherheitsanalysten

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

2026-06-08
supplychain
Informationssicherheitsanalysten

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

2026-06-08
web
Informationssicherheitsanalysten

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API exploitation.

2026-06-08
xs-leaks
Informationssicherheitsanalysten

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

2026-06-08
android
Informationssicherheitsanalysten

Android APK pentest workflow — apktool/jadx static, Frida dynamic instrumentation, SSL pinning bypass, root detection bypass, intent fuzzing, keystore extraction.

2026-06-08
mobile
Informationssicherheitsanalysten

Mobile application red team category — Android (APK) and iOS (IPA) pentest. Routing skill: identifies the platform + attack surface, then loads the matching sub-skill.

2026-06-08
c2
Informationssicherheitsanalysten

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

2026-06-08
c2-sliver
Informationssicherheitsanalysten

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

2026-06-08
web-recon
Informationssicherheitsanalysten

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

2026-06-08
anti-debug-bypass
Informationssicherheitsanalysten

Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.

2026-06-08
packer-unpacking
Informationssicherheitsanalysten

Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.

2026-06-08
reverser
Informationssicherheitsanalysten

Root pointer for the binary reversing lane. Covers triage, string extraction, packer unpacking, symbol risk, ROP, Ghidra deep analysis, and firmware extraction.

2026-06-08
abort-template
Informationssicherheitsanalysten

Abort / crisis plan generator — halt triggers, response actions, AI-aware safety gates (hallucination threshold, destructive-action gate, output validation).

2026-06-08
cleanup-template
Informationssicherheitsanalysten

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

2026-06-08
contact-template
Informationssicherheitsanalysten

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

2026-06-08
data-handling-template
Informationssicherheitsanalysten

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

2026-06-08
roe-template
Informationssicherheitsanalysten

Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.

2026-06-08
playwright-cli
Softwarequalitätssicherungsanalysten und -tester

Automate browser interactions, test web pages and work with Playwright tests.

2026-05-31
nuclei
Informationssicherheitsanalysten

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

2026-05-31
asrep-roasting
Informationssicherheitsanalysten

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

2026-05-31
certipy-esc-chain
Informationssicherheitsanalysten

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

2026-05-31
coercer
Informationssicherheitsanalysten

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

2026-05-31
Zeigt die Top 40 von 122 gesammelten Skills in diesem Repository.