Guides binary reverse engineering with static/dynamic analysis, Ghidra, radare2, GDB, .NET decompilation, and checksec workflows. Use when analyzing unknown binaries, malware samples, or supporting exploit development.
Quellsprache: Mehrsprachig
Menü
Skills in diesem Repository
SkillsMP hat 57 Skills aus Suzu-Testing/metasploit-cursor-harness gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
Suzu-Testing/metasploit-cursor-harnessEs werden 17 von 57 gesammelten Skills angezeigt.
Guides binary reverse engineering with static/dynamic analysis, Ghidra, radare2, GDB, .NET decompilation, and checksec workflows. Use when analyzing unknown binaries, malware samples, or supporting exploit development.
Quellsprache: Mehrsprachig
Guides SMB/CIFS service penetration testing. Use when port 445 or 139 is discovered during scanning or when SMB file sharing is identified on a target.
Quellsprache: Englisch
Guides SMTP mail transfer service penetration testing. Use when port 25 or 587 is discovered during scanning or when SMTP is identified on a target.
Quellsprache: Englisch
Guides SNMP network management service penetration testing. Use when port 161 or 162 is discovered during scanning or when SNMP is identified.
Quellsprache: Englisch
Guides SQL injection testing with detection probes, DB-specific payloads, bypass techniques, and sqlmap automation. Use when database errors appear, single quotes break queries, numeric parameters behave oddly, or search/filter endpoints reflect SQL-like…
Quellsprache: Englisch
Guides SSH/SFTP service penetration testing. Use when port 22 is discovered during scanning or when Secure Shell service is identified on a target.
Quellsprache: Englisch
Guides server-side request forgery testing with internal network probes, cloud metadata abuse, protocol smuggling, and filter bypass techniques. Use when the application fetches URLs, webhooks, PDFs, image proxies, or imports content from user-supplied…
Quellsprache: Englisch
Guides server-side template injection testing with engine identification probes, RCE payloads per template engine, and tplmap automation. Use when template delimiters appear in output, template engine errors surface, or user input is rendered inside…
Quellsprache: Englisch
Guides Telnet remote terminal service penetration testing. Use when port 23 is discovered during scanning or when Telnet is identified on a target.
Quellsprache: Englisch
Guides file upload vulnerability testing with extension bypass, content-type manipulation, magic byte injection, and web shell deployment. Use when file upload forms, avatar/profile uploads, or document import features are in scope.
Quellsprache: Englisch
Guides VNC remote desktop service penetration testing. Use when port 5900 is discovered during scanning or when VNC/RFB service is identified.
Quellsprache: Englisch
Guides web application penetration testing aligned with OWASP/WSTG methodology. Use for attack surface mapping, vuln class routing, auth testing, and MSF delivery after web-based initial access. Payload details live in tier-3 vuln skills.
Quellsprache: Englisch
Guides wireless network penetration testing including monitor mode setup, WPA2 handshake capture, PMKID attacks, hashcat cracking, evil twin, WPS, and WPA-Enterprise testing. Use when wireless networks are explicitly in engagement scope and ROE authorizes RF…
Quellsprache: Englisch
Guides Windows host penetration testing for local privesc, credential theft, token abuse, DPAPI, and lateral movement from a Windows foothold or non-domain Windows targets.
Quellsprache: Englisch
Guides Windows Remote Management penetration testing. Use when port 5985 or 5986 is discovered during scanning or when WinRM is identified on a target.
Quellsprache: Englisch
Guides cross-site scripting testing with context-aware payloads, filter evasion, CSP bypass, and blind XSS techniques. Use when user input appears in HTML, JavaScript, or DOM sinks, or reflected/stored content suggests script injection is possible.
Quellsprache: Englisch
Guides XML external entity injection testing with classic, blind OOB, XXE-to-SSRF, and file read payloads. Use when the application accepts XML, SOAP, SVG, DOCX/XLSX, RSS, or other XML-based uploads and parsers may resolve external entities.
Quellsprache: Englisch