Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
GitHub-Repository

ai-pentest-kb

ai-pentest-kb enthält 18 gesammelte Skills von thau0x01, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
18
Stars
5
aktualisiert
2026-06-09
Forks
2
Berufsabdeckung
1 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

engagement-management
Informationssicherheitsanalysten

Engagement-lifecycle management — pre-engagement scoping, ROE drafting, authorisation letters, threat modeling, CVSS scoring, finding write-up, executive summary, technical report, retest scoping, remediation validation. Use when the user mentions scope a pentest, ROE template, rules of engagement, get-out-of-jail letter, authorisation letter, scope statement, communications plan, blackout window, escalation matrix, threat modeling, STRIDE, PASTA, attack tree, threat actor profile, CVSS scoring, finding template, executive summary, technical report, retest, remediation validation, regression coverage, engagement kickoff, or evidence chain of custody.

2026-06-09
engagement-retest
Informationssicherheitsanalysten

Plan and execute a pentest retest — re-scope, re-execute the validation steps from prior findings, detect regressions, and write the retest report. Use when the user mentions retest, re-test, remediation validation, regression coverage, "verify the fixes", "validate remediation", retest scoping, retest report, posture trajectory, or compares "before vs after" findings.

2026-06-09
engagement-scoping
Informationssicherheitsanalysten

Drive the pre-engagement scoping conversation and produce the scope statement, Rules of Engagement, authorisation letter, and communications plan. Use when the user mentions kickoff, scoping a pentest, drafting ROE, rules of engagement, scope statement, authorisation letter, get-out-of-jail letter, communications plan, blackout window, escalation matrix, ROE drift, third-party hosting carve-out, social-engineering allowance, time-window restrictions, or evidence-handling rules.

2026-06-09
pentest-active-directory
Informationssicherheitsanalysten

Active Directory and hybrid Entra ID penetration testing. Use when the user mentions BloodHound, SharpHound, SOAPHound, AzureHound, RustHound, Kerberoast, AS-REP roast, Golden/Silver/Diamond/Sapphire ticket, DCSync, DCShadow, NTLM relay, ntlmrelayx, ADCS ESC1-ESC15+, EKUwu, Certipy, ACL abuse (GenericAll/WriteDACL/WriteOwner/shadow credentials), GPO abuse, NoPac, ZeroLogon, PetitPotam, DFSCoerce, PrinterBug, krbrelayup, AAD Connect, MSOL_, Pass-Through Auth, Seamless SSO, AdminSDHolder, SID History, krbtgt, or any "domain compromise" task.

2026-06-09
pentest-ai-llm
Informationssicherheitsanalysten

LLM-backed application, AI agent, and AI/ML supply-chain penetration testing. Use when the user mentions LLM pentest, AI red team, prompt injection (direct or indirect), jailbreak, DAN, Crescendo, GCG, many-shot jailbreak, system prompt leakage, RAG poisoning, embedding poisoning/inversion, vector DB attack, MCP / Model Context Protocol abuse, tool poisoning, agent excessive agency, function-call abuse, output handling chains (XSS/SSRF/SQLi via LLM output), training-data extraction, membership inference, modelscan/picklescan, Hugging Face poisoned model, garak, PyRIT, promptmap, Augustus, Spikee, OWASP LLM01-LLM10, MITRE ATLAS, or unbounded consumption / cost amplification.

2026-06-09
pentest-cheatsheet
Informationssicherheitsanalysten

Surface a one-page pentest cheatsheet for fast field recall. Use when the user asks for a "quick command", "cheatsheet", "one-liner", "what's the syntax for X", "remind me how to do Y", "give me the recon snippets", "AD cheatsheet", "lateral-movement one-liners", "AWS quick commands", "Azure quick commands", "mobile cheatsheet", "initial access cheatsheet", or any request that wants tools/commands without methodology overhead.

2026-06-09
pentest-checklist-lookup
Informationssicherheitsanalysten

Resolve a stable pentest-template checklist ID (e.g. WEB-AUTHN-04, AD-KRB-02, CLD-AWS-IAM-07, IOT-FW-05, RT-INIT-03, LLM-PI-03) to its full methodology, references, mappings, how-to-test block, and accept criteria. Use when the user mentions a checklist ID, asks to "look up <ID>", "what does <ID> say", "show me <ID>", "find checklist items mapped to CVE-XXXX", "find items mapped to ATT&CK Tnnn", "find items by CWE-NNN", or wants to navigate the templates by stable identifier.

2026-06-09
pentest-cloud
Informationssicherheitsanalysten

AWS, Azure/Entra ID, and GCP penetration testing. Use when the user mentions AWS pentest, Azure pentest, GCP pentest, IAM privilege escalation, S3 misconfig, IMDSv1/v2 SSRF, managed identity abuse, ScoutSuite, Prowler, Pacu, CloudFox, ROADtools, AzureHound, MicroBurst, AADInternals, Workload Identity, OIDC trust, federated credentials, cross-account / cross-tenant chains, KMS, Lambda, Cognito, App Service, Storage Account, Key Vault, GKE/EKS/AKS, GitHub Actions OIDC trust, Terraform state, or any cloud bucket / IAM enumeration task.

2026-06-09
pentest-finding-writer
Informationssicherheitsanalysten

Draft a pentest finding using the standard finding template with stable framework mappings. Use when the user says "write up this finding", "create a finding for...", "draft a vulnerability writeup", "score this with CVSS", "build the finding for the report", "promote this evidence to a finding", or similar requests to convert raw evidence into a deliverable finding. Works across web/API, mobile, infra, AD, cloud, wireless, physical, IoT/OT, AI/LLM findings.

2026-06-09
pentest-infra-external
Informationssicherheitsanalysten

External (perimeter / internet-facing) infrastructure penetration testing. Use when the user mentions external pentest, perimeter test, OSINT, subdomain enumeration, ASN, BBOT, Shodan, port scan, banner grab, service enumeration, edge-device CVEs (Ivanti, Citrix, F5, Fortinet, PAN, Sophos, MOVEit, ScreenConnect, Confluence, vCenter), credential stuffing/spraying against public portals, or cloud bucket enumeration.

2026-06-09
pentest-infra-internal
Informationssicherheitsanalysten

Internal infrastructure penetration testing from a network foothold. Use when the user mentions internal pentest, lateral movement, privilege escalation (LPE), LSASS dump, Mimikatz/NanoDump/secretsdump, PsExec, WMI, WinRM, NTLM relay, Responder, mitm6, LLMNR/NBT-NS poisoning, IPv6 takeover, DPAPI, GPP cpassword, LAPS, KeePass, SUID/GTFOBins, sudo NOPASSWD, container escape, kernel exploit, MSSQL link, or generic Windows/Linux post-exploitation.

2026-06-09
pentest-iot-ot
Informationssicherheitsanalysten

Embedded / IoT / OT / ICS penetration testing. Use when the user mentions IoT pentest, firmware analysis, OWASP FSTM, binwalk, squashfs, JFFS2, UBIFS, EMBA, FACT, Firmadyne, QEMU emulation, UART, JTAG, SWD, SPI flash, SOIC clip, CH341A, chip-off, JTAGulator, OpenOCD, glitching, ChipWhisperer, U-Boot, BLE GATT, Zigbee, LoRa, Z-Wave, NFC, sub-GHz, HackRF, URH, Modbus, DNP3, S7Comm, EtherNet/IP, BACnet, OPC UA, IEC 61850, Allen-Bradley, Siemens TIA, PLC, HMI, SCADA, engineering workstation, or ATT&CK ICS techniques.

2026-06-09
pentest-mobile
Informationssicherheitsanalysten

Android and iOS mobile application penetration testing using OWASP MASTG and MASVS. Use when the user mentions APK/IPA analysis, Frida hooking, Objection, jadx, MobSF, SSL pinning bypass, root/jailbreak detection bypass, Android exported components, iOS URL schemes / Universal Links, Keystore/Keychain, MASVS-* identifiers, or any mobile static/dynamic analysis task.

2026-06-09
pentest-physical
Informationssicherheitsanalysten

Physical penetration testing — covert entry, RFID/NFC cloning, lock bypass, on-site rogue device drop. Use when the user mentions physical pentest, on-site intrusion, tailgating, badge cloning, RFID, NFC, HID Prox, MIFARE Classic / DESFire, iCLASS, Proxmark3, ChameleonMini, Flipper Zero, ESPKey, lock pick, bump key, raking, shimming, REX bypass, Salto/ASSA/Onity/Saflok/Unsaflok, drop box, LAN Turtle, Bash Bunny, USB Rubber Ducky, OMG Cable, dumpster diving, or covert entry.

2026-06-09
pentest-report-structure
Informationssicherheitsanalysten

Author or migrate a pentest report into the modular `report/` layout that the pentest-report-manager (Piersec) ingests — one `report.md` (executive summary + index), one shared `setup.md`, one file per finding under `findings/`, one file per appendix under `appendices/`. Use when the user says "structure the report", "split the findings into files", "make this report compatible with the report manager", "import this into the Piersec tool", "create the report skeleton for engagement X", "renomeie os findings no padrão", or otherwise asks for the canonical file layout / filename convention / metadata table format. Triggers on report scaffolding, finding splitting, migration from monolithic Word/PDF to the modular markdown layout, and validation that an existing tree is parser-compliant.

2026-06-09
pentest-web-api
Informationssicherheitsanalysten

Web application and REST/GraphQL API penetration testing using OWASP WSTG, ASVS and API Top 10. Use when the user mentions web pentest, API test, BOLA, IDOR, BFLA, mass assignment, SQLi, XSS, SSRF, SSTI, CSRF, JWT, OAuth, OIDC, SAML, GraphQL introspection, file-upload abuse, deserialization, or any WSTG-* / API:2023-* identifier.

2026-06-09
pentest-wireless
Informationssicherheitsanalysten

Wireless penetration testing — 802.11, Bluetooth/BLE, Zigbee. Use when the user mentions Wi-Fi pentest, WPA/WPA2 crack, PMKID attack, WPA3 Dragonblood, WPS Pixie Dust / Reaver / Bully, Evil Twin, KARMA, MANA, hostapd-mana, eaphammer, captive portal, PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, 802.1X, aircrack-ng, hcxdumptool, hashcat WPA, BLE GATT, Sniffle, Ubertooth, BIAS, KNOB, Zigbee KillerBee, sub-GHz.

2026-06-09
red-team-emulation
Informationssicherheitsanalysten

Red-team adversary-emulation engagement (vs. straightforward pentest). Use when the user mentions red team, adversary emulation, threat-actor emulation, TIBER-EU, CBEST, CREST STAR, MITRE ATT&CK chain, kill chain, C2 (Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel, Nighthawk), AMSI/ETW bypass, indirect syscalls (SysWhispers, HellsGate), sleep obfuscation (Ekko, Foliage), donut, ScareCrow, Inceptor, Evilginx, OAuth consent phishing, MFA fatigue, BYOVD/LOLDriver, KrbRelayUp, NanoDump, malleable profile, JA3, domain fronting, redirector, OPSEC, purple team, or detection engineering.

2026-06-09