Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
tr4m0ryp
GitHub-Creator-Profil

tr4m0ryp

Repository-Ansicht von 36 gesammelten Skills in 3 GitHub-Repositories.

gesammelte Skills
36
Repositories
3
aktualisiert
2026-07-06
Repository-Explorer

Repositories und repräsentative Skills

jwt-tool
Informationssicherheitsanalysten

[exploit] Inspect and attack JSON Web Tokens — alg:none, key confusion (RS256→HS256), weak-secret cracking, claim tampering. Reach for it whenever the app authenticates with JWTs to test signature and verification flaws.

2026-06-06
naabu
Informationssicherheitsanalysten

[recon] Fast SYN/CONNECT port scanner for hosts/CIDRs (Go, libpcap). Reach for it to find open ports across many hosts quickly, then hand the open services to nmap for deep fingerprinting.

2026-06-06
trivy
Softwareentwickler

[static-analysis] All-in-one scanner over the connected repo: dependency CVEs across MANY ecosystems (npm, NuGet/.NET, Maven, Go, pip, RubyGems…), plus IaC/Dockerfile/Kubernetes misconfig and a filesystem secret sweep. Reach for it in pre-recon/vuln-analysis for SCA on stacks osv-scanner under-covers and for deeper infra-misconfig than generic SAST.

2026-06-06
semgrep
Softwareentwickler

[static-analysis] Static code analysis (SAST) over the connected repo — taint/pattern rules per vuln category, no live traffic. Reach for it in vuln-analysis to locate vulnerable code at file:line that DAST then confirms.

2026-06-06
trufflehog
Softwareentwickler

[static-analysis] Find secrets in a repo/history/filesystem and LIVE-VERIFY them against the issuing provider. Reach for it in vuln-analysis when you need to separate truly-active leaked credentials from dead noise.

2026-06-06
gitleaks
Softwareentwickler

[static-analysis] Scan a repo's files and full git history for hardcoded secrets (keys, tokens, credentials). Reach for it in vuln-analysis to find committed secrets, including ones removed from HEAD but live in history.

2026-06-06
git-security-history
Informationssicherheitsanalysten

[static-analysis] Mine the cloned repo's OWN git history for past security/fix commits and map them to recurring hot files, then fold in dependency-CVE (osv-scanner) and history-secret (gitleaks) signals. Reach for it in pre-recon to seed 'what's been exploited before' — code patched for a vuln once is the highest-yield place to re-examine.

2026-06-05
shor-setup
Informationssicherheitsanalysten

Full interactive setup guide for Shor (the web-security scanning platform). Invoke when a user wants to pentest a target: guides scan-type selection, repo analysis, compute recommendation, pre-flight, deployment, auth wiring, and Shor project + scan creation. Also covers deploying the Shor platform itself on GCP when it is not yet running. Handles black-box and white-box modes.

2026-06-05
Zeigt die Top 8 von 34 gesammelten Skills in diesem Repository.
3 von 3 Repositories angezeigt
Alle Repositories angezeigt