Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
vakaobr
GitHub-Creator-Profil

vakaobr

Repository-Ansicht von 60 gesammelten Skills in 1 GitHub-Repositories.

gesammelte Skills
60
Repositories
1
aktualisiert
2026-06-28
Repository-Karte

Wo die Skills liegen

Top-Repositories nach gesammelter Skill-Anzahl, mit ihrem Anteil an diesem Creator-Katalog und ihrer Berufsverteilung.

Repository-Explorer

Repositories und repräsentative Skills

ad-kerberos-hunter
Informationssicherheitsanalysten

Tests an authorized Active Directory domain for Kerberos-abuse paths: Kerberoasting (TGS for SPN accounts → offline crack), AS-REP roasting (accounts without pre-auth), and enumeration/proof of unconstrained, constrained (S4U), and resource-based constrained delegation (RBCD) plus shadow-credentials (msDS-KeyCredentialLink) candidates. Consumes ad-recon-hunter's ad-quickwins.md. Use after ad-recon-hunter once internal_pentest is approved and domain credentials are available. Cracking and any impersonation proof are gated. Maps findings to CWE-287/CWE-522/CWE-284 and MITRE T1558. Internal pentest only - requires .claude/security-scope.yaml internal_pentest: approved and credentials from ad_credentials_vault_path. Grounded in redteam-ad-ops.

2026-06-28
ad-recon-hunter
Informationssicherheitsanalysten

Enumerates an authorized internal Active Directory environment: network-service sweep (SMB/LDAP/MSSQL/SNMP), null/guest session harvesting, BloodHound graph collection, and low-noise LDAP queries for users, computers, SPNs, delegation flags, password-not-required accounts, GPP cpassword in SYSVOL, and LAPS-readable hosts. Produces an AD inventory and a prioritized quick-win list that feeds ad-kerberos-hunter. Use as the FIRST internal/AD skill once internal_pentest is approved and engagement credentials (or an anonymous foothold) are available. Maps findings to CWE-200/CWE-522/CWE-284. Internal pentest only - requires .claude/security-scope.yaml internal_pentest: approved and credentials from ad_credentials_vault_path. Grounded in redteam-ad-ops.

2026-06-28
api-recon
Informationssicherheitsanalysten

Maps the attack surface of REST / GraphQL / gRPC APIs - OSINT for specs and endpoints, subdomain enumeration, active service fingerprinting, OpenAPI / Swagger / GraphQL-schema discovery, and hidden-parameter fuzzing. Use before any API-class hunter skill (bola-bfla-hunter, mass-assignment-hunter, owasp-api-top10-tester, jwt-hunter, graphql-hunter); they depend on its API_INVENTORY.md output. Run AFTER web-recon-passive and in parallel with or after web-recon-active. Produces API_INVENTORY.md with endpoints, methods, parameters, auth models, and versioning. Defensive testing only, against assets listed in .claude/security-scope.yaml.

2026-06-28
attack-surface-mapper
Informationssicherheitsanalysten

Consolidates outputs from web-recon-passive, web-recon-active, and api-recon into a single prioritized attack-surface picture - merging PASSIVE_RECON.md, ATTACK_SURFACE.md, API_INVENTORY.md, and AUTH_FLOWS.md into a deduplicated inventory ranked by risk (high-impact features, new/changed code, legacy /v1 endpoints, business-logic-rich flows). Use at the end of the recon phase to produce a single decision document that the orchestrator uses to select which class-specific hunters to run in what order. Passive-active hybrid - mostly reads prior outputs, adds minimal targeted probes for priority fingerprinting. Produces CONSOLIDATED_ATTACK_SURFACE.md with prioritization rationale. Defensive testing only.

2026-06-28
auth-flaw-hunter
Informationssicherheitsanalysten

Tests authentication subsystems for username enumeration, weak / absent lockout, multi-stage bypass (skipping MFA / security-questions stage), JWT signature integrity (dispatching to jwt-hunter), alternative-channel weakness (web vs mobile vs API), default-credential probing, and cleartext credential transmission. Use when login / password-reset / MFA flows are in scope; after `web-recon-active` maps the auth surface; or when the orchestrator's phase-0 plan prioritizes authentication hardening. Produces findings with CWE-287 / CWE-307 / CWE-522 mapping and layered auth hardening. Defensive testing only, against assets listed in .claude/security-scope.yaml - service_affecting: true.

2026-06-28
auth-flow-mapper
Informationssicherheitsanalysten

Passively maps every authentication flow in the target - primary login, MFA, password reset, account registration, alternative channels (mobile API, SSO), and token issuance points - without running active attack probes. Produces AUTH_FLOWS.md with state diagrams, endpoint inventory, token-issuance timing, multi-stage sequences, and alternative-channel deltas. Consumed by auth-flaw-hunter (for attack planning), jwt-hunter (for token handoff), oauth-oidc-hunter (for OAuth-specific flows), and session-flaw-hunter (for session-layer testing). Use as a foundational T4 skill before any authentication-class hunter. Passive profile - observation only.

2026-06-28
aws-iam-hunter
Informationssicherheitsanalysten

Audits AWS IAM posture for over-privileged roles, exposed long-lived access keys, SSRF-reachable IMDS credential leaks, dangling DNS records pointing at decommissioned AWS resources, and API responses leaking internal ARNs. Use when the target runs on AWS and the assessment scope includes cloud-account review; when SSRF has been confirmed by another skill; or when the orchestrator's recon surfaces AWS-style resource names. Produces findings with CWE-732 / CWE-918 mapping, IAM-policy JSON evidence, and least-privilege remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml - READ-ONLY AWS API calls only.

2026-06-28
bola-bfla-hunter
Informationssicherheitsanalysten

Tests APIs for Broken Object-Level Authorization (API1:2023 BOLA - cross-user resource access by ID manipulation) and Broken Function-Level Authorization (API5:2023 BFLA - non-admin users reaching admin-only endpoints via URL guessing or HTTP-method swap). Complements idor-hunter for web apps; this is the API-specific sister skill with API-class methodology and OWASP API Top 10 mapping. Use when `api-recon` surfaced resource-ID parameters and multi-role endpoints; when the orchestrator identifies administrative paths; or when two test accounts at different privilege levels are available. Produces findings with CWE-639 / CWE-285 mapping and authorization-middleware remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

2026-06-28
Zeigt die Top 8 von 60 gesammelten Skills in diesem Repository.
1 von 1 Repositories angezeigt
Alle Repositories angezeigt