Skip to main content

Skills dans ce dépôt

abelrguezr/hacktricks-skills - Page 7

SkillsMP a collecté 908 skills depuis abelrguezr/hacktricks-skills. Ouvrez un skill pour examiner sa source et ses détails.

abelrguezr/hacktricks-skills

Affichage de 40 skills collectés sur 908.

métier
Analystes en sécurité de l'information
description

Bypass Linux filesystem protections (read-only, no-exec, distroless containers) for authorized security testing. Use this skill whenever you need to execute code on restricted Linux systems, containers with readOnlyRootFilesystem, distroless containers, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Bypass Linux filesystem protections (read-only, noexec, file whitelisting, hash whitelisting) by hijacking existing processes through /proc/pid/mem. Use this skill whenever you need to execute code on a restricted Linux system, bypass filesystem restrictions,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

FreeIPA penetration testing and enumeration. Use this skill whenever the user mentions FreeIPA, Kerberos on Unix, LDAP enumeration, IPA domain attacks, or any Active Directory-like infrastructure on Linux/Unix systems. This skill covers authentication,…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

How to work with Linux fundamentals including file permissions, user management, process control, and system navigation. Use this skill whenever the user needs help with Linux commands, file operations, permissions, users/groups, processes, or basic system…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

How to manage, configure, and secure Linux environment variables. Use this skill whenever the user needs to set, modify, or understand environment variables on Linux systems, configure proxies, hide command history, manage SSL certificates, customize prompts,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Linux PAM security auditing, backdoor detection, and hardening. Use this skill whenever the user mentions PAM configuration, authentication security, Linux hardening, credential harvesting detection, SSH security, or any post-exploitation concerns related to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to enumerate Linux privilege escalation vectors, check for local privilege escalation opportunities, or systematically assess a Linux system for privilege escalation paths. Trigger this when you have shell access to a Linux…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security analysis skill for Android rooting frameworks (KernelSU, Magisk, APatch, SKRoot). Use this skill when analyzing privilege escalation vulnerabilities in kernel-level rooting solutions, reviewing syscall hook authentication mechanisms, implementing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation techniques for Cisco vManage/Catalyst SD-WAN Manager. Use this skill whenever you have a low-privilege shell on a Cisco vManage system and need to escalate to root. Trigger this when you see vManage, Catalyst SD-WAN, confd, cmdptywrapper,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to perform privilege escalation using containerd's ctr command during authorized security assessments. Use this skill whenever the user mentions containerd, ctr command, container escape, privilege escalation in containerized environments, or needs to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Enumerate and exploit D-Bus services for local privilege escalation on Linux systems. Use this skill whenever you need to find misconfigured D-Bus services, discover vulnerable methods, or exploit command injection in D-Bus interfaces during authorized…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security skill for understanding, detecting, and preventing Docker socket privilege escalation attacks. Use this skill whenever the user mentions Docker security, container escape, privilege escalation, Docker socket access, container security auditing, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to analyze, create, and test AppArmor security profiles on Linux systems. Use this skill whenever the user mentions AppArmor, Linux security profiles, Docker container security, mandatory access control (MAC), or needs to audit/modify program confinement…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Audit Docker authorization plugins and identify security misconfigurations. Use this skill whenever the user mentions Docker security, authorization plugins, container access control, Docker daemon security, authz bypass, or needs to assess Docker plugin…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze Linux cgroups for security assessment, privilege escalation opportunities, and resource limit analysis. Use this skill whenever the user mentions cgroups, control groups, container resource limits, Linux process isolation, systemd slices, or wants to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Docker container escape and privilege escalation techniques. Use this skill whenever the user is inside a Docker container and wants to escape to the host, enumerate container security configurations, check for exposed docker sockets, abuse capabilities,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill when investigating Docker container escapes via cgroups release_agent vulnerability (CVE-2022-0492). Trigger when users mention container escape, privilege escalation, cgroups, release_agent, or need to understand/defend against this specific…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Docker container escape via cgroup release_agent exploit. Use this skill whenever the user mentions container escape, privilege escalation from containers, cgroup exploitation, Docker security testing, or needs to test container breakout vulnerabilities. This…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security analysis for Docker/Kubernetes container sensitive mount vulnerabilities. Use this skill whenever the user mentions container security, Docker escapes, Kubernetes pod security, sensitive mounts, /proc, /sys, /var, containerd sockets, kubelet,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze Docker --privileged container security implications, check if a container is privileged, and understand available escape vectors. Use this skill whenever the user mentions Docker containers, privileged mode, container security, privilege escalation,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to secure Docker containers, audit Docker configurations, scan for vulnerabilities, or harden Docker deployments. Trigger this for any Docker security questions, container hardening, vulnerability scanning, reviewing…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux CGroup namespaces for process isolation and security analysis. Use this skill whenever the user mentions cgroup namespaces, container isolation, process hierarchy inspection, namespace enumeration, or needs to understand how cgroups…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux IPC (Inter-Process Communication) namespaces for security isolation and privilege escalation analysis. Use this skill whenever the user needs to understand IPC namespace isolation, create isolated IPC environments, inspect IPC objects…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux mount namespaces for file system isolation and privilege escalation. Use this skill whenever the user mentions mount namespaces, namespace isolation, file system isolation, container security, or needs to create/enter/inspect mount…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

How to understand, test, and harden Docker namespace isolation for security. Use this skill whenever the user mentions Docker security, container isolation, namespace escapes, privilege escalation, container breakout, or needs to audit namespace…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux network namespaces for security testing, containerization, and system administration. Use this skill whenever the user mentions network namespaces, network isolation, container networking, nsenter, unshare, veth pairs, or needs to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux PID namespaces for container security, process isolation, and privilege escalation analysis. Use this skill whenever the user mentions containers, Docker, namespaces, process isolation, PID namespace, container escape, privilege…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Linux Time Namespace operations for security analysis, container hardening, and privilege escalation research. Use this skill whenever the user needs to create, inspect, or manipulate Linux time namespaces, check namespace membership, adjust CLOCK_MONOTONIC…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to work with Linux user namespaces for Docker security testing and privilege escalation analysis. Use this skill whenever the user mentions user namespaces, UID/GID mapping, container isolation, Docker security, namespace enumeration, or wants to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to work with Linux UTS namespaces for security testing, privilege escalation, or container security analysis. This includes checking which UTS namespace you're in, finding all UTS namespaces on a system, entering UTS…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Docker container security hardening using Seccomp syscall filtering. Use this skill whenever you need to restrict system calls in Docker containers, create custom seccomp profiles, profile applications with strace to determine required syscalls, or harden…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to execute arbitrary code in distroless containers using available binaries like openssl. Use this skill whenever the user is working on container security, penetration testing, CTF challenges, or needs to understand how to run commands in minimal…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security audit skill for identifying Node.js inspector and CEF/Chromium debugger vulnerabilities in applications. Use this skill when assessing Electron apps, Node.js services, or CEF-based applications for exposed debugging ports, remote code execution…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Techniques for escaping from Linux chroot jails, restricted bash shells, and other sandboxed environments. Use this skill whenever you need to break out of a chroot, escape a restricted shell, bypass bash limitations, or escape from Python/Lua sandboxes.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to analyze and exploit Linux privilege escalation through user ID manipulation (ruid, euid, suid). Use this skill whenever the user mentions privilege escalation, SUID binaries, setuid/setreuid/setresuid functions, execve/system calls, or needs to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Linux privilege escalation via group membership analysis. Use this skill whenever the user mentions Linux privilege escalation, group membership, sudo access, or needs to check if their current user can escalate privileges through group-based vectors. This…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation via LXD/LXC group membership. Use this skill whenever the user mentions LXD, LXC, container-based privilege escalation, or when they discover they belong to the lxd or lxc group on a Linux system. This skill provides step-by-step methods…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Check for ld.so library path privilege escalation vulnerabilities. Use this skill whenever the user mentions ld.so, library paths, /etc/ld.so.conf, ldconfig, shared library vulnerabilities, or wants to audit Linux systems for library loading…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to enumerate Active Directory from Linux and extract Kerberos tickets for privilege escalation. Use this skill whenever the user mentions Linux machines in AD environments, Kerberos tickets, CCACHE files, keytabs, FreeIPA, or wants to perform…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Linux capabilities security auditing and privilege escalation guide. Use this skill whenever the user asks about Linux capabilities, capability-based privilege escalation, container escapes, security auditing of Linux systems, or needs to understand how to…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 908.