Skip to main content

Skills dans ce dépôt

abelrguezr/hacktricks-skills - Page 8

SkillsMP a collecté 908 skills depuis abelrguezr/hacktricks-skills. Ouvrez un skill pour examiner sa source et ses détails.

abelrguezr/hacktricks-skills

Affichage de 40 skills collectés sur 908.

métier
Analystes en sécurité de l'information
description

Research, analyze, and create PoCs for CVE-2025-38352 (POSIX CPU timers TOCTOU race in Linux kernel). Use this skill whenever the user mentions kernel vulnerabilities, POSIX timers, TOCTOU races, timer exploitation, CVE-2025-38352, or wants to…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to escalate privileges through Logstash misconfigurations. Use this skill whenever you're doing security testing, CTF challenges, or privilege escalation research and encounter Logstash on a target system. Trigger this when you need to check for writable…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation via NFS no_root_squash misconfiguration. Use this skill whenever you need to escalate privileges on a Linux system with NFS shares, when you find /etc/exports with no_root_squash, when you have access to an NFS share and want to gain…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Linux privilege escalation payloads and techniques for CTFs and authorized penetration testing. Use this skill whenever the user mentions privilege escalation, privesc, SUID binaries, setuid, escalating from www-data to root, overwriting libraries, or any…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever you need to enumerate and exploit Linux privilege escalation vectors. Trigger this skill when the user mentions privilege escalation, privesc, gaining root, escalating privileges, Linux security assessment, or when they have shell…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation technique using runc container runtime to mount the host's root filesystem. Use this skill whenever you're doing privilege escalation on a Linux system and runc is available, or when you need to escape a container to access the host…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

How to understand and configure SELinux for container security. Use this skill whenever the user mentions SELinux, container security, container escape prevention, podman, docker security, or needs to harden container environments with mandatory access…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identify, test, and exploit socket command injection vulnerabilities in Unix socket-based services. Use this skill whenever you need to audit Unix sockets for command injection flaws, analyze socket-based privilege escalation vectors, or harden socket…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security assessment skill for Splunk services. Use this skill whenever the user needs to enumerate Splunk installations, assess Splunk security configurations, document Splunk vulnerabilities, or perform authorized penetration testing on Splunk…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to identify and exploit SSH agent forwarding vulnerabilities for security auditing. Use this skill whenever you need to check for SSH agent forwarding misconfigurations, find exposed SSH agent sockets, understand agent hijacking risks, or audit SSH…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever analyzing VMware Tools privilege escalation vulnerabilities, CVE-2025-41244, untrusted search path issues, or regex-driven service discovery abuse patterns. Also use when investigating vmtoolsd processes, service discovery scripts, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation via wildcard/glob argument injection. Use this skill whenever you need to exploit unquoted wildcards in privileged scripts, or when analyzing binaries like tar, rsync, zip, 7z, tcpdump, chown, chmod for argument injection vulnerabilities.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Privilege escalation techniques when you can write to root-owned files. Use this skill whenever you have write access to system files owned by root and need to escalate privileges. This includes scenarios where you can modify /etc/ld.so.preload, git hooks,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Essential Linux commands for security auditing, incident response, and system hardening. Use this skill whenever the user needs to: enumerate system vulnerabilities (SUID/SGID files, writable directories), analyze logs (journalctl, grep patterns), investigate…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Locate, shortlist, and navigate the generated skills corpus quickly. Use this skill whenever the user asks to find a relevant skill, browse the 900+ skills, identify duplicates, map topic coverage, or open the correct SKILL.MD/scripts folder for a task.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS persistence and auto-start location guide. Use this skill whenever the user asks about macOS persistence mechanisms, auto-start locations, launch agents, launch daemons, shell startup files, or any technique for maintaining access on macOS systems. This…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze and enumerate macOS Keychain entries for security assessments. Use this skill whenever you need to inspect keychain contents, understand ACL permissions, extract credentials, or perform keychain security analysis on macOS systems. Make sure to use…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security research skill for understanding and testing macOS MDM/DEP enrollment vulnerabilities. Use this skill when investigating MDM security, analyzing DEP enrollment processes, researching mobile device management attack surfaces, or conducting authorized…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Research and analyze macOS Mobile Device Management (MDM) and Device Enrollment Program (DEP) configurations, enrollment processes, and security implications. Use this skill whenever investigating MDM implementations, analyzing device enrollment flows,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Decode and analyze Apple device serial numbers to extract manufacturing location, date, and model information. Use this skill whenever you need to parse Apple serial numbers, investigate device origins, analyze hardware for security assessments, or understand…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS red teaming and offensive security operations. Use this skill whenever the user mentions macOS penetration testing, MDM abuse (JAMF, Kandji), Active Directory attacks on macOS, keychain extraction, or any macOS-specific offensive security tasks. This…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS kernel and system architecture reference for security research. Use this skill whenever the user asks about XNU kernel internals, Mach/BSD architecture, coprocessors (SEP, SMC, T2, ANE, etc.), kernel extensions, system extensions, cryptexes, RSR…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever analyzing macOS kernel drivers, IOKit vulnerabilities, or reverse engineering macOS kernel extensions. Trigger for any macOS security research involving IOKit, driver analysis, IORegistry inspection, kernel extension investigation, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to analyze macOS kernel extensions (Kexts), extract and inspect kernelcaches, enumerate loaded kexts, debug kernel panics, and identify kernel-level security issues. Use this skill whenever the user mentions kernel extensions, kexts, kernelcache, macOS…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assess macOS kernel security posture, check for known vulnerabilities (CVE-2022-46722, CVE-2024-23225, CVE-2024-23296, CVE-2023-41075, CVE-2024-44243), enumerate kernel extensions, verify SIP/Gatekeeper status, and recommend mitigations. Use this skill…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze and work with macOS System Extensions including DriverKit, Network Extensions, and Endpoint Security Framework. Use this skill when investigating macOS security, analyzing system extensions, understanding endpoint security bypasses, or working with…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze macOS APFS file system for security research, forensics, or privilege escalation. Use this skill whenever the user mentions APFS, Apple File System, macOS volumes, snapshots, firmlinks, diskutil commands, or needs to understand macOS storage…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

ARM64 assembly language reference for macOS security and reverse engineering. Use this skill whenever the user asks about ARM64 assembly, registers, instructions, exception levels, calling conventions, shellcode, or macOS system calls. This includes questions…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Reference and templates for x64 assembly programming and macOS shellcode development. Use this skill whenever the user needs to understand x64 registers, calling conventions, write assembly code, create shellcode for macOS, work with syscalls, or needs quick…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use this skill whenever analyzing macOS binaries, debugging applications, performing security research on macOS apps, or fuzzing macOS software. Trigger for any macOS binary analysis, reverse engineering, crash investigation, security assessment, or when the…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Inspect, debug, and analyze macOS/iOS objects in memory using LLDB and Frida. Use this skill whenever the user needs to examine Objective-C or Swift objects at runtime, understand memory layouts, decode type encodings, work with arm64e/PAC pointers, enumerate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze and understand Objective-C code in macOS binaries for security research, reverse engineering, and privilege escalation. Use this skill whenever you need to read Objective-C source code, analyze Mach-O binaries with class-dump, understand iOS/macOS app…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Audit and test macOS firewall configurations for potential bypass vulnerabilities. Use this skill whenever you need to assess macOS firewall security, check for known bypass techniques, enumerate allowed traffic, inspect PF rules, or validate Network…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to deploy and use macOS defensive security applications including firewalls (Little Snitch, LuLu), persistence detection tools (KnockKnock, BlockBlock), and keylogger detection (ReiKey). Use this skill whenever the user mentions macOS security, defensive…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS dynamic library injection and hijacking techniques for security research and penetration testing. Use this skill whenever the user needs to analyze macOS binaries for DYLD_INSERT_LIBRARIES vulnerabilities, perform dyld hijacking attacks, create…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS security skill for enumerating file extension handlers and URL scheme handlers via LaunchServices database. Use this skill whenever analyzing macOS systems for privilege escalation, investigating default app handlers, auditing file associations, or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze macOS application bundles for security assessment, code signing verification, and potential exploitation vectors. Use this skill whenever you need to inspect .app bundles, .framework files, or other macOS bundle types for penetration testing, security…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

macOS file system, permissions, binaries, and security reference. Use this skill whenever the user asks about macOS file structures, directory layouts, file permissions, plist files, bundles, dyld shared cache, file flags, ACLs, extended attributes, resource…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyze macOS installer packages (.pkg and .dmg files) for security vulnerabilities, privilege escalation vectors, and malicious content. Use this skill whenever you need to inspect installer packages, extract and analyze installer scripts, identify…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

How to dump and analyze macOS memory for forensic investigation. Use this skill whenever the user needs to extract memory from a macOS system, investigate memory artifacts, analyze swap files, hibernate images, or perform macOS forensics, even if they don't…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 908.