en un clic
gb-cyber
gb-cyber contient 9 skills collectées depuis philo-groves, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Aggressive debugging of authorized binaries, crashes, cores, sanitizers, and runtime behavior with the goal of turning crash data and runtime observations into high-severity vulnerabilities as fast as possible. Use when static reversing isn’t enough and you need runtime state, memory corruption details, register control, or exploitability evidence. Red-team focused: form exploit hypotheses quickly, reproduce aggressively in lab environments, and push promising leads hard toward proof.
Aggressive static reverse engineering of authorized binaries and native components with the explicit goal of finding high-severity vulnerabilities. Use when you have ELF, Mach-O, PE, firmware, packed artifacts, native libraries, or large decompiles (especially jadx trees) and need to hunt for bugs fast. Red-team oriented: form attack hypotheses early, chase weak signals, and hand off to dynamic/fuzzing aggressively when static hits a wall.
Aggressive red-team source code review for authorized bug bounty targets. Use when hunting for high-severity issues (especially critical/key-compromise class) in large codebases, decompiles, or complex protocol implementations. Optimized for offensive mindset: generate attack ideas first, pursue weak signals hard, and only become conservative at the final proof stage. Primary skill for deep dives on targets like Coinbase cb-mpc, Fireblocks MPC, Chainlink, Stripe, etc.
Aggressive use of CVE intelligence, public advisories, KEV, and EPSS data to find high-value vulnerabilities and variants in authorized bug bounty targets. Use to identify weak patterns in your current codebases, prioritize attack surfaces, hunt for similar issues, and assess real-world exploitability in your specific environment.
Actively hunt for and compose exploit chains that turn multiple smaller issues into high-impact (especially critical) findings. Use aggressively: during code review, after new leads appear in finding-tracker, and whenever one primitive unlocks another. Red-team focused — chains are how you turn "a bunch of medium findings" into something that actually pays.
Aggressive offensive finding management for authorized red team bug bounty work. Use to log, track, chain, and promote attack leads as fast as possible while still preventing real duplicate effort. Designed for hunters who want to stay aggressive: log weak signals early, keep promising leads alive longer, and only de-escalate after real effort. Works with the rest of the red-team skill suite (especially the aggressive code-vulnerability-review).
Turn high-quality proofed findings and strong evidence into submission-ready vulnerability reports optimized for high bounty payouts. Designed to work with the aggressive red-team stack, especially high-standard proof packets from triage-verifier. Produces clear, high-impact, well-structured reports for HackerOne, Bugcrowd, and other programs.
Final proof gate for red-team findings. Produce high-quality, near-submission-ready proof packets that can be used directly in strong bug bounty reports. Use only after a finding has reached "confident" in finding-tracker. The goal is not just verification — it is to create a clean, convincing, and well-documented exploit PoC that stands up to real triager scrutiny.
Aggressive red-team inspection of authorized web applications, SPAs, and APIs. Focus on finding high-severity issues (especially authorization, business logic, and account takeover class) using browser automation, HTTP manipulation, and state comparison. Designed for speed and impact — form attack hypotheses quickly and test them hard.