Skip to main content
SnailSploit
Profil créateur GitHub

SnailSploit

Vue par dépôt de 50 skills collectés dans 1 dépôts GitHub.

skills collectés
50
dépôts
1
mis à jour
26 août 2026
explorateur de dépôts

Dépôts et skills représentatifs

offensive-network-attacks
Analystes des systèmes informatiques

Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC bypass, IPv6 attacks. Tools: Bettercap, Responder, mitm6, Ettercap, Wireshark. MITRE T1557, T1040. Use when conducting…

26 août 2026
offensive-data-exfiltration
Analystes en sécurité de l'information

Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob SAS tokens, GCS…

26 août 2026
offensive-ssti
Développeurs de logiciels

Dense description covering Server-Side Template Injection across Jinja2, Twig, Freemarker, Velocity, Pebble, Smarty, Mako, Handlebars, ERB, Thymeleaf, EJS, Pug. Engine fingerprinting, filter bypass, blind exploitation, WAF evasion, SSTI-to-RCE chains. Tools:…

26 août 2026
offensive-api-abuse
Analystes en sécurité de l'information

Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific…

25 août 2026
offensive-persistence
Analystes en sécurité de l'information

Comprehensive persistence tradecraft for authorized red team engagements covering Windows and Linux mechanisms. Windows techniques include registry Run/RunOnce keys, scheduled tasks, WMI event subscriptions, DLL search order hijacking, COM object hijacking,…

25 août 2026
offensive-windows-privesc
Analystes en sécurité de l'information

Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\SYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using…

25 août 2026
offensive-dependency-confusion
Analystes en sécurité de l'information

Deep-dive offensive methodology for dependency confusion and namespace attacks across all major package ecosystems. Covers npm scope confusion exploiting the gap between public and private scoped packages and .npmrc misconfigurations where registry mappings…

25 août 2026
offensive-deserialization
Développeurs de logiciels

Insecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/phpggc/ysoserial.net, ObjectInputStream and BinaryFormatter sink identification, pickle __reduce__ RCE, phar:// wrapper…

25 août 2026
Affichage de 8 skills collectés sur 50.
1 dépôts affichés sur 1
Tous les dépôts sont affichés