Skip to main content

このリポジトリの skills

abelrguezr/hacktricks-skills - 8ページ

SkillsMP は abelrguezr/hacktricks-skills から 908 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

abelrguezr/hacktricks-skills

収集済み skill 908 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Research, analyze, and create PoCs for CVE-2025-38352 (POSIX CPU timers TOCTOU race in Linux kernel). Use this skill whenever the user mentions kernel vulnerabilities, POSIX timers, TOCTOU races, timer exploitation, CVE-2025-38352, or wants to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to escalate privileges through Logstash misconfigurations. Use this skill whenever you're doing security testing, CTF challenges, or privilege escalation research and encounter Logstash on a target system. Trigger this when you need to check for writable…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Privilege escalation via NFS no_root_squash misconfiguration. Use this skill whenever you need to escalate privileges on a Linux system with NFS shares, when you find /etc/exports with no_root_squash, when you have access to an NFS share and want to gain…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Linux privilege escalation payloads and techniques for CTFs and authorized penetration testing. Use this skill whenever the user mentions privilege escalation, privesc, SUID binaries, setuid, escalating from www-data to root, overwriting libraries, or any…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill whenever you need to enumerate and exploit Linux privilege escalation vectors. Trigger this skill when the user mentions privilege escalation, privesc, gaining root, escalating privileges, Linux security assessment, or when they have shell…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Privilege escalation technique using runc container runtime to mount the host's root filesystem. Use this skill whenever you're doing privilege escalation on a Linux system and runc is available, or when you need to escape a container to access the host…

原文の言語: 英語

更新
職業分類
ネットワーク・コンピュータシステム管理者
説明

How to understand and configure SELinux for container security. Use this skill whenever the user mentions SELinux, container security, container escape prevention, podman, docker security, or needs to harden container environments with mandatory access…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identify, test, and exploit socket command injection vulnerabilities in Unix socket-based services. Use this skill whenever you need to audit Unix sockets for command injection flaws, analyze socket-based privilege escalation vectors, or harden socket…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security assessment skill for Splunk services. Use this skill whenever the user needs to enumerate Splunk installations, assess Splunk security configurations, document Splunk vulnerabilities, or perform authorized penetration testing on Splunk…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to identify and exploit SSH agent forwarding vulnerabilities for security auditing. Use this skill whenever you need to check for SSH agent forwarding misconfigurations, find exposed SSH agent sockets, understand agent hijacking risks, or audit SSH…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill whenever analyzing VMware Tools privilege escalation vulnerabilities, CVE-2025-41244, untrusted search path issues, or regex-driven service discovery abuse patterns. Also use when investigating vmtoolsd processes, service discovery scripts, or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Privilege escalation via wildcard/glob argument injection. Use this skill whenever you need to exploit unquoted wildcards in privileged scripts, or when analyzing binaries like tar, rsync, zip, 7z, tcpdump, chown, chmod for argument injection vulnerabilities.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Privilege escalation techniques when you can write to root-owned files. Use this skill whenever you have write access to system files owned by root and need to escalate privileges. This includes scenarios where you can modify /etc/ld.so.preload, git hooks,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Essential Linux commands for security auditing, incident response, and system hardening. Use this skill whenever the user needs to: enumerate system vulnerabilities (SUID/SGID files, writable directories), analyze logs (journalctl, grep patterns), investigate…

原文の言語: 英語

更新
職業分類
ソフトウェア開発者
説明

Locate, shortlist, and navigate the generated skills corpus quickly. Use this skill whenever the user asks to find a relevant skill, browse the 900+ skills, identify duplicates, map topic coverage, or open the correct SKILL.MD/scripts folder for a task.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS persistence and auto-start location guide. Use this skill whenever the user asks about macOS persistence mechanisms, auto-start locations, launch agents, launch daemons, shell startup files, or any technique for maintaining access on macOS systems. This…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze and enumerate macOS Keychain entries for security assessments. Use this skill whenever you need to inspect keychain contents, understand ACL permissions, extract credentials, or perform keychain security analysis on macOS systems. Make sure to use…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security research skill for understanding and testing macOS MDM/DEP enrollment vulnerabilities. Use this skill when investigating MDM security, analyzing DEP enrollment processes, researching mobile device management attack surfaces, or conducting authorized…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Research and analyze macOS Mobile Device Management (MDM) and Device Enrollment Program (DEP) configurations, enrollment processes, and security implications. Use this skill whenever investigating MDM implementations, analyzing device enrollment flows,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Decode and analyze Apple device serial numbers to extract manufacturing location, date, and model information. Use this skill whenever you need to parse Apple serial numbers, investigate device origins, analyze hardware for security assessments, or understand…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS red teaming and offensive security operations. Use this skill whenever the user mentions macOS penetration testing, MDM abuse (JAMF, Kandji), Active Directory attacks on macOS, keychain extraction, or any macOS-specific offensive security tasks. This…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS kernel and system architecture reference for security research. Use this skill whenever the user asks about XNU kernel internals, Mach/BSD architecture, coprocessors (SEP, SMC, T2, ANE, etc.), kernel extensions, system extensions, cryptexes, RSR…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill whenever analyzing macOS kernel drivers, IOKit vulnerabilities, or reverse engineering macOS kernel extensions. Trigger for any macOS security research involving IOKit, driver analysis, IORegistry inspection, kernel extension investigation, or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to analyze macOS kernel extensions (Kexts), extract and inspect kernelcaches, enumerate loaded kexts, debug kernel panics, and identify kernel-level security issues. Use this skill whenever the user mentions kernel extensions, kexts, kernelcache, macOS…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Assess macOS kernel security posture, check for known vulnerabilities (CVE-2022-46722, CVE-2024-23225, CVE-2024-23296, CVE-2023-41075, CVE-2024-44243), enumerate kernel extensions, verify SIP/Gatekeeper status, and recommend mitigations. Use this skill…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze and work with macOS System Extensions including DriverKit, Network Extensions, and Endpoint Security Framework. Use this skill when investigating macOS security, analyzing system extensions, understanding endpoint security bypasses, or working with…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze macOS APFS file system for security research, forensics, or privilege escalation. Use this skill whenever the user mentions APFS, Apple File System, macOS volumes, snapshots, firmlinks, diskutil commands, or needs to understand macOS storage…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

ARM64 assembly language reference for macOS security and reverse engineering. Use this skill whenever the user asks about ARM64 assembly, registers, instructions, exception levels, calling conventions, shellcode, or macOS system calls. This includes questions…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Reference and templates for x64 assembly programming and macOS shellcode development. Use this skill whenever the user needs to understand x64 registers, calling conventions, write assembly code, create shellcode for macOS, work with syscalls, or needs quick…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill whenever analyzing macOS binaries, debugging applications, performing security research on macOS apps, or fuzzing macOS software. Trigger for any macOS binary analysis, reverse engineering, crash investigation, security assessment, or when the…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Inspect, debug, and analyze macOS/iOS objects in memory using LLDB and Frida. Use this skill whenever the user needs to examine Objective-C or Swift objects at runtime, understand memory layouts, decode type encodings, work with arm64e/PAC pointers, enumerate…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze and understand Objective-C code in macOS binaries for security research, reverse engineering, and privilege escalation. Use this skill whenever you need to read Objective-C source code, analyze Mach-O binaries with class-dump, understand iOS/macOS app…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit and test macOS firewall configurations for potential bypass vulnerabilities. Use this skill whenever you need to assess macOS firewall security, check for known bypass techniques, enumerate allowed traffic, inspect PF rules, or validate Network…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to deploy and use macOS defensive security applications including firewalls (Little Snitch, LuLu), persistence detection tools (KnockKnock, BlockBlock), and keylogger detection (ReiKey). Use this skill whenever the user mentions macOS security, defensive…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS dynamic library injection and hijacking techniques for security research and penetration testing. Use this skill whenever the user needs to analyze macOS binaries for DYLD_INSERT_LIBRARIES vulnerabilities, perform dyld hijacking attacks, create…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS security skill for enumerating file extension handlers and URL scheme handlers via LaunchServices database. Use this skill whenever analyzing macOS systems for privilege escalation, investigating default app handlers, auditing file associations, or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze macOS application bundles for security assessment, code signing verification, and potential exploitation vectors. Use this skill whenever you need to inspect .app bundles, .framework files, or other macOS bundle types for penetration testing, security…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

macOS file system, permissions, binaries, and security reference. Use this skill whenever the user asks about macOS file structures, directory layouts, file permissions, plist files, bundles, dyld shared cache, file flags, ACLs, extended attributes, resource…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze macOS installer packages (.pkg and .dmg files) for security vulnerabilities, privilege escalation vectors, and malicious content. Use this skill whenever you need to inspect installer packages, extract and analyze installer scripts, identify…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to dump and analyze macOS memory for forensic investigation. Use this skill whenever the user needs to extract memory from a macOS system, investigate memory artifacts, analyze swap files, hibernate images, or perform macOS forensics, even if they don't…

原文の言語: 英語

更新
収集済み skill 908 件中 40 件を表示しています。