Skip to main content

このリポジトリの skills

AgentFlocks/flocks - 8ページ

SkillsMP は AgentFlocks/flocks から 771 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

AgentFlocks/flocks

収集済み skill 771 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

The Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modules

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule…

原文の言語: 英語

更新
収集済み skill 771 件中 40 件を表示しています。