macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
原文の言語: 英語
メニュー
SkillsMP は CyberStrikeus/CyberStrike から 7,442 件の skill を収集しています。skill を開くとソースと詳細を確認できます。
収集済み skill 7,442 件中 40 件を表示しています。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
原文の言語: 英語
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
原文の言語: 英語
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
原文の言語: 英語
READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
原文の言語: 英語
READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
原文の言語: 英語
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
原文の言語: 英語
Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
原文の言語: 英語
GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
原文の言語: 英語
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
原文の言語: 英語
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
原文の言語: 英語
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
原文の言語: 英語
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
原文の言語: 英語
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
原文の言語: 英語
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
原文の言語: 英語
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
原文の言語: 英語
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
原文の言語: 英語
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
原文の言語: 英語
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
原文の言語: 英語
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
原文の言語: 英語
Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
原文の言語: 英語
Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
原文の言語: 英語
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
原文の言語: 英語
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
原文の言語: 英語
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
原文の言語: 英語
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
原文の言語: 英語
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
原文の言語: 英語
XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
原文の言語: 英語
Active Directory security testing and attack techniques
原文の言語: 英語
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
原文の言語: 英語
Kerberos protocol attack techniques and exploitation
原文の言語: 英語
Bug bounty and pentest reconnaissance methodology
原文の言語: 英語
API Testing Overview
原文の言語: 英語
API Reconnaissance
原文の言語: 英語
Testing for Broken Object Level Authorization (BOLA)
原文の言語: 英語
Testing GraphQL
原文の言語: 英語
Testing for Credentials Transported over an Encrypted Channel
原文の言語: 英語
Testing for Default Credentials
原文の言語: 英語
Testing for Weak Lock Out Mechanism
原文の言語: 英語
Testing for Bypassing Authentication Schema
原文の言語: 英語
Testing for Vulnerable Remember Password
原文の言語: 英語