Skip to main content

Encod3d-Sec/ClaudeBrain

SkillsMP は Encod3d-Sec/ClaudeBrain から 18 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

記録された最新のソース活動
SkillsMP カタログ更新
収集済み skills
18
GitHub スター
268
GitHub フォーク
36

このリポジトリの skills

1 件の職業カテゴリ · 100% 分類済み

収集済み skill 18 件中 18 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. sqlmap automation after manual confirmation. Wiki-first, FIND schema output.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Boot-to-root methodology for a full machine (THM/HTB/PG/CTF box, "get user.txt+root.txt", "root the box", "foothold to root"). Enforces basic-tool recon (nmap, nc, ffuf, nuclei, dig) before anything custom, wiki-first lookups, and ALWAYS pspy +…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /_vti_bin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Autonomous CTF / boot-to-root campaign driver. Runs a box end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool) every…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Autonomous pentest campaign driver. Runs a scoped engagement end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool)…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (including which…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Post-engagement knowledge harvest AND harness retrospective - after a box/bugbounty/pentest/CTF is completed, first diff how the engagement was EXECUTED against the skills/hooks that governed it (what discipline was skipped) and improve the harness, then…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Shared discipline for every hunt-* skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop conditions, marker discipline, wiki-first query and self-heal,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. Outputs to Attack-surface.md and scope/. Queries wiki before each phase. Use when starting recon on any target.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

CTF challenge router - fingerprint a challenge (file type / prompt / artifacts) into its category (pwn, rev, crypto, forensics, stego, web, osint, hash) and route to the matching wiki page, tools, and first moves. Wiki-first.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Synthesize raw recon/test output into engagement state. Reads everything dropped in targets/<active>/ingest/, extracts hosts/assets/creds/paths, merges into state.md/loot.md/paths.md, logs it, archives the raw files. Works for pentest, bugbounty, and ctf. Use…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Ranked next offensive moves from engagement state. Reads state/loot/paths, runs the deterministic analyzer, elaborates the top move. Use when asked "what next", "where to focus", "prioritize", or at the start of an engagement session.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Assemble a report-ready walkthrough.md for a SOLVED engagement - populate the Evidence gallery from the poc/ images captured during the engagement, and draft the step-by-step reproduction from state/loot/paths/log.md without fabricating. Use when asked to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. OWASP LLM Top 10. Wiki-first, FIND schema output.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exposed-secrets hunting - .git/ dir + history mining, exposed .env/config files, hardcoded keys in JS bundles + source maps, S3/blob exposure, public-repo secret search, CI/CD leakage. Live-validation mandatory. Wiki-first, FIND schema output.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

XSS hunting - reflected, stored, DOM-based. Marker discipline to avoid false positives. Blind-XSS beacons for stored contexts. SVG/markdown/redirect vectors. Wiki-first, FIND schema output.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe), then hand off to the matching vuln-class hunt. Wiki-first,…

原文の言語: 英語

更新
収集済み skill 18 件中 18 件を表示しています。