Skip to main content
GitHub リポジトリ

Mingyi-Atlas

Mingyi-Atlas には MingyiSecLab から収集した 122 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
122
Stars
9
更新
2026-06-08
Forks
0
職業カバレッジ
5 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

benchmark
その他コンピュータ職

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

2026-06-08
adcs-esc1
情報セキュリティアナリスト

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

2026-06-08
bloodhound-query
情報セキュリティアナリスト

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

2026-06-08
netexec
情報セキュリティアナリスト

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

2026-06-08
ad
情報セキュリティアナリスト

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

2026-06-08
engagement-lifecycle
その他コンピュータ職

Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.

2026-06-08
engagement-startup
その他コンピュータ職

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

2026-06-08
final-report
その他コンピュータ職

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

2026-06-08
kill-chain-analysis
その他コンピュータ職

Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.

2026-06-08
orchestration
その他コンピュータ職

Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.

2026-06-08
atlas
その他コンピュータ職

Atlas orchestrator workflow — engagement intake, OPPLAN build, execution loop via task() delegation, final report. Tools=[]; everything ships through sub-agents.

2026-06-08
k8s-pivot
その他コンピュータ職

Kubernetes attack playbook — service-account token theft, RBAC abuse, pod escape, hostPath mount abuse, kube-api-server pivoting.

2026-06-08
s3-takeover
その他コンピュータ職

Detect and claim dangling S3 buckets referenced by subdomains (CNAME → s3 hostnames where bucket no longer exists).

2026-06-08
cloud
その他コンピュータ職

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

2026-06-08
terraform-state-leak
その他コンピュータ職

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

2026-06-08
oracle-manipulation
その他コンピュータ職

Hunt single-block oracle manipulation — spot-price AMM oracles, manipulable TWAP, dependent calculations, missing staleness checks.

2026-06-08
contracts
ソフトウェア開発者

Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.

2026-06-08
crypto-decode
情報セキュリティアナリスト

Cipher detection + automated decryption via Ciphey, Cyberchef recipes, hashcat hash-ID, format conversion, common encoding chains.

2026-06-08
exploit-reporting
情報セキュリティアナリスト

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

2026-06-08
supplychain
情報セキュリティアナリスト

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

2026-06-08
web
情報セキュリティアナリスト

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API exploitation.

2026-06-08
xs-leaks
情報セキュリティアナリスト

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

2026-06-08
android
情報セキュリティアナリスト

Android APK pentest workflow — apktool/jadx static, Frida dynamic instrumentation, SSL pinning bypass, root detection bypass, intent fuzzing, keystore extraction.

2026-06-08
mobile
情報セキュリティアナリスト

Mobile application red team category — Android (APK) and iOS (IPA) pentest. Routing skill: identifies the platform + attack surface, then loads the matching sub-skill.

2026-06-08
c2
情報セキュリティアナリスト

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

2026-06-08
c2-sliver
情報セキュリティアナリスト

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

2026-06-08
web-recon
情報セキュリティアナリスト

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

2026-06-08
anti-debug-bypass
情報セキュリティアナリスト

Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.

2026-06-08
packer-unpacking
情報セキュリティアナリスト

Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.

2026-06-08
reverser
情報セキュリティアナリスト

Root pointer for the binary reversing lane. Covers triage, string extraction, packer unpacking, symbol risk, ROP, Ghidra deep analysis, and firmware extraction.

2026-06-08
abort-template
情報セキュリティアナリスト

Abort / crisis plan generator — halt triggers, response actions, AI-aware safety gates (hallucination threshold, destructive-action gate, output validation).

2026-06-08
cleanup-template
情報セキュリティアナリスト

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

2026-06-08
contact-template
情報セキュリティアナリスト

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

2026-06-08
data-handling-template
情報セキュリティアナリスト

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

2026-06-08
roe-template
情報セキュリティアナリスト

Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.

2026-06-08
playwright-cli
ソフトウェア品質保証アナリスト・テスター

Automate browser interactions, test web pages and work with Playwright tests.

2026-05-31
nuclei
情報セキュリティアナリスト

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

2026-05-31
asrep-roasting
情報セキュリティアナリスト

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

2026-05-31
certipy-esc-chain
情報セキュリティアナリスト

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

2026-05-31
coercer
情報セキュリティアナリスト

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

2026-05-31
このリポジトリの収集済み skills 122 件中、上位 40 件を表示しています。