Skip to main content
Manusで任意のスキルを実行
ワンクリックで
GitHub リポジトリ

gb-cyber

gb-cyber には philo-groves から収集した 9 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
9
Stars
0
更新
2026-05-15
Forks
0
職業カバレッジ
2 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

binary-debugging
情報セキュリティアナリスト

Aggressive debugging of authorized binaries, crashes, cores, sanitizers, and runtime behavior with the goal of turning crash data and runtime observations into high-severity vulnerabilities as fast as possible. Use when static reversing isn’t enough and you need runtime state, memory corruption details, register control, or exploitability evidence. Red-team focused: form exploit hypotheses quickly, reproduce aggressively in lab environments, and push promising leads hard toward proof.

2026-05-15
binary-reversing
情報セキュリティアナリスト

Aggressive static reverse engineering of authorized binaries and native components with the explicit goal of finding high-severity vulnerabilities. Use when you have ELF, Mach-O, PE, firmware, packed artifacts, native libraries, or large decompiles (especially jadx trees) and need to hunt for bugs fast. Red-team oriented: form attack hypotheses early, chase weak signals, and hand off to dynamic/fuzzing aggressively when static hits a wall.

2026-05-15
code-vulnerability-review
ソフトウェア品質保証アナリスト・テスター

Aggressive red-team source code review for authorized bug bounty targets. Use when hunting for high-severity issues (especially critical/key-compromise class) in large codebases, decompiles, or complex protocol implementations. Optimized for offensive mindset: generate attack ideas first, pursue weak signals hard, and only become conservative at the final proof stage. Primary skill for deep dives on targets like Coinbase cb-mpc, Fireblocks MPC, Chainlink, Stripe, etc.

2026-05-15
cve-research
情報セキュリティアナリスト

Aggressive use of CVE intelligence, public advisories, KEV, and EPSS data to find high-value vulnerabilities and variants in authorized bug bounty targets. Use to identify weak patterns in your current codebases, prioritize attack surfaces, hunt for similar issues, and assess real-world exploitability in your specific environment.

2026-05-15
exploit-chain-analysis
情報セキュリティアナリスト

Actively hunt for and compose exploit chains that turn multiple smaller issues into high-impact (especially critical) findings. Use aggressively: during code review, after new leads appear in finding-tracker, and whenever one primitive unlocks another. Red-team focused — chains are how you turn "a bunch of medium findings" into something that actually pays.

2026-05-15
finding-tracker
情報セキュリティアナリスト

Aggressive offensive finding management for authorized red team bug bounty work. Use to log, track, chain, and promote attack leads as fast as possible while still preventing real duplicate effort. Designed for hunters who want to stay aggressive: log weak signals early, keep promising leads alive longer, and only de-escalate after real effort. Works with the rest of the red-team skill suite (especially the aggressive code-vulnerability-review).

2026-05-15
report-writer
情報セキュリティアナリスト

Turn high-quality proofed findings and strong evidence into submission-ready vulnerability reports optimized for high bounty payouts. Designed to work with the aggressive red-team stack, especially high-standard proof packets from triage-verifier. Produces clear, high-impact, well-structured reports for HackerOne, Bugcrowd, and other programs.

2026-05-15
triage-verifier
ソフトウェア品質保証アナリスト・テスター

Final proof gate for red-team findings. Produce high-quality, near-submission-ready proof packets that can be used directly in strong bug bounty reports. Use only after a finding has reached "confident" in finding-tracker. The goal is not just verification — it is to create a clean, convincing, and well-documented exploit PoC that stands up to real triager scrutiny.

2026-05-15
web-app-security-inspection
情報セキュリティアナリスト

Aggressive red-team inspection of authorized web applications, SPAs, and APIs. Focus on finding high-severity issues (especially authorization, business logic, and account takeover class) using browser automation, HTTP manipulation, and state comparison. Designed for speed and impact — form attack hypotheses quickly and test them hard.

2026-05-15