AATMF T12 — RAG & Knowledge Base Manipulation. PoisonedRAG, vector store flood, embedding collision, retrieval-bias attacks.
原文の言語: 英語
メニュー
このリポジトリの skills
SkillsMP は PurpleAILAB/Decepticon から 312 件の skill を収集しています。skill を開くとソースと詳細を確認できます。
PurpleAILAB/Decepticon収集済み skill 312 件中 32 件を表示しています。
AATMF T12 — RAG & Knowledge Base Manipulation. PoisonedRAG, vector store flood, embedding collision, retrieval-bias attacks.
原文の言語: 英語
AATMF T13 — AI Supply Chain & Artifact Trust. Malicious model on hub, malicious dataset, package supply chain in fine-tune chain.
原文の言語: 英語
AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization.
原文の言語: 英語
AATMF T15 — Human-AI Coupling. Deepfake escalation, voice clone vishing, deepfake-image-driven social engineering, automation of human-targeted attacks.
原文の言語: 英語
NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.
原文の言語: 英語
Cipher detection + automated decryption via Ciphey, Cyberchef recipes, hashcat hash-ID, format conversion, common encoding chains.
原文の言語: 英語
Dependency confusion — publish a higher-version internal package name on public registry (npm/PyPI/Maven/Crates) to coerce CI/CD into pulling attacker code.
原文の言語: 英語
Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.
原文の言語: 英語
Account Takeover decision tree — 9 canonical ATO paths, chaining patterns (IDOR→ATO, XSS→ATO, OAuth→ATO), MFA bypass entry points.
原文の言語: 英語
Business logic / authentication bypass / privilege escalation — POST body field tampering (role/is_admin/user_type), 2FA bypass via response manipulation, predictable TOTP seeds, hidden authorization headers, multi-step workflow tampering. For challenges…
原文の言語: 英語
Web cache deception — trick CDN/proxy into caching authenticated responses under unauthenticated URLs, exposing PII to any visitor.
原文の言語: 英語
DOM clobbering — abuse named HTML elements to overwrite JavaScript global variables, bypass CSP, hijack object property lookups.
原文の言語: 英語
Arbitrary file upload exploitation — webshell upload, extension bypass, content-type manipulation, and upload-to-RCE techniques.
原文の言語: 英語
GraphQL exploitation — introspection, injection, authorization bypass, and data exfiltration through GraphQL APIs.
原文の言語: 英語
JSON Web Token attacks — algorithm confusion (alg=none, HS256↔RS256), kid header injection, JWKS spoofing, weak HMAC secret cracking, signature stripping.
原文の言語: 英語
LDAP injection — auth bypass via filter manipulation, blind data extraction, search filter abuse, DN injection.
原文の言語: 英語
Path traversal and Local File Inclusion (LFI) — arbitrary file reading via directory traversal, PHP filter/input/data wrappers for RCE, log poisoning, static resource disclosure, and information leakage. Use for any challenge involving file path manipulation,…
原文の言語: 英語
Mass assignment + ORM leak — inject extra fields into create/update requests, escalate to admin, leak protected fields via response.
原文の言語: 英語
NoSQL injection — MongoDB operator injection ($ne, $gt, $where, $regex), CouchDB / Firebase / Redis attack patterns, auth bypass, blind extraction.
原文の言語: 英語
OAuth 2.0 / OIDC attacks — redirect_uri bypass, state CSRF, code leak via Referer, response_type confusion, PKCE downgrade, scope creep, ATO chains.
原文の言語: 英語
Open redirect + tabnabbing — URL filter bypass, OAuth chain extension, phishing infrastructure-free, SSRF chain.
原文の言語: 英語
Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.
原文の言語: 英語
SAML 2.0 attacks — XSW (XML Signature Wrapping) variants 1-8, comment injection, signature stripping, assertion forgery, IdP metadata abuse.
原文の言語: 英語
XPath + XSLT injection — query manipulation in XML data stores, server-side XSLT RCE via document() / EXSLT extensions.
原文の言語: 英語
XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.
原文の言語: 英語
Cross-Site Scripting (XSS) — reflected, stored, DOM-based XSS exploitation. Covers filter bypass, CSP evasion, bot-triggered cookie exfiltration, admin page scraping, and headless browser flag extraction. Use for any challenge involving client-side JavaScript…
原文の言語: 英語
REST API discovery, GraphQL detection, parameter fuzzing.
原文の言語: 英語
Authentication surface — login endpoints, JWT/OAuth/SAML/SSO/API-key mechanism identification.
原文の言語: 英語
Cookie-conditional sink discovery — bisect required cookies per sink, session-write timeline for race-condition challenges.
原文の言語: 英語
Web app discovery — directory/file fuzzing, vhost discovery, JavaScript endpoint extraction.
原文の言語: 英語
Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.
原文の言語: 英語
Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.
原文の言語: 英語