Skip to main content

pentesting-checklist-security-assessment

Interactive security assessment checklist covering 23 platforms with 1,000+ checks for penetration testing, bug bounty, and security audits.

インストールへ移動

ソース情報

リポジトリ
reason-machines/security-skills
ソースの最終更新活動
2026年6月20日 16:36
検出された SKILL.md の言語
英語
スター
12
フォーク
1

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
pentesting-checklist-security-assessment
description
Interactive security assessment checklist covering 23 platforms with 1,000+ checks for penetration testing, bug bounty, and security audits.
triggers
["open the pentesting checklist tool","use the security assessment checklist","track penetration testing progress","export security assessment findings","search pentesting checklist items","mark security checks complete","filter security checklist by severity","import previous pentesting assessment"]
# Pentesting Checklist Security Assessment > Skill by [ara.so](https://ara.so) — Security Skills collection. ## Overview PentestingChecklist is a comprehensive, client-side security assessment framework covering 23 platforms (Web, API, Mobile, Cloud, Active Directory, Kubernetes, LLM, and more) with over 1,000 security checks. It runs entirely in the browser with no backend, storing all progress, notes, and findings in localStorage. **Key Features:** - Hierarchical checklist: Platform → Category → Technology → Check - Global search across all content (⌘K/Ctrl+K) - Progress tracking with status (Open/Closed/N/A) - Per-check notes for evidence and payloads - Severity-based filtering (Critical → Info) - Export to Markdown, CSV, Excel, JSON - Import JSON to resume assessments **Live Tool:** https://checklist.m14r41.in/ ## Installation & Setup This is a web-based application. For local development or self-hosting: ```bash # Clone the repository git clone https://github.com/m14r41/PentestingChecklist.git cd PentestingChecklist # Install dependencies npm install # Start development server npm run dev # Build for production npm run build # Preview production build npm run preview ``` ## Project Structure ```typescript // Typical project structure src/ ├── components/ # React/UI components ├── data/ # Checklist data (JSON/TypeScript) ├── hooks/ # Custom React hooks ├── utils/ # Helper functions ├── types/ # TypeScript type definitions └── App.tsx # Main application component ``` ## Core Data Structure The checklist follows a four-level hierarchy: ```typescript interface Platform { id: string; name: string; description: string; categories: Category[]; } interface Category { id: string; name: string; description: string; technologies: Technology[]; } interface Technology { id: string; name: string; checks: Check[]; } interface Check { id: string; title: string; description: string; severity: 'critical' | 'high' | 'medium' | 'low' | 'info'; tags: string[]; tools?: string[]; references?: string[]; status?: 'open' | 'closed' | 'na'; notes?: string; } ``` ## Using the Checklist (Browser Interface) ### Navigation ```typescript // URL structure https://checklist.m14r41.in/ # All platforms overview https://checklist.m14r41.in/checklist # Full checklist view https://checklist.m14r41.in/web-application # Web app checklist https://checklist.m14r41.in/api # API security checklist https://checklist.m14r41.in/active-directory # AD security checklist ``` ### Global Search Keyboard shortcut: **⌘K** (Mac) or **Ctrl+K** (Windows/Linux) Search across: - Platform names - Category names - Technology names - Check titles and descriptions - Tags, tools, references ### Progress Tracking ```typescript // Status options for each check type CheckStatus = 'open' | 'closed' | 'na'; // Example: Marking a check status const updateCheckStatus = (checkId: string, status: CheckStatus) => { // Stored in localStorage const key = `check_${checkId}_status`; localStorage.setItem(key, status); }; // Example: Adding notes to a check const addCheckNote = (checkId: string, note: string) => { const key = `check_${checkId}_note`; localStorage.setItem(key, note); }; ``` ### Filtering by Severity ```typescript // Severity levels (highest to lowest) const severityLevels = [ 'critical', // Immediate exploitation, severe impact 'high', // Major security impact 'medium', // Moderate security impact 'low', // Minor security impact 'info' // Informational findings ]; // Filter checks by severity const filterBySeverity = (checks: Check[], minSeverity: string): Check[] => { const severityOrder = { critical: 4, high: 3, medium: 2, low: 1, info: 0 }; const threshold = severityOrder[minSeverity] || 0; return checks.filter(check => severityOrder[check.severity] >= threshold ); }; ``` ## Export & Import ### Export Formats ```typescript // Export to Markdown const exportToMarkdown = (assessment: Assessment): string => { let markdown = `# Security Assessment Report\n\n`; markdown += `**Date:** ${new Date().toISOString()}\n\n`; assessment.platforms.forEach(platform => { markdown += `## ${platform.name}\n\n`; platform.categories.forEach(category => { markdown += `### ${category.name}\n\n`; category.technologies.forEach(tech => { markdown += `#### ${tech.name}\n\n`; tech.checks.forEach(check => { if (check.status === 'open') { markdown += `- [x] **${check.title}** (${check.severity})\n`; markdown += ` ${check.description}\n`; if (check.notes) { markdown += ` \n **Notes:** ${check.notes}\n`; } markdown += `\n`; } }); }); }); }); return markdown; }; // Export to JSON (for re-import) const exportToJSON = (assessment: Assessment): string => { return JSON.stringify({ version: '1.0', exportDate: new Date().toISOString(), platforms: assessment.platforms.map(platform => ({ id: platform.id, checks: platform.categories.flatMap(cat => cat.technologies.flatMap(tech => tech.checks .filter(check => check.status || check.notes) .map(check => ({ id: check.id, status: check.status, notes: check.notes })) ) ) })) }, null, 2); }; // Export to CSV const exportToCSV = (assessment: Assessment): string => { let csv = 'Platform,Category,Technology,Check,Severity,Status,Notes\n'; assessment.platforms.forEach(platform => { platform.categories.forEach(category => { category.technologies.forEach(tech => { tech.checks.forEach(check => { const row = [ platform.name, category.name, tech.name, check.title, check.severity, check.status || 'pending', check.notes || '' ].map(field => `"${String(field).replace(/"/g, '""')}"`); csv += row.join(',') + '\n'; }); }); }); }); return csv; }; ``` ### Import JSON Assessment ```typescript interface ImportedAssessment { version: string; exportDate: string; platforms: Array<{ id: string; checks: Array<{ id: string; status?: CheckStatus; notes?: string; }>; }>; } const importAssessment = (jsonData: string): void => { const imported: ImportedAssessment = JSON.parse(jsonData); imported.platforms.forEach(platform => { platform.checks.forEach(check => { if (check.status) { localStorage.setItem(`check_${check.id}_status`, check.status); } if (check.notes) { localStorage.setItem(`check_${check.id}_note`, check.notes); } }); }); console.log(`Imported ${imported.platforms.length} platforms from ${imported.exportDate}`); }; ``` ## Platform-Specific Examples ### Web Application Security ```typescript // Example check structure for web security const webAppChecks: Check[] = [ { id: 'web-auth-001', title: 'Test for SQL Injection in authentication', description: 'Verify input validation and parameterized queries in login forms', severity: 'critical', tags: ['injection', 'authentication', 'sqli'], tools: ['sqlmap', 'burp suite', 'manual testing'], references: [ 'OWASP Top 10 2021 - A03:2021-Injection', 'https://portswigger.net/web-security/sql-injection' ] }, { id: 'web-auth-002', title: 'Check for broken authentication', description: 'Test session management, password policies, and MFA implementation', severity: 'high', tags: ['authentication', 'session', 'password'], tools: ['burp suite', 'postman'], references: ['OWASP Top 10 2021 - A07:2021-Identification and Authentication Failures'] } ]; ``` ### API Security ```typescript // API security assessment pattern const apiSecurityChecks = [ { id: 'api-bola-001', title: 'Test for Broken Object Level Authorization (BOLA)', description: 'Manipulate object IDs to access unauthorized resources', severity: 'critical', tags: ['authorization', 'bola', 'idor'], tools: ['postman', 'burp suite', 'curl'], references: ['OWASP API Security Top 10 - API1:2023 Broken Object Level Authorization'] }, { id: 'api-rate-001', title: 'Verify rate limiting implementation', description: 'Test API endpoints for rate limiting and DoS protection', severity: 'medium', tags: ['rate-limiting', 'dos', 'resource'], tools: ['ab', 'wrk', 'postman'], references: ['OWASP API Security Top 10 - API4:2023 Unrestricted Resource Consumption'] } ]; ``` ### Active Directory Assessment ```typescript // Active Directory security checks const adSecurityChecks = [ { id: 'ad-kerb-001', title: 'Kerberoasting attack vector', description: 'Enumerate and request service tickets for accounts with SPNs', severity: 'high', tags: ['kerberos', 'spn', 'privilege-escalation'], tools: ['Rubeus', 'Invoke-Kerberoast', 'GetUserSPNs.py'], references: ['T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting'] }, { id: 'ad-acl-001', title: 'ACL abuse for privilege escalation', description: 'Identify misconfigured ACLs allowing unintended permissions', severity: 'critical', tags: ['acl', 'privilege-escalation', 'active-directory'], tools: ['BloodHound', 'PowerView', 'SharpHound'], references: ['Active Directory Security - ACL Abuse'] } ]; ``` ## LocalStorage Management ```typescript // Helper functions for localStorage operations class ChecklistStorage { private static prefix = 'pentesting_checklist_'; static saveCheckStatus(checkId: string, status: CheckStatus): void { localStorage.setItem( `${this.prefix}check_${checkId}_status`, status ); } static getCheckStatus(checkId: string): CheckStatus | null { const status = localStorage.getItem(`${this.prefix}check_${checkId}_status`); return status as CheckStatus | null; } static saveCheckNote(checkId: string, note: string): void { localStorage.setItem( `${this.prefix}check_${checkId}_note`, note ); } static getCheckNote(checkId: string): string | null { return localStorage.getItem(`${this.prefix}check_${checkId}_note`); } static clearAllData(): void { const keys = Object.keys(localStorage); keys.forEach(key => { if (key.startsWith(this.prefix)) { localStorage.removeItem(key); } }); } static exportAllData(): Record<string, string> { const data: Record<string, string> = {}; const keys = Object.keys(localStorage); keys.forEach(key => { if (key.startsWith(this.prefix)) { data[key] = localStorage.getItem(key) || ''; } }); return data; } } ``` ## Progress Calculation ```typescript // Calculate completion percentage interface ProgressStats { total: number;
GitHubで見る
この SKILL.md は非常に大きいため、SkillsMP では最初のセクションだけを表示しています。 GitHubで見る