Skip to main content
Manusで任意のスキルを実行
ワンクリックで
ShulkwiSEC
GitHub クリエイタープロフィール

ShulkwiSEC

2 件の GitHub リポジトリにある 249 件の収集済み skills をリポジトリ単位で表示します。

収集済み skills
249
リポジトリ
2
更新
2026-07-19
リポジトリエクスプローラー

リポジトリと代表的な skills

bb-huge
情報セキュリティアナリスト

Bug bounty findings secretary, tracker, and workspace initializer for the bb-huge portal. Use this skill for web security research, vulnerability hunting, and hunt workspace setup. Triggers on: "log finding", "save finding", "add to bb-huge", "record vulnerability", "update finding", "show findings", "bb-huge stats", "mark as confirmed", "mark as rewarded", "setup workspace", "pull evidence", "continue working on finding", "dump attachments", "list my skills", "what skills do I have", "/bb-huge init", "init hunt workspace", "new bug bounty program", "start hunting", "mobile bug bounty", "binary analysis", "source code review", "white-box audit", "h1-brain", "hack program", "hack()", "search disclosed", "fetch rewarded". Also auto-activates whenever a vulnerability is discovered during any recon, fuzzing, or manual testing session — do not wait to be asked.

2026-07-11
2fa-multi-factor-bypass
情報セキュリティアナリスト

Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.

2026-06-12
access-control-complete-deep-dive
情報セキュリティアナリスト

Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques

2026-06-12
active-directory-asreproasting
情報セキュリティアナリスト

Execute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag explicitly enabled. This attack generates a recoverable Ticket Granting Ticket (TGT) without requiring the attacker to authenticate first.

2026-06-12
active-directory-dcsync-attack
情報セキュリティアナリスト

Execute a DCSync attack mimicking the behavior of a legitimate Active Directory Domain Controller (DC). Leverage Directory Replication Service Remote Protocol (DRSR) permissions to silently request and extract the password hashes (NTLM/Kerberos) of any or all users in the domain without executing code on the target Domain Controller.

2026-06-12
active-directory-full-attack-chain
情報セキュリティアナリスト

Execute a complete Active Directory penetration test from initial enumeration to domain dominance. Use this skill for AD security assessments including LDAP enumeration, Kerberos attacks (Kerberoasting, AS-REP roasting), BloodHound attack path analysis, credential dumping with Mimikatz, lateral movement via PsExec/WMI/DCOM, DCSync for NTDS extraction, and Golden/Silver ticket forging. Covers the full kill chain from domain user to domain admin.

2026-06-12
active-directory-golden-ticket
情報セキュリティアナリスト

Forge highly privileged Kerberos Ticket Granting Tickets (TGTs) to gain persistent, undetectable, and long-term administrative access across an entire Active Directory domain. Use this skill during the final stages of a Red Team operation after Domain Admin access has been achieved, simulating an Advanced Persistent Threat (APT) establishing deep persistence that survives password resets.

2026-06-12
active-directory-kerberoasting
情報セキュリティアナリスト

Execute a Kerberoasting attack to extract and systematically crack the NTLM hashes of Service Principal Name (SPN) accounts in an Active Directory environment. Uses tools like Rubeus, Impacket (GetUserSPNs), and Hashcat to achieve domain privilege escalation domain: cybersecurity

2026-06-12
このリポジトリの収集済み skills 248 件中、上位 8 件を表示しています。
2 件中 2 件のリポジトリを表示
すべてのリポジトリを表示しました
ShulkwiSEC Agent Skills | SkillsMP