Skip to main content

xalgorix/xalgorix

SkillsMP は xalgorix/xalgorix から 862 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

記録された最新のソース活動
SkillsMP カタログ更新
収集済み skills
862
GitHub スター
866
GitHub フォーク
153

収集済み skill 862 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identifying and exploiting dangling DNS records pointing to unclaimed cloud services, enabling subdomain takeover for phishing, cookie stealing, and authentication bypass during authorized penetration tests.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Testing machine-learning model files and model-loading services for remote code execution caused by insecure deserialization (pickle/PyTorch), unsafe config instantiation (Hydra), archive path traversal, and dangerous layer types during authorized penetration…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a security validation pipeline using NVIDIA NeMo Guardrails Colang…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Using LLMs to accelerate vulnerability research and pentest workflows — generating syntax-valid fuzzing seeds and evolving grammars, fine-tuned mutation dictionaries, parallel agent-based proof-of-vulnerability generation, and evidence-driven passive analysis…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Testing LLM-backed applications, chatbots, and AI agents for direct and indirect prompt injection, jailbreaks, system-prompt leakage, and tool/agent abuse during authorized penetration tests, using structured payload families and reliable confirmation signals.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Testing Model Context Protocol (MCP) servers and the clients that consume them for tool poisoning, prompt injection via tool descriptions/outputs, over-permissioned and local-credential-stealing tools, config/trust bypasses, and unauthenticated RCE during…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineer configures API gateways (Kong, AWS API Gateway, Azure APIM,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API key formats with sufficient entropy, implements secure hashing for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability bugs. The tester…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with…

原文の言語: 英語

更新
収集済み skill 862 件中 40 件を表示しています。