Skip to main content

이 저장소의 skills

abelrguezr/hacktricks-skills - 6페이지

SkillsMP는 abelrguezr/hacktricks-skills에서 908개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

abelrguezr/hacktricks-skills

수집된 skill 908개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Security testing skill for SSDP/UPnP device spoofing and vulnerability assessment. Use this skill whenever the user needs to test UPnP/SSDP security, discover UPnP devices on a network, run EvilSSDP for phishing simulations, or assess UPnP-related…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Telecom network security assessment and exploitation techniques for GTP, 5G core, and industrial cellular routers. Use this skill whenever the user mentions telecom networks, mobile core protocols (GTP, PFCP, NAS), 5G security testing, SGSN/GGSN/PGW/AMF/SMF…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing skill for WebRTC DoS vulnerabilities involving race conditions between ICE consent verification and DTLS handshake. Use this skill whenever you need to test WebRTC media servers for the null cipher suite vulnerability, analyze WebRTC security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to enable monitor mode and packet injection on Android devices with Broadcom Wi-Fi chipsets using NexMon. Use this skill whenever the user wants to perform wireless penetration testing on Android, enable monitor mode on their phone, capture Wi-Fi…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to assess EAP-TLS enterprise WiFi for Evil Twin vulnerabilities. Use this skill whenever the user mentions WiFi security assessments, EAP-TLS testing, WPA2/3-Enterprise pentesting, identity leakage, TLS downgrade attacks, or rogue AP testing. This skill…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Wi-Fi security testing and penetration testing. Use this skill whenever the user mentions Wi-Fi attacks, wireless security testing, WEP/WPA/WPS cracking, Evil Twin attacks, deauthentication, handshake capture, PMKID attacks, WPA Enterprise testing, KARMA/MANA…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing methodology for AI CLI tools (Claude Code, Gemini CLI, Warp) and MCP servers. Use this skill whenever you need to assess AI agent abuse vectors, test MCP server vulnerabilities, analyze repo-controlled configuration poisoning risks, perform…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AI agent browser abuse and phishing methodology. Use this skill whenever the user mentions AI agents, browser automation, credential theft, prompt injection in browsers, agent mode phishing, hosted browser attacks, or any security testing involving AI…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze clipboard hijacking (pastejacking) attacks, ClickFix campaigns, and IUAM-style verification page lures. Use this skill whenever investigating phishing campaigns that use clipboard manipulation, fake CAPTCHA pages, or social engineering to execute…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Clone websites for phishing assessments and social engineering engagements. Use this skill whenever the user needs to create a copy of a target website for phishing campaigns, security assessments, or social engineering testing. Trigger on mentions of:…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect phishing attempts targeting your organization by analyzing domain variations, certificate transparency logs, URL telemetry, and network fingerprints. Use this skill whenever you need to hunt for phishing infrastructure, investigate suspicious domains,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze Discord invite security risks, assess server vulnerability to invite hijacking attacks, and generate security awareness materials. Use this skill whenever the user mentions Discord server security, invite link safety, phishing prevention, or needs to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect and analyze homograph/homoglyph attacks in phishing emails, URLs, and domains. Use this skill whenever the user mentions phishing analysis, email security, domain impersonation, Unicode attacks, homoglyph detection, or needs to inspect suspicious…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze mobile phishing campaigns, malicious Android APKs, and iOS mobile configuration profiles. Use this skill whenever investigating suspicious mobile apps, phishing infrastructure, or mobile malware. Trigger when users mention APK analysis, mobileconfig…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create and analyze phishing documents for authorized security testing. Use this skill whenever the user needs to create malicious Office documents (Word, Excel, PowerPoint), HTA files, LNK loaders, or steganography-based payloads for penetration testing, red…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to conduct authorized phishing assessments and security awareness testing. Use this skill whenever the user mentions phishing campaigns, email security testing, social engineering assessments, credential harvesting simulations, GoPhish configuration,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Python fundamentals reference covering data types, operators, control flow, data structures (lists, tuples, dicts, sets), classes, functions, generators, regex, and itertools. Use this skill whenever the user asks about Python syntax, basic operations, data…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to bruteforce MD5 hashes with partial matching (suffix or prefix attacks). Use this skill whenever the user mentions hash cracking, MD5 bruteforcing, partial hash matching, hash suffix attacks, loose comparison vulnerabilities, or CTF challenges involving…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to escape Python sandbox restrictions and gain code execution. Use this skill whenever the user mentions Python sandboxes, restricted Python environments, CTF challenges with Python jails, eval/exec restrictions, sandboxed code execution, or any scenario…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security assessment skill for CVE-2024-28397 (Js2Py sandbox escape). Use this skill when analyzing JavaScript-to-Python execution environments, reviewing js2py usage in codebases, testing for this specific vulnerability in authorized security assessments, or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Python bytecode OOB (out-of-bounds) read exploit for sandbox bypass. Use this skill whenever the user mentions Python sandbox bypass, bytecode manipulation, CTF challenges with Python eval restrictions, co_consts/co_names manipulation, or any Python security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security assessment skill for identifying and testing CVE-2023-33733 (ReportLab/xhtml2pdf RCE vulnerability) in authorized environments. Use this skill when you need to assess PDF generation systems for this specific sandbox escape vulnerability, verify patch…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze Python code for class pollution vulnerabilities (Python's prototype pollution), identify vulnerable merge functions, and demonstrate exploitation techniques for authorized security testing. Use this skill whenever the user mentions Python security,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze Keras model files (.keras, .h5) for deserialization vulnerabilities, create test payloads for security research, and assess ML model security posture. Use this skill whenever the user mentions Keras models, model deserialization, ML model security,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

PyScript vulnerability assessment and pentesting. Use this skill whenever the user mentions PyScript, Pyodide, browser-based Python, web application security testing, XSS in Python contexts, SSRF via Python libraries, or needs to assess PyScript…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use Python internal read gadgets to extract secrets from vulnerable applications. Trigger this skill whenever the user mentions Python format string vulnerabilities, class pollution, Flask/Django secret extraction, Werkzeug debug console access, environment…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to research and understand Python security vulnerabilities including sandbox escapes, deserialization attacks, and Pyscript exploitation. Use this skill whenever the user mentions Python security, sandbox bypass, deserialization vulnerabilities, Pyscript…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

How to create, activate, and manage Python virtual environments. Use this skill whenever the user needs to set up an isolated Python environment, install packages in a clean environment, or troubleshoot venv-related issues. Make sure to use this skill when…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Use this skill whenever you need to make HTTP requests in Python, interact with web APIs, test web applications, or automate web interactions. This includes GET/POST requests, file uploads, session management, JSON APIs, security testing, and web application…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to execute delivery receipt side-channel attacks on E2EE messengers (WhatsApp, Signal, Threema). Use this skill whenever the user wants to probe messaging protocols for timing leaks, fingerprint devices, monitor user behavior through RTT analysis, or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Create comprehensive threat models for applications and systems using established methodologies like STRIDE, DREAD, and PASTA. Use this skill whenever the user needs to identify security vulnerabilities, assess system risks, create data flow diagrams, or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Techniques for escaping restricted kiosk, locked-down, or single-application environments on Windows, iPad, and browsers. Use this skill whenever the user mentions kiosk mode, locked-down devices, restricted desktops, Citrix/RDS/VDI environments, single-app…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze MediaTek bootloader vulnerabilities, particularly bl2_ext secure-boot bypasses. Use this skill when investigating MediaTek device boot chains, analyzing secure boot verification gaps, triaging boot logs for authentication bypasses, or documenting…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing for bootloaders including U-Boot, UEFI, and SoC ROM recovery modes. Use this skill whenever you need to test device startup configurations, assess secure boot protections, exploit bootloader vulnerabilities, or perform firmware security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze embedded device firmware for security vulnerabilities. Use this skill whenever the user needs to examine firmware images, extract filesystems, find hardcoded credentials, analyze binaries, or assess IoT device security. Trigger on mentions of…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to analyze and exploit firmware integrity and signature verification flaws. Use this skill whenever the user mentions firmware analysis, embedded device security, binary exploitation, backdoor compilation, cross-compilation for embedded systems, or wants…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

MediaTek XFlash Carbonara DA2 hash bypass exploit for firmware analysis and security research. Use this skill whenever analyzing MediaTek device firmware, investigating Download Agent vulnerabilities, performing pre-OS security research, testing for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Decrypt Synology PAT/SPK encrypted firmware and application archives to extract their contents. Use this skill whenever the user needs to analyze Synology NAS firmware, extract packages from .pat or .spk files, inspect Synology system updates, or reverse…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Physical security testing and hardware attack techniques. Use this skill whenever the user mentions physical access, BIOS/UEFI password recovery, hardware security testing, cold boot attacks, DMA attacks, BadUSB/HID implants, BitLocker bypass, chassis…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Techniques for bypassing Linux shell restrictions, WAF filters, and command injection defenses. Use this skill whenever you need to execute commands in restricted environments, bypass input validation, work around shell limitations, or understand how…

원문 언어: 영어

업데이트
수집된 skill 908개 중 40개를 표시합니다.