소스 정보
- 저장소
- AeonDave/malskill
- 최근 소스 활동
- 2026년 6월 3일 13:09
- 감지된 SKILL.md 언어
- 영어
- 스타
- 18
- 포크
- 1
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
SOC 직업 분류 기준
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/AeonDave/malskill --skill dnsx명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SKILL.md 표시 중
Operate the MCPwn Kali/Debian MCP efficiently: manage sessions, discover catalog tools, choose synchronous, detached, or interactive execution, move files through workspace/CAS planes, establish tunnels and shells, and run GDB or Frida debugging in the MCPwn runtime or through explicit host/device transports. Use for MCPwn or Kali MCP work, pwn/CTF and dynamic-analysis sessions, remote targets, connectivity or file-transfer problems, and optional NeuroMatrix-backed emulation/debugging through MCPwn's emulation domain.
Operate the standalone, client-neutral NeuroMatrix emulation MCP: create isolated sessions, stage CAS artifacts, discover and run Unicorn/Qiling/QEMU/Renode tools, manage jobs and interactive processes, expose guest endpoints, and debug emulated targets with GDB. Use for reverse engineering, user-mode or full-system emulation, firmware/kernel/MCU analysis, guest-service rehosting, runtime-evidence collection, or as the optional emulation provider behind MCPwn or another orchestrator.
Create, implement, scaffold, migrate, or review Model Context Protocol (MCP) servers against modern MCP 2026-07-28. Use for server architecture, tool/resource/prompt contracts, stdio or Streamable HTTP transports, MRTR, optional extensions, authorization, security, and real-transport validation. Also use to isolate legacy initialization or session behavior. Do not use merely to configure an MCP client or invoke an existing server.
| name | dnsx |
| description | Auth/lab ref: Fast DNS resolution and brute-force tool from ProjectDiscovery. |
| license | MIT |
| compatibility | Linux, Windows, macOS. |
| metadata | {"author":"AeonDave","version":"1.1"} |
Fast DNS toolkit — resolve, brute-force, and extract DNS records at scale.
# Resolve a list of subdomains
cat subs.txt | dnsx
# DNS brute-force against a domain
dnsx -d example.com -w wordlist.txt
# Extract A records with response
cat subs.txt | dnsx -a -resp
| Flag | Description |
|---|---|
-l <file> | Input list of hosts/subdomains |
-d <domain> | Target domain (for brute-force) |
-w <wordlist> | Wordlist for brute-force |
-a | Query A records |
-aaaa | Query AAAA records |
-cname | Query CNAME records |
-mx | Query MX records |
-ns | Query NS records |
-txt | Query TXT records |
-ptr | Query PTR records |
-resp | Show DNS response |
-resp-only | Show DNS response only |
-rcode <code> | Filter by rcode (e.g., noerror,nxdomain) |
-r <resolvers> | Custom resolver file |
-rl <n> | Rate limit (requests/second) |
-t <n> | Threads (default 100) |
-timeout <n> | Timeout (default 5s) |
-silent | Print results only |
-o <file> | Output file |
-json | JSON output |
-wildcard | Filter wildcard subdomains |
-cdn | Show CDN name for resolved IPs |
-asn | Show ASN info for resolved IPs |
-recon | Query all record types at once |
-wt <n> | Wildcard threshold (default 5) |
-retry <n> | Retry failed queries |
# Pipeline: subfinder -> dnsx resolution
subfinder -d target.com -silent | dnsx -silent
# DNS brute-force with wordlist
dnsx -d target.com -w /usr/share/dnsrecon/subdomains-top1mil-5000.txt -t 50
# Get all record types in JSON
cat subs.txt | dnsx -a -cname -mx -txt -resp -o dns_records.json -json
# Resolve IPs for a list
cat domains.txt | dnsx -a -resp-only | sort -u
# Filter wildcard results
cat subs.txt | dnsx -wildcard -d target.com -silent
# Reverse DNS (PTR) on IPs
cat ips.txt | dnsx -ptr -resp-only
# Full recon pipeline: subfinder -> dnsx -> httpx
subfinder -d target.com -silent -all | \
dnsx -silent -a -resp-only | \
httpx -silent -status-code -title -tech-detect
# Extract MX/TXT for email security audit
dnsx -d target.com -mx -txt -resp -silent
# Brute-force with custom resolvers (bypass rate limits)
dnsx -d target.com -w subdomains.txt -r resolvers.txt -rl 500
# Wildcard detection + filter
dnsx -d target.com -w wordlist.txt -wildcard -wt 3 -silent
# Extract CNAMEs (find dangling/takeovers)
cat subs.txt | dnsx -cname -resp -silent | grep -v "target.com"
| File | When to load |
|---|---|
references/dns-records.md | DNS record types, brute-force wordlists, wildcard detection, subdomain takeover |