원클릭으로
system
System exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
System exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | system |
| description | System exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development. |
Test system-level security including Active Directory, privilege escalation, and exploit development.
| Type | Key Vectors |
|---|---|
| Active Directory | Kerberoasting, AS-REP roasting, DCSync, Pass-the-Hash, Golden Ticket |
| Privilege Escalation | SUID/sudo abuse, kernel exploits, service misconfig, token manipulation |
| Exploit Development | Buffer overflow, format string, ROP chains, shellcode |
reference/system-exploitation.md - AD attacks, privilege escalation, exploit development techniquesSystematic IDOR / BOLA hunting methodology. Use when testing any endpoint that accepts an ID, UUID, slug, filename, or reference to a user-owned object.
SQL injection hunting methodology across error-based, union, blind boolean, and time-based variants. Use when testing any input that might reach a database.
SSRF hunting methodology with OOB detection via interactsh, cloud metadata targets, and blind SSRF techniques. Use on any feature that accepts a URL, hostname, or external reference.
XSS hunting methodology — reflected, stored, and DOM — with context-aware payloads. Use when testing any input that could reach a browser.
OWASP Top 10 (2021) and API Top 10 (2023) quick reference with attack patterns, test ideas, and CWE mappings. Load when hunting, code-reviewing for security, or writing bug bounty reports.
Bug bounty report generation — structure, triager-friendly writing, CVSS scoring, and chain reporting. Use when finalizing a finding for submission.