Skip to main content

이 저장소의 skills

autohandai/community-skills - 7페이지

SkillsMP는 autohandai/community-skills에서 1,040개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

autohandai/community-skills

수집된 skill 1,040개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation based on real-world exploitation evidence.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format,…

원문 언어: 영어

업데이트
수집된 skill 1,040개 중 40개를 표시합니다.