원클릭으로
redteam-cms
Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | redteam-cms |
| description | Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation. |
Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation.
Activate when the user asks to:
report.md with verified findings, rejected claims, commands tried, and limitations.Please refer to references/cms-priority-matrix.md for detailed high-value risks and validation checks for each CMS.
Return Markdown with:
Scope and allowed actionsCMS fingerprint and confidenceComponent inventoryPrioritized checksCommands / requestsExpected output and success signalsStop conditions and cleanupCandidate findingsVerifier handoffReport notesConfirmed findings require affected-state proof, exploitability or impact proof, a negative control, reproduction metadata, and remediation retest steps.
WAF Evasion: Utilize HTTP Request Smuggling (CL.TE / TE.CL) or chunked encoding to bypass Edge WAFs before hitting the CMS.
Authenticated RCE paths:
functions.php via Theme Editor.Timing Attacks: Use sleep-based payloads to blindly enumerate CMS user existence or blind SQLi in CMS core/plugins.
Payload Naming (OPSEC): Never use blatant backdoor names like shell.php, cmd.php, or test.php. Blend into the target environment by using convincing names related to the application's context (e.g., class-wp-cache-helper.php, config-update.php, or index_backup.php).
Focused workflow for validating exploitability safely and turning candidate issues into reproducible, bounded proof.
Focused reconnaissance workflow for authorized security assessments, bug bounty triage, lab targets, and CTF infrastructure.
Focused reporting workflow for converting verified red-team work into clear, reproducible assessment artifacts.
Expertise in offensive security research, vulnerability analysis, CMS-focused application testing, and red team operations.
Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services.