Skip to main content

braydos-h/BreachPilot

SkillsMP는 braydos-h/BreachPilot에서 146개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
146
GitHub 스타
3
GitHub 포크
0

이 저장소의 skills

분류 대기 중

수집된 skill 146개 중 40개를 표시합니다.

직업 분류
미분류
설명

Identifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format,…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Detect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication, metrics tracking, and Jira ticketing workflows.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Build a vulnerability exception and risk acceptance tracking system with approval workflows, compensating controls documentation, and expiration management.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Conducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security posture of network…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates as high-privileged users and escalate domain privileges during authorized red team assessments.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Exploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256…

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.

원문 언어: 영어

업데이트
수집된 skill 146개 중 40개를 표시합니다.