Skip to main content

이 저장소의 skills

brucesongs/kali-claw - 2페이지

SkillsMP는 brucesongs/kali-claw에서 139개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

brucesongs/kali-claw

수집된 skill 139개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Mobile security covers the complete attack/defense chain of Android/iOS application security testing, APK/IPA reverse engineering, runtime manipulation, certificate pinning bypass, and mobile data protection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Open Banking / PSD2 / Open Finance attacks — FAPI (Financial-grade API), OpenID Connect for Financial APIs, OAuth2 PKCE, Strong Customer Authentication (SCA) bypass, AIS/PIS/CBPII API abuse, payment redirection, consent manipulation. Covers UK Open Banking,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Password attacks encompass the complete attack chain from hash extraction, hash type identification, dictionary attacks, rule-based attacks, and bruteforcing to online service brute forcing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attacking threat intelligence platforms (MISP, OpenCTI, Anomali ThreatStream, ThreatQuotient, ThreatConnect, IBM Threat Intel, Palo Alto AutoFocus, Mandiant Advantage). Covers platform CVEs (MISP CVE-2022-29527, OpenCTI vulnerabilities), API abuse,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Council provides a structured framework for analyzing security questions from multiple adversarial and defensive perspectives simultaneously.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hardware and embedded system security testing covering physical interface exploitation, firmware extraction and analysis, side-channel attacks, RFID/NFC cloning, and fault injection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Network Sniffing and MITM attacks focus on intercepting, analyzing, and manipulating network traffic between two communicating parties.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Comprehensive security checklist and review patterns for analyzing applications, configurations, and infrastructure. This skill provides structured review methodology to identify vulnerabilities across OWASP Top 10 categories during penetration testing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Active Directory is the backbone of enterprise identity and access management, making it a primary target during internal network penetration tests.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AI agent framework attack surface — orchestration-layer compromise of LangChain (Python/JS), LangGraph, CrewAI, Microsoft AutoGen, OpenAI Assistants API v2, Anthropic Claude Agent SDK, LlamaIndex, Microsoft Semantic Kernel, Google ADK, SmolAgents, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Anti-forensics is the offensive counterpart to digital forensics.

원문 언어: 영어

업데이트
직업 분류
기술 작가
설명

Transform technical findings into clear, structured written content: penetration test reports, vulnerability disclosures, security blog posts, and technical documentation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Performing repetitive enumeration across many targets - Running batch vulnerability scans on multiple hosts - Monitoring for changes in target environment - Executing attack chains that require iterative steps - User says "loop", "automate", "batch", "repeat.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Near-field wireless penetration testing skills covering Bluetooth Classic device enumeration and exploitation, BLE GATT service attacks against IoT devices, RFID card cloning (MIFARE Classic/DESFire), NFC tag manipulation, and contactless payment probing.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Automated browser-based security testing using Playwright and browser devtools. Interact with web applications as a user would — click, type, navigate — while monitoring network traffic, JavaScript execution, and DOM changes for security issues.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

A system for recording, indexing, and distilling knowledge from agent lifecycle events. Through a three-layer document system (overview -> detailed records -> knowledge distillation), raw conversation events are transformed into reusable experience.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Rapidly acquire a mental model of any unfamiliar codebase — from a 500-line script to a 100M+ line monorepo. This skill transforms raw code into structured intelligence: architecture maps, entry points, data flows, security surfaces, and onboarding confidence…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Advanced injection attacks beyond SQL - covering OS command injection, LDAP injection, NoSQL injection, template injection (SSTI), XPath injection, and comprehensive filter bypass techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Concurrency exploitation covers race condition vulnerabilities including TOCTOU, signal handler races, thread synchronization bypasses, and timing attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attacks against Trusted Execution Environments (TEEs) and confidential computing platforms — Intel SGX (Foreshadow/SGAxe/LVI/ÆPIC Leak), Intel TDX, AMD SEV/SEV-ES/SEV-SNP (CrossLine/BadRAM), Azure CCF, Marblerun, and Gramine/Occlum libos enclaves. Covers…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

After completing a penetration test engagement - When encountering a novel attack technique or defense - After a tool produces unexpected results - When identifying recurring patterns across targets - User says "learn", "remember this", "pattern.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Cyber-Physical Systems (CPS) attacks — PLCs (Siemens S7, Rockwell ControlLogix, Schneider Modicon, Mitsubishi MELSEC), ICS protocols (Modbus, DNP3, Profinet, EtherNet/IP, IEC 61850, OPC UA), HMIs, SCADA historians, OT-to-IT pivot, SIS bypass. Distinct from…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attacks for exfiltrating data from compromised networks and bypassing DLP/egress controls. Covers DNS tunneling, ICMP/HTTPS tunneling, protocol smuggling, steganographic exfil, cloud-native exfil (S3/OpenSearch/BigQuery), and DLP bypass. Use when testing…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attacks against cloud data platforms and analytics pipelines — Snowflake, Databricks, BigQuery, Redshift, dbt, Apache Airflow, and lakehouse architectures. Covers identity-based breaches (no perimeter), warehouse SQL injection at scale, IAM privilege…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automated data collection from structured sources: CVE databases, threat intelligence feeds, exploit databases, and security advisories. Transform unstructured web data into structured knowledge units.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Setting up a practice lab for penetration testing techniques - Creating isolated environments for exploit development and testing - Building vulnerable application targets for training - Testing tools against known-vulnerable configurations - User says "lab",…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attacks against edge computing platforms — Cloudflare Workers (V8 isolate), Fastly Compute@Edge (WASM/Wasmtime), AWS Lambda@Edge and CloudFront Functions, Akamai EdgeWorkers, Vercel Edge Functions, and Deno Deploy. Covers V8 isolate escape, WASM sandbox…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

End-to-end penetration test project management skill. Orchestrates the full engagement lifecycle from scoping through reporting, managing skill composition, evidence chains, and phase transitions.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Semantic search using Exa API for security research queries. Unlike keyword-based search, Exa understands context and retrieves high-quality, relevant results for technical research.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Local File Inclusion (LFI) and Remote File Inclusion (RFI) attack techniques covering path traversal, PHP wrapper abuse, log poisoning, session file inclusion, and remote payload hosting for code execution.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Firmware reverse engineering covers the full pipeline from raw firmware image acquisition through filesystem extraction, static and dynamic analysis, full-system emulation, and vulnerability/backdoor detection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hardware Security Module attacks — physical (side-channel, fault injection, decapping) and logical (PKCS#11 API abuse, key extraction, M-of-N quorum bypass, RDP, firmware exploitation). Covers Thales Luna (SafeNet), Utimaco SecurityServer, nCipher nShield,…

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Build and maintain structured, persistent knowledge graphs across sessions. Knowledge-ops transforms ephemeral session findings into reusable intelligence — connecting entities, tracking confidence over time, and enabling recall across engagements.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

IBM z/OS, RACF (Resource Access Control Facility), CICS, DB2, JES2, TSO/ISPF penetration testing; APF library abuse, dataset access control, SNA/Appc attacks, and legacy mainframe security assessment for financial/government environments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Advanced malware analysis covering unpacking (UPX, VMProtect, Themida, Enigma, custom packers), sandbox-evasion detection (anti-VM, anti-debug, anti-analysis), rootkit analysis (user-mode, kernel-mode, bootkits, UEFI), YARA rule authoring and optimization,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Building and security-testing MCP (Model Context Protocol) servers for Kali Linux security tools.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Coordinating multiple specialized agents to conduct complex penetration testing engagements through task decomposition, parallel execution, result aggregation, and conflict resolution.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Network tunneling encapsulates one protocol inside another to bypass firewalls, evade detection, and route traffic through restricted networks.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Attacks against cryptographic systems during the PQC migration period. Covers Harvest-Now-Decrypt-Later (SNDL/HNDL), hybrid PQC downgrade abuse, KEM combiner flaws, mixed-protocol failures, NIST PQC standard implementations (ML-KEM/Kyber, ML-DSA/Dilithium,…

원문 언어: 영어

업데이트
수집된 skill 139개 중 40개를 표시합니다.