Skip to main content

CyberStrikeus/CyberStrike

SkillsMP는 CyberStrikeus/CyberStrike에서 7,442개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
7,442
GitHub 스타
1,653
GitHub 포크
254

수집된 skill 7,442개 중 40개를 표시합니다.

직업 분류
미분류
설명

macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl

원문 언어: 영어

업데이트
직업 분류
미분류
설명

Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

WebSocket security testing — CSWSH, message injection, auth bypass, origin validation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Active Directory security testing and attack techniques

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Kerberos protocol attack techniques and exploitation

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bug bounty and pentest reconnaissance methodology

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

API Testing Overview

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

API Reconnaissance

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Broken Object Level Authorization (BOLA)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing GraphQL

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Credentials Transported over an Encrypted Channel

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Default Credentials

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Weak Lock Out Mechanism

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Bypassing Authentication Schema

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Testing for Vulnerable Remember Password

원문 언어: 영어

업데이트
수집된 skill 7,442개 중 40개를 표시합니다.