macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
원문 언어: 영어
메뉴
SkillsMP는 CyberStrikeus/CyberStrike에서 7,442개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.
수집된 skill 7,442개 중 40개를 표시합니다.
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
원문 언어: 영어
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
원문 언어: 영어
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
원문 언어: 영어
READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
원문 언어: 영어
READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
원문 언어: 영어
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
원문 언어: 영어
Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
원문 언어: 영어
GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
원문 언어: 영어
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
원문 언어: 영어
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
원문 언어: 영어
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
원문 언어: 영어
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
원문 언어: 영어
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
원문 언어: 영어
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
원문 언어: 영어
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
원문 언어: 영어
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
원문 언어: 영어
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
원문 언어: 영어
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
원문 언어: 영어
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
원문 언어: 영어
Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
원문 언어: 영어
Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
원문 언어: 영어
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
원문 언어: 영어
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
원문 언어: 영어
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
원문 언어: 영어
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
원문 언어: 영어
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
원문 언어: 영어
XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
원문 언어: 영어
Active Directory security testing and attack techniques
원문 언어: 영어
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
원문 언어: 영어
Kerberos protocol attack techniques and exploitation
원문 언어: 영어
Bug bounty and pentest reconnaissance methodology
원문 언어: 영어
API Testing Overview
원문 언어: 영어
API Reconnaissance
원문 언어: 영어
Testing for Broken Object Level Authorization (BOLA)
원문 언어: 영어
Testing GraphQL
원문 언어: 영어
Testing for Credentials Transported over an Encrypted Channel
원문 언어: 영어
Testing for Default Credentials
원문 언어: 영어
Testing for Weak Lock Out Mechanism
원문 언어: 영어
Testing for Bypassing Authentication Schema
원문 언어: 영어
Testing for Vulnerable Remember Password
원문 언어: 영어