Skip to main content

이 저장소의 skills

EntroVyx/hermes-agent-offsec - 2페이지

SkillsMP는 EntroVyx/hermes-agent-offsec에서 146개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

EntroVyx/hermes-agent-offsec

수집된 skill 146개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Mine GitLab for secrets, CI tokens when subdomain found.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Detect hardcoded passwords in HTML forms, JavaScript, comments, and API responses.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack cameras via RTSP, ONVIF, Axis config when 554 open.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Decode, forge, brute JWTs when Bearer auth header is seen.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

LLM prompt injection / system prompt extraction — 40+ technique catalog against hardened GPT-4o-class deployments. Covers direct/indirect/agentic attacks, encoding bypasses, delimiter smuggling, boolean extraction, positional enumeration, RAG poisoning,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Chain phpinfo to RCE via exec check when info.php exposed.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Port scan /8-/24 with Masscan+RustScan and nmap banners.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Nmap scan for MySQL, Redis, FTP, SSH, internal API services.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Exploit public bucket objects via Content-Type override to achieve stored XSS.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Enumerate and fingerprint Hikvision ISAPI endpoints on SCADA/IoT web interfaces.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Sector-specific recon for solar panel installation company websites — residential solar, commercial solar, battery storage, energy audits. Typically WordPress with financing calculators, energy savings estimators, and customer referral portals. These sites…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Mass scan for exposed env files, backups, and git configs.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt staging via crt.sh when production is WAF-hardened.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Map subdomains via crt.sh and subfinder at recon kickoff.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Exploit unauthenticated multi-step API flows — start, submit, upload, export without credentials.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt WP plugins via REST, exploit CVEs when version known.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Batch WP recon: users, CORS, XMLRPC, leaks across domains.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

GCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Multi-endpoint CORS credential test automation — batch-probes API endpoints for CORS misconfiguration, distinguishes exploitable reflect-any-origin + credentials from false positives (ACAO: * alone), generates browser PoCs, and chains findings to subdomain…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt API security misconfiguration — mass assignment, JWT attacks, prototype pollution, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies. JWT: alg=none, weak HMAC…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header injection redirects token, predictable/numeric token, Referer leak, no-expiry/reuse), (2) email change without re-auth, (3) OAuth account-link…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET (GitLab $3,370), framework-wide CSRF middleware disabled…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NET BinaryFormatter, Ruby Marshal.load, JNDI/Log4Shell. RCE via deserialization is almost always Critical. Use when target runs Java, PHP…

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Skill-set loader for /hunt orchestrator. Fingerprints the target, picks the right platform attack skills, and loads the Red Team or WAPT skill set. Use when /hunt has just received a mode answer (redteam or wapt + blackbox|greybox) and needs to load the…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt file upload bugs — RCE via webshell, XSS via SVG/HTML, SSRF via XXE in DOCX, path traversal via filename. Bypass tables (10 techniques): double extension (shell.php.jpg if server checks last ext only), magic bytes spoofing (PNG header on PHP), null byte…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Firebase / Firestore / GCP exploitation — Firebase API key discovery in JS bundles, anonymous auth via signUp endpoint, Firestore collection enumeration with anon key, Realtime Database read/write without auth, Firebase Storage bucket listing, Firebase…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over HTTP/2, internal endpoint disclosure, proto file leakage, gRPC-Web/grpc-gateway…

원문 언어: 영어

업데이트
수집된 skill 146개 중 40개를 표시합니다.