Skip to main content
GitHub 저장소

Mingyi-Atlas

Mingyi-Atlas에는 MingyiSecLab에서 수집한 skills 122개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.

수집된 skills
122
Stars
9
업데이트
2026-06-08
Forks
0
직업 범위
직업 카테고리 5개 · 100% 분류됨
저장소 탐색

이 저장소의 skills

benchmark
기타 컴퓨터 관련 직업

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

2026-06-08
adcs-esc1
정보 보안 분석가

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

2026-06-08
bloodhound-query
정보 보안 분석가

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

2026-06-08
netexec
정보 보안 분석가

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

2026-06-08
ad
정보 보안 분석가

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

2026-06-08
engagement-lifecycle
기타 컴퓨터 관련 직업

Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.

2026-06-08
engagement-startup
기타 컴퓨터 관련 직업

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

2026-06-08
final-report
기타 컴퓨터 관련 직업

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

2026-06-08
kill-chain-analysis
기타 컴퓨터 관련 직업

Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.

2026-06-08
orchestration
기타 컴퓨터 관련 직업

Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.

2026-06-08
atlas
기타 컴퓨터 관련 직업

Atlas orchestrator workflow — engagement intake, OPPLAN build, execution loop via task() delegation, final report. Tools=[]; everything ships through sub-agents.

2026-06-08
k8s-pivot
기타 컴퓨터 관련 직업

Kubernetes attack playbook — service-account token theft, RBAC abuse, pod escape, hostPath mount abuse, kube-api-server pivoting.

2026-06-08
s3-takeover
기타 컴퓨터 관련 직업

Detect and claim dangling S3 buckets referenced by subdomains (CNAME → s3 hostnames where bucket no longer exists).

2026-06-08
cloud
기타 컴퓨터 관련 직업

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

2026-06-08
terraform-state-leak
기타 컴퓨터 관련 직업

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

2026-06-08
oracle-manipulation
기타 컴퓨터 관련 직업

Hunt single-block oracle manipulation — spot-price AMM oracles, manipulable TWAP, dependent calculations, missing staleness checks.

2026-06-08
contracts
소프트웨어 개발자

Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.

2026-06-08
crypto-decode
정보 보안 분석가

Cipher detection + automated decryption via Ciphey, Cyberchef recipes, hashcat hash-ID, format conversion, common encoding chains.

2026-06-08
exploit-reporting
정보 보안 분석가

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

2026-06-08
supplychain
정보 보안 분석가

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

2026-06-08
web
정보 보안 분석가

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API exploitation.

2026-06-08
xs-leaks
정보 보안 분석가

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

2026-06-08
android
정보 보안 분석가

Android APK pentest workflow — apktool/jadx static, Frida dynamic instrumentation, SSL pinning bypass, root detection bypass, intent fuzzing, keystore extraction.

2026-06-08
mobile
정보 보안 분석가

Mobile application red team category — Android (APK) and iOS (IPA) pentest. Routing skill: identifies the platform + attack surface, then loads the matching sub-skill.

2026-06-08
c2
정보 보안 분석가

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

2026-06-08
c2-sliver
정보 보안 분석가

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

2026-06-08
web-recon
정보 보안 분석가

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

2026-06-08
anti-debug-bypass
정보 보안 분석가

Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.

2026-06-08
packer-unpacking
정보 보안 분석가

Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.

2026-06-08
reverser
정보 보안 분석가

Root pointer for the binary reversing lane. Covers triage, string extraction, packer unpacking, symbol risk, ROP, Ghidra deep analysis, and firmware extraction.

2026-06-08
abort-template
정보 보안 분석가

Abort / crisis plan generator — halt triggers, response actions, AI-aware safety gates (hallucination threshold, destructive-action gate, output validation).

2026-06-08
cleanup-template
정보 보안 분석가

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

2026-06-08
contact-template
정보 보안 분석가

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

2026-06-08
data-handling-template
정보 보안 분석가

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

2026-06-08
roe-template
정보 보안 분석가

Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.

2026-06-08
playwright-cli
소프트웨어 품질 보증 분석가·테스터

Automate browser interactions, test web pages and work with Playwright tests.

2026-05-31
nuclei
정보 보안 분석가

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

2026-05-31
asrep-roasting
정보 보안 분석가

Request AS-REP for accounts with DONT_REQ_PREAUTH set and crack offline — like kerberoast but no auth required.

2026-05-31
certipy-esc-chain
정보 보안 분석가

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

2026-05-31
coercer
정보 보안 분석가

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

2026-05-31
이 저장소에서 수집된 skills 122개 중 상위 40개를 표시합니다.