Skip to main content

이 저장소의 skills

PurpleAILAB/Decepticon - 3페이지

SkillsMP는 PurpleAILAB/Decepticon에서 312개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

PurpleAILAB/Decepticon

수집된 skill 312개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Evil-twin rogue AP with KARMA/Mana PNL-probe response, captive-portal credential capture, and post-association MITM for PSK/open networks. Distinct from wpa-enterprise-eap which targets 802.1X.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Top-level index for the Decepticon 802.11 wireless attack suite. Routes the WirelessOperator to the correct leaf skill based on the target AP's crypto column (PSK / SAE / MGT / WPS) and engagement posture. BLE, Zigbee, Z-Wave, LoRaWAN, and sub-GHz live under…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

OS Command Injection — exploiting applications that pass user input to OS commands without sanitization. Covers injection operators (;, |, ||, &&, $(), backticks, newline), blind detection (time-based, OOB callback), and bypass techniques (space, keyword,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Insecure deserialization — RCE via malicious serialized objects in Java (ysoserial), PHP (PHPGGC), .NET (ysoserial.net), and Python (pickle). Covers gadget chain selection, payload generation, and injection into cookies, POST bodies, ViewState, and API…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Insecure Direct Object References (IDOR) — authorization bypass through predictable object references (sequential IDs, UUIDs, filenames, encoded IDs). Covers horizontal/vertical privilege escalation, ID enumeration, HTTP method tampering, and JWT sub claim…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Server-Side Request Forgery (SSRF) — exploiting server-side URL fetching to access internal services, cloud metadata (AWS/GCP/Azure), internal APIs, and port scanning. Covers IP bypass techniques, DNS rebinding, Gopher protocol smuggling, and redirect-based…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Server-Side Template Injection (SSTI) — RCE through template engines. Covers Jinja2 (Python/Flask), Twig (PHP/Symfony), Freemarker (Java), ERB (Ruby), Razor (.NET). Includes engine fingerprinting, MRO chain construction, and filter bypass.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Depth-first RE investigation loop for a single binary or function cluster: decompile→rename→retype→comment→re-read, with context-rot guards and on-task checks. Use when triage has already identified the interesting area and the goal is full understanding:…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Router / IoT firmware extraction pipeline — unpack nested filesystems, locate web server, identify backdoor credentials.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Coverage-guided fuzzing methodology for compiled binaries and libraries: target scoping, fuzzer selection (AFL++/libFuzzer/Honggfuzz), harness skeleton, ASan+UBSan flags, corpus curation, crash triage and minimization (afl-tmin/minimize_corpus),…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Deep binary analysis via Ghidra — headless analyzeHeadless or live MCP bridge with 245 tools. Decompilation, xrefs, function listing, batch operations, P-code emulation, convention enforcement.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

ROP/JOP gadget hunting and exploit-chain construction — for NX/DEP bypass on x86/x64/ARM binaries.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Fast-path binary triage — identify format/arch/mitigations, grab high-signal strings and imports in under a minute.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Abort / crisis plan generator — halt triggers, response actions, AI-aware safety gates (hallucination threshold, destructive-action gate, output validation).

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Contact / communications plan generator — primary operator, escalation chain, abort signal recipient, external SOC endpoint, blackout windows.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt ReDoS (CWE-1333, Catastrophic Backtracking) — identify regexes with nested quantifiers or overlapping alternation that cause super-linear matching time, trace tainted input paths to regex sinks, demonstrate timing PoC, and validate with response-time…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Blind SQL injection under hostile WAF — manual bypass playbook for when sqlmap fails because common tokens (SUBSTRING, IF, AND, WHERE, single quotes) are filtered. Covers token-fingerprinting probe loops, arithmetic-multiplication boolean evaluation,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Web crypto exploitation — padding-oracle (Vaudenay), AES-CBC bit-flipping / IV manipulation, AES-ECB pattern attacks (cut-and-paste, prefix/suffix recovery), HMAC bypass, hash-length extension, JWT alg confusion. Covers detection signals, working in-file…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

DNS rebinding attack to bypass browser same-origin policy and reach IMDS/localhost/internal services: TTL=0 rebind mechanics, rbndr.us/singularity tooling, browser DNS cache pinning, chaining into AWS/GCP/Azure IMDS credential pivot. Use when SSRF is blocked…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Race condition / TOCTOU exploitation — concurrent and parallel-request attacks against web applications that check then act, write session state before validating it, or perform slow operations that widen the race window. Covers single-endpoint races…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

SQL Injection — automated and manual exploitation of unsanitized SQL queries. Covers Union-based, Error-based, Blind (Boolean/Time-based), and Stacked queries. Includes sqlmap automation with WAF bypass tamper scripts.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Build chains where leaked or weak credentials pivot across services to privileged access.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build chains where IDOR enables privilege escalation and high-impact control-plane actions.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Build chains from XSS into account takeover or privileged action execution.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt LLM training-data and model poisoning (OWASP LLM04:2025) — adversarial inputs that bias future model behaviour through fine-tuning, RLHF, or continuous-learning loops.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt insecure deserialization (CWE-502) across Python pickle, Java ObjectInputStream / Jackson / SnakeYAML, .NET BinaryFormatter / DataContractJson, PHP unserialize, Ruby Marshal/YAML.load, and Node.js vm. Direct path to unauthenticated RCE.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt LLM excessive agency (OWASP LLM06:2025) — agentic systems granted too many tools, too broad permissions per tool, or unsupervised authority to act on the user / business behalf, producing financial loss, data loss, or destructive operations from a single…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Insecure Direct Object Reference (CWE-639) — missing authorization checks on object IDs. Covers horizontal vs vertical privilege escalation, UUID vs integer guessing, and GraphQL introspection-driven IDOR discovery.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt improper LLM output handling (OWASP LLM05:2025) — downstream code that trusts unstructured model output and renders / executes / shells it without sanitisation, producing XSS, SSRF, SQL injection, RCE, and SSTI via the model channel.

원문 언어: 영어

업데이트
수집된 skill 312개 중 40개를 표시합니다.