Skip to main content

uphiago/recon-skills

SkillsMP는 uphiago/recon-skills에서 145개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
145
GitHub 스타
1,158
GitHub 포크
205

이 저장소의 skills

수집된 skill 145개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack SAML SSO via XSW, signature strip, metadata extract.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when two or more verified findings may combine into a higher-impact authorized attack path.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when verified WordPress findings may combine into an authorized path to administrative or server control.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Escape Docker containers to host root via 5 techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when classifying a verified web or WordPress behavior and selecting a related validation skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when starting or restructuring an authorized external web and API assessment.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when an API may expose data or privileged operations without authentication.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Mine error_log for creds, paths, SQL when leak hunt finds.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exchange/OWA NTLM AD leak, spray attack when mail subdomain.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Firebase/Supabase for data via JS config leak probe.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Flask/Werkzeug debugger exposure for traceback and SECRET leaks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Mine GitLab for secrets, CI tokens when subdomain found.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack cameras via RTSP, ONVIF, Axis config when 554 open.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Decode, forge, brute JWTs when Bearer auth header is seen.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Chain phpinfo to RCE via exec check when info.php exposed.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Port scan /8-/24 with Masscan+RustScan and nmap banners.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Nmap scan for MySQL, Redis, FTP, SSH, internal API services.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt staging via crt.sh when production is WAF-hardened.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt WP plugins via REST, exploit CVEs when version known.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Batch WP recon: users, CORS, XMLRPC, leaks across domains.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit XMLRPC multicall, pingback for brute force and SSRF.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when an authorized target exposes WordPress core, plugin, theme, REST, or XML-RPC behavior.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Parameterized sector recon using sector database.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration viatool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…

원문 언어: 영어

업데이트
수집된 skill 145개 중 40개를 표시합니다.