Skip to main content

Skills neste repositório

abelrguezr/hacktricks-skills - Página 12

O SkillsMP coletou 908 skills de abelrguezr/hacktricks-skills. Abra uma skill para revisar a origem e os detalhes.

abelrguezr/hacktricks-skills

Mostrando 40 de 908 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Pentest Oracle TNS Listener on ports 1521-1529. Use this skill whenever the user mentions Oracle database, TNS listener, port 1521, Oracle enumeration, or needs to assess Oracle database security. This includes version detection, SID enumeration, credential…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest RabbitMQ Management interfaces on port 15672. Use this skill whenever you need to assess RabbitMQ security, test default credentials, enumerate via the management API, publish messages to queues, or crack RabbitMQ authentication hashes. Trigger this…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and pentest PPTP (Point-to-Point Tunneling Protocol) services on port 1723. Use this skill whenever the user mentions PPTP, port 1723, GRE protocol, remote access tunneling, or needs to assess PPTP security during authorized penetration…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest MQTT (Mosquitto) services on port 1883 or non-standard ports. Use this skill whenever the user mentions MQTT, Mosquitto, IoT device testing, publish/subscribe protocols, or needs to enumerate and exploit MQTT brokers. This includes checking for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Docker security assessment and exploitation. Use this skill whenever the user needs to enumerate Docker services, exploit misconfigured Docker APIs (ports 2375/2376), escape containers, discover secrets in running containers, or perform privilege escalation…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest GlusterFS distributed file systems. Use this skill whenever you encounter ports 24007, 24008, 24009, or 49152+ in a scan, or when the user mentions GlusterFS, distributed storage, glusterd, or gluster-brick. This skill covers enumeration, exploitation…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Security assessment and penetration testing for MongoDB databases. Use this skill whenever the user needs to enumerate MongoDB instances, test for authentication bypass, check for ObjectID prediction vulnerabilities, assess MongoBleed (CVE-2025-14847)…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Squid HTTP proxy on port 3128. Use this skill whenever you discover a Squid proxy service, need to enumerate proxy capabilities, pivot through a proxy to scan internal networks, or configure proxychains for HTTP interaction. Trigger on mentions of…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest PPPP (CS2) P2P IP cameras and IoT devices. Use this skill whenever the user mentions P2P cameras, IP camera pentesting, PPPP protocol, CS2 Network, LookCam, device ID enumeration, or wants to test IoT camera security. This skill covers UDP/32100…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest iSCSI (Internet Small Computer Systems Interface) services on port 3260. Use this skill whenever you need to enumerate, authenticate, or mount iSCSI targets during security assessments. Trigger this skill when you see port 3260 open, need to discover…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest SAProuter (port 3299) for security assessments. Use this skill whenever the user mentions SAProuter, port 3299, SAP network penetration, SAP service discovery, or needs to enumerate/exploit SAP infrastructure. This skill covers Metasploit…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to identify and exploit Distcc vulnerabilities on port 3632. Use this skill whenever the user mentions Distcc, port 3632, distributed compilation, or needs to test for CVE-2004-2687. Make sure to use this skill for any network service enumeration that…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Subversion (SVN) servers on port 3690. Use this skill whenever you need to enumerate, exploit, or assess SVN repositories - whether you see port 3690 open, find svn:// or svn+ssh:// URLs, discover mod_dav_svn over HTTP(S), or need to extract…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest WS-Discovery (Web Services Dynamic Discovery) services on UDP port 3702. Use this skill whenever you need to discover network services via multicast, probe for devices like IP cameras, printers, or other WS-Discovery enabled endpoints, or analyze…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest NATS message bus and JetStream services. Use this skill whenever you need to enumerate, exploit, or assess NATS servers (port 4222/tcp), capture credentials via DNS hijacking, loot JetStream streams for secrets, or harden NATS deployments. Trigger…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform WHOIS enumeration and security testing on port 43 services. Use this skill whenever you need to enumerate domain/IP/ASN registration data, test WHOIS services for vulnerabilities, follow referral chains, or compare WHOIS vs RDAP data. Trigger this…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Erlang Port Mapper Daemon (epmd) on port 4369. Use this skill whenever you need to enumerate, assess, or exploit epmd services during security assessments. Trigger this when you see port 4369 open, when working with RabbitMQ or CouchDB installations,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and exploit Tiller/Helm services (port 44134) in Kubernetes clusters for privilege escalation. Use this skill whenever you're pentesting a Kubernetes cluster, find port 44134 open, discover Tiller services, or need to escalate privileges…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and pentest EtherNet/IP industrial devices on port 44818. Use this skill whenever the user mentions EtherNet/IP, industrial control systems, Rockwell Automation, PLC devices, or port 44818. Also trigger for ICS/SCADA reconnaissance, factory…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Enumerate BACnet devices on building automation networks. Use this skill whenever the user mentions BACnet, building automation, HVAC control systems, port 47808, or needs to discover and enumerate devices on industrial control networks. This skill helps…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Exploit Cisco Smart Install vulnerability (CVE-2018-0171) on port 4786 to exfiltrate device configurations. Use this skill whenever the user mentions Cisco switches, Smart Install, port 4786, CVE-2018-0171, or wants to extract configurations from Cisco…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest OPC UA (Open Platform Communications Unified Access) industrial control systems. Use this skill whenever the user mentions OPC UA, industrial protocols, PLCs, SCADA systems, port 4840, or wants to assess OT/ICS security. This skill covers discovery,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest TACACS+ authentication systems on port 49. Use this skill whenever the user mentions TACACS, TACACS+, port 49, network device authentication, AAA services, Cisco network pentesting, or wants to test network access control systems. This skill…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest Docker registries (port 5000). Use this skill whenever you need to enumerate, exploit, or backdoor a Docker registry service. Trigger this when you discover port 5000 open, see Docker registry fingerprints, need to pull/push images from a…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and exploit Apache Hadoop clusters during penetration testing. Use this skill whenever you need to assess Hadoop security, test HDFS/WebHDFS access, exploit YARN RCE vulnerabilities, or check for CVE-2023-26031. Trigger on any mention of…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest and exploit Rexec (port 512) services. Use this skill whenever you encounter port 512/tcp open during enumeration, need to brute-force rexec credentials, extract credentials from network captures, or exploit legacy r-services. Trigger for any…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest Line Printer Daemon (LPD) services on port 515/tcp. Use this skill whenever you need to assess printer security, test LPD/LPRng implementations, enumerate printer services, or exploit LPD vulnerabilities. Trigger this skill for any task…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Multicast DNS (mDNS) and DNS-SD pentesting skill. Use this whenever the user mentions mDNS, DNS-SD, service discovery, zeroconf, port 5353, .local domain, Avahi, Bonjour, AirPlay, printer spoofing, or any local network service discovery attacks. Trigger for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Amazon Redshift data warehouse (port 5439). Use this skill whenever the user mentions Redshift, AWS data warehouse, port 5439, PostgreSQL-like database on AWS, or wants to enumerate/test Redshift security. This includes checking for public access,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and test RTSP (Real Time Streaming Protocol) services on ports 554/8554. Use this skill whenever you need to assess RTSP cameras, streaming servers, or media services, check for authentication vulnerabilities, enumerate RTSP endpoints, or…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Android Debug Bridge (ADB) pentesting and exploitation. Use this skill whenever the user mentions ADB, Android debugging, port 5555, mobile device exploitation, Android security testing, wireless debugging, or any scenario involving connecting to Android…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest Kibana instances on port 5601. Use this skill whenever you need to assess Kibana security, enumerate Kibana services, check for authentication bypass, explore Elasticsearch data through Kibana, or identify vulnerabilities in the Elastic Stack.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Apple Filing Protocol (AFP) services on port 548. Use this skill whenever you need to enumerate, exploit, or assess AFP file sharing services, Netatalk daemons, NAS appliances (QNAP, Synology, WD, TrueNAS), or legacy macOS file servers. Trigger for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest CouchDB databases on ports 5984/6984. Use this skill whenever the user mentions CouchDB, document databases, port 5984, port 6984, or needs to enumerate/exploit CouchDB instances. This includes database enumeration, credential testing, privilege…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Exploit CVE-2021-38647 on Azure Linux servers running OMI (Open Management Infrastructure) to achieve root RCE. Use this skill whenever you need to test for or exploit the OMI vulnerability on ports 5985/5986, especially when you discover Azure Automation,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to pentest Windows Remote Management (WinRM) on ports 5985/5986. Use this skill whenever the user mentions WinRM, Windows remote management, ports 5985 or 5986, PowerShell remoting, evil-winrm, WS-MAN, or needs to connect to/execute commands on Windows…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Perform X11 (X Window System) security assessments and exploitation on port 6000. Use this skill whenever the user mentions X11, port 6000, X Window System, graphical interface pentesting, or needs to enumerate/exploit unauthenticated X11 access. This…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

IPMI (Intelligent Platform Management Interface) pentesting and exploitation. Use this skill whenever the user needs to discover, enumerate, or exploit IPMI services on port 623/UDP/TCP, test for IPMI vulnerabilities (cipher 0, RAKP, anonymous auth), attempt…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest Redis instances (port 6379) for enumeration, authentication bypass, data exfiltration, and RCE. Use this skill whenever the user mentions Redis, port 6379, key-value stores, in-memory databases, or needs to test Redis security. This includes checking…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

How to enumerate and exploit TFTP (Trivial File Transfer Protocol) services on UDP port 69. Use this skill whenever you need to scan for TFTP services, enumerate files on TFTP servers, download or upload files via TFTP, or assess TFTP security during…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 908 skills coletadas.