Skip to main content

这个仓库中的 skills

abelrguezr/hacktricks-skills - 第 6 页

SkillsMP 已收集 abelrguezr/hacktricks-skills 中的 908 个 Skill。打开任一 Skill 可查看来源和详情。

abelrguezr/hacktricks-skills

已展示 40 / 908 个已收集 Skill。

职业分类
信息安全分析师
描述

Security testing skill for SSDP/UPnP device spoofing and vulnerability assessment. Use this skill whenever the user needs to test UPnP/SSDP security, discover UPnP devices on a network, run EvilSSDP for phishing simulations, or assess UPnP-related…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Telecom network security assessment and exploitation techniques for GTP, 5G core, and industrial cellular routers. Use this skill whenever the user mentions telecom networks, mobile core protocols (GTP, PFCP, NAS), 5G security testing, SGSN/GGSN/PGW/AMF/SMF…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security testing skill for WebRTC DoS vulnerabilities involving race conditions between ICE consent verification and DTLS handshake. Use this skill whenever you need to test WebRTC media servers for the null cipher suite vulnerability, analyze WebRTC security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to enable monitor mode and packet injection on Android devices with Broadcom Wi-Fi chipsets using NexMon. Use this skill whenever the user wants to perform wireless penetration testing on Android, enable monitor mode on their phone, capture Wi-Fi…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to assess EAP-TLS enterprise WiFi for Evil Twin vulnerabilities. Use this skill whenever the user mentions WiFi security assessments, EAP-TLS testing, WPA2/3-Enterprise pentesting, identity leakage, TLS downgrade attacks, or rogue AP testing. This skill…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Wi-Fi security testing and penetration testing. Use this skill whenever the user mentions Wi-Fi attacks, wireless security testing, WEP/WPA/WPS cracking, Evil Twin attacks, deauthentication, handshake capture, PMKID attacks, WPA Enterprise testing, KARMA/MANA…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security testing methodology for AI CLI tools (Claude Code, Gemini CLI, Warp) and MCP servers. Use this skill whenever you need to assess AI agent abuse vectors, test MCP server vulnerabilities, analyze repo-controlled configuration poisoning risks, perform…

原文语言:英语

更新
职业分类
信息安全分析师
描述

AI agent browser abuse and phishing methodology. Use this skill whenever the user mentions AI agents, browser automation, credential theft, prompt injection in browsers, agent mode phishing, hosted browser attacks, or any security testing involving AI…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze clipboard hijacking (pastejacking) attacks, ClickFix campaigns, and IUAM-style verification page lures. Use this skill whenever investigating phishing campaigns that use clipboard manipulation, fake CAPTCHA pages, or social engineering to execute…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Clone websites for phishing assessments and social engineering engagements. Use this skill whenever the user needs to create a copy of a target website for phishing campaigns, security assessments, or social engineering testing. Trigger on mentions of:…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect phishing attempts targeting your organization by analyzing domain variations, certificate transparency logs, URL telemetry, and network fingerprints. Use this skill whenever you need to hunt for phishing infrastructure, investigate suspicious domains,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Discord invite security risks, assess server vulnerability to invite hijacking attacks, and generate security awareness materials. Use this skill whenever the user mentions Discord server security, invite link safety, phishing prevention, or needs to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect and analyze homograph/homoglyph attacks in phishing emails, URLs, and domains. Use this skill whenever the user mentions phishing analysis, email security, domain impersonation, Unicode attacks, homoglyph detection, or needs to inspect suspicious…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze mobile phishing campaigns, malicious Android APKs, and iOS mobile configuration profiles. Use this skill whenever investigating suspicious mobile apps, phishing infrastructure, or mobile malware. Trigger when users mention APK analysis, mobileconfig…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Create and analyze phishing documents for authorized security testing. Use this skill whenever the user needs to create malicious Office documents (Word, Excel, PowerPoint), HTA files, LNK loaders, or steganography-based payloads for penetration testing, red…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to conduct authorized phishing assessments and security awareness testing. Use this skill whenever the user mentions phishing campaigns, email security testing, social engineering assessments, credential harvesting simulations, GoPhish configuration,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Python fundamentals reference covering data types, operators, control flow, data structures (lists, tuples, dicts, sets), classes, functions, generators, regex, and itertools. Use this skill whenever the user asks about Python syntax, basic operations, data…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to bruteforce MD5 hashes with partial matching (suffix or prefix attacks). Use this skill whenever the user mentions hash cracking, MD5 bruteforcing, partial hash matching, hash suffix attacks, loose comparison vulnerabilities, or CTF challenges involving…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to escape Python sandbox restrictions and gain code execution. Use this skill whenever the user mentions Python sandboxes, restricted Python environments, CTF challenges with Python jails, eval/exec restrictions, sandboxed code execution, or any scenario…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security assessment skill for CVE-2024-28397 (Js2Py sandbox escape). Use this skill when analyzing JavaScript-to-Python execution environments, reviewing js2py usage in codebases, testing for this specific vulnerability in authorized security assessments, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Python bytecode OOB (out-of-bounds) read exploit for sandbox bypass. Use this skill whenever the user mentions Python sandbox bypass, bytecode manipulation, CTF challenges with Python eval restrictions, co_consts/co_names manipulation, or any Python security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security assessment skill for identifying and testing CVE-2023-33733 (ReportLab/xhtml2pdf RCE vulnerability) in authorized environments. Use this skill when you need to assess PDF generation systems for this specific sandbox escape vulnerability, verify patch…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Python code for class pollution vulnerabilities (Python's prototype pollution), identify vulnerable merge functions, and demonstrate exploitation techniques for authorized security testing. Use this skill whenever the user mentions Python security,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Keras model files (.keras, .h5) for deserialization vulnerabilities, create test payloads for security research, and assess ML model security posture. Use this skill whenever the user mentions Keras models, model deserialization, ML model security,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PyScript vulnerability assessment and pentesting. Use this skill whenever the user mentions PyScript, Pyodide, browser-based Python, web application security testing, XSS in Python contexts, SSRF via Python libraries, or needs to assess PyScript…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use Python internal read gadgets to extract secrets from vulnerable applications. Trigger this skill whenever the user mentions Python format string vulnerabilities, class pollution, Flask/Django secret extraction, Werkzeug debug console access, environment…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to research and understand Python security vulnerabilities including sandbox escapes, deserialization attacks, and Pyscript exploitation. Use this skill whenever the user mentions Python security, sandbox bypass, deserialization vulnerabilities, Pyscript…

原文语言:英语

更新
职业分类
软件开发工程师
描述

How to create, activate, and manage Python virtual environments. Use this skill whenever the user needs to set up an isolated Python environment, install packages in a clean environment, or troubleshoot venv-related issues. Make sure to use this skill when…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use this skill whenever you need to make HTTP requests in Python, interact with web APIs, test web applications, or automate web interactions. This includes GET/POST requests, file uploads, session management, JSON APIs, security testing, and web application…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to execute delivery receipt side-channel attacks on E2EE messengers (WhatsApp, Signal, Threema). Use this skill whenever the user wants to probe messaging protocols for timing leaks, fingerprint devices, monitor user behavior through RTT analysis, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Create comprehensive threat models for applications and systems using established methodologies like STRIDE, DREAD, and PASTA. Use this skill whenever the user needs to identify security vulnerabilities, assess system risks, create data flow diagrams, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Techniques for escaping restricted kiosk, locked-down, or single-application environments on Windows, iPad, and browsers. Use this skill whenever the user mentions kiosk mode, locked-down devices, restricted desktops, Citrix/RDS/VDI environments, single-app…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze MediaTek bootloader vulnerabilities, particularly bl2_ext secure-boot bypasses. Use this skill when investigating MediaTek device boot chains, analyzing secure boot verification gaps, triaging boot logs for authentication bypasses, or documenting…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security testing for bootloaders including U-Boot, UEFI, and SoC ROM recovery modes. Use this skill whenever you need to test device startup configurations, assess secure boot protections, exploit bootloader vulnerabilities, or perform firmware security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze embedded device firmware for security vulnerabilities. Use this skill whenever the user needs to examine firmware images, extract filesystems, find hardcoded credentials, analyze binaries, or assess IoT device security. Trigger on mentions of…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to analyze and exploit firmware integrity and signature verification flaws. Use this skill whenever the user mentions firmware analysis, embedded device security, binary exploitation, backdoor compilation, cross-compilation for embedded systems, or wants…

原文语言:英语

更新
职业分类
信息安全分析师
描述

MediaTek XFlash Carbonara DA2 hash bypass exploit for firmware analysis and security research. Use this skill whenever analyzing MediaTek device firmware, investigating Download Agent vulnerabilities, performing pre-OS security research, testing for…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Decrypt Synology PAT/SPK encrypted firmware and application archives to extract their contents. Use this skill whenever the user needs to analyze Synology NAS firmware, extract packages from .pat or .spk files, inspect Synology system updates, or reverse…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Physical security testing and hardware attack techniques. Use this skill whenever the user mentions physical access, BIOS/UEFI password recovery, hardware security testing, cold boot attacks, DMA attacks, BadUSB/HID implants, BitLocker bypass, chassis…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Techniques for bypassing Linux shell restrictions, WAF filters, and command injection defenses. Use this skill whenever you need to execute commands in restricted environments, bypass input validation, work around shell limitations, or understand how…

原文语言:英语

更新
已展示 40 / 908 个已收集 Skill。