macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
原文语言:英语
菜单
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
已展示 40 / 7,442 个已收集 Skill。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
原文语言:英语
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
原文语言:英语
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
原文语言:英语
READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
原文语言:英语
READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
原文语言:英语
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
原文语言:英语
Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
原文语言:英语
GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
原文语言:英语
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
原文语言:英语
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
原文语言:英语
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
原文语言:英语
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
原文语言:英语
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
原文语言:英语
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
原文语言:英语
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
原文语言:英语
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
原文语言:英语
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
原文语言:英语
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
原文语言:英语
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
原文语言:英语
Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
原文语言:英语
Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
原文语言:英语
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
原文语言:英语
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
原文语言:英语
Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
原文语言:英语
Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
原文语言:英语
WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
原文语言:英语
XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
原文语言:英语
Active Directory security testing and attack techniques
原文语言:英语
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
原文语言:英语
Kerberos protocol attack techniques and exploitation
原文语言:英语
Bug bounty and pentest reconnaissance methodology
原文语言:英语
API Testing Overview
原文语言:英语
API Reconnaissance
原文语言:英语
Testing for Broken Object Level Authorization (BOLA)
原文语言:英语
Testing GraphQL
原文语言:英语
Testing for Credentials Transported over an Encrypted Channel
原文语言:英语
Testing for Default Credentials
原文语言:英语
Testing for Weak Lock Out Mechanism
原文语言:英语
Testing for Bypassing Authentication Schema
原文语言:英语
Testing for Vulnerable Remember Password
原文语言:英语