Skip to main content
dariushoule
GitHub 创作者资料

dariushoule

按仓库查看 2 个 GitHub 仓库中的 24 个已收集 skills。

已收集 skills
24
仓库
2
更新
2026年7月19日
仓库浏览

仓库与代表性 skills

recon
信息安全分析师

Network, service, and web enumeration for authorized pentesting and CTF. Use when starting an engagement or CTF box and you need to map attack surface — discover open ports, fingerprint services, enumerate web apps, and triage what to attack first. Triggers…

2026年7月19日
hashcat
信息安全分析师

Offline password-hash cracking with hashcat on the host GPU, for authorized pentesting and CTF. Use to identify an unknown hash's type, pick the right hashcat mode, fetch a wordlist, and run a sensible wordlist→rules→mask attack ladder. Triggers on "help me…

2026年7月6日
linux-privesc
信息安全分析师

Linux local privilege escalation methodology for authorized pentesting and CTF — turn a foothold shell (often a low-priv/service account like www-data) into root. Use after landing any non-root shell on a Linux host and you need to escalate: enumerate the…

2026年7月6日
browse
软件开发工程师

Drive a real web browser as a companion to the operator during authorized pentesting/CTF — a host Chrome routed through the VPN that both the human and the agent can control over CDP (Playwright MCP). Use to explore a web app interactively, reproduce/poke at…

2026年6月28日
retro
其他计算机职业

Post-engagement retrospective that turns one run's operator↔agent interactions into durable improvements to this repo's skills, runbooks, and tooling. Use at the end of an engagement (after the work, ideally before teardown wipes scratch) to refine skills,…

2026年6月22日
wordlists
信息安全分析师

Pick and fetch the right SecLists wordlist on demand for content discovery, fuzzing, subdomain/vhost enum, parameter mining, default-cred spraying, and payload injection (LFI/SSRF/SQLi/XSS), for authorized pentesting and CTF. Use when a fuzz/brute job needs a…

2026年6月22日
cloud
信息安全分析师

Cloud-emulator and AWS-compatible-API attack methodology for authorized pentesting and CTF. Use when a target exposes an AWS-shaped API (LocalStack, moto, or a custom/look-alike mock), an instance metadata service (IMDS / 169.254.169.254) reachable via SSRF,…

2026年6月22日
vuln-research
信息安全分析师

CVE and public-exploit (PoC) research for authorized pentesting and CTF. Use after recon fingerprints a service/version to find known vulnerabilities and working exploits — GitHub PoCs, Exploit-DB, Metasploit modules — ranked by exploitability. Also sharpens…

2026年6月21日
已展示 8 / 16 个已收集 Skill。
已展示 2 / 2 个仓库
已展示全部仓库