Skip to main content
Kur1sulab
GitHub 创作者资料

Kur1sulab

按仓库查看 2 个 GitHub 仓库中的 144 个已收集 skills。

已收集 skills
144
仓库
2
更新
2026年9月23日
仓库浏览

仓库与代表性 skills

django-drf-pentest
未分类

Use when 黑盒打 Django/DRF 后端站(DEBUG取证/越权矩阵/上传/JWT爆破).

2026年9月23日
go-pentest-workbench-ops
未分类

构建/运维 Go+Docker Kali+Ollama 多模型渗透工作台。

2026年9月23日
lan-device-recon
未分类

LAN device enum and router recon from Windows.

2026年9月23日
security-agent-framework
未分类

构建 AI 驱动自动化渗透 Agent 框架。覆盖架构/双模式/工具注册/Docker Kali/Web 仪表盘。

2026年9月23日
401-403-bypass-techniques
信息安全分析师

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

2026年8月12日
active-directory-acl-abuse
信息安全分析师

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

2026年8月12日
active-directory-certificate-services
信息安全分析师

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

2026年8月12日
active-directory-kerberos-attacks
信息安全分析师

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

2026年8月12日
已展示 8 / 116 个已收集 Skill。
ai-ml-security
信息安全分析师

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

2026年8月12日
anti-debugging-techniques
信息安全分析师

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

2026年8月12日
binary-protection-bypass
信息安全分析师

Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.

2026年8月12日
classical-cipher-analysis
信息安全分析师

Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or encoded text in CTF challenges that requires frequency analysis, Kasiski examination, or known-plaintext cryptanalysis.

2026年8月12日
code-obfuscation-deobfuscation
信息安全分析师

Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.

2026年8月12日
lattice-crypto-attacks
信息安全分析师

Lattice-based cryptanalysis playbook. Use when attacking RSA via Coppersmith small roots, recovering DSA/ECDSA nonces from bias, solving knapsack problems, or applying LLL/BKZ reduction to cryptographic constructions.

2026年8月12日
memory-forensics-volatility
信息安全分析师

Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.

2026年8月12日
rsa-attack-techniques
信息安全分析师

RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.

2026年8月12日
已展示 8 / 28 个已收集 Skill。
已展示 2 / 2 个仓库
已展示全部仓库