Penetration Testing
-
alirezarezvani Bundle Red TeamPlan and execute authorized red team engagements with structured attack path analysis, MITRE ATT&CK kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting.
20.4k -
alirezarezvani Bundle AI SecurityAssess AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, and agent tool abuse, with MITRE ATLAS mapping and guardrail recommendations.
Audited 20.4k -
alirezarezvani Bundle Senior SecurityRoutes security requests to specialist skills and performs STRIDE/DREAD threat modeling with a quick secret scan.
Audited 20.4k -
antigravity Bundle 007Performs security audits, hardening, threat modeling (STRIDE/PASTA), red/blue team exercises, OWASP checks, code review, incident response, and infrastructure security for any project.
42.4k -
openai Bundle Security Threat ModelPerforms repository-grounded threat modeling by enumerating trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, then writes a concise Markdown threat model.
Audited 23.3k -
getsentry Bundle Django Access ReviewReviews Django codebases for access control vulnerabilities and IDOR by tracing authorization flows, mapping attack surfaces, and reporting confirmed gaps with enforceable fixes.
845 -
trailofbits Bundle Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
7k -
trailofbits Bundle Firebase Apk ScannerScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
7k -
bankrbot Bundle PolygraphAssigns behavioral trust grades (A–F) to MCP servers by running probes for prompt injection, permission overreach, data leaks, and adversarial-input handling, and publishes reproducible onchain attestations.
1.2k -
mukul975 Bundle Operating Havoc C2Build and operate a Havoc C2 framework for authorized red-team engagements, including team server deployment, evasive Demon agent generation, and post-exploitation.
24.6k -
mukul975 Bundle Operating Sliver C2Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
24.6k -
mukul975 Bundle Exploiting AWS With PacuUse Pacu modules for AWS privilege escalation, persistence, and backdooring during authorized penetration tests.
24.6k -
mukul975 Bundle Testing JWT Token SecurityAssess JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
24.6k -
mukul975 Bundle Escaping Containers To HostExploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.
24.6k -
mukul975 Bundle Executing Red Team ExerciseSimulates real-world adversary operations to test an organization's detection and response capabilities through the full attack lifecycle, from reconnaissance to objective completion.
24.6k -
mukul975 Bundle Red Teaming Llms With GarakRun NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.
24.6k -
mukul975 Bundle Relaying Ntlm For Adcs Esc8Coerce a domain controller to authenticate to an attacker-controlled host and relay that NTLM authentication to an AD CS web enrollment endpoint to obtain a certificate for the DC machine account, enabling full domain compromise via DCSync.
24.6k -
mukul975 Bundle Exploiting Adcs With CertipyEnumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
24.6k -
mukul975 Bundle Moving Laterally With NetexecEnumerate SMB, WinRM, LDAP, and MSSQL services, validate credentials, spray passwords, and execute commands on remote hosts using NetExec during authorized penetration tests.
24.6k -
mukul975 Bundle Testing Cors MisconfigurationIdentify and exploit Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during authorized security assessments.
24.6k -
mukul975 Bundle Performing Vlan Hopping AttackSimulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
24.6k -
mukul975 Bundle Testing Websocket API SecurityTests WebSocket API implementations for security vulnerabilities including missing authentication, Cross-Site WebSocket Hijacking, injection attacks, and denial-of-service.
24.6k -
mukul975 Bundle Conducting API Security TestingConducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using the OWASP API Security Top 10 framework.
24.6k -
mukul975 Bundle Enumerating Cloud With CloudfoxMap AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
24.6k -
mukul975 Bundle Exploiting Idor VulnerabilitiesIdentify and exploit Insecure Direct Object Reference vulnerabilities during authorized penetration tests by manipulating object identifiers in API requests and URLs.
24.6k -
mukul975 Bundle Exploiting Ipv6 VulnerabilitiesIdentifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.
24.6k -
mukul975 Bundle Performing Kerberoasting AttackEnumerate Active Directory service accounts, request Kerberos TGS tickets, and crack them offline to assess password strength and privilege escalation paths.
24.6k -
mukul975 Bundle Performing Purple Team ExerciseCoordinates purple team exercises by running MITRE ATT&CK-mapped attack scenarios with real-time detection testing and collaborative gap remediation.
24.6k -
mukul975 Bundle Performing Ssl Stripping AttackSimulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms.
24.6k -
mukul975 Bundle Testing For Xss VulnerabilitiesTests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
24.6k -
mukul975 Bundle Exploiting Broken Link HijackingDiscover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an attacker.
24.6k -
mukul975 Bundle Attacking Entra Id With RoadtoolsEnumerate Microsoft Entra ID tenants using ROADrecon and acquire/exchange tokens with roadtx for authorized red-team operations.
24.6k -
mukul975 Bundle Conducting Pass The Ticket AttackExtract Kerberos tickets from LSASS memory, inject them into an attacker session, and perform lateral movement to access remote systems as the impersonated user.
24.6k -
mukul975 Bundle Exploiting HTTP Request SmugglingDetect and exploit HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
24.6k -
mukul975 Bundle Exploiting OAUTH MisconfigurationIdentify and exploit OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during authorized security assessments.
24.6k -
mukul975 Bundle Performing Csrf Attack SimulationTest web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
24.6k