Penetration Testing
-
mukul975 Bundle Performing Red Team With CovenantAutomate red team operations using the Covenant C2 framework's REST API for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
24.6k -
mukul975 Bundle Testing For Broken Access ControlSystematically test web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
24.6k -
mukul975 Bundle Testing For Host Header InjectionTest web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
24.6k -
mukul975 Bundle Testing For System Prompt LeakageTest LLM applications for system prompt leakage using manual payloads, garak, and Promptfoo to extract embedded secrets and routing logic.
24.6k -
mukul975 Bundle Testing Mobile API AuthenticationTests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities.
24.6k -
mukul975 Bundle Analyzing Uefi Bootkit PersistenceAnalyzes UEFI bootkit persistence mechanisms including firmware implants, ESP modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families, forensic inspection, and integrity verification.
24.6k -
mukul975 Bundle Detecting Model Extraction AttacksDetect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
24.6k -
mukul975 Bundle Performing Blind Ssrf ExploitationDetect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
24.6k -
mukul975 Bundle Performing Iot Security AssessmentPerforms comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications.
24.6k -
mukul975 Bundle Performing Packet Injection AttackCrafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
24.6k -
mukul975 Bundle Testing For Email Header InjectionTest web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
24.6k -
mukul975 Bundle Abusing Dpapi For Credential AccessExtract DPAPI-protected secrets such as credentials and browser data from Windows systems during authorized penetration tests.
24.6k -
mukul975 Bundle Auditing Entra Id With AadinternalsRun Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
24.6k -
mukul975 Bundle Auditing Uefi Firmware With ChipsecAssess platform firmware security using Intel CHIPSEC: verify SPI flash write protection, BIOS lock, SMM/SMRR, Secure Boot variables, dump SPI flash, and triage UEFI variables for firmware-level threats.
24.6k -
mukul975 Bundle Conducting Network Penetration TestConducts comprehensive network penetration tests against authorized target environments using host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation following PTES methodology.
24.6k -
mukul975 Bundle Exploiting Deeplink VulnerabilitiesTests and exploits deep link vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation.
24.6k -
mukul975 Bundle Exploiting Insecure DeserializationIdentify and exploit insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications during authorized penetration tests.
24.6k -
mukul975 Bundle Performing API Fuzzing With RestlerAutomates stateful REST API fuzzing using Microsoft RESTler to discover security and reliability bugs by compiling OpenAPI specs, configuring authentication, and running test, fuzz-lean, and full fuzzing modes.
24.6k -
mukul975 Bundle Performing API Rate Limiting BypassTests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls.
24.6k -
mukul975 Bundle Performing Clickjacking Attack TestTest web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.
24.6k -
mukul975 Bundle Performing Fuzzing With AflplusplusPerform coverage-guided fuzzing of compiled binaries using AFL++ to discover memory corruption, crashes, and security vulnerabilities.
24.6k -
mukul975 Bundle Scanning Network With Nmap AdvancedPerforms advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
24.6k -
mukul975 Bundle Testing For Sensitive Data ExposureIdentify sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
24.6k -
mukul975 Bundle Testing Oauth2 Implementation FlawsTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass.
24.6k -
mukul975 Bundle Analyzing Network Traffic Of MalwareAnalyzes malware-generated network traffic from PCAP files to identify C2 protocols, data exfiltration, DNS tunneling, and beaconing patterns using Wireshark, Zeek, Suricata, and Python.
24.6k -
mukul975 Bundle Conducting Cloud Penetration TestingPerform authorized penetration testing against AWS, Azure, and GCP cloud environments using cloud-specific tools and methodologies, with findings mapped to the MITRE ATT&CK Cloud matrix.
24.6k -
mukul975 Bundle Exploiting SQL Injection With SqlmapDetect and exploit SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
24.6k -
mukul975 Bundle Exploiting Websocket VulnerabilitiesTest WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
24.6k -
mukul975 Bundle Orchestrating LLM Attacks With PyritAutomate multi-turn adversarial conversations against LLM agents using Microsoft PyRIT, including Crescendo and Tree-of-Attacks-with-Pruning (TAP) attack chains with scorer feedback loops.
24.6k -
mukul975 Bundle Performing JWT None Algorithm AttackTest JWT signature verification bypass by crafting tokens with the 'none' algorithm.
24.6k -
mukul975 Bundle Analyzing Bootkit And Rootkit SamplesAnalyzes bootkit and rootkit malware that infects MBR, VBR, or UEFI firmware for pre-OS persistence, covering boot sector analysis, UEFI module inspection, and anti-rootkit detection.
24.6k -
mukul975 Bundle Building C2 Redirector InfrastructureArchitect C2 redirectors with nginx and Apache, derive filter rules from malleable profiles, and apply OPSEC controls for resilient red-team infrastructure.
24.6k -
mukul975 Bundle Exploiting Nopac Cve 2021 42278 42287Escalate from standard domain user to Domain Admin by exploiting the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) in Active Directory environments.
24.6k -
mukul975 Bundle Performing GRAPHQL Depth Limit AttackTest GraphQL APIs for depth limit vulnerabilities by sending deeply nested recursive queries to identify denial-of-service risks.
24.6k -
mukul975 Bundle Performing Hash Cracking With HashcatCrack password hashes using Hashcat for authorized penetration testing and password policy assessment, supporting dictionary, brute-force, rule-based, and hybrid attacks.
24.6k -
mukul975 Bundle Performing Purple Team Atomic TestingExecutes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis, and runs detection validation loops to measure blue team visibility.
24.6k