Penetration Testing
-
shulkwisec Skill Bola IdorDetect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
Audited 21 -
shulkwisec Skill Param FuzzSystematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
21 -
shulkwisec Bundle AWS Metadata SsrfExploit SSRF vulnerabilities in AWS EC2-hosted applications to extract IAM credentials and User Data from the Instance Metadata Service, including techniques for bypassing basic filters against IMDSv1.
21 -
trailofbits Bundle Burpsuite Project ParserSearches and extracts data from Burp Suite project files (.burp) using the burpsuite-project-file-parser extension, enabling regex searches on response headers and bodies, extraction of security audit findings, and analysis of proxy history and site map data.
7k -
zhaoxuya520 Bundle Ot IcsAuthorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
12.8k -
zhaoxuya520 Bundle Edr Bypass ReReverse-engineers EDR, Defender, and AV hook tables, ETW providers, and AMSI implementations to build targeted bypasses including unhooking, indirect syscalls, ETW patching, and call stack spoofing for authorized red team operations.
12.8k -
zhaoxuya520 Bundle Identity FederationAuthorized assessment of federated identity systems covering SAML, OIDC, and OAuth2 flows, SSO misconfigurations, and token confusion issues.
12.8k -
zhaoxuya520 Skill Dsl Vm ReverseReverse-engineers custom JavaScript-based WASM virtual machines and risk-control engines by identifying DSL VM patterns, extracting opcodes, analyzing constant tables, and tracing exported functions through static analysis and runtime injection.
12.8k -
zhaoxuya520 Bundle Competition Web RuntimeInspects web behavior, browser state, server routing, API order, and worker-backed application flow within a sandboxed CTF environment.
12.8k -
zhaoxuya520 Bundle Competition Pcap ProtocolAnalyze PCAP files by reconstructing TCP/UDP sessions, decoding application-layer protocols, and correlating packet sequences with host or malware behavior for CTF challenges.
Audited 12.8k -
zhaoxuya520 Bundle Competition Runtime RoutingTraces which sandbox node, proxy rule, or header-derived branch serves a live request in a CTF competition environment.
Audited 12.8k -
phoroth Bundle 007Runs a structured 6-phase security audit covering attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team exercises, and a final verdict, plus incident-response and monitoring playbooks.
3 -
lucaspmarie-a11y Bundle 007Runs security audits, threat modeling, and hardening for code and infrastructure, covering OWASP checks, code review, incident response, and red/blue team exercises.
5 -
shulkwisec Skill CsptHunt Client-Side Path Traversal vulnerabilities where attacker-controlled input is concatenated into the path of a fetch() or XHR request, enabling redirection and chaining to XSS or data exfiltration.
Audited 21 -
shulkwisec Skill Auth SecRoutes authentication and authorization testing efforts by identifying the primary attack surface — login mechanics, object authorization, browser trust boundaries, or identity protocols such as JWT/OAuth/SAML — before selecting a deeper skill.
Audited 21 -
shulkwisec Skill Email SecurityAudits email infrastructure security by testing SPF, DKIM, DMARC, open relay, spoofing resilience, MTA-STS, TLS-RPT, and SMTP configuration using standard security tools.
21 -
antigravity Skill Network 101Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments, enabling hands-on practice with service enumeration, log analysis, and security testing.
42.4k -
zhaoxuya520 Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
12.8k -
zhaoxuya520 Bundle Radio SdrGuides authorized RF/SDR security research for signal identification, demodulation analysis, and replay feasibility studies in shielded lab environments.
12.8k -
zhaoxuya520 Bundle Thick ClientAuthorized security testing framework for desktop thick clients covering local storage, IPC, update channels, traffic interception, and client-side trust boundaries.
12.8k -
zhaoxuya520 Bundle Docs GeneratorGenerates task-oriented technical documentation with progressive disclosure for READMEs, API docs, architecture docs, and security reports after reverse engineering, penetration testing, or CTF tasks.
Audited 12.8k -
zhaoxuya520 Bundle Threat HuntingGuides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
12.8k -
zhaoxuya520 Bundle Database SecurityPerforms authorized database security assessments across PostgreSQL, MySQL, MSSQL, MongoDB, and Redis, checking exposure, authentication, authorization, dangerous configurations, and exploit paths.
12.8k -
zhaoxuya520 Bundle Patch Diff ExploitAnalyzes vendor security patches via binary diffing to reverse-engineer vulnerabilities, write proof-of-concept exploits, and weaponize N-day exploits against unpatched systems.
12.8k -
zhaoxuya520 Bundle Competition Firmware LayoutAnalyze the structure, boot chain, and update mechanism of a firmware image, then trace the shortest path to the decisive artifact or secret.
12.8k -
lord1egypt Skill GodmodeBypasses safety filters on API-served LLMs using jailbreak templates, input obfuscation, and multi-model racing.
2 -
shulkwisec Bundle Cors Misconfiguration Complete Deep DiveProvides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
21 -
shulkwisec Skill SstiDetect and exploit Server-Side Template Injection vulnerabilities across multiple template engines including Jinja2, Twig, Freemarker, and Velocity, with payloads for sandbox escape and remote code execution. Includes detection methodology, bypass techniques, and fix patterns.
21 -
shulkwisec Skill Dom XssDetect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
Audited 21 -
shulkwisec Bundle Dom Based Vulnerabilities Complete Deep DiveProvides exact payloads and bypass techniques for every PortSwigger DOM-based vulnerability lab variant, including zero-day extensions and blue team detection strategies.
Audited 21 -
shulkwisec Bundle File Upload Vulnerabilities Deep DiveExploits file upload vulnerabilities across PortSwigger lab variants with exact payloads, bypass techniques, and zero-day escalation methods.
21