← all plugins

Bb Huge

by @shulkwisec · plugin · 100 skills

Bb Huge from ShulkwiSEC/bb-huge.

Install the whole plugin (CLI)
npx skillmds add shulkwisec/bb-huge npx skillmds add shulkwisec/cross-site-scripting-xss-complete-deep-dive npx skillmds add shulkwisec/xxe npx skillmds add shulkwisec/cors-misconfiguration-complete-deep-dive npx skillmds add shulkwisec/cspt npx skillmds add shulkwisec/csrf npx skillmds add shulkwisec/hack npx skillmds add shulkwisec/ssrf npx skillmds add shulkwisec/ssti npx skillmds add shulkwisec/oauth-authentication-deep-dive npx skillmds add shulkwisec/osint npx skillmds add shulkwisec/report npx skillmds add shulkwisec/api-sec npx skillmds add shulkwisec/dom-xss npx skillmds add shulkwisec/auth-sec npx skillmds add shulkwisec/codebase npx skillmds add shulkwisec/jwt-authentication-complete-deep-dive npx skillmds add shulkwisec/bola-idor npx skillmds add shulkwisec/dom-based-vulnerabilities-complete-deep-dive npx skillmds add shulkwisec/gh-export npx skillmds add shulkwisec/remediate npx skillmds add shulkwisec/2fa-multi-factor-bypass npx skillmds add shulkwisec/ai-redteam npx skillmds add shulkwisec/colang-gen npx skillmds add shulkwisec/compliance npx skillmds add shulkwisec/metasploit npx skillmds add shulkwisec/param-fuzz npx skillmds add shulkwisec/websockets-deep-dive npx skillmds add shulkwisec/xss-stored npx skillmds add shulkwisec/amend-skill npx skillmds add shulkwisec/amsi-bypass npx skillmds add shulkwisec/analyze-cve npx skillmds add shulkwisec/auth-bypass npx skillmds add shulkwisec/file-upload-vulnerabilities-deep-dive npx skillmds add shulkwisec/http-host-header-attacks-deep-dive npx skillmds add shulkwisec/web-llm-attacks-deep-dive npx skillmds add shulkwisec/llm-testing npx skillmds add shulkwisec/pwn-request npx skillmds add shulkwisec/web-exploit npx skillmds add shulkwisec/api-security npx skillmds add shulkwisec/authz-bypass npx skillmds add shulkwisec/clickjacking npx skillmds add shulkwisec/graphql-idor npx skillmds add shulkwisec/graphql-api-deep-dive npx skillmds add shulkwisec/post-exploit npx skillmds add shulkwisec/request-cves npx skillmds add shulkwisec/ad-assessment npx skillmds add shulkwisec/aikido-triage npx skillmds add shulkwisec/cmd-injection npx skillmds add shulkwisec/distill-skill npx skillmds add shulkwisec/dom-based-xss npx skillmds add shulkwisec/jwt-misconfig npx skillmds add shulkwisec/observe-skill npx skillmds add shulkwisec/open-redirect npx skillmds add shulkwisec/recon-for-sec npx skillmds add shulkwisec/reverse-shell npx skillmds add shulkwisec/sql-injection npx skillmds add shulkwisec/ssl-tls-audit npx skillmds add shulkwisec/type-juggling npx skillmds add shulkwisec/wmi-execution npx skillmds add shulkwisec/xss-reflected npx skillmds add shulkwisec/access-control-complete-deep-dive npx skillmds add shulkwisec/ai-ml-security npx skillmds add shulkwisec/authentication-complete-deep-dive npx skillmds add shulkwisec/business-logic npx skillmds add shulkwisec/cloud-security npx skillmds add shulkwisec/cookie-attacks npx skillmds add shulkwisec/cors-misconfig npx skillmds add shulkwisec/crlf-injection npx skillmds add shulkwisec/email-security npx skillmds add shulkwisec/jndi-injection npx skillmds add shulkwisec/network-assess npx skillmds add shulkwisec/oauth-security npx skillmds add shulkwisec/path-traversal npx skillmds add shulkwisec/race-condition npx skillmds add shulkwisec/shodan-dorking npx skillmds add shulkwisec/xslt-injection npx skillmds add shulkwisec/web-cache-deception-deep-dive npx skillmds add shulkwisec/information-disclosure-deep-dive npx skillmds add shulkwisec/mass-assignment npx skillmds add shulkwisec/nosql-injection npx skillmds add shulkwisec/threat-modeling npx skillmds add shulkwisec/ad-cs-esc1-abuse npx skillmds add shulkwisec/ad-dcsync-attack npx skillmds add shulkwisec/ad-pass-the-hash npx skillmds add shulkwisec/api-testing-deep-dive npx skillmds add shulkwisec/credential-audit npx skillmds add shulkwisec/essential-skills-deep-dive npx skillmds add shulkwisec/file-access-vuln npx skillmds add shulkwisec/lateral-movement npx skillmds add shulkwisec/security-fuzzing npx skillmds add shulkwisec/session-fixation npx skillmds add shulkwisec/ai-data-poisoning npx skillmds add shulkwisec/ai-prompt-leaking npx skillmds add shulkwisec/aws-cognito-abuse npx skillmds add shulkwisec/aws-metadata-ssrf npx skillmds add shulkwisec/heap-exploitation npx skillmds add shulkwisec/mobile-resilience npx skillmds add shulkwisec/process-hollowing npx skillmds add shulkwisec/request-smuggling
⬇ Download

Skills in this plugin

  1. bb-huge · shulkwisec bundle
    Initializes bug bounty hunt workspaces, logs vulnerability findings with severity and evidence, and enriches them throughout a session.
    21
    repo stars
  2. cross-site-scripting-xss-complete-deep-dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21
    repo stars
  3. xxe · shulkwisec
    Detect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
    21
    repo stars
  4. cors-misconfiguration-complete-deep-dive · shulkwisec bundle
    Provides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
    21
    repo stars
  5. cspt · shulkwisec
    Hunt Client-Side Path Traversal vulnerabilities where attacker-controlled input is concatenated into the path of a fetch() or XHR request, enabling redirection and chaining to XSS or data exfiltration.
    21
    repo stars
  6. csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21
    repo stars
  7. hack · shulkwisec
    Routes security testing tasks to the correct vulnerability category, guiding recon, validation, privilege escalation, and chain building for web application and API security assessments.
    21
    repo stars
  8. ssrf · shulkwisec
    Detect and exploit Server-Side Request Forgery vulnerabilities by identifying user-controlled URL parameters, testing for internal service access, cloud metadata endpoints, and file scheme reads, with bypass techniques for common filters.
    21
    repo stars
  9. ssti · shulkwisec
    Detect and exploit Server-Side Template Injection vulnerabilities across multiple template engines including Jinja2, Twig, Freemarker, and Velocity, with payloads for sandbox escape and remote code execution. Includes detection methodology, bypass techniques, and fix patterns.
    21
    repo stars
  10. oauth-authentication-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  11. osint · shulkwisec
    Conduct passive OSINT reconnaissance on target organizations using a MITRE ATT&CK framework. Discovers employees, email patterns, subdomains, infrastructure, leaked credentials, and cloud assets with confidence-scored findings.
    21
    repo stars
  12. report · shulkwisec bundle
    Generate a NullPointer Studio styled PDF penetration test report from findings.json, producing a professional dark-themed PDF with executive summary, risk dashboard, per-finding cards, and remediation summary.
    21
    repo stars
  13. api-sec · shulkwisec
    Routes API security testing into recon, authorization, token abuse, or hidden-parameter workflows based on observed endpoint characteristics.
    21
    repo stars
  14. dom-xss · shulkwisec
    Detect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
    21
    repo stars
  15. auth-sec · shulkwisec
    Routes authentication and authorization testing efforts by identifying the primary attack surface — login mechanics, object authorization, browser trust boundaries, or identity protocols such as JWT/OAuth/SAML — before selecting a deeper skill.
    21
    repo stars
  16. codebase · shulkwisec bundle
    Performs a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
    21
    repo stars
  17. jwt-authentication-complete-deep-dive · shulkwisec bundle
    Provides exact payloads and bypass techniques for every PortSwigger JWT authentication lab variant, from unverified signatures to algorithm confusion attacks.
    21
    repo stars
  18. bola-idor · shulkwisec
    Detect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
    21
    repo stars
  19. dom-based-vulnerabilities-complete-deep-dive · shulkwisec bundle
    Provides exact payloads and bypass techniques for every PortSwigger DOM-based vulnerability lab variant, including zero-day extensions and blue team detection strategies.
    21
    repo stars
  20. gh-export · shulkwisec
    Formats all confirmed pentest findings from findings.json into copy-pasteable GitHub issue markdown blocks, following the AppSec reporting guide template.
    21
    repo stars
  21. remediate · shulkwisec
    Generates specific, implementable fixes for each vulnerability finding, producing code patches, configuration changes, dependency updates, and IaC fixes with before/after code and verification steps.
    21
    repo stars
  22. 2fa-multi-factor-bypass · shulkwisec bundle
    Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.
    21
    repo stars
  23. ai-redteam · shulkwisec bundle
    AI/LLM red-team assessment using the OWASP LLM Top 10 (2025) + OWASP AI Testing Guide (AITG v1, Nov 2025) frameworks, plus OWASP MCP Top 10 runtime testing for agentic/MCP targets. Tests prompt injection, jailbreaks, system prompt leakage, sensitive data extraction, excessive agency, improper output handling, model extraction, content bias, evasion, membership inference, MCP token exposure, MCP command injection, and more. Uses four tools in combination: FuzzyAI (single-turn jailbreak fuzzing), PyRIT (multi-turn orchestrated attacks), Garak (probe-based vulnerability scanning), and promptfoo (plugin-based red-team evaluation). Each tool covers different OWASP categories; running them together gives systematic coverage. Includes a conditional MCP reconnaissance phase and a post-access AI infrastructure phase (chained from /post-exploit). Produces: OWASP LLM Top 10 + AITG + MCP coverage matrix, findings per category, architecture diagram of the AI system, PoCs for confirmed exploits. Chains into /gh-export for
    21
    repo stars
  24. colang-gen · shulkwisec bundle
    Generates NeMo Guardrails Colang (.co) files and YAML config blocks from a plain-language description of a chatbot's purpose, allowed behaviors, and constraints. Use this skill whenever a user wants to build guardrails for a chatbot, define allowed intents for an LLM, create an AI firewall with NeMo Guardrails, generate Colang flow definitions, or configure a semantic allow-list for a bot. Trigger this skill even when the user just describes what their bot should and shouldn't do — generating the Colang and YAML is almost always what they need next.
    21
    repo stars
  25. compliance · shulkwisec bundle
    Full ASVS 5.0 compliance assessment against a codebase and/or architecture diagrams. Reads all 346 controls from the companion CSV, performs targeted code analysis per control, and produces a complete matrix marked COMPLIANT / NON_COMPLIANT / NOT_RELEVANT — with per-control reasoning and evidence (code snippets, file:line references, diagram observations). Outputs a reviewed CSV matrix and a self-contained HTML evidence report.
    21
    repo stars
  26. metasploit · shulkwisec
    Exploit validation and exploitation using Metasploit Framework. Runs in a dedicated Docker container (separate from Kali). Validates CVEs discovered by nuclei, nikto, or other scanners with actual exploit modules. Covers exploit selection, payload configuration, exploitation, and post-exploitation pivoting. Uses msfconsole, msfvenom, and the Metasploit module database. Chains from /pentester, /analyze-cve, or /post-exploit when exploitable CVEs are confirmed.
    21
    repo stars
  27. param-fuzz · shulkwisec
    Systematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
    21
    repo stars
  28. websockets-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  29. xss-stored · shulkwisec
    Stored XSS (persistent XSS) occurs when attacker-supplied input is saved server-side and later rendered unencoded to other users. Common injection points include profile fields, comments, forum posts, file upload filenames, and application logs. Detect via PHP `$_GET/$_POST/$_REQUEST/$_FILES`, ASP `Request.Form`, JSP `request.getParameter`, and BeEF hook injection. Tools: Burp Suite, OWASP ZAP, BeEF, PHP Charset Encoder, Hackvertor.
    21
    repo stars
  30. amend-skill · shulkwisec
    Inspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill. Trigger on: "improve this skill", "fix this skill", "update this skill", "why does X keep failing", "this skill is wrong", "add this to the skill", or automatically when observations/<skill-name>/runs.md contains 3 or more failure entries. Outputs the amendment as a diff the user can review before applying. Records the amendment rationale in observations/<skill-name>/runs.md after user confirmation.
    21
    repo stars
  31. amsi-bypass · shulkwisec bundle
    Bypass the Windows Antimalware Scan Interface (AMSI) using memory patching, reflection, and obfuscation techniques. Execute undetected PowerShell, VBScript, JScript, and .NET assemblies in-memory without triggering Microsoft Defender or third-party AV/EDR solutions. Use this skill during Red Team engagements when loading offensive tools (Mimikatz, Rubeus, SharpHound) in memory on defended Windows endpoints.
    21
    repo stars
  32. analyze-cve · shulkwisec
    CVE Vulnerability Analysis Workflow
    21
    repo stars
  33. auth-bypass · shulkwisec
    Bypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from linear/incremental cookies, SQL injection on login forms, PHP unserialize() boolean type juggling (b:1 payload), and credential transport over HTTP. Detectable with Burp Suite, OWASP ZAP, WebGoat.
    21
    repo stars
  34. file-upload-vulnerabilities-deep-dive · shulkwisec bundle
    Exploits file upload vulnerabilities across PortSwigger lab variants with exact payloads, bypass techniques, and zero-day escalation methods.
    21
    repo stars
  35. http-host-header-attacks-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  36. web-llm-attacks-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  37. llm-testing · shulkwisec bundle
    Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
    21
    repo stars
  38. pwn-request · shulkwisec
    Use when hunting Pwn Request vulnerabilities where pull_request_target workflows checkout attacker-controlled PR code and execute it in a privileged context with access to repository secrets. Trigger on: "pwn request", "pull_request_target", "checkout PR head", "npm install in CI", "lifecycle scripts in CI", "preinstall script", "postinstall script", "package.json scripts CI", "npm ci ignore-scripts false", "actions/checkout ref pull request head sha", privileged workflow running PR code, "Gato-X", supply chain via PR lifecycle scripts.
    21
    repo stars
  39. web-exploit · shulkwisec bundle
    Deep web exploitation beyond initial scanning. Covers SQLi (blind, OOB, second-order), NoSQL injection (MongoDB, operator bypass), GraphQL injection (introspection, batching, mutation abuse), XSS (reflected/stored/DOM with full source-sink analysis), SSTI (Jinja2/Twig/Freemarker/ERB engine identification and RCE), SSRF chains, file upload bypass (polyglot creation), XXE (blind, DOCX/SVG injection, Content-Type switching), deserialization (Java/PHP/Python/.NET), command injection, path traversal (LFI wrapper bypasses), race conditions, CSRF, JWT attacks (none/key confusion/kid injection), HTTP request smuggling (CL.TE/TE.CL/H2), CRLF injection, open redirect bypass chains, CORS exploitation, web cache deception/poisoning, OAuth misconfiguration, prototype pollution, session management, and business logic flaws. Uses sqlmap (advanced modes), commix, xsser, wapiti, davtest, and manual http(action="request", ...) payloads. Every technique includes actual payloads, commands, and code snippets for immediate use. Ch
    21
    repo stars
  40. api-security · shulkwisec
    Deep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function Level Authorization (BFLA / vertical privilege escalation), Unrestricted Access to Sensitive Business Flows, Server-Side Request Forgery via API parameters, Security Misconfiguration, Improper Inventory Management (shadow/zombie/deprecated endpoints, v1/v2 drift), and Unsafe Consumption of third-party APIs. Works across REST, GraphQL, gRPC, SOAP, and MCP servers. Discovers APIs from OpenAPI/Swagger specs, GraphQL introspection, gRPC reflection, .well-known endpoints, JS bundles, and traffic capture. Uses kiterunner, ffuf, schemathesis, restler-fuzzer, openapi-fuzzer, graphql-cop, clairvoyance, batchql, inql, jwt_tool, postman, mitmproxy, and manual http(action="request", ...) payloads. Every techniqu
    21
    repo stars
  41. authz-bypass · shulkwisec
    Test horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=, EventID=), and special header injection (X-Original-URL, X-Rewrite-URL, X-Forwarded-For, X-Remote-IP, X-Client-IP with 127.0.0.1/localhost/RFC1918 values). Tools: Burp Suite with Autorize/AuthMatrix extensions, OWASP ZAP Access Control Testing add-on.
    21
    repo stars
  42. clickjacking · shulkwisec
    Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.
    21
    repo stars
  43. graphql-idor · shulkwisec bundle
    Identify and exploit Insecure Direct Object Reference (IDOR) or Broken Object Level Authorization (BOLA) vulnerabilities specifically within GraphQL APIs. This skill focuses on manipulating node IDs, changing variables, and utilizing aliases to access unauthorized data.
    21
    repo stars
  44. graphql-api-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  45. post-exploit · shulkwisec
    Post-exploitation workflow. Covers privilege escalation (Linux SUID/sudo/kernel, Windows UAC/service/token), persistence assessment, local enumeration, credential harvesting, and pivot preparation. Structured workflows for Linux and Windows targets using impacket, netexec, john, linpeas/winpeas, and standard Kali tools. Includes kernel exploit reference tables, GTFOBins exploitation chains, Potato attack selection, Docker/container escapes, DLL hijacking, SSH key harvesting, credential recovery from memory, and Windows token manipulation. Chains from /pentester or /credential-audit when access is obtained.
    21
    repo stars
  46. request-cves · shulkwisec
    Generates CVE request packages from pentest findings. Reads cve-candidates.json (auto-generated at pentest completion) or findings.json directly, then produces for each qualifying vulnerability: MITRE CVE form data, GitHub Security Advisory draft, full disclosure report, and vendor notification email. Invoke manually after a pentest engagement when you have true-positive findings that warrant CVE IDs.
    21
    repo stars
  47. ad-assessment · shulkwisec
    Active Directory security audit using the MITRE ATT&CK framework. Full domain enumeration, trust mapping, GPO analysis, ACL abuse paths, ADCS attacks (ESC1-ESC8), delegation abuse (constrained/unconstrained/RBCD), fine-grained password policies, LAPS deployment, service account security, and Kerberos configuration. Uses enum4linux-ng, netexec, impacket, ldapsearch, certipy-ad, bloodhound-python, and rpcclient. Produces attack path diagrams, prioritized risk register, and PoCs. Chains into /gh-export for issue filing.
    21
    repo stars
  48. aikido-triage · shulkwisec
    Aikido Findings Triage Workflow
    21
    repo stars
  49. cmd-injection · shulkwisec
    OS command injection occurs when user input is passed unsanitized to a system shell via dangerous APIs: Java `Runtime.exec()`, Python `os.system/subprocess`, PHP `system/shell_exec/exec/proc_open`, C `system/exec`. Detect via pipe `|`, semicolon `;`, `&&`, `||`, backtick, `$()` operators, and time-delay payloads (`sleep 5`). Tools: Commix, Burp Suite, OWASP WebGoat.
    21
    repo stars
  50. distill-skill · shulkwisec
    Use when the user wants to extract reusable offensive security knowledge from any source and generate a SKILL.md file. Trigger on: "distill this", "extract skill from", "turn this into a skill", "generate skill from", "convert this report/blog/book/walkthrough into a skill", or when the user pastes raw security content (bug report, pentest report, CTF writeup, blog post, ezine, book chapter) and wants it transformed into structured hunting methodology.
    21
    repo stars
  51. dom-based-xss · shulkwisec bundle
    Exploit Document Object Model (DOM) Based Cross-Site Scripting (XSS) vulnerabilities. Unlike Reflected or Stored XSS, the attack payload is executed purely on the client-side as a result of modifying the DOM environment, often without the payload ever reaching the backend server.
    21
    repo stars
  52. jwt-misconfig · shulkwisec
    JWT Misconfiguration
    21
    repo stars
  53. observe-skill · shulkwisec
    Logs the outcome of a skill execution to observations/<skill-name>/runs.md. Trigger on: "log this run", "skill worked", "skill failed", "this didn't work", "log the outcome", "record this", "note that", or after any skill completes with a clear success, partial, or failure outcome. Creates the observations file if it does not exist, then appends an entry with date, task description, skill used, outcome, what worked, what failed, and any error messages observed.
    21
    repo stars
  54. open-redirect · shulkwisec
    Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
    21
    repo stars
  55. recon-for-sec · shulkwisec
    Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.
    21
    repo stars
  56. reverse-shell · shulkwisec
    Reverse shell generation and listener management. Generates platform-specific reverse shell payloads (bash, python, php, powershell, java, ruby, perl, netcat, socat, msfvenom) and sets up listeners in the Kali container. Supports one-liner generation, encoded payloads for WAF/filter bypass, listener setup with session capture, and shell stabilization. Chains from /pentester, /metasploit, or /post-exploit when command execution is confirmed.
    21
    repo stars
  57. sql-injection · shulkwisec
    SQL injection occurs when untrusted user input is interpolated directly into database queries, allowing attackers to alter query logic. Detect via single-quote errors, boolean-based blind responses (AND 1=1 vs AND 1=2), time-delay payloads (SLEEP, WAITFOR), UNION column enumeration, and error messages from MySQL, Oracle, MSSQL, PostgreSQL. Tools: sqlmap, sqlbftools, Burp Suite, wfuzz with SQLi fuzz strings.
    21
    repo stars
  58. ssl-tls-audit · shulkwisec
    TLS/SSL configuration audit. Tests protocol versions (SSLv2/3, TLS 1.0/1.1/1.2/1.3), cipher strength and ordering, certificate chain validation (intermediates, CT logs, OCSP stapling, pinning), known vulnerabilities (POODLE, BEAST, CRIME, Heartbleed, ROBOT, DROWN, Ticketbleed, GOLDENDOODLE), session management (ticket reuse, resumption, fixation), renegotiation attacks, TLS 1.3-specific issues (0-RTT replay, PSK modes, downgrade), HSTS deep analysis (preload, subdomains, bypass), and certificate revocation (CRL, OCSP responder, stapled response freshness). Compliance-mapped to PCI DSS 4.0 (full Section 4), NIST SP 800-52r2, and FedRAMP. Uses testssl.sh, sslscan, sslyze, openssl, nmap NSE scripts, and nuclei SSL templates. Multi-port scanning across 20+ TLS-bearing services.
    21
    repo stars
  59. type-juggling · shulkwisec
    PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
    21
    repo stars
  60. wmi-execution · shulkwisec bundle
    Utilize Windows Management Instrumentation (WMI) to execute malicious payloads, establish lateral movement, and execute commands stealthily across an Active Directory environment without dropping binaries to disk or relying on traditional Service Creation (PsExec) mechanics.
    21
    repo stars
  61. xss-reflected · shulkwisec
    Reflected XSS occurs when user-supplied input is echoed in an HTTP response without sanitization, allowing script execution in the victim's browser. Detect via injecting `<script>alert(1)</script>`, event handlers like `onfocus`, HTML entity bypass, and encoding variants. Tools: Burp Suite, OWASP ZAP, PHP Charset Encoder (PCE), Hackvertor, XSS-Proxy, ratproxy.
    21
    repo stars
  62. access-control-complete-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  63. ai-ml-security · shulkwisec
    AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.
    21
    repo stars
  64. authentication-complete-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  65. business-logic · shulkwisec
    Application-level business logic security testing for any domain. Takes an understanding-first approach: map the intended workflows before probing them. Covers: value/quantity logic abuse (negative, zero, overflow, rounding on any numeric field), workflow and state machine bypass (skipping required steps, forcing illegal state transitions, reusing one-time tokens), trust boundary violations (BOLA horizontal/vertical, BFLA, cross-tenant access, negative ownership attacks), idempotency and replay attacks (duplicate submissions, double-spend, same-reference reuse), multi-step flow integrity (checkout, registration, approval, verification), quota and rate limit bypass, time/date manipulation, and authorization code / reference number predictability. Domain-agnostic — applies to SaaS, e-commerce, banking, gaming, social platforms, APIs, or any multi-user application with stateful workflows. Chains from /pentester; chains into /param-fuzz when boundary violations or mass assignment are confirmed.
    21
    repo stars
  66. cloud-security · shulkwisec
    Cloud security posture assessment for AWS, Azure, and GCP. Tests IAM privilege escalation paths, public storage exposure, serverless attack surface, database exposure, logging gaps, container registry security, and cloud-specific attacks. Both authenticated (with cloud credentials) and unauthenticated (external) modes. Uses nuclei cloud templates, Prowler, ScoutSuite, manual IMDS/metadata probing, and deep AWS/Azure/GCP CLI enumeration. Produces: cloud architecture diagram, attack path map, findings per category, compliance mapping (SOC 2, PCI DSS 4.0, HIPAA, CIS), PoCs for confirmed exploits. Chains into /gh-export for issue filing.
    21
    repo stars
  67. cookie-attacks · shulkwisec
    Audit and attack session cookies via missing Secure/HttpOnly/SameSite attributes, overly broad Domain/Path scope, non-expiring persistent cookies, absent __Host- and __Secure- prefixes, browser cache leakage (Cache-Control: no-store missing), session token predictability via Burp Sequencer analysis, server-side session not invalidated on logout, and SSO single-logout bypass. Tools: Burp Suite Repeater/Sequencer, OWASP ZAP, EditThisCookie, Tamper Data, Cookiebro.
    21
    repo stars
  68. cors-misconfig · shulkwisec
    CORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the `Origin` header in `Access-Control-Allow-Origin` or set it to `*` with `Access-Control-Allow-Credentials: true`. Detect via `Origin: https://attacker.com` reflection in `Access-Control-Allow-Origin` response header, wildcard `*` on credentialed endpoints, and null origin acceptance. Tools: OWASP ZAP, Burp Suite, manual `fetch()` with `credentials: include`.
    21
    repo stars
  69. crlf-injection · shulkwisec
    CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.
    21
    repo stars
  70. email-security · shulkwisec
    Audits email infrastructure security by testing SPF, DKIM, DMARC, open relay, spoofing resilience, MTA-STS, TLS-RPT, and SMTP configuration using standard security tools.
    21
    repo stars
  71. jndi-injection · shulkwisec
    JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especially via Log4j2, Spring, or any code path reaching InitialContext.lookup().
    21
    repo stars
  72. network-assess · shulkwisec
    Internal network assessment. VLAN hopping, ARP spoofing detection, broadcast protocol abuse (LLMNR/NBT-NS/mDNS), network segmentation verification, SNMP enumeration, NFS exposure, router/switch audit, and internal service mapping. Assumes attacker has network access. Uses nmap, arp-scan, nbtscan, snmpwalk, onesixtyone, smbmap, nfs-common, masscan, hping3, and netexec.
    21
    repo stars
  73. oauth-security · shulkwisec
    Deep OAuth 2.0 / OpenID Connect security assessment. Covers the full attack surface: redirect_uri validation bypass (path traversal, open redirect chains, subdomain confusion, URL parsing tricks, parameter pollution, response mode switching), missing/broken state parameter CSRF, PKCE downgrade and absent-challenge attacks, implicit grant token leakage (Referer, browser history, XSS fragment theft), authorization code injection, scope escalation, client confusion attacks, mutable-claims account takeover (iss+sub confusion, email-keyed identity merging), pre-account takeover via unverified registration, OpenID Connect dynamic client registration SSRF (logo_uri, jwks_uri, sector_identifier_uri, request_uri), nonce replay, ID token validation failures, Device Code phishing flow, mobile custom URI scheme hijacking, refresh token persistence, token introspection enumeration, consent screen clickjacking, host header injection, and cross-IdP mix-up attacks. Uses KOAuth, jwt_tool, nuclei oauth templates, and manual ht
    21
    repo stars
  74. path-traversal · shulkwisec
    Exploit path traversal and local/remote file inclusion (LFI/RFI) via URL parameters, cookies, and hidden fields using ../ sequences, URL encoding (%2e%2e%2f), double encoding (%252e%252e%255c), Unicode bypasses (..%c0%af), and Windows UNC paths. PHP include/require with $_GET/$_POST/$_COOKIE pattern. Target /etc/passwd, boot.ini, web.config. Tools: DotDotPwn, WFuzz, Burp Suite, ZAP.
    21
    repo stars
  75. race-condition · shulkwisec
    Race condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turbo Intruder gates, HTTP/2 single-packet attacks, and CWE-362-style synchronization gaps.
    21
    repo stars
  76. shodan-dorking · shulkwisec bundle
    Utilize Shodan, the search engine for Internet-connected devices, to discover exposed assets, vulnerable ports, default credentials, and specific infrastructure configurations using advanced search queries (dorks).
    21
    repo stars
  77. xslt-injection · shulkwisec
    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.
    21
    repo stars
  78. web-cache-deception-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  79. information-disclosure-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  80. mass-assignment · shulkwisec
    Mass Assignment
    21
    repo stars
  81. nosql-injection · shulkwisec
    NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.
    21
    repo stars
  82. threat-modeling · shulkwisec
    Structured threat modeling skill using the PASTA framework (Process for Attack Simulation and Threat Analysis) combined with Adam Shostack's 4-question framework. Use this skill whenever the user asks to do threat modeling, security analysis, map the attack surface, identify threats, or review an application for security risks — even if they don't mention PASTA or a specific framework by name. Core activities: Component Mapping (architecture + data flows), Critical Assessment (business impact prioritization), and Logic Flaw Identification (attacker mindset on business logic). Produces: component map diagram (Mermaid), data flow diagram (Mermaid), attack tree (Mermaid), STRIDE threat table, prioritized risk register, and an actionable mitigation plan. Invoke proactively for any security review, architecture review, or "what could go wrong?" session.
    21
    repo stars
  83. ad-cs-esc1-abuse · shulkwisec bundle
    Exploit Active Directory Certificate Services (AD CS) misconfigurations, specifically ESC1. By requesting a certificate based on a overly permissive template that allows the enrollee to supply a Subject Alternative Name (SAN), an attacker can impersonate highly privileged users (like Domain Admins) and seamlessly escalate privileges across the entire AD environment.
    21
    repo stars
  84. ad-dcsync-attack · shulkwisec bundle
    Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
    21
    repo stars
  85. ad-pass-the-hash · shulkwisec bundle
    Exploit Active Directory environments using Pass-the-Hash (PtH). This skill details how to authenticate to remote systems using the NTLM hash of a user's password instead of the plaintext password, enabling lateral movement and privilege escalation without cracking hashes.
    21
    repo stars
  86. api-testing-deep-dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  87. credential-audit · shulkwisec
    Authentication and credential security assessment. Tests password brute-force, credential stuffing, password spraying, default credential testing, credential harvesting, lockout analysis, MFA bypass, OAuth/OIDC abuse, session token entropy, Kerberos attacks, and intelligent wordlist generation. Uses hydra, john, ncrack, medusa, cewl, crunch, netexec, impacket, kerbrute, and nuclei default-login templates. Covers OWASP A07:2021 Identification and Authentication Failures.
    21
    repo stars
  88. essential-skills-deep-dive · shulkwisec bundle
    PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21
    repo stars
  89. file-access-vuln · shulkwisec
    Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.
    21
    repo stars
  90. lateral-movement · shulkwisec
    Active Directory and network lateral movement assessment. Pass-the-hash, pass-the-ticket, Kerberoasting, AS-REP roasting, NTLM relay, SMB relay, WMI/WinRM/PSRemoting abuse, constrained/unconstrained delegation, RBCD, cross-trust exploitation, and pivoting. Uses impacket, netexec, enum4linux-ng, smbmap, smbclient, bloodhound-python, Responder, ntlmrelayx, mitm6, and ldap-utils. Chains from /post-exploit or /credential-audit.
    21
    repo stars
  91. security-fuzzing · shulkwisec bundle
    Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
    21
    repo stars
  92. session-fixation · shulkwisec
    Detect and exploit session fixation (WSTG-SESS-01, WSTG-SESS-03) and session exposure (WSTG-SESS-04) by testing whether the server issues a new session token post-authentication, whether pre-login tokens remain valid after login, and whether session IDs are transmitted over HTTP or included in GET parameters. Analyze token randomness via Burp Sequencer. Test JSESSIONID, ASP.NET Forms Auth cookies. Tools: OWASP ZAP, Burp Suite Repeater/Sequencer, JHijack.
    21
    repo stars
  93. ai-data-poisoning · shulkwisec bundle
    Execute and analyze AI Data Poisoning attacks. By subtly injecting malicious or targeted misinformation into an LLM's training or fine-tuning dataset, an attacker can covertly manipulate the model's future outputs, implant backdoors, or enforce biases without altering the model architecture.
    21
    repo stars
  94. ai-prompt-leaking · shulkwisec bundle
    Systematically extract hidden system prompts, core directives, and invisible context intentionally concealed within Large Language Model (LLM) applications. This skill utilizes targeted linguistic engineering and boundary manipulation to bypass prompt opacity.
    21
    repo stars
  95. aws-cognito-abuse · shulkwisec bundle
    Exploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege escalation via custom attributes to access broader AWS infrastructure.
    21
    repo stars
  96. aws-metadata-ssrf · shulkwisec bundle
    Exploit SSRF vulnerabilities in AWS EC2-hosted applications to extract IAM credentials and User Data from the Instance Metadata Service, including techniques for bypassing basic filters against IMDSv1.
    21
    repo stars
  97. heap-exploitation · shulkwisec bundle
    Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.
    21
    repo stars
  98. mobile-resilience · shulkwisec
    Detects weak reverse engineering and tampering protections in mobile apps (Android/iOS). Trigger on: root detection bypass, jailbreak detection bypass, Frida detection, debugger detection, anti-debugging, ptrace, sysctl, emulator detection, code obfuscation absent, debug symbols present, get-task-allow, ProGuard disabled, R8 disabled, string encryption, integrity check, file tampering, repackaging, dynamic instrumentation, runtime hook, Magisk hide, Magisk, frida-server, objection bypass, signing verification, apk resign. Covers MASVS-RESILIENCE-1/2/3/4.
    21
    repo stars
  99. process-hollowing · shulkwisec bundle
    Execute advanced evasion by injecting malicious code into the memory space of a legitimate, suspended process (Process Hollowing). This skill details techniques to bypass static and dynamic analysis by masking malicious activity behind trusted processes like svchost.exe or explorer.exe.
    21
    repo stars
  100. request-smuggling · shulkwisec bundle
    HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/1 translation, or when exploring client-side desync via browser fetch pipelines.
    21
    repo stars