Bb Huge
by @shulkwisec · plugin · 100 skills
Bb Huge from ShulkwiSEC/bb-huge.
Install the whole plugin (CLI)
npx skillmds add shulkwisec/bb-huge
npx skillmds add shulkwisec/cross-site-scripting-xss-complete-deep-dive
npx skillmds add shulkwisec/xxe
npx skillmds add shulkwisec/cors-misconfiguration-complete-deep-dive
npx skillmds add shulkwisec/cspt
npx skillmds add shulkwisec/csrf
npx skillmds add shulkwisec/hack
npx skillmds add shulkwisec/ssrf
npx skillmds add shulkwisec/ssti
npx skillmds add shulkwisec/oauth-authentication-deep-dive
npx skillmds add shulkwisec/osint
npx skillmds add shulkwisec/report
npx skillmds add shulkwisec/api-sec
npx skillmds add shulkwisec/dom-xss
npx skillmds add shulkwisec/auth-sec
npx skillmds add shulkwisec/codebase
npx skillmds add shulkwisec/jwt-authentication-complete-deep-dive
npx skillmds add shulkwisec/bola-idor
npx skillmds add shulkwisec/dom-based-vulnerabilities-complete-deep-dive
npx skillmds add shulkwisec/gh-export
npx skillmds add shulkwisec/remediate
npx skillmds add shulkwisec/2fa-multi-factor-bypass
npx skillmds add shulkwisec/ai-redteam
npx skillmds add shulkwisec/colang-gen
npx skillmds add shulkwisec/compliance
npx skillmds add shulkwisec/metasploit
npx skillmds add shulkwisec/param-fuzz
npx skillmds add shulkwisec/websockets-deep-dive
npx skillmds add shulkwisec/xss-stored
npx skillmds add shulkwisec/amend-skill
npx skillmds add shulkwisec/amsi-bypass
npx skillmds add shulkwisec/analyze-cve
npx skillmds add shulkwisec/auth-bypass
npx skillmds add shulkwisec/file-upload-vulnerabilities-deep-dive
npx skillmds add shulkwisec/http-host-header-attacks-deep-dive
npx skillmds add shulkwisec/web-llm-attacks-deep-dive
npx skillmds add shulkwisec/llm-testing
npx skillmds add shulkwisec/pwn-request
npx skillmds add shulkwisec/web-exploit
npx skillmds add shulkwisec/api-security
npx skillmds add shulkwisec/authz-bypass
npx skillmds add shulkwisec/clickjacking
npx skillmds add shulkwisec/graphql-idor
npx skillmds add shulkwisec/graphql-api-deep-dive
npx skillmds add shulkwisec/post-exploit
npx skillmds add shulkwisec/request-cves
npx skillmds add shulkwisec/ad-assessment
npx skillmds add shulkwisec/aikido-triage
npx skillmds add shulkwisec/cmd-injection
npx skillmds add shulkwisec/distill-skill
npx skillmds add shulkwisec/dom-based-xss
npx skillmds add shulkwisec/jwt-misconfig
npx skillmds add shulkwisec/observe-skill
npx skillmds add shulkwisec/open-redirect
npx skillmds add shulkwisec/recon-for-sec
npx skillmds add shulkwisec/reverse-shell
npx skillmds add shulkwisec/sql-injection
npx skillmds add shulkwisec/ssl-tls-audit
npx skillmds add shulkwisec/type-juggling
npx skillmds add shulkwisec/wmi-execution
npx skillmds add shulkwisec/xss-reflected
npx skillmds add shulkwisec/access-control-complete-deep-dive
npx skillmds add shulkwisec/ai-ml-security
npx skillmds add shulkwisec/authentication-complete-deep-dive
npx skillmds add shulkwisec/business-logic
npx skillmds add shulkwisec/cloud-security
npx skillmds add shulkwisec/cookie-attacks
npx skillmds add shulkwisec/cors-misconfig
npx skillmds add shulkwisec/crlf-injection
npx skillmds add shulkwisec/email-security
npx skillmds add shulkwisec/jndi-injection
npx skillmds add shulkwisec/network-assess
npx skillmds add shulkwisec/oauth-security
npx skillmds add shulkwisec/path-traversal
npx skillmds add shulkwisec/race-condition
npx skillmds add shulkwisec/shodan-dorking
npx skillmds add shulkwisec/xslt-injection
npx skillmds add shulkwisec/web-cache-deception-deep-dive
npx skillmds add shulkwisec/information-disclosure-deep-dive
npx skillmds add shulkwisec/mass-assignment
npx skillmds add shulkwisec/nosql-injection
npx skillmds add shulkwisec/threat-modeling
npx skillmds add shulkwisec/ad-cs-esc1-abuse
npx skillmds add shulkwisec/ad-dcsync-attack
npx skillmds add shulkwisec/ad-pass-the-hash
npx skillmds add shulkwisec/api-testing-deep-dive
npx skillmds add shulkwisec/credential-audit
npx skillmds add shulkwisec/essential-skills-deep-dive
npx skillmds add shulkwisec/file-access-vuln
npx skillmds add shulkwisec/lateral-movement
npx skillmds add shulkwisec/security-fuzzing
npx skillmds add shulkwisec/session-fixation
npx skillmds add shulkwisec/ai-data-poisoning
npx skillmds add shulkwisec/ai-prompt-leaking
npx skillmds add shulkwisec/aws-cognito-abuse
npx skillmds add shulkwisec/aws-metadata-ssrf
npx skillmds add shulkwisec/heap-exploitation
npx skillmds add shulkwisec/mobile-resilience
npx skillmds add shulkwisec/process-hollowing
npx skillmds add shulkwisec/request-smugglingSkills in this plugin
- ▌ bb-huge · shulkwisec bundleInitializes bug bounty hunt workspaces, logs vulnerability findings with severity and evidence, and enriches them throughout a session.
- ▌ cross-site-scripting-xss-complete-deep-dive · shulkwisec bundleProvides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
- ▌ xxe · shulkwisecDetect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
- ▌ cors-misconfiguration-complete-deep-dive · shulkwisec bundleProvides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
- ▌ cspt · shulkwisecHunt Client-Side Path Traversal vulnerabilities where attacker-controlled input is concatenated into the path of a fetch() or XHR request, enabling redirection and chaining to XSS or data exfiltration.
- ▌ csrf · shulkwisecDetect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
- ▌ hack · shulkwisecRoutes security testing tasks to the correct vulnerability category, guiding recon, validation, privilege escalation, and chain building for web application and API security assessments.
- ▌ ssrf · shulkwisecDetect and exploit Server-Side Request Forgery vulnerabilities by identifying user-controlled URL parameters, testing for internal service access, cloud metadata endpoints, and file scheme reads, with bypass techniques for common filters.
- ▌ ssti · shulkwisecDetect and exploit Server-Side Template Injection vulnerabilities across multiple template engines including Jinja2, Twig, Freemarker, and Velocity, with payloads for sandbox escape and remote code execution. Includes detection methodology, bypass techniques, and fix patterns.
- ▌ oauth-authentication-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ osint · shulkwisecConduct passive OSINT reconnaissance on target organizations using a MITRE ATT&CK framework. Discovers employees, email patterns, subdomains, infrastructure, leaked credentials, and cloud assets with confidence-scored findings.
- ▌ report · shulkwisec bundleGenerate a NullPointer Studio styled PDF penetration test report from findings.json, producing a professional dark-themed PDF with executive summary, risk dashboard, per-finding cards, and remediation summary.
- ▌ api-sec · shulkwisecRoutes API security testing into recon, authorization, token abuse, or hidden-parameter workflows based on observed endpoint characteristics.
- ▌ dom-xss · shulkwisecDetect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
- ▌ auth-sec · shulkwisecRoutes authentication and authorization testing efforts by identifying the primary attack surface — login mechanics, object authorization, browser trust boundaries, or identity protocols such as JWT/OAuth/SAML — before selecting a deeper skill.
- ▌ codebase · shulkwisec bundlePerforms a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
- ▌ jwt-authentication-complete-deep-dive · shulkwisec bundleProvides exact payloads and bypass techniques for every PortSwigger JWT authentication lab variant, from unverified signatures to algorithm confusion attacks.
- ▌ bola-idor · shulkwisecDetect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
- ▌ dom-based-vulnerabilities-complete-deep-dive · shulkwisec bundleProvides exact payloads and bypass techniques for every PortSwigger DOM-based vulnerability lab variant, including zero-day extensions and blue team detection strategies.
- ▌ gh-export · shulkwisecFormats all confirmed pentest findings from findings.json into copy-pasteable GitHub issue markdown blocks, following the AppSec reporting guide template.
- ▌ remediate · shulkwisecGenerates specific, implementable fixes for each vulnerability finding, producing code patches, configuration changes, dependency updates, and IaC fixes with before/after code and verification steps.
- ▌ 2fa-multi-factor-bypass · shulkwisec bundleExploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.
- ▌ ai-redteam · shulkwisec bundleAI/LLM red-team assessment using the OWASP LLM Top 10 (2025) + OWASP AI Testing Guide (AITG v1, Nov 2025) frameworks, plus OWASP MCP Top 10 runtime testing for agentic/MCP targets. Tests prompt injection, jailbreaks, system prompt leakage, sensitive data extraction, excessive agency, improper output handling, model extraction, content bias, evasion, membership inference, MCP token exposure, MCP command injection, and more. Uses four tools in combination: FuzzyAI (single-turn jailbreak fuzzing), PyRIT (multi-turn orchestrated attacks), Garak (probe-based vulnerability scanning), and promptfoo (plugin-based red-team evaluation). Each tool covers different OWASP categories; running them together gives systematic coverage. Includes a conditional MCP reconnaissance phase and a post-access AI infrastructure phase (chained from /post-exploit). Produces: OWASP LLM Top 10 + AITG + MCP coverage matrix, findings per category, architecture diagram of the AI system, PoCs for confirmed exploits. Chains into /gh-export for
- ▌ colang-gen · shulkwisec bundleGenerates NeMo Guardrails Colang (.co) files and YAML config blocks from a plain-language description of a chatbot's purpose, allowed behaviors, and constraints. Use this skill whenever a user wants to build guardrails for a chatbot, define allowed intents for an LLM, create an AI firewall with NeMo Guardrails, generate Colang flow definitions, or configure a semantic allow-list for a bot. Trigger this skill even when the user just describes what their bot should and shouldn't do — generating the Colang and YAML is almost always what they need next.
- ▌ compliance · shulkwisec bundleFull ASVS 5.0 compliance assessment against a codebase and/or architecture diagrams. Reads all 346 controls from the companion CSV, performs targeted code analysis per control, and produces a complete matrix marked COMPLIANT / NON_COMPLIANT / NOT_RELEVANT — with per-control reasoning and evidence (code snippets, file:line references, diagram observations). Outputs a reviewed CSV matrix and a self-contained HTML evidence report.
- ▌ metasploit · shulkwisecExploit validation and exploitation using Metasploit Framework. Runs in a dedicated Docker container (separate from Kali). Validates CVEs discovered by nuclei, nikto, or other scanners with actual exploit modules. Covers exploit selection, payload configuration, exploitation, and post-exploitation pivoting. Uses msfconsole, msfvenom, and the Metasploit module database. Chains from /pentester, /analyze-cve, or /post-exploit when exploitable CVEs are confirmed.
- ▌ param-fuzz · shulkwisecSystematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
- ▌ websockets-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ xss-stored · shulkwisecStored XSS (persistent XSS) occurs when attacker-supplied input is saved server-side and later rendered unencoded to other users. Common injection points include profile fields, comments, forum posts, file upload filenames, and application logs. Detect via PHP `$_GET/$_POST/$_REQUEST/$_FILES`, ASP `Request.Form`, JSP `request.getParameter`, and BeEF hook injection. Tools: Burp Suite, OWASP ZAP, BeEF, PHP Charset Encoder, Hackvertor.
- ▌ amend-skill · shulkwisecInspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill. Trigger on: "improve this skill", "fix this skill", "update this skill", "why does X keep failing", "this skill is wrong", "add this to the skill", or automatically when observations/<skill-name>/runs.md contains 3 or more failure entries. Outputs the amendment as a diff the user can review before applying. Records the amendment rationale in observations/<skill-name>/runs.md after user confirmation.
- ▌ amsi-bypass · shulkwisec bundleBypass the Windows Antimalware Scan Interface (AMSI) using memory patching, reflection, and obfuscation techniques. Execute undetected PowerShell, VBScript, JScript, and .NET assemblies in-memory without triggering Microsoft Defender or third-party AV/EDR solutions. Use this skill during Red Team engagements when loading offensive tools (Mimikatz, Rubeus, SharpHound) in memory on defended Windows endpoints.
- ▌
- ▌ auth-bypass · shulkwisecBypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from linear/incremental cookies, SQL injection on login forms, PHP unserialize() boolean type juggling (b:1 payload), and credential transport over HTTP. Detectable with Burp Suite, OWASP ZAP, WebGoat.
- ▌ file-upload-vulnerabilities-deep-dive · shulkwisec bundleExploits file upload vulnerabilities across PortSwigger lab variants with exact payloads, bypass techniques, and zero-day escalation methods.
- ▌ http-host-header-attacks-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ web-llm-attacks-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ llm-testing · shulkwisec bundleComprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
- ▌ pwn-request · shulkwisecUse when hunting Pwn Request vulnerabilities where pull_request_target workflows checkout attacker-controlled PR code and execute it in a privileged context with access to repository secrets. Trigger on: "pwn request", "pull_request_target", "checkout PR head", "npm install in CI", "lifecycle scripts in CI", "preinstall script", "postinstall script", "package.json scripts CI", "npm ci ignore-scripts false", "actions/checkout ref pull request head sha", privileged workflow running PR code, "Gato-X", supply chain via PR lifecycle scripts.
- ▌ web-exploit · shulkwisec bundleDeep web exploitation beyond initial scanning. Covers SQLi (blind, OOB, second-order), NoSQL injection (MongoDB, operator bypass), GraphQL injection (introspection, batching, mutation abuse), XSS (reflected/stored/DOM with full source-sink analysis), SSTI (Jinja2/Twig/Freemarker/ERB engine identification and RCE), SSRF chains, file upload bypass (polyglot creation), XXE (blind, DOCX/SVG injection, Content-Type switching), deserialization (Java/PHP/Python/.NET), command injection, path traversal (LFI wrapper bypasses), race conditions, CSRF, JWT attacks (none/key confusion/kid injection), HTTP request smuggling (CL.TE/TE.CL/H2), CRLF injection, open redirect bypass chains, CORS exploitation, web cache deception/poisoning, OAuth misconfiguration, prototype pollution, session management, and business logic flaws. Uses sqlmap (advanced modes), commix, xsser, wapiti, davtest, and manual http(action="request", ...) payloads. Every technique includes actual payloads, commands, and code snippets for immediate use. Ch
- ▌ api-security · shulkwisecDeep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function Level Authorization (BFLA / vertical privilege escalation), Unrestricted Access to Sensitive Business Flows, Server-Side Request Forgery via API parameters, Security Misconfiguration, Improper Inventory Management (shadow/zombie/deprecated endpoints, v1/v2 drift), and Unsafe Consumption of third-party APIs. Works across REST, GraphQL, gRPC, SOAP, and MCP servers. Discovers APIs from OpenAPI/Swagger specs, GraphQL introspection, gRPC reflection, .well-known endpoints, JS bundles, and traffic capture. Uses kiterunner, ffuf, schemathesis, restler-fuzzer, openapi-fuzzer, graphql-cop, clairvoyance, batchql, inql, jwt_tool, postman, mitmproxy, and manual http(action="request", ...) payloads. Every techniqu
- ▌ authz-bypass · shulkwisecTest horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=, EventID=), and special header injection (X-Original-URL, X-Rewrite-URL, X-Forwarded-For, X-Remote-IP, X-Client-IP with 127.0.0.1/localhost/RFC1918 values). Tools: Burp Suite with Autorize/AuthMatrix extensions, OWASP ZAP Access Control Testing add-on.
- ▌ clickjacking · shulkwisecClickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.
- ▌ graphql-idor · shulkwisec bundleIdentify and exploit Insecure Direct Object Reference (IDOR) or Broken Object Level Authorization (BOLA) vulnerabilities specifically within GraphQL APIs. This skill focuses on manipulating node IDs, changing variables, and utilizing aliases to access unauthorized data.
- ▌ graphql-api-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ post-exploit · shulkwisecPost-exploitation workflow. Covers privilege escalation (Linux SUID/sudo/kernel, Windows UAC/service/token), persistence assessment, local enumeration, credential harvesting, and pivot preparation. Structured workflows for Linux and Windows targets using impacket, netexec, john, linpeas/winpeas, and standard Kali tools. Includes kernel exploit reference tables, GTFOBins exploitation chains, Potato attack selection, Docker/container escapes, DLL hijacking, SSH key harvesting, credential recovery from memory, and Windows token manipulation. Chains from /pentester or /credential-audit when access is obtained.
- ▌ request-cves · shulkwisecGenerates CVE request packages from pentest findings. Reads cve-candidates.json (auto-generated at pentest completion) or findings.json directly, then produces for each qualifying vulnerability: MITRE CVE form data, GitHub Security Advisory draft, full disclosure report, and vendor notification email. Invoke manually after a pentest engagement when you have true-positive findings that warrant CVE IDs.
- ▌ ad-assessment · shulkwisecActive Directory security audit using the MITRE ATT&CK framework. Full domain enumeration, trust mapping, GPO analysis, ACL abuse paths, ADCS attacks (ESC1-ESC8), delegation abuse (constrained/unconstrained/RBCD), fine-grained password policies, LAPS deployment, service account security, and Kerberos configuration. Uses enum4linux-ng, netexec, impacket, ldapsearch, certipy-ad, bloodhound-python, and rpcclient. Produces attack path diagrams, prioritized risk register, and PoCs. Chains into /gh-export for issue filing.
- ▌
- ▌ cmd-injection · shulkwisecOS command injection occurs when user input is passed unsanitized to a system shell via dangerous APIs: Java `Runtime.exec()`, Python `os.system/subprocess`, PHP `system/shell_exec/exec/proc_open`, C `system/exec`. Detect via pipe `|`, semicolon `;`, `&&`, `||`, backtick, `$()` operators, and time-delay payloads (`sleep 5`). Tools: Commix, Burp Suite, OWASP WebGoat.
- ▌ distill-skill · shulkwisecUse when the user wants to extract reusable offensive security knowledge from any source and generate a SKILL.md file. Trigger on: "distill this", "extract skill from", "turn this into a skill", "generate skill from", "convert this report/blog/book/walkthrough into a skill", or when the user pastes raw security content (bug report, pentest report, CTF writeup, blog post, ezine, book chapter) and wants it transformed into structured hunting methodology.
- ▌ dom-based-xss · shulkwisec bundleExploit Document Object Model (DOM) Based Cross-Site Scripting (XSS) vulnerabilities. Unlike Reflected or Stored XSS, the attack payload is executed purely on the client-side as a result of modifying the DOM environment, often without the payload ever reaching the backend server.
- ▌
- ▌ observe-skill · shulkwisecLogs the outcome of a skill execution to observations/<skill-name>/runs.md. Trigger on: "log this run", "skill worked", "skill failed", "this didn't work", "log the outcome", "record this", "note that", or after any skill completes with a clear success, partial, or failure outcome. Creates the observations file if it does not exist, then appends an entry with date, task description, skill used, outcome, what worked, what failed, and any error messages observed.
- ▌ open-redirect · shulkwisecOpen redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
- ▌ recon-for-sec · shulkwisecEntry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.
- ▌ reverse-shell · shulkwisecReverse shell generation and listener management. Generates platform-specific reverse shell payloads (bash, python, php, powershell, java, ruby, perl, netcat, socat, msfvenom) and sets up listeners in the Kali container. Supports one-liner generation, encoded payloads for WAF/filter bypass, listener setup with session capture, and shell stabilization. Chains from /pentester, /metasploit, or /post-exploit when command execution is confirmed.
- ▌ sql-injection · shulkwisecSQL injection occurs when untrusted user input is interpolated directly into database queries, allowing attackers to alter query logic. Detect via single-quote errors, boolean-based blind responses (AND 1=1 vs AND 1=2), time-delay payloads (SLEEP, WAITFOR), UNION column enumeration, and error messages from MySQL, Oracle, MSSQL, PostgreSQL. Tools: sqlmap, sqlbftools, Burp Suite, wfuzz with SQLi fuzz strings.
- ▌ ssl-tls-audit · shulkwisecTLS/SSL configuration audit. Tests protocol versions (SSLv2/3, TLS 1.0/1.1/1.2/1.3), cipher strength and ordering, certificate chain validation (intermediates, CT logs, OCSP stapling, pinning), known vulnerabilities (POODLE, BEAST, CRIME, Heartbleed, ROBOT, DROWN, Ticketbleed, GOLDENDOODLE), session management (ticket reuse, resumption, fixation), renegotiation attacks, TLS 1.3-specific issues (0-RTT replay, PSK modes, downgrade), HSTS deep analysis (preload, subdomains, bypass), and certificate revocation (CRL, OCSP responder, stapled response freshness). Compliance-mapped to PCI DSS 4.0 (full Section 4), NIST SP 800-52r2, and FedRAMP. Uses testssl.sh, sslscan, sslyze, openssl, nmap NSE scripts, and nuclei SSL templates. Multi-port scanning across 20+ TLS-bearing services.
- ▌ type-juggling · shulkwisecPHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
- ▌ wmi-execution · shulkwisec bundleUtilize Windows Management Instrumentation (WMI) to execute malicious payloads, establish lateral movement, and execute commands stealthily across an Active Directory environment without dropping binaries to disk or relying on traditional Service Creation (PsExec) mechanics.
- ▌ xss-reflected · shulkwisecReflected XSS occurs when user-supplied input is echoed in an HTTP response without sanitization, allowing script execution in the victim's browser. Detect via injecting `<script>alert(1)</script>`, event handlers like `onfocus`, HTML entity bypass, and encoding variants. Tools: Burp Suite, OWASP ZAP, PHP Charset Encoder (PCE), Hackvertor, XSS-Proxy, ratproxy.
- ▌ access-control-complete-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ ai-ml-security · shulkwisecAI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.
- ▌ authentication-complete-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ business-logic · shulkwisecApplication-level business logic security testing for any domain. Takes an understanding-first approach: map the intended workflows before probing them. Covers: value/quantity logic abuse (negative, zero, overflow, rounding on any numeric field), workflow and state machine bypass (skipping required steps, forcing illegal state transitions, reusing one-time tokens), trust boundary violations (BOLA horizontal/vertical, BFLA, cross-tenant access, negative ownership attacks), idempotency and replay attacks (duplicate submissions, double-spend, same-reference reuse), multi-step flow integrity (checkout, registration, approval, verification), quota and rate limit bypass, time/date manipulation, and authorization code / reference number predictability. Domain-agnostic — applies to SaaS, e-commerce, banking, gaming, social platforms, APIs, or any multi-user application with stateful workflows. Chains from /pentester; chains into /param-fuzz when boundary violations or mass assignment are confirmed.
- ▌ cloud-security · shulkwisecCloud security posture assessment for AWS, Azure, and GCP. Tests IAM privilege escalation paths, public storage exposure, serverless attack surface, database exposure, logging gaps, container registry security, and cloud-specific attacks. Both authenticated (with cloud credentials) and unauthenticated (external) modes. Uses nuclei cloud templates, Prowler, ScoutSuite, manual IMDS/metadata probing, and deep AWS/Azure/GCP CLI enumeration. Produces: cloud architecture diagram, attack path map, findings per category, compliance mapping (SOC 2, PCI DSS 4.0, HIPAA, CIS), PoCs for confirmed exploits. Chains into /gh-export for issue filing.
- ▌ cookie-attacks · shulkwisecAudit and attack session cookies via missing Secure/HttpOnly/SameSite attributes, overly broad Domain/Path scope, non-expiring persistent cookies, absent __Host- and __Secure- prefixes, browser cache leakage (Cache-Control: no-store missing), session token predictability via Burp Sequencer analysis, server-side session not invalidated on logout, and SSO single-logout bypass. Tools: Burp Suite Repeater/Sequencer, OWASP ZAP, EditThisCookie, Tamper Data, Cookiebro.
- ▌ cors-misconfig · shulkwisecCORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the `Origin` header in `Access-Control-Allow-Origin` or set it to `*` with `Access-Control-Allow-Credentials: true`. Detect via `Origin: https://attacker.com` reflection in `Access-Control-Allow-Origin` response header, wildcard `*` on credentialed endpoints, and null origin acceptance. Tools: OWASP ZAP, Burp Suite, manual `fetch()` with `credentials: include`.
- ▌ crlf-injection · shulkwisecCRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.
- ▌ email-security · shulkwisecAudits email infrastructure security by testing SPF, DKIM, DMARC, open relay, spoofing resilience, MTA-STS, TLS-RPT, and SMTP configuration using standard security tools.
- ▌ jndi-injection · shulkwisecJNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especially via Log4j2, Spring, or any code path reaching InitialContext.lookup().
- ▌ network-assess · shulkwisecInternal network assessment. VLAN hopping, ARP spoofing detection, broadcast protocol abuse (LLMNR/NBT-NS/mDNS), network segmentation verification, SNMP enumeration, NFS exposure, router/switch audit, and internal service mapping. Assumes attacker has network access. Uses nmap, arp-scan, nbtscan, snmpwalk, onesixtyone, smbmap, nfs-common, masscan, hping3, and netexec.
- ▌ oauth-security · shulkwisecDeep OAuth 2.0 / OpenID Connect security assessment. Covers the full attack surface: redirect_uri validation bypass (path traversal, open redirect chains, subdomain confusion, URL parsing tricks, parameter pollution, response mode switching), missing/broken state parameter CSRF, PKCE downgrade and absent-challenge attacks, implicit grant token leakage (Referer, browser history, XSS fragment theft), authorization code injection, scope escalation, client confusion attacks, mutable-claims account takeover (iss+sub confusion, email-keyed identity merging), pre-account takeover via unverified registration, OpenID Connect dynamic client registration SSRF (logo_uri, jwks_uri, sector_identifier_uri, request_uri), nonce replay, ID token validation failures, Device Code phishing flow, mobile custom URI scheme hijacking, refresh token persistence, token introspection enumeration, consent screen clickjacking, host header injection, and cross-IdP mix-up attacks. Uses KOAuth, jwt_tool, nuclei oauth templates, and manual ht
- ▌ path-traversal · shulkwisecExploit path traversal and local/remote file inclusion (LFI/RFI) via URL parameters, cookies, and hidden fields using ../ sequences, URL encoding (%2e%2e%2f), double encoding (%252e%252e%255c), Unicode bypasses (..%c0%af), and Windows UNC paths. PHP include/require with $_GET/$_POST/$_COOKIE pattern. Target /etc/passwd, boot.ini, web.config. Tools: DotDotPwn, WFuzz, Burp Suite, ZAP.
- ▌ race-condition · shulkwisecRace condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turbo Intruder gates, HTTP/2 single-packet attacks, and CWE-362-style synchronization gaps.
- ▌ shodan-dorking · shulkwisec bundleUtilize Shodan, the search engine for Internet-connected devices, to discover exposed assets, vulnerable ports, default credentials, and specific infrastructure configurations using advanced search queries (dorks).
- ▌ xslt-injection · shulkwisecXSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.
- ▌ web-cache-deception-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ information-disclosure-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌
- ▌ nosql-injection · shulkwisecNoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.
- ▌ threat-modeling · shulkwisecStructured threat modeling skill using the PASTA framework (Process for Attack Simulation and Threat Analysis) combined with Adam Shostack's 4-question framework. Use this skill whenever the user asks to do threat modeling, security analysis, map the attack surface, identify threats, or review an application for security risks — even if they don't mention PASTA or a specific framework by name. Core activities: Component Mapping (architecture + data flows), Critical Assessment (business impact prioritization), and Logic Flaw Identification (attacker mindset on business logic). Produces: component map diagram (Mermaid), data flow diagram (Mermaid), attack tree (Mermaid), STRIDE threat table, prioritized risk register, and an actionable mitigation plan. Invoke proactively for any security review, architecture review, or "what could go wrong?" session.
- ▌ ad-cs-esc1-abuse · shulkwisec bundleExploit Active Directory Certificate Services (AD CS) misconfigurations, specifically ESC1. By requesting a certificate based on a overly permissive template that allows the enrollee to supply a Subject Alternative Name (SAN), an attacker can impersonate highly privileged users (like Domain Admins) and seamlessly escalate privileges across the entire AD environment.
- ▌ ad-dcsync-attack · shulkwisec bundleExploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
- ▌ ad-pass-the-hash · shulkwisec bundleExploit Active Directory environments using Pass-the-Hash (PtH). This skill details how to authenticate to remote systems using the NTLM hash of a user's password instead of the plaintext password, enabling lateral movement and privilege escalation without cracking hashes.
- ▌ api-testing-deep-dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ credential-audit · shulkwisecAuthentication and credential security assessment. Tests password brute-force, credential stuffing, password spraying, default credential testing, credential harvesting, lockout analysis, MFA bypass, OAuth/OIDC abuse, session token entropy, Kerberos attacks, and intelligent wordlist generation. Uses hydra, john, ncrack, medusa, cewl, crunch, netexec, impacket, kerbrute, and nuclei default-login templates. Covers OWASP A07:2021 Identification and Authentication Failures.
- ▌ essential-skills-deep-dive · shulkwisec bundlePortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ file-access-vuln · shulkwisecEntry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.
- ▌ lateral-movement · shulkwisecActive Directory and network lateral movement assessment. Pass-the-hash, pass-the-ticket, Kerberoasting, AS-REP roasting, NTLM relay, SMB relay, WMI/WinRM/PSRemoting abuse, constrained/unconstrained delegation, RBCD, cross-trust exploitation, and pivoting. Uses impacket, netexec, enum4linux-ng, smbmap, smbclient, bloodhound-python, Responder, ntlmrelayx, mitm6, and ldap-utils. Chains from /post-exploit or /credential-audit.
- ▌ security-fuzzing · shulkwisec bundleEssential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
- ▌ session-fixation · shulkwisecDetect and exploit session fixation (WSTG-SESS-01, WSTG-SESS-03) and session exposure (WSTG-SESS-04) by testing whether the server issues a new session token post-authentication, whether pre-login tokens remain valid after login, and whether session IDs are transmitted over HTTP or included in GET parameters. Analyze token randomness via Burp Sequencer. Test JSESSIONID, ASP.NET Forms Auth cookies. Tools: OWASP ZAP, Burp Suite Repeater/Sequencer, JHijack.
- ▌ ai-data-poisoning · shulkwisec bundleExecute and analyze AI Data Poisoning attacks. By subtly injecting malicious or targeted misinformation into an LLM's training or fine-tuning dataset, an attacker can covertly manipulate the model's future outputs, implant backdoors, or enforce biases without altering the model architecture.
- ▌ ai-prompt-leaking · shulkwisec bundleSystematically extract hidden system prompts, core directives, and invisible context intentionally concealed within Large Language Model (LLM) applications. This skill utilizes targeted linguistic engineering and boundary manipulation to bypass prompt opacity.
- ▌ aws-cognito-abuse · shulkwisec bundleExploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege escalation via custom attributes to access broader AWS infrastructure.
- ▌ aws-metadata-ssrf · shulkwisec bundleExploit SSRF vulnerabilities in AWS EC2-hosted applications to extract IAM credentials and User Data from the Instance Metadata Service, including techniques for bypassing basic filters against IMDSv1.
- ▌ heap-exploitation · shulkwisec bundleHeap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.
- ▌ mobile-resilience · shulkwisecDetects weak reverse engineering and tampering protections in mobile apps (Android/iOS). Trigger on: root detection bypass, jailbreak detection bypass, Frida detection, debugger detection, anti-debugging, ptrace, sysctl, emulator detection, code obfuscation absent, debug symbols present, get-task-allow, ProGuard disabled, R8 disabled, string encryption, integrity check, file tampering, repackaging, dynamic instrumentation, runtime hook, Magisk hide, Magisk, frida-server, objection bypass, signing verification, apk resign. Covers MASVS-RESILIENCE-1/2/3/4.
- ▌ process-hollowing · shulkwisec bundleExecute advanced evasion by injecting malicious code into the memory space of a legitimate, suspended process (Process Hollowing). This skill details techniques to bypass static and dynamic analysis by masking malicious activity behind trusted processes like svchost.exe or explorer.exe.
- ▌ request-smuggling · shulkwisec bundleHTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/1 translation, or when exploring client-side desync via browser fetch pipelines.