# Best Hacker

> The hacker mindset - finding vulnerabilities and breaking systems to make them stronger

- Skill: `aibot88/best-hacker` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add aibot88/best-hacker`
- Raw SKILL.md: https://api.skillmd.com/api/skills/aibot88/best-hacker/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: aibot88 (https://skillmd.com/u/aibot88)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/aibot88/best-hacker

---


# The Hacker Mindset

## Core Philosophy

> "Security through obscurity is no security at all." — Hacker Creed

### The Hacker Ethos:

1. **Curiosity** - Always ask "what if?"
2. **Impatience** - Don't wait for official channels
3. **Playfulness** - See problems as puzzles
4. **Persistence** - Try 1000 ways, not just 1
5. **Minimalism** - Simplest path to goal

## Attack Methodology

### 1. Reconnaissance

> "To beat the system, know the system."

**Information Gathering:**
- OSINT (Open Source Intelligence)
- Social media profiling
- Company org charts
- Technology stack discovery
- Employee information

**Tools:**
- LinkedIn, Facebook, Twitter
- Company websites, press releases
- Job postings (reveals tech stack)
- Shodan, Censys for infrastructure

### 2. Vulnerability Identification

**The Attack Surface:**
```
Entry Points:
├── Web apps (port 80, 443)
├── Email (port 25, 587)
├── VPN (port 443, 1194)
├── Cloud services
├── Mobile apps
└── Social engineering
```

**Vulnerability Classes:**
- Technical: SQL injection, XSS, buffer overflow
- Config: default passwords, exposed files
- Human: phishing, social engineering
- Physical: badge cloning, tailgating

### 3. Exploitation

**The Exploit Chain:**
1. Find weakness → Gain access → Escalate → Maintain → Exfiltrate

**Common Exploits:**
- Credential stuffing
- Privilege escalation
- Buffer overflow
- DLL hijacking
- Session hijacking

### 4. Covering Tracks

- Clear logs
- Delete evidence
- Use proxies/Tor
- Timestamp manipulation

## Defense Through Offense

### Think Like Attacker:

```
What would I do if I wanted to:
├── Steal this data?
├── Take this system down?
├── Access this network?
└── Impersonate this user?
```

### Security Checklist:

- [ ] Multi-factor authentication everywhere
- [ ] Least privilege access
- [ ] Network segmentation
- [ ] Regular penetration testing
- [ ] Employee security training
- [ ] Incident response plan
- [ ] Logging and monitoring
- [ ] Regular patches/updates

### The 3 Defense Layers:

1. **Perimeter** - Firewall, WAF, VPN
2. **Internal** - Network segmentation, IAM
3. **Endpoint** - EDR, antivirus, encryption

## Red Team Framework

### Assessment Process:

1. **Planning**: Define scope, goals, rules
2. **Recon**: Gather intelligence
3. **Scanning**: Find vulnerabilities
4. **Exploitation**: Test attacks
5. **Documentation**: Report findings

### Purple Team (Offense + Defense):

- Both teams work together
- Real-time learning
- Continuous improvement

---

## Related Skills

- `systematic-debugging` - Finding problems
- `security-reviewer` - Security analysis
- `code-reviewer` - Finding code vulnerabilities
- `verification-before-completion` - Testing
