abelrguezr
- 861 skills
- 0 followers
- 1 week ago last updated
- ▌ Telecom Network Exploitation · abelrguezr bundleTelecom network security assessment and exploitation techniques for GTP, 5G core, and industrial cellular routers. Use this skill whenever the user mentions telecom networks, mobile core protocols (GTP, PFCP, NAS), 5G security testing, SGSN/GGSN/PGW/AMF/SMF exploitation, industrial cellular routers (Milesight UR-series), GRX/IPX roaming backbones, or any mobile network penetration testing. This skill covers reconnaissance, protocol exploitation, covert channels, privilege escalation on network elements, and detection evasion in telecom environments.
- ▌ Posix Cpu Timer Vuln Research · abelrguezr bundleResearch and analyze CVE-2025-38352 (POSIX CPU Timers TOCTOU race). Use this skill whenever investigating Linux kernel timer vulnerabilities, analyzing TOCTOU race conditions, setting up kernel exploitation test environments, or researching privilege escalation primitives involving CPU timers. Make sure to use this skill when the user mentions kernel races, POSIX timers, TOCTOU vulnerabilities, CVE-2025-38352, or wants to set up a safe kernel exploitation lab.
- ▌ Github Leaked Secrets · abelrguezr bundleFind leaked credentials, API keys, and secrets in GitHub repositories using automated scanners and dork searches. Use this skill whenever the user needs to scan repos for exposed secrets, search for leaked credentials in GitHub, perform org-wide secret detection, or investigate potential credential exposure. Trigger for any request involving secret scanning, credential hunting, API key discovery, or GitHub security auditing.
- ▌ Mediatek Carbonara Exploit · abelrguezr bundleMediaTek XFlash Carbonara DA2 hash bypass exploit for firmware analysis and security research. Use this skill whenever analyzing MediaTek device firmware, investigating Download Agent vulnerabilities, performing pre-OS security research, testing for Carbonara/heapb8 vulnerabilities, or working with mtkclient/penumbra tools. Trigger on any mention of MediaTek, XFlash, DA1, DA2, Download Agent, preloader, firmware security, or boot exploit analysis.
- ▌ Macos Mdm Enrollment Research · abelrguezr bundleSecurity research skill for understanding and testing macOS MDM/DEP enrollment vulnerabilities. Use this skill when investigating MDM security, analyzing DEP enrollment processes, researching mobile device management attack surfaces, or conducting authorized penetration testing on macOS device enrollment systems. This skill covers binary instrumentation techniques, DEP profile analysis, and MDM security assessment methodologies.
- ▌ Csp Bypass Research · abelrguezr bundleContent Security Policy (CSP) bypass research and testing for security assessments. Use this skill when analyzing CSP configurations, testing bypass techniques for authorized security assessments, or researching CSP vulnerabilities. Trigger when users mention CSP, Content-Security-Policy, CSP bypass, security policy testing, web security assessments involving CSP, or need to understand CSP bypass vectors for defensive purposes.
- ▌ Postgresql Large Object Upload · abelrguezr bundleUpload binary files to PostgreSQL using large objects (pg_largeobject). Use this skill whenever you need to store files in PostgreSQL, exfiltrate data via SQL injection, upload malware payloads, or work with pg_largeobject, lo_creat, lo_import, lo_export functions. Trigger for any PostgreSQL file upload task, binary data storage, or when dealing with SQL injection scenarios requiring file operations.
- ▌ Postgresql Dblink Lo Import Exfiltration · abelrguezr bundlePostgreSQL data exfiltration using dblink and lo_import functions. Use this skill whenever the user needs to extract data from a PostgreSQL database through SQL injection, mentions dblink, lo_import, file exfiltration, database data extraction, CTF challenges involving PostgreSQL, or any scenario where they need to bypass database restrictions to read files or export data. This is for authorized security testing and CTF challenges only.
- ▌ Ad External Forest Trust · abelrguezr bundleActive Directory external forest trust exploitation methodology. Use this skill whenever the user mentions forest trusts, cross-domain access, AD trust enumeration, SID history abuse, RBCD across forests, inter-realm TGT/TGS, or any scenario involving multiple Active Directory domains with trust relationships. Trigger for trust-based lateral movement, cross-forest privilege escalation, or when analyzing trust configurations for security assessments.
- ▌ Resource Based Constrained Delegation · abelrguezr bundleExecute Resource-based Constrained Delegation (RBCD) attacks in Active Directory environments. Use this skill whenever the user needs to exploit write permissions on computer accounts to gain privileged access, perform S4U attacks, enumerate RBCD configurations, or troubleshoot Kerberos delegation issues. Trigger this skill for any AD Kerberos delegation task, machine account manipulation, or when the user mentions RBCD, msDS-AllowedToActOnBehalfOfOtherIdentity, S4U2Self, S4U2Proxy, or constrained delegation abuse.
- ▌ Windows Kernel Token Theft Analysis · abelrguezr bundleAnalyze and explain Windows kernel privilege escalation via token theft when arbitrary kernel R/W primitives are available. Use this skill when investigating kernel vulnerabilities, reviewing exploit code, understanding EPROCESS token manipulation, or developing defensive controls against token theft attacks. Trigger for any questions about Windows kernel exploitation, EPROCESS structures, token stealing techniques, or kernel vulnerability analysis.
- ▌ Windows Named Pipe Impersonation · abelrguezr bundleWindows local privilege escalation via named pipe client impersonation. Use this skill whenever the user mentions privilege escalation, named pipes, ImpersonateNamedPipeClient, Potato attacks, PrintSpoofer, RoguePotato, JuicyPotato, EFSRPC, or wants to escalate from a privileged user to SYSTEM on Windows. This skill helps generate exploit code, identify coercion triggers, and troubleshoot impersonation issues.
- ▌ IOS Custom Uri Handlers Pentest · abelrguezr bundleiOS security testing for custom URI handlers, deeplinks, and custom schemes. Use this skill whenever testing iOS apps for URL scheme vulnerabilities, deeplink security, custom protocol handling, Info.plist URL configuration, or inter-app communication attacks. Trigger this skill for any iOS pentest involving URL schemes, canOpenURL, LSApplicationQueriesSchemes, URL hijacking, OAuth token theft via custom schemes, or Frida-based URL fuzzing.
- ▌ Wasm Memory Corruption Xss · abelrguezr bundleExploit WebAssembly linear memory corruption to bypass XSS filters and achieve DOM XSS. Use this skill whenever the user mentions WebAssembly, WASM, Emscripten, linear memory corruption, memory overflow, heap corruption, XSS bypass, or any scenario where a web app uses WASM modules and sanitization might be bypassed through memory manipulation. This is especially relevant when investigating Emscripten-compiled applications with user-controlled data that gets rendered to the DOM.
- ▌ Badsuccessor Ad Dmsa Attack · abelrguezr bundleGuide for testing the BadSuccessor vulnerability in Active Directory Delegated Managed Service Accounts (dMSAs). Use this skill when assessing Windows Server 2025 environments for dMSA privilege escalation risks, when you need to understand the msDS-ManagedAccountPrecededByLink attack vector, or when performing authorized penetration testing on AD infrastructure with dMSA objects. This skill covers reconnaissance, exploitation methodology, and credential extraction techniques for the BadSuccessor attack.
- ▌ Ad Cs Persistence · abelrguezr bundleActive Directory Certificate Services (AD CS) domain persistence techniques for authorized security testing. Use this skill whenever the user needs to maintain long-term access to a compromised Active Directory environment through certificate-based methods. This includes golden certificates, rogue CA trust, malicious misconfigurations, and certificate renewal abuse. Trigger this skill for any AD CS persistence scenario, certificate forgery, NTAuth manipulation, or when the user mentions maintaining access after initial compromise, especially in environments with certificate-based authentication.
- ▌ Windows Uac Bypass · abelrguezr bundleWindows UAC bypass and privilege escalation techniques. Use this skill whenever the user needs to bypass User Account Control on Windows, check UAC status, understand UAC policies, or escalate from medium to high integrity. Trigger on mentions of UAC, elevation, admin approval mode, fodhelper, token duplication, or any Windows privilege escalation scenario where the user is in the Administrators group but needs higher privileges.
- ▌ Powershell Pentesting · abelrguezr bundleWindows PowerShell commands and techniques for penetration testing, reconnaissance, and post-exploitation. Use this skill whenever the user needs to perform Windows system enumeration, execute remote payloads, bypass AMSI/Defender, enumerate users/groups, check network configurations, handle credentials, or any other Windows pentesting task involving PowerShell. Trigger for any Windows security assessment, red team operation, or post-exploitation scenario.
- ▌ Windows Potato Priv Esc · abelrguezr bundleWindows local privilege escalation using Potato-family tools (RoguePotato, PrintSpoofer, GodPotato, SigmaPotato, DeadPotato, etc.) to escalate from SeImpersonatePrivilege to NT AUTHORITY\SYSTEM. Use this skill whenever the user mentions Windows privilege escalation, Potato tools, SeImpersonatePrivilege, gaining SYSTEM access, or any Windows local privilege escalation scenario.
- ▌ Heap Security Checks · abelrguezr bundleReference for libc heap memory function security checks and error messages. Use this skill whenever the user is debugging heap vulnerabilities, analyzing heap exploitation, studying glibc malloc/free internals, or needs to understand what specific heap error messages mean. Trigger on mentions of heap corruption, malloc/free errors, tcache, fastbins, unsorted bins, or any libc heap function security checks.
- ▌ Linux Arm64 Kaslr Bypass · abelrguezr bundleHow to bypass KASLR on arm64 Android kernels using the static linear map. Use this skill whenever the user mentions arm64 kernel exploitation, KASLR bypass, Android kernel exploits, physical to virtual address conversion, linear map, memstart_addr, or needs to calculate stable kernel addresses. This is essential for any arm64 Android kernel exploit that needs to patch kernel data structures without leaking the KASLR slide.
- ▌ Macos Privilege Escalation · abelrguezr bundlemacOS privilege escalation techniques and triage. Use this skill whenever the user mentions macOS privilege escalation, privesc, gaining root, escalating privileges on macOS, TCC bypass, LaunchDaemon abuse, XPC vulnerabilities, or any macOS security research involving privilege escalation. Also use when analyzing macOS systems for privilege escalation vectors, reviewing macOS security configurations, or documenting macOS attack paths.
- ▌ IOS Entitlements Extractor · abelrguezr bundleExtract entitlements and mobile provision files from iOS app binaries (IPA files, compiled apps, or jailbroken device binaries). Use this skill whenever the user needs to analyze iOS app permissions, review embedded entitlements, extract plist data from compiled binaries, or perform iOS security testing. Trigger for any request involving iOS app binary analysis, entitlement extraction, mobile provision file recovery, or MASVS-PLATFORM security testing.
- ▌ Kerberos Ticket Harvesting · abelrguezr bundleHow to harvest Kerberos tickets from Windows systems using Mimikatz and Rubeus. Use this skill whenever you need to extract, dump, triage, renew, or convert Kerberos tickets from Windows environments during security assessments, penetration testing, or red team operations. Trigger this skill for any Windows Kerberos ticket manipulation tasks, including lsass memory extraction, ticket export, and offline cracking preparation.
- ▌ Postmessage Race Condition Exploit · abelrguezr bundleHow to exploit postMessage vulnerabilities using race conditions to steal sensitive data from parent pages. Use this skill whenever the user mentions postMessage, iframe exploitation, cross-origin communication vulnerabilities, race conditions in web security, stealing data from parent windows, or any scenario where an iframe needs to intercept messages before the parent page processes them. This is especially useful for CTF challenges, bug bounties, or security assessments involving blob documents, isolated iframes, or message-passing between windows.
- ▌ Windows Enterprise Ipc Exploitation · abelrguezr bundleAnalyze and document Windows local privilege escalation chains in enterprise software (endpoint agents, auto-updaters, driver utilities). Use this skill whenever investigating IPC vulnerabilities, auto-updater hijacking, TOCTOU race conditions, or supply-chain attacks in products like Netskope, ASUS DriverHub, MSI Center, Acer Control Centre, or similar enterprise tools. Also use when creating detection rules for these attack patterns or documenting privilege escalation paths for security assessments.
- ▌ Linux Kerberos Ticket Harvesting · abelrguezr bundleHarvest Kerberos tickets from Linux systems during post-exploitation. Use this skill whenever you have shell access to a Linux machine and need to extract Kerberos credentials (TGTs, TGS tickets) from file caches, kernel keyrings, KCM, or process memory. Trigger this when the user mentions Kerberos ticket extraction, credential harvesting on Linux, klist, keyctl, ccache extraction, or any scenario where you need to steal or copy Kerberos tickets from a compromised Linux host.
- ▌ Postgresql Extension Rce · abelrguezr bundlePostgreSQL Remote Code Execution via Extensions - Use this skill when testing PostgreSQL databases for extension loading vulnerabilities, analyzing RCE attack vectors through shared library injection, or understanding how to exploit CREATE FUNCTION to load malicious C extensions. Trigger this skill for any PostgreSQL security assessment involving extension mechanisms, shared library loading, or when investigating potential code execution paths through database functions. This covers PostgreSQL 8.1 through latest versions including directory traversal attacks.
- ▌ Ssrf Pentest · abelrguezr bundleServer-Side Request Forgery (SSRF) vulnerability assessment and exploitation. Use this skill whenever the user mentions SSRF, server-side request forgery, internal network access, cloud metadata endpoints, blind SSRF, gopher protocol payloads, or any scenario where a server might be tricked into making requests to internal or attacker-controlled resources. This includes testing for SSRF in web applications, analyzing proxy misconfigurations, exploiting cloud metadata services, and generating payloads for various protocols.
- ▌ Ad Cs Certificate Theft · abelrguezr bundleHow to steal and abuse Active Directory Certificate Services (AD CS) certificates. Use this skill whenever you need to extract, decrypt, or abuse certificates in a Windows/AD environment, including user certificates, machine certificates, certificate files, or NTLM credential theft via PKINIT. Make sure to use this skill when you mention certificates, AD CS, PKINIT, DPAPI, Mimikatz, SharpDPAPI, or any certificate-related attack in Active Directory.
- ▌ Adcs Domain Escalation · abelrguezr bundleActive Directory Certificate Services (AD CS) domain escalation techniques. Use this skill whenever the user mentions AD CS, certificate templates, ESC vulnerabilities, PKI misconfigurations, certificate-based authentication attacks, or wants to enumerate/exploit certificate authority weaknesses in Active Directory environments. This covers ESC1-ESC16 techniques including misconfigured templates, enrollment agent abuse, access control issues, NTLM relay to AD CS, and certificate mapping vulnerabilities.
- ▌ Ad Dynamic Objects Anti Forensics · abelrguezr bundleUse this skill whenever you need to perform Active Directory operations that require stealth, anti-forensics, or evidence elimination. Trigger this for any AD assessment involving computer account creation, group membership manipulation, GPO modifications, DNS changes, or when you need to leave no trace of your activities. Also use when investigating potential dynamicObject abuse or building detection rules for entryTTL/msDS-Entry-Time-To-Die attributes.
- ▌ Windows Dll Hijacking · abelrguezr bundleWindows DLL hijacking for privilege escalation and code execution. Use this skill whenever the user mentions DLL hijacking, DLL sideloading, DLL search order, phantom DLL, missing DLL exploitation, Windows privilege escalation via DLLs, or any scenario involving manipulating trusted applications to load malicious DLLs. Also trigger for Narrator hijacking, MSI dropper analysis, signed binary abuse, or when investigating DLL-related vulnerabilities on Windows systems.
- ▌ Rop Exploitation · abelrguezr bundleHow to create Return-Oriented Programming (ROP) and Jump-Oriented Programming (JOP) exploits for binary exploitation. Use this skill whenever the user needs to bypass NX/DEP protections, construct ROP chains for x86/x64/ARM64 architectures, find gadgets, handle stack alignment, or work with ret2lib/ret2syscall techniques. Make sure to use this skill when the user mentions ROP, gadgets, stack pivoting, binary exploitation, buffer overflow exploitation, or needs to call functions like system() through ROP chains.
- ▌ Lua Sandbox Security · abelrguezr bundleSecurity research and penetration testing for Lua sandbox environments. Use this skill when analyzing Lua VM security in game clients, embedded applications, or scripting engines. Trigger when users mention Lua sandboxes, embedded Lua, game client security, bytecode exploitation, sandbox escape, or need to enumerate Lua environments for security assessments. Also use when hardening Lua environments or reviewing Lua security configurations.
- ▌ Linux Network Namespaces · abelrguezr bundleHow to work with Linux network namespaces for security testing, containerization, and system administration. Use this skill whenever the user mentions network namespaces, network isolation, container networking, nsenter, unshare, veth pairs, or needs to inspect/create/enter network namespaces. Also trigger when users want to understand network stack isolation, troubleshoot container networking, or perform privilege escalation research involving network namespaces.
- ▌ Macos Firewall Bypass Audit · abelrguezr bundleAudit and test macOS firewall configurations for potential bypass vulnerabilities. Use this skill whenever you need to assess macOS firewall security, check for known bypass techniques, enumerate allowed traffic, inspect PF rules, or validate Network Extension filter configurations. This skill helps security professionals identify weaknesses in firewall rules, test for CVE-2024-44206 and other recent vulnerabilities, and harden macOS systems against firewall evasion attacks.
- ▌ Macos File Extension Apps · abelrguezr bundlemacOS security skill for enumerating file extension handlers and URL scheme handlers via LaunchServices database. Use this skill whenever analyzing macOS systems for privilege escalation, investigating default app handlers, auditing file associations, or researching application capabilities. Trigger when users mention file extensions, URL schemes, LaunchServices, default apps, or macOS application handlers.
- ▌ Android App Virtualization Detection · abelrguezr bundleDetect and analyze Android application-level virtualization (app cloning/container frameworks like DroidPlugin). Use this skill whenever you need to investigate suspicious Android apps, analyze potential app virtualization abuse, check for permission escalation via shared UIDs, or detect stealthy code loading. Trigger this skill for any Android security analysis involving app containers, plugin frameworks, or when you suspect an app is running multiple APKs under a single process.
- ▌ Pid Namespace Security · abelrguezr bundleHow to work with Linux PID namespaces for container security, process isolation, and privilege escalation analysis. Use this skill whenever the user mentions containers, Docker, namespaces, process isolation, PID namespace, container escape, privilege escalation, runc, unshare, nsenter, or any security analysis involving Linux process namespaces. This skill helps create, inspect, and audit PID namespaces, understand exploitation techniques, and harden container security.
- ▌ Uts Namespace Security · abelrguezr bundleUse this skill whenever you need to work with Linux UTS namespaces for security testing, privilege escalation, or container security analysis. This includes checking which UTS namespace you're in, finding all UTS namespaces on a system, entering UTS namespaces, detecting containers that share the host UTS namespace, or understanding UTS namespace security implications. Trigger this skill for any task involving hostname isolation, NIS domain names, container UTS configuration, or UTS-based privilege escalation scenarios.
- ▌ Android Debuggable Exploitation · abelrguezr bundleUse this skill whenever you need to analyze, test, or exploit debuggable Android applications during authorized security assessments. Trigger this when the user mentions Android app security testing, debuggable APKs, JDWP debugging, bypassing security checks, root detection bypass, or CVE-2024-31317 exploitation. This skill covers making apps debuggable, runtime code injection, and forcing debug mode on non-debuggable apps.
- ▌ Android Smali Patching · abelrguezr bundleHow to reverse engineer Android APKs, analyze and modify smali code to bypass game conditions, unlock features, or extract flags. Use this skill whenever the user needs to decompile an APK, modify smali bytecode, change comparison operators, bypass win conditions, or perform any Android app reverse engineering. Trigger on mentions of APK analysis, smali modification, Android pentesting, game hacking, or CTF challenges involving Android apps.
- ▌ Android Play Store Location Spoofing · abelrguezr bundleHow to bypass regional restrictions on Google Play Store during Android app security testing. Use this skill whenever you need to access region-locked Android applications, test geo-restricted app behavior, or install apps unavailable in your current location for security assessment purposes. Trigger this when the user mentions Play Store restrictions, regional app availability, country-locked apps, or needs to test apps from different geographic regions.
- ▌ Z3 Smt Reversing · abelrguezr bundleUse Z3 SMT solver to solve constraints from reversing tasks, crackmes, and binary analysis. Use this skill whenever you need to solve symbolic constraints, reverse engineer license checks, find valid inputs for binaries, or work with bit-vector arithmetic from decompiled code. Trigger this skill for any task involving constraint solving, symbolic execution, or finding values that satisfy conditions extracted from binaries.
- ▌ Linux Forensics · abelrguezr bundlePerform Linux digital forensics investigations. Use this skill whenever the user needs to investigate a Linux system for security incidents, malware, unauthorized access, or suspicious activity. This includes gathering system information, analyzing logs, checking for persistence mechanisms, examining file systems, recovering deleted files, and documenting findings. Trigger on requests involving Linux forensics, incident response, malware investigation, system compromise analysis, or security auditing of Linux systems.
- ▌ Linux Time Namespace · abelrguezr bundleLinux Time Namespace operations for security analysis, container hardening, and privilege escalation research. Use this skill whenever the user needs to create, inspect, or manipulate Linux time namespaces, check namespace membership, adjust CLOCK_MONOTONIC or CLOCK_BOOTTIME offsets, understand time namespace security implications, or harden container runtimes against time-based attacks. Trigger on mentions of time namespaces, timens, namespace isolation, container time manipulation, or Linux clock virtualization.
- ▌ Docker User Namespace · abelrguezr bundleHow to work with Linux user namespaces for Docker security testing and privilege escalation analysis. Use this skill whenever the user mentions user namespaces, UID/GID mapping, container isolation, Docker security, namespace enumeration, or wants to understand how user namespaces work for privilege escalation. This includes creating namespaces, checking mappings, entering namespaces, and understanding capability implications.
- ▌ Postgresql Password Bruteforce · abelrguezr bundlePostgreSQL PL/pgSQL password bruteforce attack for security testing. Use this skill when you have SQL injection access to a PostgreSQL database and want to test password security. Trigger when the user mentions PostgreSQL brute force, password cracking, SQL injection exploitation, or testing database authentication. This skill helps create PL/pgSQL functions that attempt to brute force database credentials using the dblink extension.
- ▌ Ad Certificate Enumeration · abelrguezr bundleActive Directory Certificate Services (AD CS) enumeration and vulnerability assessment. Use this skill whenever the user mentions AD certificates, PKI, certificate templates, AD CS, certificate authorities, or wants to enumerate/assess certificate infrastructure in Active Directory environments. Also trigger for requests about Certify, Certipy, certificate exploitation, ESC vulnerabilities, or any AD PKI security assessment.
- ▌ Overpass The Hash Ptk · abelrguezr bundleExecute Overpass The Hash/Pass The Key (PTK) attacks in Active Directory environments where NTLM is restricted and Kerberos authentication is required. Use this skill whenever the user mentions Kerberos attacks, NTLM hashes, TGT tickets, pass-the-hash variations, Active Directory credential attacks, or needs to authenticate using stolen hashes/keys to access network resources. This is the go-to technique when traditional Pass the Hash fails due to NTLM restrictions.
- ▌ Cet Shadow Stack · abelrguezr bundleControl Flow Enforcement Technology (CET) and Shadow Stack analysis for binary exploitation. Use this skill whenever the user mentions CET, shadow stack, control flow integrity, ROP/JOP attacks, binary security protections, or needs to understand how modern CPU features prevent control-flow hijacking. Trigger for security research, binary analysis, exploitation learning, or when discussing hardware-level security mitigations.
- ▌ Docker Forensics · abelrguezr bundlePerform forensic analysis on Docker containers and images. Use this skill whenever investigating compromised containers, analyzing suspicious Docker images, extracting credentials from container memory, or comparing container states. Trigger when users mention Docker forensics, container investigation, image analysis, docker diff, container-diff, dive tool, or need to find modifications in Docker environments.
- ▌ Malware Analysis · abelrguezr bundleMalware analysis and reverse engineering toolkit. Use this skill whenever the user needs to analyze suspicious files, extract IOCs, deobfuscate malware, analyze Android APKs, trace Node.js loaders, or perform any malware-related investigation. Trigger on mentions of malware, suspicious executables, PE/ELF analysis, Yara rules, ClamAV, Android malware, obfuscation, control-flow analysis, or any security investigation involving potentially malicious software.
- ▌ Delivery Receipt Side Channel · abelrguezr bundleHow to execute delivery receipt side-channel attacks on E2EE messengers (WhatsApp, Signal, Threema). Use this skill whenever the user wants to probe messaging protocols for timing leaks, fingerprint devices, monitor user behavior through RTT analysis, or understand silent delivery receipt vulnerabilities. Trigger on any request about messenger security testing, protocol-level reconnaissance, device fingerprinting via messaging apps, or covert channel exploitation.
- ▌ Mount Namespace · abelrguezr bundleHow to work with Linux mount namespaces for file system isolation and privilege escalation. Use this skill whenever the user mentions mount namespaces, namespace isolation, file system isolation, container security, or needs to create/enter/inspect mount namespaces. Also use when debugging namespace-related errors like "Cannot allocate memory" with unshare. Make sure to use this skill for any Linux security research involving namespaces, container escape scenarios, or when the user wants to understand how processes can have different views of the file system.
- ▌ Macos Objective C Analysis · abelrguezr bundleAnalyze and understand Objective-C code in macOS binaries for security research, reverse engineering, and privilege escalation. Use this skill whenever you need to read Objective-C source code, analyze Mach-O binaries with class-dump, understand iOS/macOS app internals, or work with Objective-C runtime concepts in a security context. Trigger this skill for any macOS binary analysis, Objective-C code review, or when investigating app behavior through class/method inspection.
- ▌ Android Work Profile Bypass · abelrguezr bundleAndroid Enterprise Work Profile security testing and bypass techniques. Use this skill whenever the user mentions Android Work Profiles, MDM bypass, Intune required apps, BYOD security testing, CVE-2023-21257, or any scenario involving Android Enterprise device management security assessment. This skill covers reconnaissance, exploitation chains, and post-exploitation opportunities for Work Profile environments.
- ▌ Dotnet Soap Wsdl Exploitation · abelrguezr bundleExploit .NET SOAP/WSDL client proxy vulnerabilities for NTLM relay, arbitrary file writes, and RCE. Use this skill whenever you need to test for SoapHttpClientProtocol abuse, WSDL import vulnerabilities, or HttpWebClientProtocol scheme-agnostic bugs in .NET applications. Trigger this skill for any .NET web service testing, SOAP endpoint analysis, WSDL import functionality, or when investigating Barracuda, Ivanti, Umbraco, PowerShell, or SSIS SOAP-related vulnerabilities.
- ▌ Postgresql Language Injection · abelrguezr bundleExploit PostgreSQL scripting languages (plpythonu, plperlu, plrubyu, etc.) to achieve remote code execution from a compromised database. Use this skill whenever you have SQL access to a PostgreSQL database and want to enumerate available languages, trust untrusted languages, or execute arbitrary commands on the underlying OS. Trigger this for any PostgreSQL exploitation, database-to-OS privilege escalation, or when you need to run system commands through SQL.
- ▌ Ldap Hardening · abelrguezr bundleHow to harden Active Directory against LDAP relay attacks using LDAP signing and channel binding. Use this skill whenever the user mentions LDAP security, AD hardening, LDAP signing, channel binding, LDAP relay prevention, Active Directory security, or wants to protect Domain Controllers from MITM/relay attacks. Make sure to use this skill even if they don't explicitly say "hardening" or "security" — if they're asking about LDAP configuration, GPO settings for DCs, or protecting against Kerberos/NTLM relays, this skill applies.
- ▌ Dpapi Credential Extraction · abelrguezr bundleHow to extract and decrypt Windows DPAPI-protected credentials and secrets. Use this skill whenever the user needs to access DPAPI-encrypted data, extract master keys, decrypt credential blobs, work with Chrome/Edge cookies, or perform offline DPAPI decryption. Trigger on mentions of DPAPI, Windows credential extraction, master key decryption, Chrome password extraction, SharpDPAPI, Mimikatz DPAPI, or any Windows credential dumping scenario.
- ▌ Leaked Handle Exploitation · abelrguezr bundleWindows local privilege escalation via leaked handle exploitation. Use this skill whenever the user mentions Windows privilege escalation, handle enumeration, process handle leaks, inherited handles, or needs to escalate from a low-privileged process to SYSTEM/administrator. Also trigger when users ask about Windows security testing, handle-based attacks, or finding privilege escalation vectors in Windows environments.
- ▌ Linux Kernel Af Unix Oob Uaf · abelrguezr bundleUse this skill when analyzing or researching AF_UNIX MSG_OOB use-after-free vulnerabilities in Linux kernels, particularly CVE-2025-38236. Trigger this skill for kernel exploitation research involving socket buffer (SKB) primitives, arbitrary kernel read/write techniques, page allocator manipulation, or when users mention MSG_OOB, unix_stream_recv_urg, manage_oob, kernel UAF, SKB exploitation, or Chrome renderer-to-kernel escapes. This skill provides methodology for understanding the vulnerability chain, exploitation primitives, and mitigation strategies.
- ▌ Synology Archive Decryption · abelrguezr bundleDecrypt Synology PAT/SPK encrypted firmware and application archives to extract their contents. Use this skill whenever the user needs to analyze Synology NAS firmware, extract packages from .pat or .spk files, inspect Synology system updates, or reverse engineer Synology applications. Trigger on mentions of Synology, DSM, BSM, PAT files, SPK files, firmware extraction, or NAS package analysis.
- ▌ Cgroup Namespace · abelrguezr bundleHow to work with Linux CGroup namespaces for process isolation and security analysis. Use this skill whenever the user mentions cgroup namespaces, container isolation, process hierarchy inspection, namespace enumeration, or needs to understand how cgroups virtualize resource views. Also trigger when investigating privilege escalation paths, container escape scenarios, or analyzing process isolation boundaries.
- ▌ Android Biometric Bypass · abelrguezr bundleAndroid biometric authentication pentesting and bypass techniques. Use this skill whenever testing Android app security, analyzing biometric authentication implementations, or performing mobile security assessments. Trigger for fingerprint authentication testing, biometric prompt analysis, Android Keystore security reviews, or any mobile app security work involving authentication mechanisms. Don't skip this skill for Android security testing even if the user doesn't explicitly mention 'biometric' or 'fingerprint' - authentication security is always in scope.
- ▌ Browser Extension Xss Testing · abelrguezr bundleHow to test browser extensions for XSS vulnerabilities including iframe-based XSS, DOM-based XSS, and clickjacking attacks. Use this skill whenever the user mentions browser extension security testing, Chrome extension vulnerabilities, XSS in extensions, web_accessible_resources exploitation, or CSP bypass in extensions. Make sure to use this skill for any pentesting task involving browser extensions, even if the user doesn't explicitly mention XSS.
- ▌ Active Directory Pentest · abelrguezr bundleUse this skill whenever you need to enumerate, attack, or escalate privileges in an Active Directory environment. Trigger on any AD-related tasks including reconnaissance, credential attacks, Kerberos abuse, trust exploitation, privilege escalation, or post-exploitation. Make sure to use this skill when the user mentions Active Directory, domain enumeration, Kerberos attacks, AD pentesting, Windows domain security, or any AD attack methodology.
- ▌ Blockchain Security Analyst · abelrguezr bundleExpert guidance on blockchain and cryptocurrency security, privacy mechanisms, and Web3 threat analysis. Use this skill whenever the user asks about blockchain concepts, Bitcoin/Ethereum transactions, privacy attacks, DeFi security, smart contract vulnerabilities, or Web3 red teaming. Trigger for any questions about cryptocurrency privacy, transaction analysis, consensus mechanisms, or blockchain security best practices—even if the user doesn't explicitly mention "security" or "blockchain."
- ▌ Fhrp Attack · abelrguezr bundleExecute FHRP (First Hop Redundancy Protocol) attacks including GLBP and HSRP hijacking for network penetration testing. Use this skill whenever the user mentions GLBP, HSRP, FHRP, gateway redundancy protocols, router hijacking, network MITM attacks, or wants to intercept traffic through virtual gateway takeover. This skill provides attack methodologies, packet crafting, and network configuration for both authenticated and unauthenticated scenarios.
- ▌ Clipboard Hijacking Analysis · abelrguezr bundleAnalyze clipboard hijacking (pastejacking) attacks, ClickFix campaigns, and IUAM-style verification page lures. Use this skill whenever investigating phishing campaigns that use clipboard manipulation, fake CAPTCHA pages, or social engineering to execute commands via Win+R/Terminal paste. Also use for threat hunting clipboard-based attacks, analyzing pastejacking payloads, or building detection rules for clipboard-to-console attack chains.
- ▌ Pam Hardening · abelrguezr bundleLinux PAM security auditing, backdoor detection, and hardening. Use this skill whenever the user mentions PAM configuration, authentication security, Linux hardening, credential harvesting detection, SSH security, or any post-exploitation concerns related to authentication. Also trigger for security audits, penetration testing, or when investigating suspicious login behavior.
- ▌ Macos Defensive Apps · abelrguezr bundleHow to deploy and use macOS defensive security applications including firewalls (Little Snitch, LuLu), persistence detection tools (KnockKnock, BlockBlock), and keylogger detection (ReiKey). Use this skill whenever the user mentions macOS security, defensive tools, firewall setup, malware detection, persistence monitoring, keylogger protection, or wants to harden their Mac against threats. Also trigger when users ask about Objective-See tools, network monitoring on Mac, or how to detect suspicious connections.
- ▌ Iis Pentesting · abelrguezr bundleIIS (Internet Information Services) pentesting and exploitation. Use this skill whenever the user mentions IIS, Microsoft web servers, ASPX, ASP.NET, .NET applications, web.config, trace.axd, Telerik, or any Microsoft Windows web server testing. This skill covers webshell deployment, path traversal, authentication bypass, configuration decryption, fileless backdoors, and known IIS vulnerabilities. Trigger for any IIS reconnaissance, exploitation, or post-exploitation tasks.
- ▌ Browser Extension Clickjacking · abelrguezr bundleAnalyze browser extensions for clickjacking vulnerabilities. Use this skill whenever you need to audit browser extensions (Chrome, Firefox, Edge) for security issues, review manifest.json files, test web_accessible_resources configurations, or investigate extension-based attacks. Trigger this skill for any pentesting task involving browser extensions, Chrome extensions, Firefox add-ons, or when analyzing extension security, even if the user doesn't explicitly mention 'clickjacking' or 'vulnerability'.
- ▌ Http2 Request Smuggling · abelrguezr bundleHow to identify and exploit HTTP/2 request smuggling vulnerabilities in downgrade scenarios. Use this skill whenever the user mentions HTTP/2, request smuggling, H2.TE, H2.CL, HTTP downgrade attacks, proxy misconfigurations, or wants to test for HTTP/2 to HTTP/1.x translation vulnerabilities. Also trigger for CVE-2023-25690, CVE-2023-25950, CVE-2022-41721, or any HTTP/2 security testing.
- ▌ Phishing Assessment · abelrguezr bundleHow to conduct authorized phishing assessments and security awareness testing. Use this skill whenever the user mentions phishing campaigns, email security testing, social engineering assessments, credential harvesting simulations, GoPhish configuration, domain impersonation techniques, or security awareness training. Make sure to use this skill for any authorized security testing involving email-based attacks, MFA bypass scenarios, or help-desk social engineering simulations.
- ▌ Ipc Namespace · abelrguezr bundleHow to work with Linux IPC (Inter-Process Communication) namespaces for security isolation and privilege escalation analysis. Use this skill whenever the user needs to understand IPC namespace isolation, create isolated IPC environments, inspect IPC objects across namespaces, or analyze IPC namespace configurations for security hardening. Make sure to use this skill when the user mentions IPC namespaces, shared memory isolation, System V IPC objects, process isolation, or namespace security.
- ▌ Homograph Detection · abelrguezr bundleDetect and analyze homograph/homoglyph attacks in phishing emails, URLs, and domains. Use this skill whenever the user mentions phishing analysis, email security, domain impersonation, Unicode attacks, homoglyph detection, or needs to inspect suspicious sender names, subjects, or URLs for character substitution attacks. Trigger even if the user just says "check this email" or "analyze this URL" if there's any suspicion of spoofing or impersonation.
- ▌ Docker Namespace Security · abelrguezr bundleHow to understand, test, and harden Docker namespace isolation for security. Use this skill whenever the user mentions Docker security, container isolation, namespace escapes, privilege escalation, container breakout, or needs to audit namespace configurations. This skill covers PID, Mount, Network, IPC, UTS, Time, and User namespaces.
- ▌ Objection Android Pentest · abelrguezr bundleUse Objection for runtime Android mobile app exploration and security testing. Use this skill whenever the user needs to perform dynamic analysis on Android apps, bypass SSL pinning, disable root detection, hook methods, inspect memory, or explore app internals at runtime. Trigger for any Android pentesting task involving Frida, runtime manipulation, or mobile security assessment.
- ▌ Play Integrity Bypass · abelrguezr bundleAndroid pentesting skill for bypassing Play Integrity API attestation (SafetyNet replacement). Use this skill whenever you need to test Android app security, bypass device attestation checks, achieve MEETS_BASIC_INTEGRITY/MEETS_DEVICE_INTEGRITY/MEETS_STRONG_INTEGRITY, or work with root hiding and key attestation spoofing. Trigger this for any Android security testing involving Play Integrity, SafetyNet, device certification, or app attestation validation.
- ▌ Epmd Pentest · abelrguezr bundlePentest Erlang Port Mapper Daemon (epmd) on port 4369. Use this skill whenever you need to enumerate, assess, or exploit epmd services during security assessments. Trigger this when you see port 4369 open, when working with RabbitMQ or CouchDB installations, when you need to extract Erlang node information, or when attempting cookie-based RCE attacks. Don't forget to use this for any epmd-related reconnaissance or exploitation tasks.
- ▌ Kerberos Double Hop · abelrguezr bundleHow to understand and work around the Kerberos double hop authentication problem in Windows environments. Use this skill whenever you need to authenticate across multiple hops in Active Directory, troubleshoot Kerberos authentication failures between servers, set up PowerShell remoting across multiple systems, or work with WinRM/SSH in multi-hop scenarios. This applies to penetration testing, security assessments, and legitimate administrative tasks where you need to chain authentication through intermediate servers.
- ▌ Windows Acl Analysis · abelrguezr bundleAnalyze and explain Windows Access Control Lists (ACLs), DACLs, SACLs, and ACEs for security auditing, privilege escalation research, permission troubleshooting, or hardening. Use this skill whenever the user mentions Windows permissions, access control, ACLs, DACLs, SACLs, ACEs, file/folder permissions, security descriptors, privilege escalation, or anything related to Windows access control mechanisms. Trigger even if the user doesn't explicitly use these terms but is asking about who can access what on Windows systems.
- ▌ Binary Exploitation Tools · abelrguezr bundleA comprehensive guide to binary exploitation tools and techniques. Use this skill whenever the user needs help with buffer overflow exploitation, reverse engineering, debugging binaries, or working with tools like GDB, Metasploit, Ghidra, or analyzing vulnerable binaries. Trigger for any binary exploitation task, CTF challenges, vulnerability analysis, or when the user mentions stack overflows, shellcode, ROP gadgets, or binary analysis.
- ▌ Libc Protections · abelrguezr bundleHow to understand and bypass modern libc memory protections including chunk alignment, pointer mangling, safe-linking, and pointer guard. Use this skill whenever working on heap exploitation, binary exploitation challenges, CTF heap tasks, analyzing glibc vulnerabilities, or when you need to understand how to leak and demangle pointers in modern glibc versions (2.32+). Make sure to use this skill when you mention heap, glibc, malloc, fastbin, tcache, pointer guard, safe-linking, or any binary exploitation context.
- ▌ Slirp Nat Heap Exploitation · abelrguezr bundleAnalyze and understand VirtualBox Slirp NAT packet heap exploitation vulnerabilities. Use this skill whenever the user needs to understand Slirp NAT heap corruption, mbuf allocator exploitation, UMA zone hijacking, or similar allocator-based vulnerabilities in network stacks. Also use when analyzing packet buffer overflows, heap grooming techniques, or when creating educational content about VirtualBox security research.
- ▌ Phishing Documents · abelrguezr bundleCreate and analyze phishing documents for authorized security testing. Use this skill whenever the user needs to create malicious Office documents (Word, Excel, PowerPoint), HTA files, LNK loaders, or steganography-based payloads for penetration testing, red teaming, or security research. Trigger on requests about phishing campaigns, document-based attacks, macro payloads, HTA execution, NTLM authentication forcing, or any file-based social engineering techniques.
- ▌ Distroless Exploitation · abelrguezr bundleHow to execute arbitrary code in distroless containers using available binaries like openssl. Use this skill whenever the user is working on container security, penetration testing, CTF challenges, or needs to understand how to run commands in minimal container environments that lack standard shells and tools. Trigger this for any distroless container exploitation, container escape scenarios, or when analyzing container security posture.
- ▌ Nfs Privilege Escalation · abelrguezr bundlePrivilege escalation via NFS no_root_squash misconfiguration. Use this skill whenever you need to escalate privileges on a Linux system with NFS shares, when you find /etc/exports with no_root_squash, when you have access to an NFS share and want to gain root, or when you're doing Linux privilege escalation and NFS is available. This includes both remote exploits (mounting from attacker machine) and local exploits (using libnfs to forge RPC calls).
- ▌ Hadoop Pentest · abelrguezr bundleHow to enumerate and exploit Apache Hadoop clusters during penetration testing. Use this skill whenever you need to assess Hadoop security, test HDFS/WebHDFS access, exploit YARN RCE vulnerabilities, or check for CVE-2023-26031. Trigger on any mention of Hadoop, HDFS, YARN, MapReduce, distributed data processing security, or when you see ports 50030, 50060, 50070, 50075, 50090, 8088, 8042, 8031, 8032, 9870, 9864, or 14000 in a pentest engagement.
- ▌ Format String Arbitrary Read · abelrguezr bundleExploit format string vulnerabilities to perform arbitrary memory reads. Use this skill whenever the user mentions format string bugs, printf vulnerabilities, %s/%p format specifiers, leaking stack/heap/libc addresses, or needs to read arbitrary memory locations in binary exploitation. Trigger on any C code with vulnerable printf() calls, pwn challenges involving format strings, or requests to leak secrets/passwords from memory.
- ▌ Stack Shellcode Arm64 · abelrguezr bundleCreate stack shellcode exploits for ARM64 buffer overflow vulnerabilities. Use this skill whenever the user needs to exploit a stack-based buffer overflow on ARM64 architecture, mentions shellcode injection, stack pivoting, or needs help crafting pwn payloads for ARM64 binaries. This includes finding offsets, generating shellcode, and handling ASLR/NX considerations.
- ▌ Containerd Privilege Escalation · abelrguezr bundleHow to perform privilege escalation using containerd's ctr command during authorized security assessments. Use this skill whenever the user mentions containerd, ctr command, container escape, privilege escalation in containerized environments, or needs to test container security. Make sure to use this skill when you find the ctr binary on a system during penetration testing or security audits.
- ▌ Drozer Android Pentest · abelrguezr bundleUse Drozer to perform Android application security testing. Use this skill whenever you need to analyze Android APKs for security vulnerabilities, test exported components (activities, services, content providers, broadcast receivers), or perform mobile penetration testing. This skill covers Drozer setup, connection to Android devices, and running security assessment modules. Make sure to use this skill when the user mentions Android security testing, APK analysis, mobile pentesting, exported components, or Drozer commands.
- ▌ Frida Android Hooking · abelrguezr bundleUse Frida to hook Android methods, bypass security checks, brute-force functions, and intercept arguments/return values. Use this skill whenever the user mentions Android pentesting, Frida, Java hooking, method interception, PIN bypass, encryption analysis, or needs to modify Android app behavior at runtime. Also trigger for Android 14/15/16 compatibility issues, Zygisk stealth injection, or when analyzing APK security.
- ▌ Frida Android Pentesting · abelrguezr bundleHow to use Frida for Android app security testing and reverse engineering. Use this skill whenever the user needs to hook Android Java methods, intercept function calls, modify runtime behavior, find class instances, or create Python-Frida automation scripts. Trigger for any Android pentesting task involving Frida, Java method hooking, runtime instrumentation, or dynamic analysis of APKs.
- ▌ Glusterfs Pentest · abelrguezr bundlePentest GlusterFS distributed file systems. Use this skill whenever you encounter ports 24007, 24008, 24009, or 49152+ in a scan, or when the user mentions GlusterFS, distributed storage, glusterd, or gluster-brick. This skill covers enumeration, exploitation of known CVEs (2022-2025), privilege escalation via gluster_shared_storage, and hardening recommendations.