AeonDave
- 336 skills
- 0 followers
- 19 hours ago last updated
- ▌ Ssrfmap · aeondave bundleAuth/lab ref: automated SSRF (Server-Side Request Forgery) exploitation tool using Burp-style request files.
- ▌ Sstimap · aeondave bundleAuth/lab ref: actively maintained SSTI detection and exploitation tool with interactive and predetermined modes across Jinja2, Twig, Smarty, Freemarker, Velocity, ERB, Pug, Nunjucks, and more.
- ▌ Testssl · aeondave bundleAuth/lab ref: testssl.sh: broad TLS/SSL testing script checking protocol support, cipher suites, vulnerabilities (BEAST, POODLE, Heartbleed, ROBOT, DROWN, etc.), and certificate issues.
- ▌ Sparrow Wifi · aeondave bundleAuth/lab ref: Linux Wi-Fi and Bluetooth analyzer with GPS, remote agent, JSON API, and SDR integrations including HackRF One and Ubertooth.
- ▌ Heap Exploitation Dev · aeondave bundleAuth/lab dev: heap exploitability research; glibc/musl/Windows allocators, UAF/double-free/overflow models, heap shaping, mitigations.
- ▌ Windows Internals Dev · aeondave bundleAuth/lab dev: Windows internals; PEB/TEB, PE/COFF, syscalls, unwinding, memory/heap, tokens, kernel objects, ETW/AMSI telemetry.
- ▌ Offensive Reverse Role · aeondaveScoped routing: Reverse Engineer. Static and dynamic analysis of binaries, malware, and unknown protocols.
- ▌ Offensive Windows Role · aeondaveScoped routing: Windows Operator. Handles AD enumeration, Kerberos exploitation, and Windows local privilege escalation.
- ▌ Fuzzing Technique · aeondave bundleAuth/lab: fuzzing methodology; target model, oracle, harness quality, corpus, campaign triage for parsers, binaries, protocols, APIs.
- ▌ Network Technique · aeondave bundleAuth/IR: network investigation; service exposure, traffic, PCAP/protocol logs, pivots, scan evidence, incident reconstruction.
- ▌ Cyberchef · aeondave bundleAuth/lab ref: Web-based data transformation and crypto analysis workbench. For rapidly decoding layered encodings, transforming binary/text formats, prototyping crypto/decode pipelines, or sharing reproducible recipes.
- ▌ Vuln Research · aeondave bundleAuth/lab ref: Exploit research workflow: a target software version or CVE: triage CVSS severity, find public PoCs on NVD/sploitus/PoC-in-GitHub/ExploitDB, assess exploitability, and locate Metasploit modules.
- ▌ Gitleaks · aeondave bundleAuth/lab ref: Gitleaks secret scanning; repo/directory/stdin checks, regex+entropy rules, pre-commit/CI evidence, remediation workflow.
- ▌ Nosqlmap · aeondave bundleAuth/lab ref: automated NoSQL injection detection and exploitation tool targeting MongoDB, CouchDB, and other NoSQL databases.
- ▌ Design Before Implementation · aeondave bundleUse before creative or multi-file implementation work: new features, behavior changes, refactors, new skills, offensive tooling workflows, exploit chains, research pipelines, or architecture decisions. Clarifies intent, scope, alternatives, constraints, success criteria, and non-goals before coding or executing.
- ▌ Asm Offensive Patterns · aeondave bundleAuth/lab ASM patterns; x86-64/ARM64, syscalls, SSN resolution, stack traces, PEB/IAT-free lookup, PIC data access, ETW/AMSI telemetry, BOF/loader review.
- ▌ Stack Exploitation Dev · aeondave bundleAuth/lab dev: stack exploitability research; frame layout, canaries, ret2libc/ROP/SROP/JOP paths, mitigations, data-only outcomes.
- ▌ Offensive Forensic Role · aeondaveScoped routing: Forensic Operator. Extracting credentials and timelines from memory dumps, disk images, and PCAP.
- ▌ Offensive Hardware Role · aeondaveScoped routing: Hardware Operator. Physical device compromise via UART, JTAG, SPI, and embedded interfaces.
- ▌ Cracking Technique · aeondave bundleAuth/lab: password/hash recovery methodology; hash triage, candidate design, rules/masks, campaign evidence, audit-safe reporting.
- ▌ Forensic Technique · aeondave bundleIncident forensics: preservation, triage, timelines, artifact correlation, reporting across disk (E01/DD/RAW), memory, PCAP.
- ▌ Hardware Technique · aeondave bundleAuth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
- ▌ Phishing Technique · aeondave bundleAuthorized simulation: email/social campaign infrastructure; domain hygiene, SPF/DKIM/DMARC, GoPhish/Evilginx planning, metrics.
- ▌ Wireless Technique · aeondave bundleAuth assessment: wireless methodology; Wi-Fi/BLE survey, WPA/WPA3 handshake/PMKID labs, WPS, rogue-AP simulation, auth-material handoff.
- ▌ Name That Hash · aeondaveAuth/lab ref: hash-identification helper for narrowing candidate algorithms before cracking.
- ▌ Rsactftool · aeondave bundleAuth/lab ref: RSA testing automation tool for weak public keys. For targeting RSA key recovery or plaintext recovery from public data (n, e, ciphertext, partial leaks).
- ▌ Linux Persistence · aeondaveAuth/lab ref: Linux durability-risk audit; cron/systemd/SSH/PAM/LD_PRELOAD indicators, validation, cleanup and remediation notes.
- ▌ Burpsuite · aeondave bundleAuth/lab ref: Burp Suite: integrated web application security testing platform with proxy, scanner, intruder, and repeater.
- ▌ Container Technique · aeondave bundleContainer methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.
- ▌ Emulation Technique · aeondave bundleAuth/lab: generic emulation methodology for binaries, firmware, kernels, and MCU/board targets; static-to-dynamic routing, tool choice, validation signals.
- ▌ Reversing Technique · aeondave bundleAuth/lab: reverse engineering methodology; malware triage, patch diffing, firmware/protocol RE, protections, exploitability handoff evidence.
- ▌ Trufflehog · aeondave bundleAuth/lab ref: TruffleHog secret scanning; verified secret types, git/cloud/CI sources, validation evidence, remediation workflow.
- ▌ Verification Before Completion · aeondave bundleUse when about to claim work is done, fixed, passing, validated, merged, report-ready, or safe to proceed. Requires fresh verification evidence before success claims, commits, pull requests, task completion, operator reports, cleanup claims, or moving to the next step.
- ▌ Offensive Supervisor Role · aeondave bundleHigh-level orchestration role for authorized red-team, lab, and CTF engagements. Use to decompose objectives into strict delegable tasks, package cold-start context per dispatch, journal routing decisions, preserve multi-level worker failures, and gate the whole engagement on evidence before handoff.
- ▌ Vibe Audit Technique · aeondave bundleWhite-box auditing methodology for AI-generated ('vibe-coded') applications from Lovable, Bolt.new, v0, Cursor, Replit Agent, and Claude Code. Focuses on modern stack misconfigurations (Supabase, Firebase, Next.js, Vercel, Expo).
- ▌ Mosquitto Clients · aeondaveAuth/lab ref: Mosquitto client tools, primarily `mosquitto_pub` and `mosquitto_sub`, for interacting with MQTT brokers.