akashrpatil
- 20 skills
- 0 followers
- 16 hours ago last updated
- ▌ Linux Privilege Escalation · akashrpatil bundleEscalate privileges from a low-privilege shell to root on Linux systems using kernel exploits, SUID binaries, capabilities, cron jobs, PATH hijacking, and misconfigured services. Use this skill during penetration tests after gaining initial access to a Linux host. Covers automated enumeration with LinPEAS, manual techniques, Docker/container escapes, and sudo abuse for complete privilege escalation.
- ▌ HTTP Request Smuggling · akashrpatil bundleExploit discrepancies in how reverse proxies and back-end servers parse HTTP requests (Content-Length vs. Transfer-Encoding). This skill details CL.TE, TE.CL, and TE.TE attacks to bypass security controls, steal credentials, and execute unauthorized actions.
- ▌ Windows Privilege Escalation · akashrpatil bundleEscalate privileges from a standard user to SYSTEM/Administrator on Windows systems using service misconfigurations, unquoted service paths, token manipulation, registry exploits, and kernel vulnerabilities. Use this skill during penetration tests after gaining initial access to a Windows host. Covers automated enumeration with WinPEAS, PowerUp, manual techniques, UAC bypass, and potato attacks.
- ▌ Ssrf Server Side Request Forgery · akashrpatil bundleDetect and exploit Server-Side Request Forgery (SSRF) vulnerabilities to access internal services, cloud metadata endpoints, and restricted network resources. Use this skill when testing URL fetch features, webhook configurations, file imports, PDF generators, or any functionality that makes server-side HTTP requests. Covers blind SSRF, DNS rebinding, cloud metadata exploitation (AWS/GCP/Azure), and protocol smuggling for maximum impact.
- ▌ Business Logic Vulnerabilities Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Path Traversal Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Nosql Injection Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Prototype Pollution Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ HTTP Request Smuggling Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ LLM Prompt Injection · akashrpatil bundleIdentify and exploit vulnerabilities in Applications integrating Large Language Models (LLMs). Prompt Injection involves crafting inputs that override the original system instructions provided by the developer, allowing an attacker to exfiltrate data, bypass restrictions, or manipulate the AI's output logic.
- ▌ Cobalt Strike Malleable C2 · akashrpatil bundleConstruct and deploy advanced Malleable C2 profiles in Cobalt Strike to deeply obfuscate Command and Control traffic. Use this skill to camouflage malicious beacons as legitimate jQuery, Amazon AWS, or Microsoft Office 365 HTTP/HTTPS web traffic, bypassing network-based IDS/IPS.
- ▌ GRAPHQL Introspection Abuse · akashrpatil bundleExploit misconfigured GraphQL endpoints possessing enabled Introspection functionality. By running a massive introspection query, an attacker can reliably extract the entire API schema, revealing hidden functionality, undocumented queries/mutations, and sensitive data structures for further exploitation.
- ▌ Cyberskills Browser · akashrpatilBrowse, search, and fetch offensive security skills from the CyberSkills Elite collection. Use this skill whenever a user wants to discover available security skills, search for specific attack techniques, list skills by category, or load a specific skill for use. Trigger for: "show me skills", "what skills do you have", "find a skill for X", "list AI red teaming skills", "search for JWT attacks", "load the SSRF skill".
- ▌ Attack Chain Composer · akashrpatilCombine multiple offensive security skills into multi-step attack chains for maximum impact. Use this skill when a user wants to chain vulnerabilities together, escalate from a low-severity finding to critical impact, plan a full kill chain, or turn a single bug into a $50K+ report. Trigger for: "chain this vulnerability", "how do I escalate this", "turn this into account takeover", "plan attack chain", "what can I chain with SSRF", "full kill chain for this target", "how to go from XSS to RCE", "compose an attack path".
- ▌ Xxe Injection Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Csrf Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Ssrf Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Server Side Template Injection Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Clickjacking Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ SQL Injection Complete Deep Dive · akashrpatil bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques