← all publishers

akashrpatil

@akashrpatil source repo

20 published skills

  1. Linux Privilege Escalation · akashrpatil bundle
    Escalate privileges from a low-privilege shell to root on Linux systems using kernel exploits, SUID binaries, capabilities, cron jobs, PATH hijacking, and misconfigured services. Use this skill during penetration tests after gaining initial access to a Linux host. Covers automated enumeration with LinPEAS, manual techniques, Docker/container escapes, and sudo abuse for complete privilege escalation.
    0 installs
  2. HTTP Request Smuggling · akashrpatil bundle
    Exploit discrepancies in how reverse proxies and back-end servers parse HTTP requests (Content-Length vs. Transfer-Encoding). This skill details CL.TE, TE.CL, and TE.TE attacks to bypass security controls, steal credentials, and execute unauthorized actions.
    0 installs
  3. Windows Privilege Escalation · akashrpatil bundle
    Escalate privileges from a standard user to SYSTEM/Administrator on Windows systems using service misconfigurations, unquoted service paths, token manipulation, registry exploits, and kernel vulnerabilities. Use this skill during penetration tests after gaining initial access to a Windows host. Covers automated enumeration with WinPEAS, PowerUp, manual techniques, UAC bypass, and potato attacks.
    0 installs
  4. Ssrf Server Side Request Forgery · akashrpatil bundle
    Detect and exploit Server-Side Request Forgery (SSRF) vulnerabilities to access internal services, cloud metadata endpoints, and restricted network resources. Use this skill when testing URL fetch features, webhook configurations, file imports, PDF generators, or any functionality that makes server-side HTTP requests. Covers blind SSRF, DNS rebinding, cloud metadata exploitation (AWS/GCP/Azure), and protocol smuggling for maximum impact.
    0 installs
  5. Business Logic Vulnerabilities Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  6. Path Traversal Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  7. Nosql Injection Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  8. Prototype Pollution Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  9. HTTP Request Smuggling Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  10. LLM Prompt Injection · akashrpatil bundle
    Identify and exploit vulnerabilities in Applications integrating Large Language Models (LLMs). Prompt Injection involves crafting inputs that override the original system instructions provided by the developer, allowing an attacker to exfiltrate data, bypass restrictions, or manipulate the AI's output logic.
    0 installs
  11. Cobalt Strike Malleable C2 · akashrpatil bundle
    Construct and deploy advanced Malleable C2 profiles in Cobalt Strike to deeply obfuscate Command and Control traffic. Use this skill to camouflage malicious beacons as legitimate jQuery, Amazon AWS, or Microsoft Office 365 HTTP/HTTPS web traffic, bypassing network-based IDS/IPS.
    0 installs
  12. GRAPHQL Introspection Abuse · akashrpatil bundle
    Exploit misconfigured GraphQL endpoints possessing enabled Introspection functionality. By running a massive introspection query, an attacker can reliably extract the entire API schema, revealing hidden functionality, undocumented queries/mutations, and sensitive data structures for further exploitation.
    0 installs
  13. Cyberskills Browser · akashrpatil
    Browse, search, and fetch offensive security skills from the CyberSkills Elite collection. Use this skill whenever a user wants to discover available security skills, search for specific attack techniques, list skills by category, or load a specific skill for use. Trigger for: "show me skills", "what skills do you have", "find a skill for X", "list AI red teaming skills", "search for JWT attacks", "load the SSRF skill".
    0 installs
  14. Attack Chain Composer · akashrpatil
    Combine multiple offensive security skills into multi-step attack chains for maximum impact. Use this skill when a user wants to chain vulnerabilities together, escalate from a low-severity finding to critical impact, plan a full kill chain, or turn a single bug into a $50K+ report. Trigger for: "chain this vulnerability", "how do I escalate this", "turn this into account takeover", "plan attack chain", "what can I chain with SSRF", "full kill chain for this target", "how to go from XSS to RCE", "compose an attack path".
    0 installs
  15. Xxe Injection Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  16. Csrf Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  17. Ssrf Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  18. Server Side Template Injection Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  19. Clickjacking Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs
  20. SQL Injection Complete Deep Dive · akashrpatil bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    0 installs