crtvrffnrt
- 23 skills
- 0 followers
- 19 hours ago last updated
- ▌ Pentest Xss · crtvrffnrt bundleXSS assessment skill for reflected XSS, stored XSS, DOM XSS, blind XSS, CSP bypass, WAF bypass, source-to-sink analysis, browser context validation, safe payload design, and evidence collection.
- ▌ Pentest Gemini Az · crtvrffnrtAzure, Microsoft 365, Microsoft Graph, and Entra ID operator skill using the current Azure CLI session and `az rest` for scoped read, list, create, update, delete, and evidence collection tasks.
- ▌ Web Pentest Skill · crtvrffnrtAnalyze supplied artifacts from authorized web assessments with bounded defensive reasoning, evidence review, resumable workflow planning, and static reporting. Use for offline artifact analysis and explicitly reviewed task planning; never for autonomous exploitation, unreviewed target scanning, or executing model-generated commands.
- ▌ Incident Response Bec · crtvrffnrtBEC and AiTM incident-response skill for suspicious sign-ins, mailbox abuse, forwarding, inbox rules, session theft, token replay, consent abuse, and secondary phishing.
- ▌ Pentest Shodan Helper · crtvrffnrtShodan CLI-only search workflow for query design, filter selection, count/stats validation, and search-result retrieval through /root/.local/bin/shodan.
- ▌ Incident Response Main · crtvrffnrt bundleDefensive incident-response companion for Microsoft Entra ID, Microsoft 365, Defender, and mixed identity or endpoint incidents. Use for sign-in triage, public-IP enrichment, initial scoping, containment planning, and analyst-ready notes.
- ▌ Pentest Gemini Sub Htb · crtvrffnrtControlled lab skill for Hack The Box, CTF, and private lab workflows from reconnaissance, enumeration, vulnerability research, exploitation, foothold, and privilege escalation through evidence consolidation.
- ▌ Pentest Osint Linkedin · crtvrffnrt bundleAuthenticated LinkedIn OSINT helper using local `cookies.txt` and bundled scripts for people, company, role, certification, post, and network-context research.
- ▌ Pentest Web Enumeration · crtvrffnrt bundleAuthorized web enumeration for one or many websites or web applications, including live-target normalization, HTTP and TLS fingerprinting, technology and platform identification, virtual-host discovery, crawling, JavaScript and API endpoint extraction, focused directory and sensitive-file discovery, CMS-specific checks, and Nuclei-led early vulnerability triage. Use when the owner phase is practical HTTP(S) information gathering intended to identify web applications, exposed attack surface, and evidence-backed initial-access candidates before focused validation.
- ▌ Incident Response Report · crtvrffnrtIncident-response reporting skill for decision-ready summaries, timelines, containment records, executive handoff, remediation plans, and unresolved evidence gaps.
- ▌ Pentest Hacktricks Finder · crtvrffnrtSupport skill for HackTricks technique research, payload ideas, bypasses, prerequisites, caveats, and edge-case behavior across web, network, cloud, and application security topics. Use as owner only when research is the current blocker.
- ▌ Pentest Business Logic Abuse · crtvrffnrtBusiness logic and workflow abuse assessment for state-machine manipulation, race conditions, replay, quota abuse, order-of-operations flaws, delegated execution abuse, and unauthorized state transitions. Hands off to recon, input/protocol, exploit, or reporting workflows when those become the owner phase.
- ▌ Pentest Cve Reverse Engineer · crtvrffnrtManual vulnerability research skill for finding advisories, downloading affected and fixed artifacts, diffing patches, confirming root cause, and writing reliable reports across products and technologies.
- ▌ Incident Response Fileanalyser · crtvrffnrt bundleStatic malware reverse-engineering and threat-intelligence triage for unknown files, Windows EXE/PE binaries, scripts, archives, ISOs, JavaScript, PowerShell, documents, and unpacked payloads. Use when a user provides a sample path, hash, filename, or file and asks whether it is malicious, benign, suspicious, contains IoCs, or should be reverse engineered with Ghidra, strings, capa, YARA, public TI, and structured phase artifacts.
- ▌ Pentest Recon Surface Analysis · crtvrffnrtReconnaissance and attack-surface mapping for endpoint discovery, asset inventory, service enumeration, technology fingerprinting, control-plane surfaces, trust boundaries, and prioritized next tests.
- ▌ Pentest Input Protocol Manipulation · crtvrffnrtInput validation and protocol manipulation assessment for injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, and payload mutation. Hands off to authz, business-logic, exploit, or reporting workflows when those become the owner phase.
- ▌ Pentest Web Application Logic Mapper · crtvrffnrtWeb application logic mapper for spidering, crawling, hidden API discovery, workflow mapping, state-machine analysis, route relationships, and handoff targets for authz, business logic, XSS, input/protocol, OOB, CVE, exploit, or reporting workflows.
- ▌ Pentest Advanced Access Control Auditor · crtvrffnrtFocused authorization assessment for access control, IDOR, BOLA, BFLA, RBAC, object ownership, function authorization, tenant isolation, and horizontal or vertical privilege escalation. Uses paired roles, alternate objects, methods, and controls to prove boundaries safely.
- ▌ Pentest Cve Vulnerability Research Helper · crtvrffnrtCVE and vulnerability research skill for exact CVE lookup, product/version applicability, exploit maturity, KEV/PoC status, source ranking, contradiction handling, and non-destructive validation guidance.
- ▌ Pentest Exploit Execution Payload Control · crtvrffnrtDeterministic exploit execution and payload control from validated primitives. Use for exploit implementation, payload hardening, chaining confirmed weaknesses, post-exploitation proof, controlled impact demonstration, reliability notes, and rollback or containment planning.
- ▌ Pentest Outbound Interaction Oob Detection · crtvrffnrtOutbound interaction and OOB validation for SSRF callbacks, blind XSS beacons, webhook abuse, XXE/OOB behavior, DNS/HTTP/HTTPS callback correlation, asynchronous server-side interaction proof, and egress validation.
- ▌ Pentest Authentication Authorization Review · crtvrffnrtAuthentication and authorization security assessment for sessions, tokens, MFA, account takeover, IDOR, BOLA, BFLA, privilege escalation, tenant isolation, and identity boundary validation. Hands off to recon, input/protocol, access-control deep dive, exploit, or reporting workflows when those become the owner phase.
- ▌ Pentest Evidence Structuring Report Synthesis · crtvrffnrtEvidence structuring and report synthesis for confirmed findings, severity ranking, remediation guidance, executive summaries, technical appendices, and unresolved evidence gaps. Hands off to live validation workflows when proof is incomplete.