ferr079
- 32 skills
- 0 followers
- 6 hours ago last updated
- ▌ Humanizer Fr · ferr079 bundleSupprime les marques d'écriture IA dans un texte français. À utiliser pour relire ou réécrire du texte afin qu'il sonne humain. Adaptation française du skill « humanizer » de blader/humanizer, fondée sur le guide Wikipédia « Signs of AI writing ». Repère et corrige l'inflation de portée, le langage promotionnel, les attributions vagues, la voix passive, la règle de trois, le parallélisme négatif, les anglicismes calqués, les tics typographiques (guillemets droits, capitalisation à l'anglaise, abus du tiret cadratin) et les formules de remplissage propres au français.
- ▌
- ▌ Ssti · ferr079Detect and exploit server-side template injection (Jinja2, Twig, Freemarker, Velocity) up to remote code execution. Use during an authorized test when input reaches a template engine.
- ▌
- ▌
- ▌ Dns Enum · ferr079DNS enumeration and zone transfers — record analysis, brute forcing, infrastructure mapping. Use during authorized reconnaissance of a target's external surface.
- ▌ Bloodhound · ferr079Map Active Directory attack paths with BloodHound — collection, Cypher queries, shortest path to Domain Admin. Use during an authorized AD assessment.
- ▌
- ▌ Sqli Sqlmap · ferr079Exploit SQL injection with sqlmap — detection, DBMS fingerprinting, data extraction, WAF evasion, out-of-band techniques. Use during an authorized web application test.
- ▌ Web Pentest · ferr079Run a full web application penetration test — recon, authentication, session, injection, access control, business logic — mapped to OWASP WSTG. Use to structure an authorized engagement end to end.
- ▌ Xss Testing · ferr079Test for reflected, stored and DOM-based XSS with context-aware payloads and CSP bypass checks, following OWASP WSTG. Use during an authorized web application test.
- ▌ Kerberoasting · ferr079Extract and crack Kerberos service tickets with Impacket. Use during an authorized Active Directory assessment when valid domain credentials are available.
- ▌ Nmap Advanced · ferr079Advanced Nmap scanning — asset discovery, service and version enumeration, NSE scripting, timing and evasion tuning. Use during an authorized assessment when mapping a network or fingerprinting services.
- ▌
- ▌ Binary Exploit · ferr079Analyze ELF binaries for memory corruption — protections, fuzzing, ROP chains, exploit development. Use on an authorized target or a CTF binary.
- ▌ Race Condition · ferr079Find and exploit race conditions (TOCTOU, limit overrun) with parallel-request techniques. Use when testing authorized transactional functionality such as payments or coupons.
- ▌ Subdomain Enum · ferr079Enumerate subdomains with subfinder and friends, then resolve, probe and triage what is actually live. Use during authorized recon or in-scope bug bounty discovery.
- ▌
- ▌ Deserialization · ferr079Exploit insecure deserialization in Java, PHP, Python and .NET, including gadget-chain selection with ysoserial. Use during an authorized test when the target processes serialized data.
- ▌ Suricata Config · ferr079Configure Suricata as an IDS/IPS — multi-threading, capture tuning, rule management, alert output. Use when deploying or troubleshooting network monitoring.
- ▌
- ▌
- ▌ Docker Forensics · ferr079Investigate a compromised container or container host — image and layer analysis, runtime artifacts, escape indicators. Use during container incident response.
- ▌ Docker Hardening · ferr079Harden Docker for production — daemon configuration, non-root containers, capabilities, seccomp and AppArmor, image supply chain. Use when reviewing or deploying container workloads.
- ▌
- ▌ Linux Audit Logs · ferr079Investigate a Linux host through auditd and system logs — rule design, searching, reconstructing an intrusion timeline. Use when triaging suspected unauthorized access or privilege escalation.
- ▌ Security Headers · ferr079Audit HTTP security headers — CSP, HSTS, frame options, permissions policy — with concrete fixes for each gap. Use when reviewing a web application's configuration.
- ▌ Dns Exfil Analysis · ferr079Analyze DNS logs for tunneling and exfiltration using entropy, volume and query-pattern analysis. Use when investigating suspected data theft over DNS.
- ▌ Wireshark Analysis · ferr079Analyze captured traffic with Wireshark and tshark — display filters, stream reconstruction, command-and-control and exfiltration indicators. Use when investigating an intrusion from a pcap.
- ▌
- ▌
- ▌ Lateral Movement Detect · ferr079Detect lateral movement — pass-the-hash, PSExec, RDP hopping, remote service creation — from Windows and network telemetry. Use when hunting post-compromise activity.