all publishers

ShulkwiSEC

@shulkwisec source repo

354 published skills · page 1 of 4

  1. ▌
    Insecure File Upload · shulkwisec
    Insecure File Upload
    21 repo stars
  2. ▌
    Bbsa · shulkwisec bundle
    CLI and MCP server for the bugbounty.sa bug bounty platform (PyPI package bugbounty.sa; executables bbsa and bbsa-mcp). This skill should be used when the user asks to read data from bugbounty.sa — their researcher profile, bug bounty programs, reports, invoices, finance, transactions, leaderboard, companies, or notifications — to draft a new vulnerability report for the user to review and submit, or needs help setting up or troubleshooting the bbsa token and MCP server. Triggers on "bbsa", "bugbounty.sa", "check my reports", "list programs", "submit a report", "draft a report", "file a bug bounty report", "my leaderboard", "bug bounty platform", "bugbounty.sa MCP". Provides exact CLI commands, MCP tool mappings, and JSON output patterns.
    21 repo stars
  3. ▌
    Cmdi Command Injection · shulkwisec
    Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.
    21 repo stars
  4. ▌
    Container K8S Security · shulkwisec
    Container and Kubernetes security assessment. Tests container escape vectors, Docker/containerd socket exposure, K8s RBAC misconfigurations, pod security violations, exposed API servers, etcd access, service account token abuse, image layer secrets, private registry attacks, SSRF to metadata services, cross-namespace network bypass, CIS benchmarks, crypto miner detection, resource exhaustion, and admission controller gaps. Both external and internal (compromised pod) perspectives. Uses trivy, kube-bench, kubectl, nuclei, dive, amicontained, and docker-bench-security. Covers OWASP Kubernetes Top 10 and all 22 Kubernetes Goat attack scenarios.
    21 repo stars
  5. ▌
    Email Header Injection · shulkwisec
    Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF injection in headers, SPF/DKIM/DMARC bypass, and phishing amplification.
    21 repo stars
  6. ▌
    Ghost Bits Cast Attack · shulkwisec bundle
    Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF injection, request smuggling, and SMTP injection. Affects Tomcat, Spring, Jetty, Undertow, Vert.x, Jackson, Fastjson, Apache Commons BCEL, Apache HttpClient, Angus Mail, JDK HttpServer, Lettuce, Jodd, XMLWriter and re-enables many "patched" CVEs through WAF bypass.
    21 repo stars
  7. ▌
    Hash Attack Techniques · shulkwisec
    Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.
    21 repo stars
  8. ▌
    HTTP Request Smuggling · shulkwisec
    HTTP request smuggling exploits disagreements between a front-end proxy and back-end server on where one HTTP request ends and the next begins, using conflicting `Content-Length` and `Transfer-Encoding: chunked` headers (CL.TE, TE.CL, TE.TE variants). Enables bypassing access controls, cache poisoning, session hijacking, and capturing other users' requests. Detect via timing attacks, differential responses, and tools like Burp's HTTP Request Smuggler extension.
    21 repo stars
  9. ▌
    Http2 Specific Attacks · shulkwisec
    HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, stream multiplexing abuse, or H2→H1 downgrade translation flaws.
    21 repo stars
  10. ▌
    Ipv6 Dns Takeover Mitm · shulkwisec bundle
    Execute an IPv6 DNS Spoofing attack using `mitm6` on an IPv4-only corporate network. Exploit default Windows behavior (preferring IPv6 DHCP/DNS) to intercept NTLMv2 hashes, force WPAD rogue proxy settings, and relay credentials to Active Directory services.
    21 repo stars
  11. ▌
    Lattice Crypto Attacks · shulkwisec
    Lattice-based cryptanalysis playbook. Use when attacking RSA via Coppersmith small roots, recovering DSA/ECDSA nonces from bias, solving knapsack problems, or applying LLL/BKZ reduction to cryptographic constructions.
    21 repo stars
  12. ▌
    Linux Lateral Movement · shulkwisec
    Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.
    21 repo stars
  13. ▌
    Stack Overflow And Rop · shulkwisec bundle
    Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.
    21 repo stars
  14. ▌
    Tunneling And Pivoting · shulkwisec
    Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
    21 repo stars
  15. ▌
    Wmi Event Subscription · shulkwisec bundle
    [DEPRECATED: This skill has been consolidated into wmi-event-subscriptions.] For WMI Event Subscription persistence techniques, use the comprehensive wmi-event-subscriptions skill which covers all trigger types (startup, logon, process launch, time-based), multiple consumer types (CommandLine, ActiveScript), full cleanup procedures, and OPSEC considerations.
    21 repo stars
  16. ▌
    Zeek Conn Log Analysis · shulkwisec bundle
    Analyze Zeek (formerly Bro) `conn.log` files to hunt for malicious network behaviors, including C2 beaconing, long-lived anomalous connections, and data exfiltration patterns.
    21 repo stars
  17. ▌
    Browser Exploitation V8 · shulkwisec bundle
    Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.
    21 repo stars
  18. ▌
    Docker Container Escape · shulkwisec bundle
    Escape from Docker containers to the host system using container misconfigurations, mounted sockets, privileged mode, capabilities abuse, and kernel exploits. Use this skill when testing containerized environments for breakout vulnerabilities during penetration tests. Covers Docker socket mounting, cgroup escapes, nsenter techniques, and Kubernetes pod escapes.
    21 repo stars
  19. ▌
    Ipv6 Dns Takeover Mitm6 · shulkwisec bundle
    Exploit modern Windows environments that prefer IPv6 by using mitm6 to intercept and spoof DHCPv6 and DNS traffic. This skill covers how to poison DNS resolution for the local network, forcing NTLM authentication to a rogue server for credential capture or relay.
    21 repo stars
  20. ▌
    JWT Algorithm Confusion · shulkwisec bundle
    Identify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) to symmetric (HS256) and using the public key as the symmetric secret.
    21 repo stars
  21. ▌
    JWT OAUTH Token Attacks · shulkwisec
    JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
    21 repo stars
  22. ▌
    Kaido Proxy Integration · shulkwisec
    Integrate Kaido (Caido) proxy with Claude Code CLI for automated HTTP interception, request replay, and vulnerability scanning. Based on Critical Thinking Ep. 166.
    21 repo stars
  23. ▌
    Macos Process Injection · shulkwisec bundle
    macOS process injection playbook. Use when you need to inject code into running or launching macOS processes via dylib hijacking, DYLD environment variables, XPC exploitation, Mach port manipulation, or Electron/Chromium abuse.
    21 repo stars
  24. ▌
    Mobile Insecure Storage · shulkwisec
    Detects sensitive data stored insecurely on mobile devices (Android/iOS). Trigger on: SharedPreferences, NSUserDefaults, SQLite, Room DB, DataStore, Core Data, Keychain misconfiguration, external storage, backup exposure, plaintext files, unencrypted databases, adb backup, iCloud backup, NSFileProtection, EncryptedSharedPreferences, SQLCipher, allowBackup, FLAG_SECURE, keyboard cache, sensitive logs. Covers MASVS-STORAGE-1 (local storage) and MASVS-STORAGE-2 (exposure to unauthorized actors).
    21 repo stars
  25. ▌
    Mobile Network Security · shulkwisec
    Detects insecure network communication in mobile apps (Android/iOS). Trigger on: cleartext HTTP, TLS misconfiguration, certificate pinning bypass, hostname verification disabled, allowCleartextTraffic, NSAllowsArbitraryLoads, ATS exceptions, custom TrustManager, ALLOW_ALL_HOSTNAME_VERIFIER, TLS 1.0/1.1, weak cipher suites, certificate pinning absent, Network Security Configuration, onReceivedSslError, SSLSocket, OkHttp, NSURL, URLSession, certificate transparency, HSTS, MITM. Covers MASVS-NETWORK-1 (TLS required) and MASVS-NETWORK-2 (certificate validation).
    21 repo stars
  26. ▌
    Model Inversion Attacks · shulkwisec bundle
    Extract sensitive training data and internal capabilities from AI models through repeated programmatic querying. Use this skill when testing LLMs and ML models for data privacy leaks, intellectual property exposure, or unintended memorization. Covers membership inference, prompt extraction, training data reconstruction, and API boundary testing.
    21 repo stars
  27. ▌
    OAUTH Flow Exploitation · shulkwisec bundle
    Identify and exploit logical flaws in OAuth 2.0 and OpenID Connect workflows. Use this skill when testing "Sign in with Google/Facebook/Apple" features, focusing on Authorization Code interception, Implicit flow token leakage, standard CSRF bypassing via missing `state` parameters, and redirect logic flaws.
    21 repo stars
  28. ▌
    PHP Deserialization Rce · shulkwisec bundle
    Exploit PHP object serialization vulnerabilities (Insecure Deserialization). This skill details how to identify unserialize() injection points and construct malicious serialized objects using Property Oriented Programming (POP) chains to achieve Remote Code Execution (RCE).
    21 repo stars
  29. ▌
    Prototype Pollution Rce · shulkwisec bundle
    Identify and exploit Prototype Pollution vulnerabilities in JavaScript/Node.js applications. This skill covers the progression from polluting `Object.prototype` to identifying functional gadgets (like `child_process.spawn`) to achieve Remote Code Execution (RCE).
    21 repo stars
  30. ▌
    Psexec Lateral Movement · shulkwisec bundle
    Execute commands and binaries on remote Windows systems utilizing PsExec and SMB/RPC mechanisms. This skill details the mechanics behind tools like Sysinternals PsExec, Impacket's psexec.py, and their role in lateral movement via hidden administrative shares.
    21 repo stars
  31. ▌
    Remote Hunting Workflow · shulkwisec
    Set up 3 remote control modes for Claude Code CLI — local iTerm pair hacking, Discord bot for mobile control, and tmux multi-pane multi-target workflows. Includes dangerouslySkipPermissions security hardening. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  32. ▌
    Ssrf AWS Metadata Abuse · shulkwisec bundle
    Exploit Server-Side Request Forgery (SSRF) vulnerabilities in applications hosted on AWS to access the highly sensitive Instance Metadata Service (IMDS). This allows an attacker to steal valid IAM roles and temporary security credentials, leading to catastrophic cloud account compromise.
    21 repo stars
  33. ▌
    Vm And Bytecode Reverse · shulkwisec
    Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.
    21 repo stars
  34. ▌
    Wmi Event Subscriptions · shulkwisec bundle
    Establish highly stealthy, fileless persistence on compromised Windows systems using WMI (Windows Management Instrumentation) Event Subscriptions. Create malicious Event Filters, Event Consumers, and FilterToConsumer Bindings to execute payloads (reverse shells, beacons, keyloggers) triggered by system events — startup, user logon, process creation, or time intervals. This persistence survives reboots and evades Autoruns, file-based AV, and standard EDR sweeps.
    21 repo stars
  35. ▌
    Xxe XML External Entity · shulkwisec bundle
    XXE playbook. Use when XML, SVG, OOXML, SOAP, or parser-driven imports may resolve external entities, files, or internal network resources.
    21 repo stars
  36. ▌
    Zero Day Research Skill · shulkwisec
    Systematic zero-day vulnerability research in source code and compiled binaries. Find bugs that scanners and AI training data have never seen. Based on Critical Thinking Bug Bounty Podcast Episode 166 and Eugene's methodology.
    21 repo stars
  37. ▌
    Zero Logon Exploitation · shulkwisec bundle
    Exploit the critical ZeroLogon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol (MS-NRPC) to instantly obtain Domain Administrator privileges on a Windows Active Directory domain by resetting the machine account password of the Primary Domain Controller (PDC) to an empty string.
    21 repo stars
  38. ▌
    Binary Protection Bypass · shulkwisec bundle
    Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.
    21 repo stars
  39. ▌
    Bug Bounty Report Writer · shulkwisec bundle
    Writes professional bug bounty reports for HackerOne, Bugcrowd, and Intigriti with CVSS 4.0 scoring, business impact, working exploits, and remediation. Runs 5-check Pre-Report Verification first: hallucination detection, AI writing patterns, PoC reproducibility, duplicate detection, and impact plausibility. Use when user describes a vulnerability, shares HTTP logs, HAR files, recon output, or screenshots; says 'write a bug report', 'format my finding', 'draft a vuln report', 'is this valid', 'rate my vulnerability', 'verify my report', or any variant. Trigger for partial or messy input — raw notes, one-liners, or full writeups all work. Do not wait for perfect input.
    21 repo stars
  40. ▌
    Deserialization Insecure · shulkwisec bundle
    Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.
    21 repo stars
  41. ▌
    Dynamic Malware Analysis · shulkwisec bundle
    Execute and analyze malware samples within a highly controlled, instrumented sandbox environment to observe their true behavior, network communications, file system modifications, and registry changes in real-time.
    21 repo stars
  42. ▌
    GRAPHQL Batching Attacks · shulkwisec bundle
    Exploit GraphQL API architectural features to execute highly efficient brute-force, Credential Stuffing, and Denial of Service (DoS) attacks. Utilize Query Batching and Alias injection to bypass rate limits by packing thousands of requests into a single HTTP POST request.
    21 repo stars
  43. ▌
    HTTP Host Header Attacks · shulkwisec
    HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.
    21 repo stars
  44. ▌
    HTTP Parameter Pollution · shulkwisec
    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.
    21 repo stars
  45. ▌
    Insecure Deserialization Complete Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  46. ▌
    Network Protocol Attacks · shulkwisec bundle
    Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.
    21 repo stars
  47. ▌
    Pass The Hash And Ticket · shulkwisec bundle
    Execute lateral movement within Active Directory environments using credential material (NTLM hashes and Kerberos tickets) instead of plaintext passwords. Use this skill when engaging in red team operations or internal network penetration tests to expand access, bypass authentication portals, and achieve Domain Dominance without relying on crackable passwords.
    21 repo stars
  48. ▌
    Reverse Shell Techniques · shulkwisec bundle
    Reverse shell techniques playbook. Use when establishing remote shells including language one-liners, encrypted shells (OpenSSL/socat/ncat), web shells, PTY upgrades, file transfer methods, PowerShell shells, and Windows payload generation.
    21 repo stars
  49. ▌
    Steganography Techniques · shulkwisec bundle
    Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.
    21 repo stars
  50. ▌
    Symbolic Execution Tools · shulkwisec bundle
    Symbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or automating binary analysis with angr, Z3, or Unicorn Engine.
    21 repo stars
  51. ▌
    Symmetric Cipher Attacks · shulkwisec bundle
    Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.
    21 repo stars
  52. ▌
    Wifi Penetration Testing · shulkwisec bundle
    Conduct comprehensive penetration testing against Wireless Networks (802.11). Use this skill when assessing the physical/wireless perimeter of an organization. Covers monitor mode, packet injection, WPA/WPA2 PSK cracking via 4-way handshakes and PMKID, WPA Enterprise (802.1x) evil twin attacks, WPS PIN bruteforcing, and rogue access point deployment.
    21 repo stars
  53. ▌
    Windows Lateral Movement · shulkwisec bundle
    Windows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass-the-hash, overpass-the-hash, or pass-the-ticket techniques.
    21 repo stars
  54. ▌
    Xss Cross Site Scripting · shulkwisec bundle
    XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.
    21 repo stars
  55. ▌
    Xss Reflected Stored Dom · shulkwisec bundle
    Detect and exploit Cross-Site Scripting (XSS) vulnerabilities including Reflected, Stored, and DOM-based variants. Use this skill when testing web applications for JavaScript injection, HTML injection, input sanitization bypass, or Content Security Policy evasion. Covers WAF bypass payloads, mutation XSS, blind XSS with out-of-band callbacks, and exploitation chains for session hijacking and account takeover.
    21 repo stars
  56. ▌
    401 403 Bypass Techniques · shulkwisec
    401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.
    21 repo stars
  57. ▌
    Android Pentesting Tricks · shulkwisec bundle
    Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.
    21 repo stars
  58. ▌
    Anti Debugging Techniques · shulkwisec bundle
    Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.
    21 repo stars
  59. ▌
    API Authentication Bypass · shulkwisec bundle
    Test APIs for authentication and authorization bypass vulnerabilities including JWT manipulation, OAuth2 flaws, API key leakage, broken authentication, and token forgery. Use this skill when assessing REST/GraphQL APIs for access control weaknesses, session management flaws, or credential handling issues. Covers JWT algorithm confusion, OAuth redirect manipulation, and rate limit bypass.
    21 repo stars
  60. ▌
    Av Edr Evasion Techniques · shulkwisec bundle
    Bypass antivirus and Endpoint Detection & Response solutions during red team operations using payload obfuscation, process injection, AMSI bypass, ETW patching, and custom loaders. Use this skill when AV/EDR is blocking your payloads, tooling, or post-exploitation activities. Covers shellcode encryption, syscall-based injection, unhooking techniques, and living-off-the-land approaches for opsec-safe red team operations.
    21 repo stars
  61. ▌
    Azure Ad Lateral Movement · shulkwisec bundle
    Execute lateral movement within Microsoft Entra ID (formerly Azure AD) and Microsoft 365 environments. Use this skill to traverse cloud resources using compromised user tokens, managed identities, Primary Refresh Tokens (PRT), and application permissions (Service Principals) to achieve Global Administrator access.
    21 repo stars
  62. ▌
    Classical Cipher Analysis · shulkwisec
    Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or encoded text in CTF challenges that requires frequency analysis, Kasiski examination, or known-plaintext cryptanalysis.
    21 repo stars
  63. ▌
    Cve 2023 36884 Office Rce · shulkwisec bundle
    Exploit CVE-2023-36884, a critical Remote Code Execution vulnerability in Windows and Office associated with the Storm-0978 APT. This skill covers the weaponization of malicious Word documents to achieve code execution upon opening, bypassing Mark-of-the-Web (MotW) defenses.
    21 repo stars
  64. ▌
    Dangling Markup Injection · shulkwisec
    Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.
    21 repo stars
  65. ▌
    Indirect Prompt Injection · shulkwisec bundle
    Execute Indirect Prompt Injection attacks against Large Language Models (LLMs) by subtly embedding malicious instructions within external data sources (e.g., websites, documents, databases) that the LLM autonomously ingests. This forces the model to execute attacker-controlled commands under the guise of processing legitimate user requests.
    21 repo stars
  66. ▌
    LLM Jailbreaking Personas · shulkwisec bundle
    Execute advanced LLM Jailbreaking techniques using roleplay, nested environments (virtual machines), and complex personas to completely bypass safety constraints and ethical alignments embedded in AI models.
    21 repo stars
  67. ▌
    MCP Protocol Exploitation · shulkwisec bundle
    Test Model Context Protocol (MCP) servers and tool-calling systems for security vulnerabilities including tool injection, parameter manipulation, privilege escalation, and data exfiltration through AI agent tool interfaces. Use this skill when assessing MCP server implementations, AI agent tool integrations, or any system that exposes tools to language models. Covers tool confusion attacks, cross-tool exploitation, and MCP server hardening assessment.
    21 repo stars
  68. ▌
    Mobile Ssl Pinning Bypass · shulkwisec
    Mobile SSL pinning bypass playbook. Use when intercepting HTTPS traffic from mobile applications that implement certificate pinning, public key pinning, or SPKI hash pinning on Android and iOS, including React Native, Flutter, and Xamarin frameworks.
    21 repo stars
  69. ▌
    Sandbox Escape Techniques · shulkwisec bundle
    Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browser sandbox, or namespace isolation to achieve unrestricted code execution or file access.
    21 repo stars
  70. ▌
    Sqli Manual And Automated · shulkwisec bundle
    Detect and exploit SQL injection vulnerabilities using both manual techniques and automated tools. Use this skill when testing web applications for database injection flaws including UNION-based, error-based, blind boolean, blind time-based, and out-of-band SQL injection. Covers WAF bypass, second-order SQLi, authentication bypass, and full database extraction with sqlmap.
    21 repo stars
  71. ▌
    Vlan Hopping And Trunking · shulkwisec bundle
    exploit misconfigured network switches to jump from a low-privilege VLAN (e.g., Guest Network) into a restricted VLAN (e.g., Corporate or Management Network). Use this skill during internal network penetration tests when physical access is achieved or when assessing network segmentation and zero-trust architectures. Covers Switch Spoofing (DTP) and Double Tagging (802.1Q).
    21 repo stars
  72. ▌
    Windows Prefetch Analysis · shulkwisec bundle
    Analyze Windows prefetch files (.pf) to determine evidence of program execution. This skill details how to extract execution times, run counts, and the paths of files accessed by a program, which is critical for incident response and malware timeline reconstruction.
    21 repo stars
  73. ▌
    Yara Rule Writing Malware · shulkwisec bundle
    Write custom YARA rules to identify and classify malware based on textual and binary patterns. This skill focuses on creating robust signatures using strings, regular expressions, and hexadecimal opcodes extracted during malware analysis for enterprise threat hunting.
    21 repo stars
  74. ▌
    Active Directory Acl Abuse · shulkwisec bundle
    Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.
    21 repo stars
  75. ▌
    API Authorization And Bola · shulkwisec
    API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.
    21 repo stars
  76. ▌
    Bug Bounty Workflow Funnel · shulkwisec
    Implement the 5-stage Funnel workflow (Notes → Leads → Primitives → Findings → Reports) for structured bug bounty hunting. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  77. ▌
    Cicd Bot Command Injection · shulkwisec
    Use when hunting CI/CD bot comment command vulnerabilities where issue_comment or pull_request_review_comment triggers invoke privileged workflows without verifying the commenter's identity or authorization. Trigger on: "bot command injection", "issue_comment trigger", "@github-actions", "slash command CI", "CI bot command", "comment triggered workflow", "unauthenticated bot", "github-actions publish", "comment dispatch", no authorization check on workflow_dispatch from comment, chatops CI/CD, supply chain via PR comment.
    21 repo stars
  78. ▌
    Clickjacking UI Redressing · shulkwisec bundle
    Identify and exploit Clickjacking (UI Redressing) vulnerabilities where a malicious website iframes a target application, tricking victims into performing unintended actions (e.g., transferring funds, deleting accounts, or granting permissions) via hidden layers.
    21 repo stars
  79. ▌
    Cobalt Strike Malleable C2 · shulkwisec bundle
    Create and implement Malleable C2 profiles in Cobalt Strike to evade network intrusion detection systems (NIDS/IPS) and endpoint detection architectures. This skill focuses on molding the Beacon's HTTP/HTTPS traffic to resemble legitimate network traffic like Amazon, Google, or jQuery.
    21 repo stars
  80. ▌
    Command Injection Os Level · shulkwisec bundle
    Identify and exploit OS Command Injection vulnerabilities where web applications insecurely pass user input into system shell commands. Use this skill when applications feature ping utilities, file conversions, network diagnostics, or PDF generators to execute arbitrary system commands and achieve Remote Code Execution (RCE).
    21 repo stars
  81. ▌
    Domain And Asn Enumeration · shulkwisec bundle
    Identify and map the external corporate footprint of a target organization. Use this skill at the absolute beginning of an engagement (Reconnaissance) to identify all registered domains, subdomains, IP ranges, and Autonomous System Numbers (ASNs) owned by the target. This skill forms the foundation for all subsequent external penetration testing and attack surface management.
    21 repo stars
  82. ▌
    Format String Exploitation · shulkwisec
    Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook overwrites, and canary/libc/PIE leaks.
    21 repo stars
  83. ▌
    Idor Vulnerability Hunting · shulkwisec bundle
    Detect and exploit Insecure Direct Object Reference (IDOR) vulnerabilities in web applications and APIs. Use this skill when testing for unauthorized access to resources by manipulating object identifiers like user IDs, order numbers, file references, or API endpoints. Covers parameter tampering, UUID prediction, hash manipulation, and chained IDOR attacks for maximum impact in bug bounty programs.
    21 repo stars
  84. ▌
    Linux Capabilities Privesc · shulkwisec bundle
    Identify and exploit misconfigured Linux Capabilities. This skill covers how attackers escalate privileges to root without relying on SUID binaries or kernel exploits by abusing excessive capabilities like cap_dac_read_search, cap_sys_ptrace, or cap_setuid assigned to ordinary files.
    21 repo stars
  85. ▌
    Linux Privilege Escalation · shulkwisec bundle
    Linux privilege escalation playbook. Use when you have low-privilege shell access and need to escalate to root via SUID/SGID binaries, capabilities, cron abuse, kernel exploits, misconfigurations, or credential harvesting on Linux systems.
    21 repo stars
  86. ▌
    LLM Supply Chain Poisoning · shulkwisec bundle
    Identify and exploit vulnerabilities in the AI Supply Chain by injecting malicious models, datasets, or dependencies. Use this skill to simulate advanced persistent threats (APTs) compromising Hugging Face repositories, manipulating pre-trained weights (Model Poisoning), and exploiting insecure deserialization during model loading (e.g., Pickle files).
    21 repo stars
  87. ▌
    Macos Unified Log Analysis · shulkwisec bundle
    Perform forensic analysis of the macOS Unified Logging System (ULS) to investigate system events, application crashes, kernel panics, and potential indicators of compromise (IoCs) such as persistence mechanisms or unauthorized access.
    21 repo stars
  88. ▌
    Nodejs Deserialization Rce · shulkwisec bundle
    Exploit insecure deserialization in Node.js applications (specifically targeting libraries like `node-serialize`) by crafting malicious Immediately Invoked Function Expressions (IIFE) hidden within serialized JSON objects to achieve Remote Code Execution (RCE).
    21 repo stars
  89. ▌
    Saml Sso Assertion Attacks · shulkwisec
    SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.
    21 repo stars
  90. ▌
    Spring Boot Actuator Abuse · shulkwisec bundle
    Identify and exploit misconfigured Spring Boot Actuator endpoints. This skill covers how to extract sensitive configuration details, heap dumps, environment variables, and ultimately escalating to Remote Code Execution (RCE) via `spring-cloud-starter` vulnerabilities.
    21 repo stars
  91. ▌
    Ssrf Nextjs Server Actions · shulkwisec bundle
    Identify and exploit Server-Side Request Forgery (SSRF) vulnerabilities in Next.js applications, specifically focusing on insecure server actions or API routes fetching user-controlled URLs on the server-side.
    21 repo stars
  92. ▌
    Windows Registry Forensics · shulkwisec bundle
    Conduct expert-level incident response analysis of the Windows Registry structure (SAM, SYSTEM, SOFTWARE, NTUSER.DAT). Extract pivotal artifacts detailing threat actor execution (ShimCache, Amcache, UserAssist), persistence mechanisms (RunKeys), and lateral movement activities (RDP connections, mapped drives).
    21 repo stars
  93. ▌
    Advanced SQL Injection Sqli · shulkwisec bundle
    Execute advanced SQL Injection attacks to bypass WAFs and extract data from complex architectures. Use this skill for Boolean-Based Blind, Time-Based Blind, Second-Order SQLi, and Out-of-Band (OOB) SQLi across MySQL, PostgreSQL, MSSQL, and Oracle.
    21 repo stars
  94. ▌
    AI Data Extraction Via Ssrf · shulkwisec bundle
    Exploit AI assistants equipped with web-browsing capabilities or internal API plugins to perform Server-Side Request Forgery (SSRF). This skill details injecting prompts that force the LLM to request sensitive internal endpoints, such as underlying cloud metadata services or internal networks.
    21 repo stars
  95. ▌
    AI Jailbreak System Prompts · shulkwisec bundle
    Advanced techniques for bypassing LLM safety filters, instruction tuning, and system prompt restrictions using specialized linguistic constructs, hypothetical scenarios, and persona adoption.
    21 repo stars
  96. ▌
    AI Pair Hunting With Claude · shulkwisec
    Configure Claude as a "Pair Hunter" — autonomous overnight hacking, context management via per-target .claudemd files, sub-agent compaction avoidance, and scope enforcement. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  97. ▌
    Certutil Download Execution · shulkwisec bundle
    Utilize the native Windows binary `certutil.exe` to download malicious payloads and optionally decode Base64 encoded files as a Living-off-the-Land (LotL) technique. This skill details how attackers bypass application whitelisting and fetch stage-2 implants.
    21 repo stars
  98. ▌
    Container Escape Techniques · shulkwisec bundle
    Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.
    21 repo stars
  99. ▌
    GRAPHQL Introspection Abuse · shulkwisec bundle
    Exploit exposed GraphQL introspection endpoints to map the entire API schema. This skill details how to extract available queries, mutations, types, and fields, which significantly aids in identifying hidden endpoints, Broken Object Level Authorization (BOLA/IDOR), and mass assignment vulnerabilities.
    21 repo stars
  100. ▌
    LLM Direct Prompt Injection · shulkwisec bundle
    Test Large Language Models for direct prompt injection vulnerabilities where user input overrides system instructions, extracts system prompts, bypasses safety filters, or causes unauthorized actions. Use this skill when assessing chatbots, AI assistants, LLM-powered tools, or any application that processes natural language input through an LLM. Covers role-playing attacks, instruction hierarchy exploitation, multi-turn manipulation, and context window abuse for comprehensive AI security testing.
    21 repo stars