ShulkwiSEC
- 354 skills
- 0 followers
- 21 repo stars
- 2 weeks ago last updated
- ▌
- ▌ Bbsa · shulkwisec bundleCLI and MCP server for the bugbounty.sa bug bounty platform (PyPI package bugbounty.sa; executables bbsa and bbsa-mcp). This skill should be used when the user asks to read data from bugbounty.sa — their researcher profile, bug bounty programs, reports, invoices, finance, transactions, leaderboard, companies, or notifications — to draft a new vulnerability report for the user to review and submit, or needs help setting up or troubleshooting the bbsa token and MCP server. Triggers on "bbsa", "bugbounty.sa", "check my reports", "list programs", "submit a report", "draft a report", "file a bug bounty report", "my leaderboard", "bug bounty platform", "bugbounty.sa MCP". Provides exact CLI commands, MCP tool mappings, and JSON output patterns.
- ▌ Cmdi Command Injection · shulkwisecCommand injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.
- ▌ Container K8S Security · shulkwisecContainer and Kubernetes security assessment. Tests container escape vectors, Docker/containerd socket exposure, K8s RBAC misconfigurations, pod security violations, exposed API servers, etcd access, service account token abuse, image layer secrets, private registry attacks, SSRF to metadata services, cross-namespace network bypass, CIS benchmarks, crypto miner detection, resource exhaustion, and admission controller gaps. Both external and internal (compromised pod) perspectives. Uses trivy, kube-bench, kubectl, nuclei, dive, amicontained, and docker-bench-security. Covers OWASP Kubernetes Top 10 and all 22 Kubernetes Goat attack scenarios.
- ▌ Email Header Injection · shulkwisecEmail header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF injection in headers, SPF/DKIM/DMARC bypass, and phishing amplification.
- ▌ Ghost Bits Cast Attack · shulkwisec bundleJava "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF injection, request smuggling, and SMTP injection. Affects Tomcat, Spring, Jetty, Undertow, Vert.x, Jackson, Fastjson, Apache Commons BCEL, Apache HttpClient, Angus Mail, JDK HttpServer, Lettuce, Jodd, XMLWriter and re-enables many "patched" CVEs through WAF bypass.
- ▌ Hash Attack Techniques · shulkwisecHash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.
- ▌ HTTP Request Smuggling · shulkwisecHTTP request smuggling exploits disagreements between a front-end proxy and back-end server on where one HTTP request ends and the next begins, using conflicting `Content-Length` and `Transfer-Encoding: chunked` headers (CL.TE, TE.CL, TE.TE variants). Enables bypassing access controls, cache poisoning, session hijacking, and capturing other users' requests. Detect via timing attacks, differential responses, and tools like Burp's HTTP Request Smuggler extension.
- ▌ Http2 Specific Attacks · shulkwisecHTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, stream multiplexing abuse, or H2→H1 downgrade translation flaws.
- ▌ Ipv6 Dns Takeover Mitm · shulkwisec bundleExecute an IPv6 DNS Spoofing attack using `mitm6` on an IPv4-only corporate network. Exploit default Windows behavior (preferring IPv6 DHCP/DNS) to intercept NTLMv2 hashes, force WPAD rogue proxy settings, and relay credentials to Active Directory services.
- ▌ Lattice Crypto Attacks · shulkwisecLattice-based cryptanalysis playbook. Use when attacking RSA via Coppersmith small roots, recovering DSA/ECDSA nonces from bias, solving knapsack problems, or applying LLL/BKZ reduction to cryptographic constructions.
- ▌ Linux Lateral Movement · shulkwisecLinux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.
- ▌ Stack Overflow And Rop · shulkwisec bundleStack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.
- ▌ Tunneling And Pivoting · shulkwisecTunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
- ▌ Wmi Event Subscription · shulkwisec bundle[DEPRECATED: This skill has been consolidated into wmi-event-subscriptions.] For WMI Event Subscription persistence techniques, use the comprehensive wmi-event-subscriptions skill which covers all trigger types (startup, logon, process launch, time-based), multiple consumer types (CommandLine, ActiveScript), full cleanup procedures, and OPSEC considerations.
- ▌ Zeek Conn Log Analysis · shulkwisec bundleAnalyze Zeek (formerly Bro) `conn.log` files to hunt for malicious network behaviors, including C2 beaconing, long-lived anomalous connections, and data exfiltration patterns.
- ▌ Browser Exploitation V8 · shulkwisec bundleBrowser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.
- ▌ Docker Container Escape · shulkwisec bundleEscape from Docker containers to the host system using container misconfigurations, mounted sockets, privileged mode, capabilities abuse, and kernel exploits. Use this skill when testing containerized environments for breakout vulnerabilities during penetration tests. Covers Docker socket mounting, cgroup escapes, nsenter techniques, and Kubernetes pod escapes.
- ▌ Ipv6 Dns Takeover Mitm6 · shulkwisec bundleExploit modern Windows environments that prefer IPv6 by using mitm6 to intercept and spoof DHCPv6 and DNS traffic. This skill covers how to poison DNS resolution for the local network, forcing NTLM authentication to a rogue server for credential capture or relay.
- ▌ JWT Algorithm Confusion · shulkwisec bundleIdentify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) to symmetric (HS256) and using the public key as the symmetric secret.
- ▌ JWT OAUTH Token Attacks · shulkwisecJWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
- ▌ Kaido Proxy Integration · shulkwisecIntegrate Kaido (Caido) proxy with Claude Code CLI for automated HTTP interception, request replay, and vulnerability scanning. Based on Critical Thinking Ep. 166.
- ▌ Macos Process Injection · shulkwisec bundlemacOS process injection playbook. Use when you need to inject code into running or launching macOS processes via dylib hijacking, DYLD environment variables, XPC exploitation, Mach port manipulation, or Electron/Chromium abuse.
- ▌ Mobile Insecure Storage · shulkwisecDetects sensitive data stored insecurely on mobile devices (Android/iOS). Trigger on: SharedPreferences, NSUserDefaults, SQLite, Room DB, DataStore, Core Data, Keychain misconfiguration, external storage, backup exposure, plaintext files, unencrypted databases, adb backup, iCloud backup, NSFileProtection, EncryptedSharedPreferences, SQLCipher, allowBackup, FLAG_SECURE, keyboard cache, sensitive logs. Covers MASVS-STORAGE-1 (local storage) and MASVS-STORAGE-2 (exposure to unauthorized actors).
- ▌ Mobile Network Security · shulkwisecDetects insecure network communication in mobile apps (Android/iOS). Trigger on: cleartext HTTP, TLS misconfiguration, certificate pinning bypass, hostname verification disabled, allowCleartextTraffic, NSAllowsArbitraryLoads, ATS exceptions, custom TrustManager, ALLOW_ALL_HOSTNAME_VERIFIER, TLS 1.0/1.1, weak cipher suites, certificate pinning absent, Network Security Configuration, onReceivedSslError, SSLSocket, OkHttp, NSURL, URLSession, certificate transparency, HSTS, MITM. Covers MASVS-NETWORK-1 (TLS required) and MASVS-NETWORK-2 (certificate validation).
- ▌ Model Inversion Attacks · shulkwisec bundleExtract sensitive training data and internal capabilities from AI models through repeated programmatic querying. Use this skill when testing LLMs and ML models for data privacy leaks, intellectual property exposure, or unintended memorization. Covers membership inference, prompt extraction, training data reconstruction, and API boundary testing.
- ▌ OAUTH Flow Exploitation · shulkwisec bundleIdentify and exploit logical flaws in OAuth 2.0 and OpenID Connect workflows. Use this skill when testing "Sign in with Google/Facebook/Apple" features, focusing on Authorization Code interception, Implicit flow token leakage, standard CSRF bypassing via missing `state` parameters, and redirect logic flaws.
- ▌ PHP Deserialization Rce · shulkwisec bundleExploit PHP object serialization vulnerabilities (Insecure Deserialization). This skill details how to identify unserialize() injection points and construct malicious serialized objects using Property Oriented Programming (POP) chains to achieve Remote Code Execution (RCE).
- ▌ Prototype Pollution Rce · shulkwisec bundleIdentify and exploit Prototype Pollution vulnerabilities in JavaScript/Node.js applications. This skill covers the progression from polluting `Object.prototype` to identifying functional gadgets (like `child_process.spawn`) to achieve Remote Code Execution (RCE).
- ▌ Psexec Lateral Movement · shulkwisec bundleExecute commands and binaries on remote Windows systems utilizing PsExec and SMB/RPC mechanisms. This skill details the mechanics behind tools like Sysinternals PsExec, Impacket's psexec.py, and their role in lateral movement via hidden administrative shares.
- ▌ Remote Hunting Workflow · shulkwisecSet up 3 remote control modes for Claude Code CLI — local iTerm pair hacking, Discord bot for mobile control, and tmux multi-pane multi-target workflows. Includes dangerouslySkipPermissions security hardening. Based on Critical Thinking Bug Bounty Podcast Episode 166.
- ▌ Ssrf AWS Metadata Abuse · shulkwisec bundleExploit Server-Side Request Forgery (SSRF) vulnerabilities in applications hosted on AWS to access the highly sensitive Instance Metadata Service (IMDS). This allows an attacker to steal valid IAM roles and temporary security credentials, leading to catastrophic cloud account compromise.
- ▌ Vm And Bytecode Reverse · shulkwisecCustom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.
- ▌ Wmi Event Subscriptions · shulkwisec bundleEstablish highly stealthy, fileless persistence on compromised Windows systems using WMI (Windows Management Instrumentation) Event Subscriptions. Create malicious Event Filters, Event Consumers, and FilterToConsumer Bindings to execute payloads (reverse shells, beacons, keyloggers) triggered by system events — startup, user logon, process creation, or time intervals. This persistence survives reboots and evades Autoruns, file-based AV, and standard EDR sweeps.
- ▌ Xxe XML External Entity · shulkwisec bundleXXE playbook. Use when XML, SVG, OOXML, SOAP, or parser-driven imports may resolve external entities, files, or internal network resources.
- ▌ Zero Day Research Skill · shulkwisecSystematic zero-day vulnerability research in source code and compiled binaries. Find bugs that scanners and AI training data have never seen. Based on Critical Thinking Bug Bounty Podcast Episode 166 and Eugene's methodology.
- ▌ Zero Logon Exploitation · shulkwisec bundleExploit the critical ZeroLogon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol (MS-NRPC) to instantly obtain Domain Administrator privileges on a Windows Active Directory domain by resetting the machine account password of the Primary Domain Controller (PDC) to an empty string.
- ▌ Binary Protection Bypass · shulkwisec bundleBinary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.
- ▌ Bug Bounty Report Writer · shulkwisec bundleWrites professional bug bounty reports for HackerOne, Bugcrowd, and Intigriti with CVSS 4.0 scoring, business impact, working exploits, and remediation. Runs 5-check Pre-Report Verification first: hallucination detection, AI writing patterns, PoC reproducibility, duplicate detection, and impact plausibility. Use when user describes a vulnerability, shares HTTP logs, HAR files, recon output, or screenshots; says 'write a bug report', 'format my finding', 'draft a vuln report', 'is this valid', 'rate my vulnerability', 'verify my report', or any variant. Trigger for partial or messy input — raw notes, one-liners, or full writeups all work. Do not wait for perfect input.
- ▌ Deserialization Insecure · shulkwisec bundleInsecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.
- ▌ Dynamic Malware Analysis · shulkwisec bundleExecute and analyze malware samples within a highly controlled, instrumented sandbox environment to observe their true behavior, network communications, file system modifications, and registry changes in real-time.
- ▌ GRAPHQL Batching Attacks · shulkwisec bundleExploit GraphQL API architectural features to execute highly efficient brute-force, Credential Stuffing, and Denial of Service (DoS) attacks. Utilize Query Batching and Alias injection to bypass rate limits by packing thousands of requests into a single HTTP POST request.
- ▌ HTTP Host Header Attacks · shulkwisecHTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.
- ▌ HTTP Parameter Pollution · shulkwisecHTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.
- ▌ Insecure Deserialization Complete Deep Dive · shulkwisec bundleComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
- ▌ Network Protocol Attacks · shulkwisec bundleNetwork protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.
- ▌ Pass The Hash And Ticket · shulkwisec bundleExecute lateral movement within Active Directory environments using credential material (NTLM hashes and Kerberos tickets) instead of plaintext passwords. Use this skill when engaging in red team operations or internal network penetration tests to expand access, bypass authentication portals, and achieve Domain Dominance without relying on crackable passwords.
- ▌ Reverse Shell Techniques · shulkwisec bundleReverse shell techniques playbook. Use when establishing remote shells including language one-liners, encrypted shells (OpenSSL/socat/ncat), web shells, PTY upgrades, file transfer methods, PowerShell shells, and Windows payload generation.
- ▌ Steganography Techniques · shulkwisec bundleSteganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.
- ▌ Symbolic Execution Tools · shulkwisec bundleSymbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or automating binary analysis with angr, Z3, or Unicorn Engine.
- ▌ Symmetric Cipher Attacks · shulkwisec bundleSymmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.
- ▌ Wifi Penetration Testing · shulkwisec bundleConduct comprehensive penetration testing against Wireless Networks (802.11). Use this skill when assessing the physical/wireless perimeter of an organization. Covers monitor mode, packet injection, WPA/WPA2 PSK cracking via 4-way handshakes and PMKID, WPA Enterprise (802.1x) evil twin attacks, WPS PIN bruteforcing, and rogue access point deployment.
- ▌ Windows Lateral Movement · shulkwisec bundleWindows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass-the-hash, overpass-the-hash, or pass-the-ticket techniques.
- ▌ Xss Cross Site Scripting · shulkwisec bundleXSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.
- ▌ Xss Reflected Stored Dom · shulkwisec bundleDetect and exploit Cross-Site Scripting (XSS) vulnerabilities including Reflected, Stored, and DOM-based variants. Use this skill when testing web applications for JavaScript injection, HTML injection, input sanitization bypass, or Content Security Policy evasion. Covers WAF bypass payloads, mutation XSS, blind XSS with out-of-band callbacks, and exploitation chains for session hijacking and account takeover.
- ▌ 401 403 Bypass Techniques · shulkwisec401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.
- ▌ Android Pentesting Tricks · shulkwisec bundleAndroid pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.
- ▌ Anti Debugging Techniques · shulkwisec bundleAnti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.
- ▌ API Authentication Bypass · shulkwisec bundleTest APIs for authentication and authorization bypass vulnerabilities including JWT manipulation, OAuth2 flaws, API key leakage, broken authentication, and token forgery. Use this skill when assessing REST/GraphQL APIs for access control weaknesses, session management flaws, or credential handling issues. Covers JWT algorithm confusion, OAuth redirect manipulation, and rate limit bypass.
- ▌ Av Edr Evasion Techniques · shulkwisec bundleBypass antivirus and Endpoint Detection & Response solutions during red team operations using payload obfuscation, process injection, AMSI bypass, ETW patching, and custom loaders. Use this skill when AV/EDR is blocking your payloads, tooling, or post-exploitation activities. Covers shellcode encryption, syscall-based injection, unhooking techniques, and living-off-the-land approaches for opsec-safe red team operations.
- ▌ Azure Ad Lateral Movement · shulkwisec bundleExecute lateral movement within Microsoft Entra ID (formerly Azure AD) and Microsoft 365 environments. Use this skill to traverse cloud resources using compromised user tokens, managed identities, Primary Refresh Tokens (PRT), and application permissions (Service Principals) to achieve Global Administrator access.
- ▌ Classical Cipher Analysis · shulkwisecClassical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or encoded text in CTF challenges that requires frequency analysis, Kasiski examination, or known-plaintext cryptanalysis.
- ▌ Cve 2023 36884 Office Rce · shulkwisec bundleExploit CVE-2023-36884, a critical Remote Code Execution vulnerability in Windows and Office associated with the Storm-0978 APT. This skill covers the weaponization of malicious Word documents to achieve code execution upon opening, bypassing Mark-of-the-Web (MotW) defenses.
- ▌ Dangling Markup Injection · shulkwisecDangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.
- ▌ Indirect Prompt Injection · shulkwisec bundleExecute Indirect Prompt Injection attacks against Large Language Models (LLMs) by subtly embedding malicious instructions within external data sources (e.g., websites, documents, databases) that the LLM autonomously ingests. This forces the model to execute attacker-controlled commands under the guise of processing legitimate user requests.
- ▌ LLM Jailbreaking Personas · shulkwisec bundleExecute advanced LLM Jailbreaking techniques using roleplay, nested environments (virtual machines), and complex personas to completely bypass safety constraints and ethical alignments embedded in AI models.
- ▌ MCP Protocol Exploitation · shulkwisec bundleTest Model Context Protocol (MCP) servers and tool-calling systems for security vulnerabilities including tool injection, parameter manipulation, privilege escalation, and data exfiltration through AI agent tool interfaces. Use this skill when assessing MCP server implementations, AI agent tool integrations, or any system that exposes tools to language models. Covers tool confusion attacks, cross-tool exploitation, and MCP server hardening assessment.
- ▌ Mobile Ssl Pinning Bypass · shulkwisecMobile SSL pinning bypass playbook. Use when intercepting HTTPS traffic from mobile applications that implement certificate pinning, public key pinning, or SPKI hash pinning on Android and iOS, including React Native, Flutter, and Xamarin frameworks.
- ▌ Sandbox Escape Techniques · shulkwisec bundleSandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browser sandbox, or namespace isolation to achieve unrestricted code execution or file access.
- ▌ Sqli Manual And Automated · shulkwisec bundleDetect and exploit SQL injection vulnerabilities using both manual techniques and automated tools. Use this skill when testing web applications for database injection flaws including UNION-based, error-based, blind boolean, blind time-based, and out-of-band SQL injection. Covers WAF bypass, second-order SQLi, authentication bypass, and full database extraction with sqlmap.
- ▌ Vlan Hopping And Trunking · shulkwisec bundleexploit misconfigured network switches to jump from a low-privilege VLAN (e.g., Guest Network) into a restricted VLAN (e.g., Corporate or Management Network). Use this skill during internal network penetration tests when physical access is achieved or when assessing network segmentation and zero-trust architectures. Covers Switch Spoofing (DTP) and Double Tagging (802.1Q).
- ▌ Windows Prefetch Analysis · shulkwisec bundleAnalyze Windows prefetch files (.pf) to determine evidence of program execution. This skill details how to extract execution times, run counts, and the paths of files accessed by a program, which is critical for incident response and malware timeline reconstruction.
- ▌ Yara Rule Writing Malware · shulkwisec bundleWrite custom YARA rules to identify and classify malware based on textual and binary patterns. This skill focuses on creating robust signatures using strings, regular expressions, and hexadecimal opcodes extracted during malware analysis for enterprise threat hunting.
- ▌ Active Directory Acl Abuse · shulkwisec bundleActive Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.
- ▌ API Authorization And Bola · shulkwisecAPI authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.
- ▌ Bug Bounty Workflow Funnel · shulkwisecImplement the 5-stage Funnel workflow (Notes → Leads → Primitives → Findings → Reports) for structured bug bounty hunting. Based on Critical Thinking Bug Bounty Podcast Episode 166.
- ▌ Cicd Bot Command Injection · shulkwisecUse when hunting CI/CD bot comment command vulnerabilities where issue_comment or pull_request_review_comment triggers invoke privileged workflows without verifying the commenter's identity or authorization. Trigger on: "bot command injection", "issue_comment trigger", "@github-actions", "slash command CI", "CI bot command", "comment triggered workflow", "unauthenticated bot", "github-actions publish", "comment dispatch", no authorization check on workflow_dispatch from comment, chatops CI/CD, supply chain via PR comment.
- ▌ Clickjacking UI Redressing · shulkwisec bundleIdentify and exploit Clickjacking (UI Redressing) vulnerabilities where a malicious website iframes a target application, tricking victims into performing unintended actions (e.g., transferring funds, deleting accounts, or granting permissions) via hidden layers.
- ▌ Cobalt Strike Malleable C2 · shulkwisec bundleCreate and implement Malleable C2 profiles in Cobalt Strike to evade network intrusion detection systems (NIDS/IPS) and endpoint detection architectures. This skill focuses on molding the Beacon's HTTP/HTTPS traffic to resemble legitimate network traffic like Amazon, Google, or jQuery.
- ▌ Command Injection Os Level · shulkwisec bundleIdentify and exploit OS Command Injection vulnerabilities where web applications insecurely pass user input into system shell commands. Use this skill when applications feature ping utilities, file conversions, network diagnostics, or PDF generators to execute arbitrary system commands and achieve Remote Code Execution (RCE).
- ▌ Domain And Asn Enumeration · shulkwisec bundleIdentify and map the external corporate footprint of a target organization. Use this skill at the absolute beginning of an engagement (Reconnaissance) to identify all registered domains, subdomains, IP ranges, and Autonomous System Numbers (ASNs) owned by the target. This skill forms the foundation for all subsequent external penetration testing and attack surface management.
- ▌ Format String Exploitation · shulkwisecFormat string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook overwrites, and canary/libc/PIE leaks.
- ▌ Idor Vulnerability Hunting · shulkwisec bundleDetect and exploit Insecure Direct Object Reference (IDOR) vulnerabilities in web applications and APIs. Use this skill when testing for unauthorized access to resources by manipulating object identifiers like user IDs, order numbers, file references, or API endpoints. Covers parameter tampering, UUID prediction, hash manipulation, and chained IDOR attacks for maximum impact in bug bounty programs.
- ▌ Linux Capabilities Privesc · shulkwisec bundleIdentify and exploit misconfigured Linux Capabilities. This skill covers how attackers escalate privileges to root without relying on SUID binaries or kernel exploits by abusing excessive capabilities like cap_dac_read_search, cap_sys_ptrace, or cap_setuid assigned to ordinary files.
- ▌ Linux Privilege Escalation · shulkwisec bundleLinux privilege escalation playbook. Use when you have low-privilege shell access and need to escalate to root via SUID/SGID binaries, capabilities, cron abuse, kernel exploits, misconfigurations, or credential harvesting on Linux systems.
- ▌ LLM Supply Chain Poisoning · shulkwisec bundleIdentify and exploit vulnerabilities in the AI Supply Chain by injecting malicious models, datasets, or dependencies. Use this skill to simulate advanced persistent threats (APTs) compromising Hugging Face repositories, manipulating pre-trained weights (Model Poisoning), and exploiting insecure deserialization during model loading (e.g., Pickle files).
- ▌ Macos Unified Log Analysis · shulkwisec bundlePerform forensic analysis of the macOS Unified Logging System (ULS) to investigate system events, application crashes, kernel panics, and potential indicators of compromise (IoCs) such as persistence mechanisms or unauthorized access.
- ▌ Nodejs Deserialization Rce · shulkwisec bundleExploit insecure deserialization in Node.js applications (specifically targeting libraries like `node-serialize`) by crafting malicious Immediately Invoked Function Expressions (IIFE) hidden within serialized JSON objects to achieve Remote Code Execution (RCE).
- ▌ Saml Sso Assertion Attacks · shulkwisecSAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.
- ▌ Spring Boot Actuator Abuse · shulkwisec bundleIdentify and exploit misconfigured Spring Boot Actuator endpoints. This skill covers how to extract sensitive configuration details, heap dumps, environment variables, and ultimately escalating to Remote Code Execution (RCE) via `spring-cloud-starter` vulnerabilities.
- ▌ Ssrf Nextjs Server Actions · shulkwisec bundleIdentify and exploit Server-Side Request Forgery (SSRF) vulnerabilities in Next.js applications, specifically focusing on insecure server actions or API routes fetching user-controlled URLs on the server-side.
- ▌ Windows Registry Forensics · shulkwisec bundleConduct expert-level incident response analysis of the Windows Registry structure (SAM, SYSTEM, SOFTWARE, NTUSER.DAT). Extract pivotal artifacts detailing threat actor execution (ShimCache, Amcache, UserAssist), persistence mechanisms (RunKeys), and lateral movement activities (RDP connections, mapped drives).
- ▌ Advanced SQL Injection Sqli · shulkwisec bundleExecute advanced SQL Injection attacks to bypass WAFs and extract data from complex architectures. Use this skill for Boolean-Based Blind, Time-Based Blind, Second-Order SQLi, and Out-of-Band (OOB) SQLi across MySQL, PostgreSQL, MSSQL, and Oracle.
- ▌ AI Data Extraction Via Ssrf · shulkwisec bundleExploit AI assistants equipped with web-browsing capabilities or internal API plugins to perform Server-Side Request Forgery (SSRF). This skill details injecting prompts that force the LLM to request sensitive internal endpoints, such as underlying cloud metadata services or internal networks.
- ▌ AI Jailbreak System Prompts · shulkwisec bundleAdvanced techniques for bypassing LLM safety filters, instruction tuning, and system prompt restrictions using specialized linguistic constructs, hypothetical scenarios, and persona adoption.
- ▌ AI Pair Hunting With Claude · shulkwisecConfigure Claude as a "Pair Hunter" — autonomous overnight hacking, context management via per-target .claudemd files, sub-agent compaction avoidance, and scope enforcement. Based on Critical Thinking Bug Bounty Podcast Episode 166.
- ▌ Certutil Download Execution · shulkwisec bundleUtilize the native Windows binary `certutil.exe` to download malicious payloads and optionally decode Base64 encoded files as a Living-off-the-Land (LotL) technique. This skill details how attackers bypass application whitelisting and fetch stage-2 implants.
- ▌ Container Escape Techniques · shulkwisec bundleContainer escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.
- ▌ GRAPHQL Introspection Abuse · shulkwisec bundleExploit exposed GraphQL introspection endpoints to map the entire API schema. This skill details how to extract available queries, mutations, types, and fields, which significantly aids in identifying hidden endpoints, Broken Object Level Authorization (BOLA/IDOR), and mass assignment vulnerabilities.
- ▌ LLM Direct Prompt Injection · shulkwisec bundleTest Large Language Models for direct prompt injection vulnerabilities where user input overrides system instructions, extracts system prompts, bypasses safety filters, or causes unauthorized actions. Use this skill when assessing chatbots, AI assistants, LLM-powered tools, or any application that processes natural language input through an LLM. Covers role-playing attacks, instruction hierarchy exploitation, multi-turn manipulation, and context window abuse for comprehensive AI security testing.