all publishers

ShulkwiSEC

@shulkwisec source repo

354 published skills · page 2 of 4

  1. ▌
    LLM Jailbreaking Techniques · shulkwisec bundle
    Systematically bypass LLM safety filters and content moderation systems using advanced jailbreaking techniques. Use this skill when testing AI systems for safety alignment robustness, evaluating content moderation effectiveness, or conducting authorized AI red team assessments. Covers role-play attacks, few-shot manipulation, encoding bypass, multi-modal exploitation, and automated jailbreak discovery methods.
    21 repo stars
  2. ▌
    Memory Forensics Volatility · shulkwisec bundle
    Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.
    21 repo stars
  3. ▌
    Mobile Platform Interaction · shulkwisec
    Detects insecure platform interaction in mobile apps (Android/iOS). Trigger on: exported Activity, exported Service, exported BroadcastReceiver, Content Provider, Intent injection, deep link hijacking, WebView JavaScript enabled, JavascriptInterface, addJavascriptInterface, setJavaScriptEnabled, intent:// scheme, file:// scheme, WKWebView, WKScriptMessageHandler, UIPasteboard, URL scheme hijacking, Universal Links, PendingIntent, FLAG_IMMUTABLE, overlay attack, tapjacking, screenshot prevention, FLAG_SECURE, Broadcast sniffing, IPC data exposure. Covers MASVS-PLATFORM-1/2/3.
    21 repo stars
  4. ▌
    OAUTH Oidc Misconfiguration · shulkwisec
    OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.
    21 repo stars
  5. ▌
    OAUTH State Parameter Abuse · shulkwisec bundle
    Identify and exploit logic flaws in OAuth implementations, focusing specifically on the absence or improper validation of the `state` parameter, which leads to Cross-Site Request Forgery (CSRF) and account takeover (ATO).
    21 repo stars
  6. ▌
    Phishing Payload Generation · shulkwisec bundle
    Generate sophisticated initial access payloads designed to bypass email gateways and endpoint antivirus systems while executing Command and Control (C2) agents. Use this skill to craft malicious LNKs, ISOs, Weaponized Office Documents, and HTML Smuggling techniques for Red Team campaigns.
    21 repo stars
  7. ▌
    Semgrep Custom Rule Writing · shulkwisec bundle
    Write custom Semgrep rules to identify organization-specific logic flaws, improper cryptography usage, or missing authorization checks during source code review. This skill focuses on moving beyond default rulesets to locate complex vulnerabilities.
    21 repo stars
  8. ▌
    Volatility Memory Forensics · shulkwisec bundle
    Analyze full RAM captures (memory dumps) to extract forensic artifacts, detect stealthy malware, recover injected shellcode, and identify rootkits that bypass traditional disk-based antivirus scanning. Use this skill during Incident Response and advanced threat hunting engagements to identify what was actively running on a compromised system at a specific point in time.
    21 repo stars
  9. ▌
    Websocket Hijacking Testing · shulkwisec bundle
    Identify and exploit vulnerabilities within WebSocket communications, including Cross-Site WebSocket Hijacking (CSWSH), unauthenticated message spoofing, and data manipulation. Use this skill when auditing real-time applications such as trading platforms, live chat applications, or collaborative dashboards.
    21 repo stars
  10. ▌
    Windows Event Logs Analysis · shulkwisec bundle
    Conduct comprehensive forensic analysis of Windows Event Logs (.evtx) to trace attacker activity including lateral movement, privilege escalation, credential dumping, persistence mechanisms, and remote code execution. Use this skill during incident response, threat hunting, or post-breach forensic investigations on Windows systems and Active Directory environments.
    21 repo stars
  11. ▌
    Windows Token Impersonation · shulkwisec bundle
    Execute advanced Privilege Escalation on Windows operating systems utilizing Access Token Impersonation. Use this skill (often via Potato exploits or Metasploit/Incognito) when compromising services running as Local Service or Network Service to escalate to the highest privilege level: NT AUTHORITY\SYSTEM.
    21 repo stars
  12. ▌
    AI Report Writing Guardrails · shulkwisec
    Prevent common AI report pitfalls — bug blending, inflated threat models, and generic language. Train Claude with your best past reports for concise, technical submissions. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  13. ▌
    AWS Iam Privilege Escalation · shulkwisec bundle
    Identify and exploit misconfigured Identity and Access Management (IAM) permissions within Amazon Web Services (AWS) to escalate privileges. Use this skill to move from a low-privileged compromised IAM user/role (e.g., via SSRF) to full AdministratorAccess by abusing AssumeRole, PassRole, inline policies, or resource attachments.
    21 repo stars
  14. ▌
    Azure Managed Identity Abuse · shulkwisec bundle
    Abuse Azure Managed Identities from compromised Azure Virtual Machines (VMs), Functions, or App Services to seamlessly request valid, highly-privileged Azure AD access tokens and laterally move throughout the cloud environment without requiring explicit credentials.
    21 repo stars
  15. ▌
    Claude Skills For Bug Bounty · shulkwisec
    Build production-grade Claude Code CLI skills with fallback architecture, TypeScript implementation, and creativity directives. Based on Critical Thinking Bug Bounty Podcast Episode 166 — "Building Claude Skills as a Bug Bounty Hunter."
    21 repo stars
  16. ▌
    Csrf Token Bypass Techniques · shulkwisec bundle
    Identify and exploit Cross-Site Request Forgery (CSRF) vulnerabilities by bypassing weak or flawed anti-CSRF token implementations, SameSite cookie attributes, and Origin/Referer headers. Use this skill when testing state-changing web application endpoints for session riding attacks. Covers token removal, token fixation, multipart manipulation, and chaining with XSS for complete bypass.
    21 repo stars
  17. ▌
    Data Exfiltration Techniques · shulkwisec bundle
    Test organizational egress controls by executing various data exfiltration techniques during a red team engagement. Use this skill to simulate an adversary attempting to steal sensitive data without triggering DLP (Data Loss Prevention) or network monitoring alerts. Covers exfiltration over DNS, ICMP, HTTP/S, alternative protocols (SSH/FTP), cloud services, and physical methods.
    21 repo stars
  18. ▌
    Data Poisoning And Backdoors · shulkwisec bundle
    Simulate supply chain and adversarial machine learning attacks by injecting poisoned data or targeted backdoors into training and fine-tuning datasets. Use this skill when assessing the integrity controls of MLOps pipelines or evaluating the resilience of AI models against highly targeted, stealthy manipulation intended to alter model behavior on specific triggers.
    21 repo stars
  19. ▌
    HTTP Request Smuggling Te Te · shulkwisec bundle
    Exploit advanced HTTP Request Smuggling combining Transfer-Encoding vulnerabilities (TE.TE). By obscuring the Transfer-Encoding header, an attacker forces desynchronization between a frontend proxy (which processes the request one way) and the backend server (which processes it another way), allowing the smuggling of malicious requests to bypass security controls or poison caches.
    21 repo stars
  20. ▌
    Kubernetes Rbac Exploitation · shulkwisec bundle
    Exploit misconfigured Kubernetes Role-Based Access Control (RBAC) to escalate privileges within a cluster. This skill covers identifying overly permissive roles and bindings, and leveraging them to gain cluster-admin access or compromise the host nodes.
    21 repo stars
  21. ▌
    LLM Training Data Extraction · shulkwisec bundle
    Extract sensitive training data (PII, API keys, intellectual property, or code) directly from a deployed Large Language Model (LLM). This AI Red Teaming skill focuses on forcing models to regurgitate memorized, unredacted data from their massive internet-scraped datasets through repetition attacks, prefix continuation, and context window manipulation.
    21 repo stars
  22. ▌
    Mass Assignment Exploitation · shulkwisec bundle
    Exploit Mass Assignment vulnerabilities in APIs and web frameworks to inject unauthorized parameters. This skill details how attackers uncover hidden fields and manipulate JSON or HTTP bodies to elevate privileges or tamper with data logic.
    21 repo stars
  23. ▌
    Portable Executable Analysis · shulkwisec bundle
    Perform static reverse engineering and analysis on Windows Portable Executable (PE) files to identify malicious indicators without executing the file. Use this skill during Incident Response, malware triage, or threat hunting to safely extract metadata, imported APIs, exported functions, embedded strings, and packed indicators from suspicious Windows binaries (.exe, .dll, .sys).
    21 repo stars
  24. ▌
    Prototype Pollution Advanced · shulkwisec bundle
    Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics. Use when you've confirmed pollution and need to escalate to code execution or find framework-specific gadgets.
    21 repo stars
  25. ▌
    Rogue Access Point Evil Twin · shulkwisec bundle
    Deploy an Evil Twin (Rogue Access Point) to clone a legitimate Wi-Fi network's SSID and MAC address. By combining this with targeted deauthentication attacks, an attacker aggressively forces nearby victims to silently connect to the malicious AP, enabling pervasive Man-in-the-Middle (MitM), captive portal phishing, and credentials interception.
    21 repo stars
  26. ▌
    Self Hosted Runner Poisoning · shulkwisec
    Use when hunting self-hosted GitHub Actions runner vulnerabilities where fork pull requests can execute on privileged non-ephemeral runners. Trigger on: "self-hosted runner", "runs-on self-hosted", "fork PR workflow", "non-ephemeral runner", "first-time contributor approval", "runner images", "azure-builds runner", "outside collaborator approval", "runs-on matrix", "persistent runner", "Gato GitHub Attack Toolkit", "runner agent", self-hosted CI/CD runner abuse, "git config token", "workflow log deletion", runner C2.
    21 repo stars
  27. ▌
    Windows Privilege Escalation · shulkwisec bundle
    Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, or registry autoruns.
    21 repo stars
  28. ▌
    AI Jailbreak Prompt Injection · shulkwisec bundle
    Execute sophisticated Prompt Injection and Jailbreak techniques against Large Language Models (LLMs) to bypass safety filters, extract system prompts, and manipulate the AI's output to perform malicious or disallowed actions.
    21 repo stars
  29. ▌
    AWS Cloud Penetration Testing · shulkwisec bundle
    Penetration test AWS cloud environments for misconfigurations, privilege escalation, data exposure, and lateral movement. Use this skill when assessing AWS accounts for security weaknesses including S3 bucket misconfigurations, IAM policy flaws, EC2 metadata exploitation, Lambda function abuse, and cross-account attack paths. Covers both external and authenticated AWS pentesting.
    21 repo stars
  30. ▌
    Data Extraction Training Data · shulkwisec bundle
    Execute sophisticated Data Extraction and Privacy Leakage attacks explicitly against Large Language Models (LLMs) to natively force the neural network entirely into organically regurgitating exact, verbatim strings of Highly Confidential Personally Identifiable Information (PII), proprietary source code, or copyrighted material categorically memorized intrinsically during its foundational pre-training phase.
    21 repo stars
  31. ▌
    Expression Language Injection · shulkwisec
    Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.
    21 repo stars
  32. ▌
    GRAPHQL And Hidden Parameters · shulkwisec
    GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.
    21 repo stars
  33. ▌
    Host Header Injection Attacks · shulkwisec bundle
    Exploit insecure handling of the HTTP Host header to poison password resets, generate cache poisoning vectors, or bypass internal routing restrictions. Use this skill when web applications dynamically generate URLs, links, or redirects based on the arbitrary Host header value supplied by the client rather than relying on a static, trusted server configuration.
    21 repo stars
  34. ▌
    HTTP Request Smuggling Desync · shulkwisec bundle
    Identify and exploit HTTP Request Smuggling (HTTP Desync) vulnerabilities caused by discrepancies in how front-end proxies (load balancers, CDNs) and back-end servers parse the Content-Length and Transfer-Encoding headers. Use this to bypass security controls, hijack user sessions, and poison web caches.
    21 repo stars
  35. ▌
    IOS Application Hooking Frida · shulkwisec bundle
    Execute dynamic instrumentation utilizing Frida to inject custom JavaScript into running iOS applications (IPAs) on jailbroken devices. Hook native functions, bypass SSL Pinning, bypass Jailbreak Detection, and manipulate in-memory data at runtime.
    21 repo stars
  36. ▌
    LLM Indirect Prompt Injection · shulkwisec bundle
    Test for indirect prompt injection vulnerabilities where malicious instructions are injected through external data sources (websites, emails, documents, database records) that the LLM processes. Use this skill when assessing LLM-integrated applications that process user-generated content, retrieve web pages, parse emails, or read documents. Covers injection via web content, email bodies, user profiles, and database records that are fed to LLM context.
    21 repo stars
  37. ▌
    LLM Prompt Injection Indirect · shulkwisec bundle
    Exploit AI applications using Indirect Prompt Injection. This skill focuses on hiding malicious instructions within data sources (web pages, documents, emails) that the LLM processes, causing the AI to execute unintended actions or leak data without direct user interaction.
    21 repo stars
  38. ▌
    Ntlm Relay Smb Signing Bypass · shulkwisec bundle
    Execute advanced Man-in-the-Middle (MITM) NTLM Relay attacks specifically targeting environments where SMB Signing is purportedly enabled but improperly configured (e.g., exclusively required on Domain Controllers but NOT enforced universally on standard Workstations or File Servers). Utilize powerful tools like Responder and Impacket's NTLMRelayX to coercively capture NTLMv2 authentications (via LLMNR, WPAD, or Coercion methods like PetitPotam) and seamlessly relay them across the network identically yielding immediate Local Administrator command execution.
    21 repo stars
  39. ▌
    Prompt Leaking System Prompts · shulkwisec bundle
    Extract the hidden foundational System Prompts, internal instructions, backend APIs, and confidential contextual data powering Large Language Model (LLM) applications using targeted prompt injection manipulation and adversarial psychological engineering.
    21 repo stars
  40. ▌
    Web Cache Poisoning Deception · shulkwisec bundle
    Identify and exploit Web Cache Poisoning vulnerabilities by manipulating unkeyed inputs (HTTP headers, hostnames) to force a caching server (CDN or reverse proxy) to save a malicious response and serve it to all subsequent users requesting the same legitimate URL.
    21 repo stars
  41. ▌
    Active Directory Asreproasting · shulkwisec bundle
    Execute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag explicitly enabled. This attack generates a recoverable Ticket Granting Ticket (TGT) without requiring the attacker to authenticate first.
    21 repo stars
  42. ▌
    Active Directory Dcsync Attack · shulkwisec bundle
    Execute a DCSync attack mimicking the behavior of a legitimate Active Directory Domain Controller (DC). Leverage Directory Replication Service Remote Protocol (DRSR) permissions to silently request and extract the password hashes (NTLM/Kerberos) of any or all users in the domain without executing code on the target Domain Controller.
    21 repo stars
  43. ▌
    Active Directory Golden Ticket · shulkwisec bundle
    Forge highly privileged Kerberos Ticket Granting Tickets (TGTs) to gain persistent, undetectable, and long-term administrative access across an entire Active Directory domain. Use this skill during the final stages of a Red Team operation after Domain Admin access has been achieved, simulating an Advanced Persistent Threat (APT) establishing deep persistence that survives password resets.
    21 repo stars
  44. ▌
    Active Directory Kerberoasting · shulkwisec bundle
    Execute a Kerberoasting attack to extract and systematically crack the NTLM hashes of Service Principal Name (SPN) accounts in an Active Directory environment. Uses tools like Rubeus, Impacket (GetUserSPNs), and Hashcat to achieve domain privilege escalation domain: cybersecurity
    21 repo stars
  45. ▌
    AWS Metadata Ssrf Exploitation · shulkwisec bundle
    Exploit Server-Side Request Forgery (SSRF) vulnerabilities on Amazon Web Services (AWS) EC2 instances to access the highly sensitive Instance Metadata Service (IMDS). Circumvent basic protections and extract temporary IAM access keys, escalating privileges comprehensively across the AWS Cloud environment.
    21 repo stars
  46. ▌
    Azure Ad Illicit Consent Grant · shulkwisec bundle
    Exploit Illicit Consent Grants in Azure Active Directory (Entra ID). This skill covers crafting a malicious OAuth application to trick victims into granting broad permissions (like reading emails, modifying files) without requiring their password or MFA.
    21 repo stars
  47. ▌
    Business Logic Vulnerabilities · shulkwisec bundle
    Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
    21 repo stars
  48. ▌
    Code Obfuscation Deobfuscation · shulkwisec
    Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.
    21 repo stars
  49. ▌
    Github Actions Cache Poisoning · shulkwisec
    Use when hunting GitHub Actions cache poisoning vulnerabilities where an attacker can inject malicious content into the CI/CD cache and have it restored by a privileged downstream workflow. Trigger on: "cache poisoning", "actions/cache", "actions/setup-node", "node_modules cache", "GitHub Actions cache", "pnpm cache", "LRU eviction", "10GB limit", "Cacheract", "poisoned cache", "workflow cache attack", supply chain via CI cache, "ng-renovate", "cache stuffing", scheduled workflow cache restore, shared cache key, "hashFiles package.json", cross-workflow cache, PR workflow release workflow same key, "npm install prefer-offline", Cacheract, Gato-X, supply chain npm token.
    21 repo stars
  50. ▌
    Javascript Prototype Pollution · shulkwisec bundle
    Identify and exploit Prototype Pollution vulnerabilities in JavaScript applications to achieve client-side Cross-Site Scripting (XSS), bypass authentication, or execute Remote Code Execution (RCE) on Node.js servers by manipulating the core Object prototype.
    21 repo stars
  51. ▌
    Kerberoasting Active Directory · shulkwisec bundle
    Execute a Kerberoasting attack to extract Service Principal Name (SPN) ticket hashes from Active Directory and crack them offline. This allows an attacker with any valid domain credentials to escalate privileges by obtaining the plaintext password of highly-privileged service accounts.
    21 repo stars
  52. ▌
    LLM Overreliance Hallucination · shulkwisec bundle
    Exploit an application's absolute trust in its underlying LLM (Overreliance). Use this skill to induce critical "hallucinations" (confident falsehoods) that cause downstream logical systems or automated agents tracking the LLM's output to make destructive actions or grant unauthorized access.
    21 repo stars
  53. ▌
    Nmap Advanced Network Scanning · shulkwisec bundle
    Perform advanced network scanning and service enumeration using Nmap for penetration testing and security assessments. Use this skill when conducting network reconnaissance, port scanning, service version detection, OS fingerprinting, and vulnerability scanning. Covers stealth scanning, firewall evasion, NSE script usage, and network mapping for infrastructure penetration tests.
    21 repo stars
  54. ▌
    Open Redirect Chaining Attacks · shulkwisec bundle
    Identify Open Redirect vulnerabilities where applications route users to arbitrary external URLs based on unvalidated input. Prove maximum impact by chaining Open Redirects with OAuth token theft, SSRF, or Phishing, graduating this typically low-risk finding into a high-severity report.
    21 repo stars
  55. ▌
    Server Side Template Injection · shulkwisec bundle
    Identify and exploit Server-Side Template Injection (SSTI) vulnerabilities within web applications. Use this skill when testing web applications that render dynamic content using template engines like Jinja2 (Python), Twig (PHP), Freemarker (Java), or Pug (Node.js). Covers identification via mathematical evaluation, context mapping, escaping sandboxes, and achieving Remote Code Execution (RCE).
    21 repo stars
  56. ▌
    Smart Contract Vulnerabilities · shulkwisec bundle
    Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.
    21 repo stars
  57. ▌
    AI Data Poisoning Model Skewing · shulkwisec bundle
    Identify and simulate Data Poisoning attacks aimed at degrading or skewing an AI model's accuracy. This skill focuses on Adversarial Machine Learning concepts where attackers inject malicious or mislabelled data points into training or fine-tuning datasets (e.g., feedback loops) to bias the AI.
    21 repo stars
  58. ▌
    Android Apk Reverse Engineering · shulkwisec bundle
    Decompile, analyze, and reverse engineer Android applications (APKs). Utilize tools like JADX, Apktool, and dex2jar to extract source code (Java/Kotlin), analyze manifest configurations (Intents, Activities), and identify hardcoded secrets or insecure API endpoints.
    21 repo stars
  59. ▌
    Authbypass Authentication Flaws · shulkwisec
    Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.
    21 repo stars
  60. ▌
    Burp Suite Advanced Methodology · shulkwisec bundle
    Master Burp Suite Professional for comprehensive web application security testing. Use this skill when performing manual web application assessments with Burp Suite including proxy interception, Scanner automation, Intruder attacks, Repeater analysis, and extension integration. Covers advanced techniques like match-and-replace rules, macro authentication, Collaborator for OOB testing, and Turbo Intruder for high-speed fuzzing.
    21 repo stars
  61. ▌
    Cobalt Strike Beacon Operations · shulkwisec bundle
    Operate Cobalt Strike for red team engagements including Beacon deployment, C2 communication, post-exploitation, lateral movement, and evasion. Use this skill when conducting authorized red team operations that require a commercial C2 framework. Covers malleable C2 profiles, staged/stageless payloads, sleep and jitter configuration, SOCKS proxying, and advanced BOF (Beacon Object Files) usage for opsec-safe operations.
    21 repo stars
  62. ▌
    Csrf Cross Site Request Forgery · shulkwisec
    CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.
    21 repo stars
  63. ▌
    Deepfake Detection And Analysis · shulkwisec bundle
    Analyze and detect synthetic media, including deepfake videos, AI-generated images, and cloned voice audio. Use this skill when investigating potential disinformation campaigns, verifying the authenticity of digital evidence, or assessing social engineering attacks leveraging synthetic media (e.g., vishing with voice clones, spear-phishing with deepfake video calls). Covers artifact analysis, frequency detection, metadata tracing, and automated detection tools.
    21 repo stars
  64. ▌
    Github Actions Script Injection · shulkwisec
    Use when auditing GitHub Actions workflows for script injection vulnerabilities via unsanitized context expressions. Trigger on: "github actions injection", "workflow injection", "head_ref injection", "github context injection", "pwn request", "github.head_ref", "github.event.pull_request.title", "github.event.issue.body", pull_request_target workflows, run: steps interpolating GitHub context variables, CI/CD script injection, GitHub Actions security audit.
    21 repo stars
  65. ▌
    GRAPHQL Injection Introspection · shulkwisec bundle
    Identify and exploit GraphQL API vulnerabilities by leveraging Introspection queries to dump the entire database schema, performing query batching to bypass rate limits (brute forcing), and extracting deeply nested unauthorized data via graph relationship abuse.
    21 repo stars
  66. ▌
    Insecure Source Code Management · shulkwisec
    Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.
    21 repo stars
  67. ▌
    JWT Forgery Algorithm Confusion · shulkwisec bundle
    Exploit implementations of JSON Web Tokens (JWT) through algorithmic confusion (e.g., RS256 to HS256), "none" algorithm attacks, and signature stripping. Use this skill to forge administration tokens and achieve unauthenticated Account Takeover (ATO) on REST APIs and modern web applications.
    21 repo stars
  68. ▌
    AI Jailbreak Obfuscation Ciphers · shulkwisec bundle
    Bypass AI safety filters by encoding malicious prompts using ciphers and obfuscation techniques (e.g., Base64, ROT13, Leetspeak, Morse code). This skill exploits the gap where the LLM can decode the request, but intermediate keyword-based safety classifiers cannot.
    21 repo stars
  69. ▌
    API Mass Assignment Exploitation · shulkwisec bundle
    Identify and exploit Mass Assignment vulnerabilities in APIs. Use this skill when testing REST APIs or application forms that directly map user-supplied JSON or POST input to internal database objects. An attacker can inject undocumented variables (e.g., `is_admin`, `verified`) to illegally modify restricted properties.
    21 repo stars
  70. ▌
    API Rate Limit Bypass Techniques · shulkwisec bundle
    Identify and exploit flaws in API rate limiting enforcement. Use this skill when encountering HTTP 429 Too Many Requests errors during password brute-forcing, OTP validation, credential stuffing, or enumeration attacks. These bypasses leverage IP spoofing, parameter manipulation, and edge-case application logic.
    21 repo stars
  71. ▌
    Idor Broken Object Authorization · shulkwisec
    IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.
    21 repo stars
  72. ▌
    Ssrf Server Side Request Forgery · shulkwisec bundle
    SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
    21 repo stars
  73. ▌
    Sysmon Process Creation Analysis · shulkwisec bundle
    Analyze Sysmon Event ID 1 (Process Creation) logs to identify malicious executions, living-off-the-land binaries (LOLBins), command-line obfuscation, and suspicious parent-child process relationships.
    21 repo stars
  74. ▌
    Active Directory Kerberos Attacks · shulkwisec bundle
    Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.
    21 repo stars
  75. ▌
    API Enumeration Fuzzing Discovery · shulkwisec bundle
    Systematically discover hidden Application Programming Interfaces (APIs), uncover undocumented endpoints (Shadow APIs), and fuzz parameters. Use this skill as the pivotal first step in API Bug Hunting, transforming a basic frontend application into a vast mapped attack surface.
    21 repo stars
  76. ▌
    Broken Object Level Authorization · shulkwisec bundle
    Identify and exploit Broken Object Level Authorization (BOLA), historically known as Insecure Direct Object Reference (IDOR), in API architectures. Extremely common and critical flaw where an API fails to validate whether the currently authenticated user actually owns or retains permissions over the specifically requested database resource (ID).
    21 repo stars
  77. ▌
    Xxe XML External Entity Injection · shulkwisec bundle
    Exploit XML External Entity (XXE) vulnerabilities in web applications to read arbitrary files, perform SSRF, or execute denial of service attacks. Use this skill when the server parses XML input from the user (such as SAML, SOAP, DOCX, or direct XML payloads).
    21 repo stars
  78. ▌
    Active Directory Full Attack Chain · shulkwisec bundle
    Execute a complete Active Directory penetration test from initial enumeration to domain dominance. Use this skill for AD security assessments including LDAP enumeration, Kerberos attacks (Kerberoasting, AS-REP roasting), BloodHound attack path analysis, credential dumping with Mimikatz, lateral movement via PsExec/WMI/DCOM, DCSync for NTDS extraction, and Golden/Silver ticket forging. Covers the full kill chain from domain user to domain admin.
    21 repo stars
  79. ▌
    Cors Cross Origin Misconfiguration · shulkwisec bundle
    CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.
    21 repo stars
  80. ▌
    Cors Misconfiguration Exploitation · shulkwisec bundle
    Identify and exploit Cross-Origin Resource Sharing (CORS) misconfigurations. Use this skill when auditing APIs or web applications that share sensitive data across domains, forcing victims' browsers to inadvertently leak private information (e.g., API keys, PII, CSRF tokens) to an attacker-controlled website.
    21 repo stars
  81. ▌
    Dom Based Cross Site Scripting Xss · shulkwisec bundle
    Identify and exploit DOM-based Cross-Site Scripting (XSS) vulnerabilities where malicious payloads are executed entirely within the victim's browser via insecure JavaScript execution, often bypassing server-side WAFs completely.
    21 repo stars
  82. ▌
    Race Condition Toctou Exploitation · shulkwisec bundle
    Exploit Time-of-Check to Time-of-Use (TOCTOU) race conditions in web applications and APIs. Use this skill when testing transactional operations (e.g., applying coupons, transferring funds, redeeming rewards, or purchasing items) to bypass business logic and duplicate actions before the server updates its database state.
    21 repo stars
  83. ▌
    Windows Registry Autorun Forensics · shulkwisec bundle
    Analyze the Windows Registry to uncover malicious persistence mechanisms. This skill details how to investigate Run keys, Services, Scheduled Tasks registry keys, and Image File Execution Options (IFEO) to locate hidden backdoors.
    21 repo stars
  84. ▌
    Wmi Event Subscription Persistence · shulkwisec bundle
    [DEPRECATED: This skill has been consolidated into wmi-event-subscriptions.] For WMI Event Subscription persistence techniques, use the comprehensive wmi-event-subscriptions skill which covers all trigger types (startup, logon, process launch, time-based), multiple consumer types (CommandLine, ActiveScript), full cleanup procedures, and OPSEC considerations.
    21 repo stars
  85. ▌
    GRAPHQL Idor Via Introspection Leak · shulkwisec
    Covers object-level authorization bypass in GraphQL APIs where introspection reveals hidden fields or mutations that accept arbitrary user/resource IDs without ownership checks. Trigger on keywords like "GraphQL", "query", "mutation", "introspection", "resolver", "node ID", "relay", "object type", "schema", "batching", or "alias". Applies to dual-stack REST+GraphQL apps, Relay-style global IDs, and unauthenticated resolvers.
    21 repo stars
  86. ▌
    RAG Poisoning And Data Exfiltration · shulkwisec bundle
    Test Retrieval-Augmented Generation (RAG) systems for data poisoning, prompt injection via retrieved documents, and data exfiltration through manipulated context windows. Use this skill when assessing RAG-based chatbots, knowledge bases, enterprise AI assistants, or any system that augments LLM responses with external document retrieval. Covers document injection, embedding manipulation, knowledge base poisoning, and cross-document inference attacks.
    21 repo stars
  87. ▌
    Ssti Server Side Template Injection · shulkwisec bundle
    SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.
    21 repo stars
  88. ▌
    Unauthorized Access Common Services · shulkwisec bundle
    Unauthorized access playbook for common exposed services. Use when Redis, Rsync, PHP-FPM, AJP/Ghostcat, Hadoop YARN, H2 Console, or similar management interfaces are exposed without authentication.
    21 repo stars
  89. ▌
    Active Directory Certificate Services · shulkwisec bundle
    AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.
    21 repo stars
  90. ▌
    Insecure Direct Object Reference Idor · shulkwisec bundle
    Identify and exploit Insecure Direct Object Reference (IDOR), or Broken Object Level Authorization (BOLA), vulnerabilities. Manipulate internal identifiers (e.g., user IDs, database primary keys, transaction IDs) within HTTP request parameters or API payloads to unauthorizedly access, modify, or delete data belonging to other users.
    21 repo stars
  91. ▌
    Web Application Recon And Enumeration · shulkwisec bundle
    Perform comprehensive web application reconnaissance and enumeration including subdomain discovery, directory bruteforcing, technology fingerprinting, port scanning, and content discovery. Use this skill as the first step in any bug bounty or web penetration test to map the target's attack surface before exploitation. Covers passive and active recon, JavaScript analysis, and API endpoint enumeration.
    21 repo stars
  92. ▌
    Java Insecure Deserialization Ysoserial · shulkwisec bundle
    Exploit Java Insecure Deserialization vulnerabilities leading to Remote Code Execution (RCE). Identify serialized Java objects natively passed within HTTP parameters, cookies, or sockets (e.g., `rO0AB...`). Utilize `ysoserial` to meticulously craft malignant payload chains exploiting vulnerable gadget libraries like CommonsCollections inherently present in the application's classpath.
    21 repo stars
  93. ▌
    Phishing And Social Engineering Campaigns · shulkwisec bundle
    Plan and execute authorized phishing and social engineering campaigns for red team engagements. Use this skill when conducting simulated social engineering attacks including email phishing, spear phishing, vishing, pretexting, and credential harvesting. Covers GoPhish setup, pretext development, payload delivery, and measuring human vulnerability. Requires explicit written authorization before any testing.
    21 repo stars
  94. ▌
    AI Agent Tool Abuse And Privilege Escalation · shulkwisec bundle
    Test AI agent systems for tool abuse, unauthorized actions, privilege escalation through tool chaining, and safety bypass via agentic workflows. Use this skill when assessing autonomous AI agents that use tool-calling (function calling, plugins, actions) to interact with external systems. Covers multi-step attack chains, implicit trust exploitation, and capability boundary testing for AI agents.
    21 repo stars
  95. ▌
    Security Patterns · shulkwisec bundle
    Sensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.
    21 repo stars
  96. ▌
    Security Payloads · shulkwisec bundle
    Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
    21 repo stars
  97. ▌
    API Recon And Docs · shulkwisec
    API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.
    21 repo stars
  98. ▌
    Injection Checking · shulkwisec bundle
    Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.
    21 repo stars
  99. ▌
    JWT Null Signature · shulkwisec bundle
    Exploit JSON Web Tokens (JWT) by implementing the 'None' algorithm attack. This skill details how to bypass authentication mechanisms when a server improperly accepts JWTs with the `alg` header set to `none`, allowing attackers to forge tokens without a valid signature.
    21 repo stars
  100. ▌
    Mobile Auth Bypass · shulkwisec
    Detects authentication and biometric bypass vulnerabilities in mobile apps (Android/iOS). Trigger on: BiometricPrompt, LocalAuthentication, LAContext, evaluatePolicy, CryptoObject, Android Keystore, Secure Enclave, kSecAccessControlBiometryCurrentSet, userAuthenticationValidityDurationSeconds, confirmCredentials, biometric fallback, PIN bypass, passive authentication, enrolled biometrics detection, Frida hook auth, jailbreak bypass, TouchID, FaceID, fingerprint. Covers MASVS-AUTH-1/2/3.
    21 repo stars