ShulkwiSEC
- 354 skills
- 0 followers
- 21 repo stars
- 2 weeks ago last updated
- ▌ LLM Jailbreaking Techniques · shulkwisec bundleSystematically bypass LLM safety filters and content moderation systems using advanced jailbreaking techniques. Use this skill when testing AI systems for safety alignment robustness, evaluating content moderation effectiveness, or conducting authorized AI red team assessments. Covers role-play attacks, few-shot manipulation, encoding bypass, multi-modal exploitation, and automated jailbreak discovery methods.
- ▌ Memory Forensics Volatility · shulkwisec bundleMemory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.
- ▌ Mobile Platform Interaction · shulkwisecDetects insecure platform interaction in mobile apps (Android/iOS). Trigger on: exported Activity, exported Service, exported BroadcastReceiver, Content Provider, Intent injection, deep link hijacking, WebView JavaScript enabled, JavascriptInterface, addJavascriptInterface, setJavaScriptEnabled, intent:// scheme, file:// scheme, WKWebView, WKScriptMessageHandler, UIPasteboard, URL scheme hijacking, Universal Links, PendingIntent, FLAG_IMMUTABLE, overlay attack, tapjacking, screenshot prevention, FLAG_SECURE, Broadcast sniffing, IPC data exposure. Covers MASVS-PLATFORM-1/2/3.
- ▌ OAUTH Oidc Misconfiguration · shulkwisecOAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.
- ▌ OAUTH State Parameter Abuse · shulkwisec bundleIdentify and exploit logic flaws in OAuth implementations, focusing specifically on the absence or improper validation of the `state` parameter, which leads to Cross-Site Request Forgery (CSRF) and account takeover (ATO).
- ▌ Phishing Payload Generation · shulkwisec bundleGenerate sophisticated initial access payloads designed to bypass email gateways and endpoint antivirus systems while executing Command and Control (C2) agents. Use this skill to craft malicious LNKs, ISOs, Weaponized Office Documents, and HTML Smuggling techniques for Red Team campaigns.
- ▌ Semgrep Custom Rule Writing · shulkwisec bundleWrite custom Semgrep rules to identify organization-specific logic flaws, improper cryptography usage, or missing authorization checks during source code review. This skill focuses on moving beyond default rulesets to locate complex vulnerabilities.
- ▌ Volatility Memory Forensics · shulkwisec bundleAnalyze full RAM captures (memory dumps) to extract forensic artifacts, detect stealthy malware, recover injected shellcode, and identify rootkits that bypass traditional disk-based antivirus scanning. Use this skill during Incident Response and advanced threat hunting engagements to identify what was actively running on a compromised system at a specific point in time.
- ▌ Websocket Hijacking Testing · shulkwisec bundleIdentify and exploit vulnerabilities within WebSocket communications, including Cross-Site WebSocket Hijacking (CSWSH), unauthenticated message spoofing, and data manipulation. Use this skill when auditing real-time applications such as trading platforms, live chat applications, or collaborative dashboards.
- ▌ Windows Event Logs Analysis · shulkwisec bundleConduct comprehensive forensic analysis of Windows Event Logs (.evtx) to trace attacker activity including lateral movement, privilege escalation, credential dumping, persistence mechanisms, and remote code execution. Use this skill during incident response, threat hunting, or post-breach forensic investigations on Windows systems and Active Directory environments.
- ▌ Windows Token Impersonation · shulkwisec bundleExecute advanced Privilege Escalation on Windows operating systems utilizing Access Token Impersonation. Use this skill (often via Potato exploits or Metasploit/Incognito) when compromising services running as Local Service or Network Service to escalate to the highest privilege level: NT AUTHORITY\SYSTEM.
- ▌ AI Report Writing Guardrails · shulkwisecPrevent common AI report pitfalls — bug blending, inflated threat models, and generic language. Train Claude with your best past reports for concise, technical submissions. Based on Critical Thinking Bug Bounty Podcast Episode 166.
- ▌ AWS Iam Privilege Escalation · shulkwisec bundleIdentify and exploit misconfigured Identity and Access Management (IAM) permissions within Amazon Web Services (AWS) to escalate privileges. Use this skill to move from a low-privileged compromised IAM user/role (e.g., via SSRF) to full AdministratorAccess by abusing AssumeRole, PassRole, inline policies, or resource attachments.
- ▌ Azure Managed Identity Abuse · shulkwisec bundleAbuse Azure Managed Identities from compromised Azure Virtual Machines (VMs), Functions, or App Services to seamlessly request valid, highly-privileged Azure AD access tokens and laterally move throughout the cloud environment without requiring explicit credentials.
- ▌ Claude Skills For Bug Bounty · shulkwisecBuild production-grade Claude Code CLI skills with fallback architecture, TypeScript implementation, and creativity directives. Based on Critical Thinking Bug Bounty Podcast Episode 166 — "Building Claude Skills as a Bug Bounty Hunter."
- ▌ Csrf Token Bypass Techniques · shulkwisec bundleIdentify and exploit Cross-Site Request Forgery (CSRF) vulnerabilities by bypassing weak or flawed anti-CSRF token implementations, SameSite cookie attributes, and Origin/Referer headers. Use this skill when testing state-changing web application endpoints for session riding attacks. Covers token removal, token fixation, multipart manipulation, and chaining with XSS for complete bypass.
- ▌ Data Exfiltration Techniques · shulkwisec bundleTest organizational egress controls by executing various data exfiltration techniques during a red team engagement. Use this skill to simulate an adversary attempting to steal sensitive data without triggering DLP (Data Loss Prevention) or network monitoring alerts. Covers exfiltration over DNS, ICMP, HTTP/S, alternative protocols (SSH/FTP), cloud services, and physical methods.
- ▌ Data Poisoning And Backdoors · shulkwisec bundleSimulate supply chain and adversarial machine learning attacks by injecting poisoned data or targeted backdoors into training and fine-tuning datasets. Use this skill when assessing the integrity controls of MLOps pipelines or evaluating the resilience of AI models against highly targeted, stealthy manipulation intended to alter model behavior on specific triggers.
- ▌ HTTP Request Smuggling Te Te · shulkwisec bundleExploit advanced HTTP Request Smuggling combining Transfer-Encoding vulnerabilities (TE.TE). By obscuring the Transfer-Encoding header, an attacker forces desynchronization between a frontend proxy (which processes the request one way) and the backend server (which processes it another way), allowing the smuggling of malicious requests to bypass security controls or poison caches.
- ▌ Kubernetes Rbac Exploitation · shulkwisec bundleExploit misconfigured Kubernetes Role-Based Access Control (RBAC) to escalate privileges within a cluster. This skill covers identifying overly permissive roles and bindings, and leveraging them to gain cluster-admin access or compromise the host nodes.
- ▌ LLM Training Data Extraction · shulkwisec bundleExtract sensitive training data (PII, API keys, intellectual property, or code) directly from a deployed Large Language Model (LLM). This AI Red Teaming skill focuses on forcing models to regurgitate memorized, unredacted data from their massive internet-scraped datasets through repetition attacks, prefix continuation, and context window manipulation.
- ▌ Mass Assignment Exploitation · shulkwisec bundleExploit Mass Assignment vulnerabilities in APIs and web frameworks to inject unauthorized parameters. This skill details how attackers uncover hidden fields and manipulate JSON or HTTP bodies to elevate privileges or tamper with data logic.
- ▌ Portable Executable Analysis · shulkwisec bundlePerform static reverse engineering and analysis on Windows Portable Executable (PE) files to identify malicious indicators without executing the file. Use this skill during Incident Response, malware triage, or threat hunting to safely extract metadata, imported APIs, exported functions, embedded strings, and packed indicators from suspicious Windows binaries (.exe, .dll, .sys).
- ▌ Prototype Pollution Advanced · shulkwisec bundleAdvanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics. Use when you've confirmed pollution and need to escalate to code execution or find framework-specific gadgets.
- ▌ Rogue Access Point Evil Twin · shulkwisec bundleDeploy an Evil Twin (Rogue Access Point) to clone a legitimate Wi-Fi network's SSID and MAC address. By combining this with targeted deauthentication attacks, an attacker aggressively forces nearby victims to silently connect to the malicious AP, enabling pervasive Man-in-the-Middle (MitM), captive portal phishing, and credentials interception.
- ▌ Self Hosted Runner Poisoning · shulkwisecUse when hunting self-hosted GitHub Actions runner vulnerabilities where fork pull requests can execute on privileged non-ephemeral runners. Trigger on: "self-hosted runner", "runs-on self-hosted", "fork PR workflow", "non-ephemeral runner", "first-time contributor approval", "runner images", "azure-builds runner", "outside collaborator approval", "runs-on matrix", "persistent runner", "Gato GitHub Attack Toolkit", "runner agent", self-hosted CI/CD runner abuse, "git config token", "workflow log deletion", runner C2.
- ▌ Windows Privilege Escalation · shulkwisec bundleWindows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, or registry autoruns.
- ▌ AI Jailbreak Prompt Injection · shulkwisec bundleExecute sophisticated Prompt Injection and Jailbreak techniques against Large Language Models (LLMs) to bypass safety filters, extract system prompts, and manipulate the AI's output to perform malicious or disallowed actions.
- ▌ AWS Cloud Penetration Testing · shulkwisec bundlePenetration test AWS cloud environments for misconfigurations, privilege escalation, data exposure, and lateral movement. Use this skill when assessing AWS accounts for security weaknesses including S3 bucket misconfigurations, IAM policy flaws, EC2 metadata exploitation, Lambda function abuse, and cross-account attack paths. Covers both external and authenticated AWS pentesting.
- ▌ Data Extraction Training Data · shulkwisec bundleExecute sophisticated Data Extraction and Privacy Leakage attacks explicitly against Large Language Models (LLMs) to natively force the neural network entirely into organically regurgitating exact, verbatim strings of Highly Confidential Personally Identifiable Information (PII), proprietary source code, or copyrighted material categorically memorized intrinsically during its foundational pre-training phase.
- ▌ Expression Language Injection · shulkwisecExpression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.
- ▌ GRAPHQL And Hidden Parameters · shulkwisecGraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.
- ▌ Host Header Injection Attacks · shulkwisec bundleExploit insecure handling of the HTTP Host header to poison password resets, generate cache poisoning vectors, or bypass internal routing restrictions. Use this skill when web applications dynamically generate URLs, links, or redirects based on the arbitrary Host header value supplied by the client rather than relying on a static, trusted server configuration.
- ▌ HTTP Request Smuggling Desync · shulkwisec bundleIdentify and exploit HTTP Request Smuggling (HTTP Desync) vulnerabilities caused by discrepancies in how front-end proxies (load balancers, CDNs) and back-end servers parse the Content-Length and Transfer-Encoding headers. Use this to bypass security controls, hijack user sessions, and poison web caches.
- ▌ IOS Application Hooking Frida · shulkwisec bundleExecute dynamic instrumentation utilizing Frida to inject custom JavaScript into running iOS applications (IPAs) on jailbroken devices. Hook native functions, bypass SSL Pinning, bypass Jailbreak Detection, and manipulate in-memory data at runtime.
- ▌ LLM Indirect Prompt Injection · shulkwisec bundleTest for indirect prompt injection vulnerabilities where malicious instructions are injected through external data sources (websites, emails, documents, database records) that the LLM processes. Use this skill when assessing LLM-integrated applications that process user-generated content, retrieve web pages, parse emails, or read documents. Covers injection via web content, email bodies, user profiles, and database records that are fed to LLM context.
- ▌ LLM Prompt Injection Indirect · shulkwisec bundleExploit AI applications using Indirect Prompt Injection. This skill focuses on hiding malicious instructions within data sources (web pages, documents, emails) that the LLM processes, causing the AI to execute unintended actions or leak data without direct user interaction.
- ▌ Ntlm Relay Smb Signing Bypass · shulkwisec bundleExecute advanced Man-in-the-Middle (MITM) NTLM Relay attacks specifically targeting environments where SMB Signing is purportedly enabled but improperly configured (e.g., exclusively required on Domain Controllers but NOT enforced universally on standard Workstations or File Servers). Utilize powerful tools like Responder and Impacket's NTLMRelayX to coercively capture NTLMv2 authentications (via LLMNR, WPAD, or Coercion methods like PetitPotam) and seamlessly relay them across the network identically yielding immediate Local Administrator command execution.
- ▌ Prompt Leaking System Prompts · shulkwisec bundleExtract the hidden foundational System Prompts, internal instructions, backend APIs, and confidential contextual data powering Large Language Model (LLM) applications using targeted prompt injection manipulation and adversarial psychological engineering.
- ▌ Web Cache Poisoning Deception · shulkwisec bundleIdentify and exploit Web Cache Poisoning vulnerabilities by manipulating unkeyed inputs (HTTP headers, hostnames) to force a caching server (CDN or reverse proxy) to save a malicious response and serve it to all subsequent users requesting the same legitimate URL.
- ▌ Active Directory Asreproasting · shulkwisec bundleExecute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag explicitly enabled. This attack generates a recoverable Ticket Granting Ticket (TGT) without requiring the attacker to authenticate first.
- ▌ Active Directory Dcsync Attack · shulkwisec bundleExecute a DCSync attack mimicking the behavior of a legitimate Active Directory Domain Controller (DC). Leverage Directory Replication Service Remote Protocol (DRSR) permissions to silently request and extract the password hashes (NTLM/Kerberos) of any or all users in the domain without executing code on the target Domain Controller.
- ▌ Active Directory Golden Ticket · shulkwisec bundleForge highly privileged Kerberos Ticket Granting Tickets (TGTs) to gain persistent, undetectable, and long-term administrative access across an entire Active Directory domain. Use this skill during the final stages of a Red Team operation after Domain Admin access has been achieved, simulating an Advanced Persistent Threat (APT) establishing deep persistence that survives password resets.
- ▌ Active Directory Kerberoasting · shulkwisec bundleExecute a Kerberoasting attack to extract and systematically crack the NTLM hashes of Service Principal Name (SPN) accounts in an Active Directory environment. Uses tools like Rubeus, Impacket (GetUserSPNs), and Hashcat to achieve domain privilege escalation domain: cybersecurity
- ▌ AWS Metadata Ssrf Exploitation · shulkwisec bundleExploit Server-Side Request Forgery (SSRF) vulnerabilities on Amazon Web Services (AWS) EC2 instances to access the highly sensitive Instance Metadata Service (IMDS). Circumvent basic protections and extract temporary IAM access keys, escalating privileges comprehensively across the AWS Cloud environment.
- ▌ Azure Ad Illicit Consent Grant · shulkwisec bundleExploit Illicit Consent Grants in Azure Active Directory (Entra ID). This skill covers crafting a malicious OAuth application to trick victims into granting broad permissions (like reading emails, modifying files) without requiring their password or MFA.
- ▌ Business Logic Vulnerabilities · shulkwisec bundleBusiness logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
- ▌ Code Obfuscation Deobfuscation · shulkwisecCode obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.
- ▌ Github Actions Cache Poisoning · shulkwisecUse when hunting GitHub Actions cache poisoning vulnerabilities where an attacker can inject malicious content into the CI/CD cache and have it restored by a privileged downstream workflow. Trigger on: "cache poisoning", "actions/cache", "actions/setup-node", "node_modules cache", "GitHub Actions cache", "pnpm cache", "LRU eviction", "10GB limit", "Cacheract", "poisoned cache", "workflow cache attack", supply chain via CI cache, "ng-renovate", "cache stuffing", scheduled workflow cache restore, shared cache key, "hashFiles package.json", cross-workflow cache, PR workflow release workflow same key, "npm install prefer-offline", Cacheract, Gato-X, supply chain npm token.
- ▌ Javascript Prototype Pollution · shulkwisec bundleIdentify and exploit Prototype Pollution vulnerabilities in JavaScript applications to achieve client-side Cross-Site Scripting (XSS), bypass authentication, or execute Remote Code Execution (RCE) on Node.js servers by manipulating the core Object prototype.
- ▌ Kerberoasting Active Directory · shulkwisec bundleExecute a Kerberoasting attack to extract Service Principal Name (SPN) ticket hashes from Active Directory and crack them offline. This allows an attacker with any valid domain credentials to escalate privileges by obtaining the plaintext password of highly-privileged service accounts.
- ▌ LLM Overreliance Hallucination · shulkwisec bundleExploit an application's absolute trust in its underlying LLM (Overreliance). Use this skill to induce critical "hallucinations" (confident falsehoods) that cause downstream logical systems or automated agents tracking the LLM's output to make destructive actions or grant unauthorized access.
- ▌ Nmap Advanced Network Scanning · shulkwisec bundlePerform advanced network scanning and service enumeration using Nmap for penetration testing and security assessments. Use this skill when conducting network reconnaissance, port scanning, service version detection, OS fingerprinting, and vulnerability scanning. Covers stealth scanning, firewall evasion, NSE script usage, and network mapping for infrastructure penetration tests.
- ▌ Open Redirect Chaining Attacks · shulkwisec bundleIdentify Open Redirect vulnerabilities where applications route users to arbitrary external URLs based on unvalidated input. Prove maximum impact by chaining Open Redirects with OAuth token theft, SSRF, or Phishing, graduating this typically low-risk finding into a high-severity report.
- ▌ Server Side Template Injection · shulkwisec bundleIdentify and exploit Server-Side Template Injection (SSTI) vulnerabilities within web applications. Use this skill when testing web applications that render dynamic content using template engines like Jinja2 (Python), Twig (PHP), Freemarker (Java), or Pug (Node.js). Covers identification via mathematical evaluation, context mapping, escaping sandboxes, and achieving Remote Code Execution (RCE).
- ▌ Smart Contract Vulnerabilities · shulkwisec bundleSmart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.
- ▌ AI Data Poisoning Model Skewing · shulkwisec bundleIdentify and simulate Data Poisoning attacks aimed at degrading or skewing an AI model's accuracy. This skill focuses on Adversarial Machine Learning concepts where attackers inject malicious or mislabelled data points into training or fine-tuning datasets (e.g., feedback loops) to bias the AI.
- ▌ Android Apk Reverse Engineering · shulkwisec bundleDecompile, analyze, and reverse engineer Android applications (APKs). Utilize tools like JADX, Apktool, and dex2jar to extract source code (Java/Kotlin), analyze manifest configurations (Intents, Activities), and identify hardcoded secrets or insecure API endpoints.
- ▌ Authbypass Authentication Flaws · shulkwisecAuthentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.
- ▌ Burp Suite Advanced Methodology · shulkwisec bundleMaster Burp Suite Professional for comprehensive web application security testing. Use this skill when performing manual web application assessments with Burp Suite including proxy interception, Scanner automation, Intruder attacks, Repeater analysis, and extension integration. Covers advanced techniques like match-and-replace rules, macro authentication, Collaborator for OOB testing, and Turbo Intruder for high-speed fuzzing.
- ▌ Cobalt Strike Beacon Operations · shulkwisec bundleOperate Cobalt Strike for red team engagements including Beacon deployment, C2 communication, post-exploitation, lateral movement, and evasion. Use this skill when conducting authorized red team operations that require a commercial C2 framework. Covers malleable C2 profiles, staged/stageless payloads, sleep and jitter configuration, SOCKS proxying, and advanced BOF (Beacon Object Files) usage for opsec-safe operations.
- ▌ Csrf Cross Site Request Forgery · shulkwisecCSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.
- ▌ Deepfake Detection And Analysis · shulkwisec bundleAnalyze and detect synthetic media, including deepfake videos, AI-generated images, and cloned voice audio. Use this skill when investigating potential disinformation campaigns, verifying the authenticity of digital evidence, or assessing social engineering attacks leveraging synthetic media (e.g., vishing with voice clones, spear-phishing with deepfake video calls). Covers artifact analysis, frequency detection, metadata tracing, and automated detection tools.
- ▌ Github Actions Script Injection · shulkwisecUse when auditing GitHub Actions workflows for script injection vulnerabilities via unsanitized context expressions. Trigger on: "github actions injection", "workflow injection", "head_ref injection", "github context injection", "pwn request", "github.head_ref", "github.event.pull_request.title", "github.event.issue.body", pull_request_target workflows, run: steps interpolating GitHub context variables, CI/CD script injection, GitHub Actions security audit.
- ▌ GRAPHQL Injection Introspection · shulkwisec bundleIdentify and exploit GraphQL API vulnerabilities by leveraging Introspection queries to dump the entire database schema, performing query batching to bypass rate limits (brute forcing), and extracting deeply nested unauthorized data via graph relationship abuse.
- ▌ Insecure Source Code Management · shulkwisecSource control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.
- ▌ JWT Forgery Algorithm Confusion · shulkwisec bundleExploit implementations of JSON Web Tokens (JWT) through algorithmic confusion (e.g., RS256 to HS256), "none" algorithm attacks, and signature stripping. Use this skill to forge administration tokens and achieve unauthenticated Account Takeover (ATO) on REST APIs and modern web applications.
- ▌ AI Jailbreak Obfuscation Ciphers · shulkwisec bundleBypass AI safety filters by encoding malicious prompts using ciphers and obfuscation techniques (e.g., Base64, ROT13, Leetspeak, Morse code). This skill exploits the gap where the LLM can decode the request, but intermediate keyword-based safety classifiers cannot.
- ▌ API Mass Assignment Exploitation · shulkwisec bundleIdentify and exploit Mass Assignment vulnerabilities in APIs. Use this skill when testing REST APIs or application forms that directly map user-supplied JSON or POST input to internal database objects. An attacker can inject undocumented variables (e.g., `is_admin`, `verified`) to illegally modify restricted properties.
- ▌ API Rate Limit Bypass Techniques · shulkwisec bundleIdentify and exploit flaws in API rate limiting enforcement. Use this skill when encountering HTTP 429 Too Many Requests errors during password brute-forcing, OTP validation, credential stuffing, or enumeration attacks. These bypasses leverage IP spoofing, parameter manipulation, and edge-case application logic.
- ▌ Idor Broken Object Authorization · shulkwisecIDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.
- ▌ Ssrf Server Side Request Forgery · shulkwisec bundleSSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
- ▌ Sysmon Process Creation Analysis · shulkwisec bundleAnalyze Sysmon Event ID 1 (Process Creation) logs to identify malicious executions, living-off-the-land binaries (LOLBins), command-line obfuscation, and suspicious parent-child process relationships.
- ▌ Active Directory Kerberos Attacks · shulkwisec bundleKerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.
- ▌ API Enumeration Fuzzing Discovery · shulkwisec bundleSystematically discover hidden Application Programming Interfaces (APIs), uncover undocumented endpoints (Shadow APIs), and fuzz parameters. Use this skill as the pivotal first step in API Bug Hunting, transforming a basic frontend application into a vast mapped attack surface.
- ▌ Broken Object Level Authorization · shulkwisec bundleIdentify and exploit Broken Object Level Authorization (BOLA), historically known as Insecure Direct Object Reference (IDOR), in API architectures. Extremely common and critical flaw where an API fails to validate whether the currently authenticated user actually owns or retains permissions over the specifically requested database resource (ID).
- ▌ Xxe XML External Entity Injection · shulkwisec bundleExploit XML External Entity (XXE) vulnerabilities in web applications to read arbitrary files, perform SSRF, or execute denial of service attacks. Use this skill when the server parses XML input from the user (such as SAML, SOAP, DOCX, or direct XML payloads).
- ▌ Active Directory Full Attack Chain · shulkwisec bundleExecute a complete Active Directory penetration test from initial enumeration to domain dominance. Use this skill for AD security assessments including LDAP enumeration, Kerberos attacks (Kerberoasting, AS-REP roasting), BloodHound attack path analysis, credential dumping with Mimikatz, lateral movement via PsExec/WMI/DCOM, DCSync for NTDS extraction, and Golden/Silver ticket forging. Covers the full kill chain from domain user to domain admin.
- ▌ Cors Cross Origin Misconfiguration · shulkwisec bundleCORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.
- ▌ Cors Misconfiguration Exploitation · shulkwisec bundleIdentify and exploit Cross-Origin Resource Sharing (CORS) misconfigurations. Use this skill when auditing APIs or web applications that share sensitive data across domains, forcing victims' browsers to inadvertently leak private information (e.g., API keys, PII, CSRF tokens) to an attacker-controlled website.
- ▌ Dom Based Cross Site Scripting Xss · shulkwisec bundleIdentify and exploit DOM-based Cross-Site Scripting (XSS) vulnerabilities where malicious payloads are executed entirely within the victim's browser via insecure JavaScript execution, often bypassing server-side WAFs completely.
- ▌ Race Condition Toctou Exploitation · shulkwisec bundleExploit Time-of-Check to Time-of-Use (TOCTOU) race conditions in web applications and APIs. Use this skill when testing transactional operations (e.g., applying coupons, transferring funds, redeeming rewards, or purchasing items) to bypass business logic and duplicate actions before the server updates its database state.
- ▌ Windows Registry Autorun Forensics · shulkwisec bundleAnalyze the Windows Registry to uncover malicious persistence mechanisms. This skill details how to investigate Run keys, Services, Scheduled Tasks registry keys, and Image File Execution Options (IFEO) to locate hidden backdoors.
- ▌ Wmi Event Subscription Persistence · shulkwisec bundle[DEPRECATED: This skill has been consolidated into wmi-event-subscriptions.] For WMI Event Subscription persistence techniques, use the comprehensive wmi-event-subscriptions skill which covers all trigger types (startup, logon, process launch, time-based), multiple consumer types (CommandLine, ActiveScript), full cleanup procedures, and OPSEC considerations.
- ▌ GRAPHQL Idor Via Introspection Leak · shulkwisecCovers object-level authorization bypass in GraphQL APIs where introspection reveals hidden fields or mutations that accept arbitrary user/resource IDs without ownership checks. Trigger on keywords like "GraphQL", "query", "mutation", "introspection", "resolver", "node ID", "relay", "object type", "schema", "batching", or "alias". Applies to dual-stack REST+GraphQL apps, Relay-style global IDs, and unauthenticated resolvers.
- ▌ RAG Poisoning And Data Exfiltration · shulkwisec bundleTest Retrieval-Augmented Generation (RAG) systems for data poisoning, prompt injection via retrieved documents, and data exfiltration through manipulated context windows. Use this skill when assessing RAG-based chatbots, knowledge bases, enterprise AI assistants, or any system that augments LLM responses with external document retrieval. Covers document injection, embedding manipulation, knowledge base poisoning, and cross-document inference attacks.
- ▌ Ssti Server Side Template Injection · shulkwisec bundleSSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.
- ▌ Unauthorized Access Common Services · shulkwisec bundleUnauthorized access playbook for common exposed services. Use when Redis, Rsync, PHP-FPM, AJP/Ghostcat, Hadoop YARN, H2 Console, or similar management interfaces are exposed without authentication.
- ▌ Active Directory Certificate Services · shulkwisec bundleAD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.
- ▌ Insecure Direct Object Reference Idor · shulkwisec bundleIdentify and exploit Insecure Direct Object Reference (IDOR), or Broken Object Level Authorization (BOLA), vulnerabilities. Manipulate internal identifiers (e.g., user IDs, database primary keys, transaction IDs) within HTTP request parameters or API payloads to unauthorizedly access, modify, or delete data belonging to other users.
- ▌ Web Application Recon And Enumeration · shulkwisec bundlePerform comprehensive web application reconnaissance and enumeration including subdomain discovery, directory bruteforcing, technology fingerprinting, port scanning, and content discovery. Use this skill as the first step in any bug bounty or web penetration test to map the target's attack surface before exploitation. Covers passive and active recon, JavaScript analysis, and API endpoint enumeration.
- ▌ Java Insecure Deserialization Ysoserial · shulkwisec bundleExploit Java Insecure Deserialization vulnerabilities leading to Remote Code Execution (RCE). Identify serialized Java objects natively passed within HTTP parameters, cookies, or sockets (e.g., `rO0AB...`). Utilize `ysoserial` to meticulously craft malignant payload chains exploiting vulnerable gadget libraries like CommonsCollections inherently present in the application's classpath.
- ▌ Phishing And Social Engineering Campaigns · shulkwisec bundlePlan and execute authorized phishing and social engineering campaigns for red team engagements. Use this skill when conducting simulated social engineering attacks including email phishing, spear phishing, vishing, pretexting, and credential harvesting. Covers GoPhish setup, pretext development, payload delivery, and measuring human vulnerability. Requires explicit written authorization before any testing.
- ▌ AI Agent Tool Abuse And Privilege Escalation · shulkwisec bundleTest AI agent systems for tool abuse, unauthorized actions, privilege escalation through tool chaining, and safety bypass via agentic workflows. Use this skill when assessing autonomous AI agents that use tool-calling (function calling, plugins, actions) to interact with external systems. Covers multi-step attack chains, implicit trust exploitation, and capability boundary testing for AI agents.
- ▌ Security Patterns · shulkwisec bundleSensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.
- ▌ Security Payloads · shulkwisec bundleEssential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
- ▌ API Recon And Docs · shulkwisecAPI reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.
- ▌ Injection Checking · shulkwisec bundleEntry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.
- ▌ JWT Null Signature · shulkwisec bundleExploit JSON Web Tokens (JWT) by implementing the 'None' algorithm attack. This skill details how to bypass authentication mechanisms when a server improperly accepts JWTs with the `alg` header set to `none`, allowing attackers to forge tokens without a valid signature.
- ▌ Mobile Auth Bypass · shulkwisecDetects authentication and biometric bypass vulnerabilities in mobile apps (Android/iOS). Trigger on: BiometricPrompt, LocalAuthentication, LAContext, evaluatePolicy, CryptoObject, Android Keystore, Secure Enclave, kSecAccessControlBiometryCurrentSet, userAuthenticationValidityDurationSeconds, confirmCredentials, biometric fallback, PIN bypass, passive authentication, enrolled biometrics detection, Frida hook auth, jailbreak bypass, TouchID, FaceID, fingerprint. Covers MASVS-AUTH-1/2/3.