← all publishers

wufufu770

@wufufu770 source repo

232 published skills · page 2 of 3

  1. IOS Redteam Pipeline · wufufu770
    App Store search API (no auth, no scraping needed)
    0
    installs
  2. Hunt Business Logic · wufufu770
    Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow (Shipt), client-side checkout amount trust on PayPal redirect (WordPress.org), price-per-unit mass-assignment (Krisp), and archived-price swap /
    0
    installs
  3. Hunt Race Condition · wufufu770
    Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Ke
    0
    installs
  4. Operating Havoc C2 · wufufu770
    Deploy a Havoc C2 team server with Yaotl malleable profiles, generate evasive Demon agents using indirect syscalls and sleep obfuscation, an…
    0
    installs
  5. Hunt Deserialization · wufufu770
    Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NET BinaryFormatter, Ruby Marshal.load, JNDI/Log4Shell. RCE via deserialization is almost always Critical. Use when target runs Java, PHP serialization, Python pickle, .NET, or Ruby on Rails.
    0
    installs
  6. Operating Sliver C2 · wufufu770
    Stand up a Sliver C2 server and mTLS listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/…
    0
    installs
  7. Cloud Saas Exposure · wufufu770
    <2-5 sentences — issue + attacker impact, not a terse restatement of the title> evidence: url: <where found> timestamp: <UTC ISO8601> sha256: <hash of any downloaded artifact — never an object body, see §5> raw: <truncated to 2 KiB> references: [<advisory URL, vendor doc>] remediation: <action the asset owner can take> ``` UTC timestamps everywhere.
    0
    installs
  8. Attack Path Stitcher · wufufu770
    Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edge…
    0
    installs
  9. Dimensional Analysis · wufufu770
    Perform dimensional analysis assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  10. Enterprise Vpn Attack · wufufu770
    Look for: Set-Cookie: webvpn=; X-Frame-Options: SAMEORIGIN; CSP: ... block-all-mixed-content
    0
    installs
  11. Audit Context Building · wufufu770
    Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use…
    0
    installs
  12. Agentic Actions Auditor · wufufu770
    Perform agentic actions auditor assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  13. Burpsuite Project Parser · wufufu770
    Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patte…
    0
    installs
  14. Relaying Ntlm For Adcs Esc8 · wufufu770
    Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer, printerbug) to relay NTLM authentication from a coerced domain cont…
    0
    installs
  15. Testing Cors Misconfiguration · wufufu770
    Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential t…
    0
    installs
  16. Exploiting Adcs With Certipy · wufufu770
    Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, N…
    0
    installs
  17. Moving Laterally With Netexec · wufufu770
    Use NetExec (nxc) to validate credentials, enumerate SMB shares/users/policy, password-spray safely across lockout thresholds, execute comma…
    0
    installs
  18. Claude In Chrome Troubleshooting · wufufu770
    Perform claude in chrome troubleshooting assessment during authorized security testing. Use this skill when indicators of the vulnerability class are
    0
    installs
  19. Performing Ssl Stripping Attack · wufufu770
    Perform performing ssl stripping attack assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  20. Enumerating Cloud With Cloudfox · wufufu770
    Run CloudFox's read-only Describe/List/Get enumeration (all-checks, role-trusts, secrets, endpoints, and permissions commands) to map AWS an…
    0
    installs
  21. Performing Vlan Hopping Attack · wufufu770
    Perform performing vlan hopping attack assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  22. Exploiting Broken Link Hijacking · wufufu770
    Perform exploiting broken link hijacking assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  23. Performing Malware Ioc Extraction · wufufu770
    Perform performing malware ioc extraction assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  24. Exploiting Ipv6 Vulnerabilities · wufufu770
    Identifies and exploits IPv6-specific vulnerabilities including SLAAC
    0
    installs
  25. Performing Csrf Attack Simulation · wufufu770
    Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions…
    0
    installs
  26. Testing For Host Header Injection · wufufu770
    Perform testing for host header injection assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  27. Performing Osint With Spiderfoot · wufufu770
    Perform performing osint with spiderfoot assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  28. Performing Malware Triage With Yara · wufufu770
    Perform performing malware triage with yara assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  29. Scanning Iac And Images With Trivy · wufufu770
    Scans container images, Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes manifests, Dockerfile, Helm), filesystems, git repos…
    0
    installs
  30. Testing For Email Header Injection · wufufu770
    Perform testing for email header injection assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  31. Exploiting Deeplink Vulnerabilities · wufufu770
    Tests and exploits deep link (URL scheme and App Link) vulnerabilities
    0
    installs
  32. Performing Clickjacking Attack Test · wufufu770
    Perform performing clickjacking attack test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  33. Performing Packet Injection Attack · wufufu770
    Crafts and injects custom network packets using Scapy, hping3, and Nemesis
    0
    installs
  34. Conducting Mobile App Penetration Test · wufufu770
    Perform conducting mobile app penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  35. Analyzing Heap Spray Exploitation · wufufu770
    Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and…
    0
    installs
  36. Scanning Infrastructure With Nessus · wufufu770
    Perform scanning infrastructure with nessus assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  37. Analyzing Security Logs With Splunk · wufufu770
    Perform analyzing security logs with splunk assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  38. Configuring Oauth2 Authorization Flow · wufufu770
    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant…
    0
    installs
  39. Conducting Cloud Penetration Testing · wufufu770
    Perform conducting cloud penetration testing assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  40. Abusing Dpapi For Credential Access · wufufu770
    Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or…
    0
    installs
  41. Analyzing Network Packets With Scapy · wufufu770
    Perform analyzing network packets with scapy assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  42. Testing API Authentication Weaknesses · wufufu770
    Perform testing api authentication weaknesses assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  43. Analyzing Active Directory Acl Abuse · wufufu770
    Perform analyzing active directory acl abuse assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  44. Performing Iot Security Assessment · wufufu770
    Perform performing iot security assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  45. Performing Ssl Tls Security Assessment · wufufu770
    >- Assess SSL/TLS server configurations using the sslyze Python scanning library to evaluate supported protocol versions, cipher suite stren…
    0
    installs
  46. Scanning Containers With Trivy In Cicd · wufufu770
    Perform scanning containers with trivy in cicd assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  47. Analyzing Powershell Empire Artifacts · wufufu770
    Perform analyzing powershell empire artifacts assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  48. Building C2 Redirector Infrastructure · wufufu770
    Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleabl…
    0
    installs
  49. Analyzing Linux Kernel Rootkits · wufufu770
    Perform analyzing linux kernel rootkits assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  50. Abusing Shadow Credentials For Privesc · wufufu770
    Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker…
    0
    installs
  51. Exploiting Kerberoasting With Impacket · wufufu770
    Request TGS tickets for all Kerberoastable accounts
    0
    installs
  52. Exploiting Insecure Data Storage In Mobile · wufufu770
    Perform exploiting insecure data storage in mobile assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  53. Intercepting Mobile Traffic With Burpsuite · wufufu770
    Perform intercepting mobile traffic with burpsuite assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  54. Performing Dynamic Analysis Of Android App · wufufu770
    Perform performing dynamic analysis of android app assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  55. Exploiting Nopac Cve 2021 42278 42287 · wufufu770
    Exploits the noPac Active Directory privilege-escalation chain (CVE-2021-42278 sAMAccountName spoofing plus CVE-2021-42287 KDC PAC confusion…
    0
    installs
  56. Analyzing PDF Malware With Pdfid · wufufu770
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
    0
    installs
  57. Reverse Engineering Rust Malware · wufufu770
    Perform reverse engineering rust malware assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  58. Exploiting Type Juggling Vulnerabilities · wufufu770
    Perform exploiting type juggling vulnerabilities assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  59. Exploiting Constrained Delegation Abuse · wufufu770
    Perform exploiting constrained delegation abuse assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  60. Analyzing Supply Chain Malware Artifacts · wufufu770
    Perform analyzing supply chain malware artifacts assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  61. Exploiting Bgp Hijacking Vulnerabilities · wufufu770
    Analyzes and simulates BGP hijacking scenarios in authorized lab environments
    0
    installs
  62. Performing Initial Access With Evilginx3 · wufufu770
    Perform performing initial access with evilginx3 assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  63. Performing Binary Exploitation Analysis · wufufu770
    Analyze ELF binaries for memory-corruption vulnerabilities and build proof-of-concept
    0
    installs
  64. Analyzing Uefi Bootkit Persistence · wufufu770
    Perform analyzing uefi bootkit persistence assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  65. Performing Steganography Detection · wufufu770
    >- Detects and extracts hidden data embedded in images, audio, and other media files using steganalysis tools such as StegDetect, zsteg, ste…
    0
    installs
  66. Performing HTTP Parameter Pollution Attack · wufufu770
    Perform performing http parameter pollution attack assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  67. Performing Web Application Firewall Bypass · wufufu770
    Perform performing web application firewall bypass assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  68. Testing For Business Logic Vulnerabilities · wufufu770
    Perform testing for business logic vulnerabilities assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  69. Scanning Kubernetes Manifests With Kubesec · wufufu770
    Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and…
    0
    installs
  70. Conducting Domain Persistence With Dcsync · wufufu770
    Perform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extrac…
    0
    installs
  71. Conducting Full Scope Red Team Engagement · wufufu770
    Perform conducting full scope red team engagement assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  72. Performing Arp Spoofing Attack Simulation · wufufu770
    Perform performing arp spoofing attack simulation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  73. Reverse Engineering Android Malware With Jadx · wufufu770
    Perform reverse engineering android malware with jadx assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  74. Analyzing Malicious PDF With Peepdf · wufufu770
    Perform analyzing malicious pdf with peepdf assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  75. Performing Authenticated Scan With Openvas · wufufu770
    Perform performing authenticated scan with openvas assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  76. Performing Docker Bench Security Assessment · wufufu770
    Perform performing docker bench security assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  77. Performing Web Application Penetration Test · wufufu770
    Perform performing web application penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  78. Analyzing Malware Sandbox Evasion Techniques · wufufu770
    Perform analyzing malware sandbox evasion techniques assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  79. Performing Privilege Escalation Assessment · wufufu770
    Perform performing privilege escalation assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  80. Analyzing Malicious Url With Urlscan · wufufu770
    Perform analyzing malicious url with urlscan assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  81. Analyzing Network Traffic Of Malware · wufufu770
    Perform analyzing network traffic of malware assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  82. Performing Firmware Malware Analysis · wufufu770
    Perform performing firmware malware analysis assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  83. Performing Authenticated Vulnerability Scan · wufufu770
    Perform performing authenticated vulnerability scan assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  84. Performing Bluetooth Security Assessment · wufufu770
    Perform performing bluetooth security assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  85. Performing Physical Intrusion Assessment · wufufu770
    Perform performing physical intrusion assessment assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  86. Exploiting Active Directory With Bloodhound · wufufu770
    Perform exploiting active directory with bloodhound assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  87. Integrating Dast With Owasp Zap In Pipeline · wufufu770
    Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration aga…
    0
    installs
  88. Analyzing Command And Control Communication · wufufu770
    Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
    0
    installs
  89. Analyzing Bootkit And Rootkit Samples · wufufu770
    Perform analyzing bootkit and rootkit samples assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  90. Bypassing Authentication With Forced Browsing · wufufu770
    Perform bypassing authentication with forced browsing assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  91. Configuring Tls 1 3 For Secure Communications · wufufu770
    Configures TLS 1.3 (RFC 8446) on servers, covering cipher suite and key-exchange group selection, and validates the resulting configuration…
    0
    installs
  92. Exploiting Template Injection Vulnerabilities · wufufu770
    Perform exploiting template injection vulnerabilities assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  93. Performing Cryptographic Audit Of Application · wufufu770
    Perform performing cryptographic audit of application assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  94. Reverse Engineering Dotnet Malware With Dnspy · wufufu770
    Perform reverse engineering dotnet malware with dnspy assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  95. Auditing Kubernetes Rbac Privilege Escalation · wufufu770
    Perform auditing kubernetes rbac privilege escalation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  96. Conducting Internal Network Penetration Test · wufufu770
    Perform conducting internal network penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  97. Executing Active Directory Attack Simulation · wufufu770
    Perform executing active directory attack simulation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  98. Performing External Network Penetration Test · wufufu770
    Perform performing external network penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  99. Analyzing Cobalt Strike Beacon Configuration · wufufu770
    Perform analyzing cobalt strike beacon configuration assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs
  100. Analyzing Cobaltstrike Malleable C2 Profiles · wufufu770
    Perform analyzing cobaltstrike malleable c2 profiles assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
    0
    installs