Skills publicadas
network-anonymity
Network anonymity and traffic concealment for red team operations. Use this skill whenever the user mentions "proxy chain", "proxychains", "SOCKS5", "Tor", "onion routing", "VPN", "WireGuard", "OpenVPN", "multi-hop", "IP rotation", "MAC spoofing", "MAC randomization", "macchanger", "DNS leak", "WebRTC leak", "IPv6 leak", "identity rotation", "anonymity", "traffic analysis", "traffic obfuscation",
vps-security
This skill covers end-to-end VPS security for red team attack infrastructure. Use it when the user mentions "VPS", "virtual private server", "cloud server", "droplet", "Linode", "Vultr", "Hetzner", "DigitalOcean", "AWS EC2", "OVH", "server provisioning", "LUKS", "dm-crypt", "full disk encryption", "encrypted disk", "remote server", "C2 server", "redirector", "team server", "attack infrastructure",
data-acquisition
This skill should be used when the user mentions "dump database", "acquire data", "download dump", "extract records", "mongodump", "elasticdump", "mongoexport", "database dump", "data extraction", "redis dump", "couch dump", or discusses safely pulling data from an open database, converting database export formats, setting extraction limits, or monitoring dump progress. It routes data acquisition
leak-hunting
This skill should be used when the user mentions "hunt leaks", "find breaches", "credential leaks", "data leak", "breach database", "hunt dumps", "leak finder", "leak hunting", "discover leaks", "breached credentials", "combo list", "combolist", "credential dump", "paste site", "pastebin leak", "breach forums", "BreachForums", "Exploit.in", "RaidForums", "Telegram leaks", "leak channel", "h8mail",
cloud-lateral
Activate this skill whenever the user mentions cloud lateral movement, cloud privilege escalation, cloud post-exploitation, cloud red team, multi-cloud attack, cloud pentesting, AWS, Amazon Web Services, EC2, S3, Lambda, IAM, STS, SSM, Systems Manager, CloudTrail, GuardDuty, CloudShell, Secrets Manager, Parameter Store, RDS, ECS, EKS, Fargate, ECR, CodeBuild, CodePipeline, Glue, SageMaker, instanc
reporting
This skill should be used when the user mentions "generate report", "pentest report", "engagement report", "findings report", "executive summary", "technical report", "vulnerability report", "remediation report", "remediation plan", "retest report", "write up findings", "document findings", "report findings", "create report", "final report", "assessment report", "security report", "audit report",
web-assessment
This skill activates when the user mentions "XSS", "cross-site scripting", "reflected XSS", "stored XSS", "DOM XSS", "blind XSS", "SQL injection", "SQLi", "blind SQLi", "union injection", "error-based injection", "time-based injection", "stacked queries", "second-order injection", "SSRF", "server-side request forgery", "cloud metadata", "IMDS", "internal service access", "IDOR", "insecure direct o
binary-diffing
This skill activates when the user mentions "patch analysis", "binary diff", "binary diffing", "bindiff", "BinDiff", "Diaphora", "diaphora", "radiff2", "DarunGrim", "turbodiff", "version comparison", "what changed between versions", "compare binaries", "diff binaries", "function comparison", "code delta", "patch Tuesday", "Patch Tuesday diffing", "security patch analysis", "CVE diffing", "1-day ex
malware-classification
Activate this skill when the user mentions ANY of: "YARA", "YARA rules", "YARA signature", "write YARA", "detection rule", "packer detection", "packer identification", "packed binary", "UPX", "Themida", "VMProtect", "ASPack", "crypter", "obfuscated binary", "entropy", "entropy analysis", "section entropy", "high entropy", "malware family", "malware classification", "malware triage", "classify samp
secret-extraction
This skill activates when the user mentions "extract secrets", "find credentials", "hardcoded passwords", "API keys", "embedded keys", "connection strings", "tokens", "secret scanning", "credential extraction", "extract crypto keys", "private keys", "certificate extraction", "config extraction", "encryption keys", "AES key", "RSA key", "HMAC secret", "JWT secret", "bearer token", "OAuth token", "A
system-hardening
This skill should be used when the user mentions "harden", "hardening", "sysctl", "kernel parameters", "SSH config", "sshd_config", "firewall rules", "iptables", "nftables", "ufw", "fail2ban", "file permissions", "SUID", "SGID", "service minimization", "disable services", "auditd", "SELinux", "AppArmor", "CIS benchmark", "security baseline", "OS hardening", "attack platform", "operator machine", "
exposed-databases
This skill should be used when the user mentions "Shodan", "Censys", "MongoDB exposed", "Elasticsearch open", "Redis no auth", "open database", "unauthenticated database", "exposed MongoDB", "exposed Elasticsearch", "exposed Redis", "exposed CouchDB", "exposed MySQL", "exposed PostgreSQL", "port 27017", "port 9200", "port 6379", "port 5984", "port 3306", "port 5432", "find open databases", "databa
payment-security
This skill should be used when the user mentions "payment", "payment gateway", "checkout", "IDOR payment", "payment bypass", "Stripe", "MercadoPago", "Binance Pay", "PIX", "PayPal", "Adyen", "Braintree", "Square", "Razorpay", "Mollie", "webhook", "payment webhook", "price manipulation", "amount tampering", "currency manipulation", "e-commerce", "shopping cart", "cart manipulation", "checkout flow"
network-recon
Activate this skill whenever the user mentions port scan, port scanning, nmap, nmap scan, masscan, rustscan, service detection, service enumeration, service fingerprinting, network scan, network scanning, network mapping, network discovery, network topology, open ports, closed ports, filtered ports, banner grabbing, banner grab, host discovery, live hosts, ping sweep, ARP scan, ARP discovery, OS f
engagement-setup
This skill should be used when the user mentions "new engagement", "setup engagement", "initialize workspace", "start operation", "new pentest", "setup project", "create workspace", "engagement setup", "initialize engagement", "new investigation", "start campaign", "new operation", "workspace init", "set up a new operation", "begin engagement", or discusses setting up a new offensive security enga
api-testing
Activate this skill whenever the user mentions API endpoint, REST API, RESTful, GraphQL, GraphQL introspection, GraphQL mutation, gRPC, gRPC reflection, WebSocket, WebSocket upgrade, WS endpoint, API security, API fuzzing, API enumeration, API versioning, API gateway, API rate limit, JWT, JSON Web Token, bearer token, access token, refresh token, API key, OAuth, OAuth2, OIDC, OpenID Connect, PKCE,
anti-forensics
This skill should be used when the user mentions "log cleaning", "clear logs", "wipe logs", "timestomp", "timestamp manipulation", "metadata stripping", "exiftool", "mat2", "file wiping", "shred", "srm", "secure delete", "bleachbit", "memory clearing", "swap wipe", "bash history", "wtmp", "btmp", "lastlog", "auth.log", "journal", "journalctl", "forensic artifacts", "anti-forensics", "trace removal
opsec-reporting
This skill should be used when the user mentions "generate report", "opsec report", "engagement report", "pentest report", "red team report", "purple team report", "security assessment", "hardening report", "compliance report", "audit report", "findings report", "evidence handling", "chain of custody", "redaction", "redact", "report delivery", "secure delivery", "debrief", "debrief prep", "post-en
cross-plugin-pipeline
This skill should be used when the user mentions "handoff to elliot", "pipeline to elliot", "cross-plugin", "elliot handoff", "transfer to elliot", "handoff package", "generate handoff", "build handoff", "elliot engagement", "pass to elliot", "bridge to elliot", "return flow", "elliot return", "post-exploitation return", "feed back to tyrell", "ingest from elliot", "credential handoff", "target en
source-intelligence
This skill should be used when the user mentions "Google dork", "search operator", "inurl:", "filetype:", "intitle:", "site:", "intext:", "dork pattern", "breach forum", "BreachForums", "Exploit.in", "XSS.is", "RaidForums", "forum intelligence", "forum navigation", "seller credibility", "paste site", "Pastebin", "Ghostbin", "paste search", "paste monitoring", "Telegram leak", "Telegram channel", "
password-attacks
This skill should be used when the user mentions "brute force", "password cracking", "hydra", "hashcat", "john the ripper", "credential stuffing", "password spray", "password spraying", "hash cracking", "wordlist", "dictionary attack", "mask attack", "rainbow table", "NTLM", "NTLMv2", "bcrypt", "Kerberoast", "Kerberoasting", "AS-REP roasting", "AS-REP roast", "golden ticket", "silver ticket", "tic
waf-bypass
This skill should be used when the user mentions "WAF", "web application firewall", "WAF bypass", "WAF evasion", "WAF detection", "WAF fingerprint", "wafw00f", "firewall bypass", "firewall evasion", "request filtering", "request blocked", "payload blocked", "blocked by WAF", "403 forbidden", "406 not acceptable", "429 too many requests", "rate limit", "rate limiting", "IP ban", "IP block", "IP rep
wordpress-hacking
Activate this skill whenever the user mentions WordPress, WP, WooCommerce, WP plugin, WP theme, wp-admin, wp-content, wp-login, wp-json, wp-includes, xmlrpc, XML-RPC, wp-cron, admin-ajax, wp-config, wpscan, WordPress vulnerability, WordPress exploit, WordPress enumeration, WordPress brute force, WordPress RCE, WordPress shell upload, WordPress backdoor, WordPress privilege escalation, WordPress au
dotnet-reversing
Activate this skill when the user mentions ".NET", "CLR", "managed code", "C# binary", "C# decompile", "decompile C#", "VB.NET", "F# binary", "ILSpy", "dnSpy", "de4dot", "dotPeek", ".NET Reflector", "monodis", "ilspycmd", "ilasm", "ildasm", "Cecil", "Mono.Cecil", "dnlib", ".NET Reactor", "ConfuserEx", "Dotfuscator", "SmartAssembly", "Eazfuscator", "Babel obfuscator", "Crypto Obfuscator", "Agile.NE
pe-analysis
Activate this skill whenever the user mentions PE analysis, PE file, PE header, portable executable, Windows executable analysis, EXE analysis, DLL analysis, SYS driver analysis, OCX analysis, PE structure, PE format, PE parsing, PE triage, PE inspection, binary headers, file headers, DOS header, MZ header, COFF header, optional header, PE signature, image base, entry point, AddressOfEntryPoint, s
Alerta por categoria