← Back to catalog
hypnguyen1209

Author in the catalog

hypnguyen1209

25 skills6,250 stars totalgithub.com/hypnguyen1209

Published skills

offensive-claude

250

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Segurança#testby hypnguyen1209

shellcode-dev

250

Shellcode development — PIC techniques, PEB walking, API hashing, null-byte avoidance, encoders, loaders, PE-to-shellcode conversion, cross-platform shellcode

Segurança#test#apiby hypnguyen1209

initial-access

250

Modern initial access techniques — phishing, payload delivery, HTML smuggling, ISO/IMG bypass, supply chain attacks, credential stuffing, exposed service exploitation

Segurança#ai#testby hypnguyen1209

offensive-claude

250

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Segurança#testby hypnguyen1209

network-attack

250

Network penetration testing — lateral movement, pivoting, protocol attacks, traffic interception, Active Directory exploitation, wireless attacks

Segurança#testby hypnguyen1209

privesc-linux

250

Linux privilege escalation — SUID/SGID abuse, kernel exploits, capabilities, sudo misconfig, cron jobs, writable paths, container escape

Design e Frontend#ai#testby hypnguyen1209

threat-hunting

250

Proactive threat hunting, IOC extraction, MITRE ATT&CK mapping, behavioral anomaly detection, log analysis correlation

Segurança#testby hypnguyen1209

vulnerability-analysis

250

Expert-level source code security auditing — taint analysis, memory safety, injection classes, auth flaws, crypto weaknesses, concurrency bugs, supply chain risks

Segurança#ai#testby hypnguyen1209

offensive-claude

250

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Segurança#testby hypnguyen1209

coding-mastery

250

Advanced software engineering — systems programming, exploit development tooling, automation scripting, network programming, cryptography implementation

Desenvolvimento#testby hypnguyen1209

crypto-analysis

250

Cryptographic assessment — cipher identification, TLS auditing, hash analysis, key strength evaluation, side-channel detection, crypto implementation review

Segurança#testby hypnguyen1209

edr-evasion

250

EDR/AV bypass — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection, AMSI bypass, ETW patching, memory encryption, behavioral evasion

Segurança#testby hypnguyen1209

exploit-development

250

PoC development, payload crafting, shellcode generation, ROP chains, heap exploitation, bypass techniques for modern mitigations (ASLR, DEP, CFI, stack canaries)

Segurança#ai#testby hypnguyen1209

incident-response

250

IR playbook execution — evidence collection, timeline analysis, memory forensics, disk forensics, containment strategies, post-incident reporting

Segurança#ai#testby hypnguyen1209

malware-analysis

250

Static/dynamic malware analysis, YARA rules, sandbox evasion detection, behavioral profiling, unpacking, anti-analysis bypass

Segurança#testby hypnguyen1209

mobile-pentest

250

Mobile application penetration testing — Android/iOS static/dynamic analysis, Frida instrumentation, SSL pinning bypass, root/jailbreak detection bypass, deep-link abuse, exported components, insecure storage, biometric bypass

Segurança#ai#testby hypnguyen1209

red-team-ops

250

Full red team engagement — initial access, persistence, privilege escalation, defense evasion, C2 infrastructure, EDR bypass, living-off-the-land

Segurança#testby hypnguyen1209

reverse-engineering

250

Binary analysis, disassembly, decompilation, firmware RE, protocol reverse engineering, anti-reversing bypass, malware unpacking

Segurança#testby hypnguyen1209

active-directory-attack

250

Active Directory penetration testing — BloodHound enumeration, Kerberos attacks (Kerberoasting, AS-REP, Golden/Silver Ticket), NTLM relay, DCSync, lateral movement, domain dominance

Segurança#ai#testby hypnguyen1209

ai-security

250

AI/ML security assessment — prompt injection, jailbreak detection, RAG poisoning, model extraction, adversarial examples, supply chain risks in ML pipelines

Segurança#ai#testby hypnguyen1209

cloud-security

250

Cloud penetration testing — AWS/Azure/GCP privilege escalation, container escape, Kubernetes attacks, serverless exploitation, IaC misconfigurations

DevOps e Infra#ai#testby hypnguyen1209

privesc-windows

250

Windows privilege escalation — token abuse, service exploitation, UAC bypass, credential harvesting, AD escalation paths

Segurança#testby hypnguyen1209

recon-osint

250

Comprehensive reconnaissance and OSINT — subdomain enumeration, CVE lookup, breach intelligence, DNS history, social profiling, attack surface mapping

Marketing#ai#testby hypnguyen1209

web-pentest

250

Full-spectrum web application penetration testing — OWASP Top 10, API security, authentication attacks, business logic, WAF bypass, race conditions

Segurança#test#apiby hypnguyen1209

offensive-claude

250

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Segurança#testby hypnguyen1209

Category alert

Get new Segurança skills every Monday