Explore skills
4,856 skills found
Category alert
Get new DevOps e Infra skills every Monday
redteam-report-template
This skill codifies a client-facing red-team deliverable format, detailing the Subject, Observations, Description, Impact, Recommendation, and PoC structure for external engagements. It's tailored for a distinct audience and tone compared to bug-bounty reports, originating from an authorized engagement.
security-arsenal
Provides security payloads, bypass tables, wordlists, gf pattern names, bug lists, and conditionally-valid-with-chain tables. Use it for specific payloads for vulnerabilities like XSS/SSRF/SQLi, bypass techniques, or to check a finding's submittability and what not to submit.
triage-validation
This skill provides a rigorous validation process for security findings, featuring a 7-Question Gate and pre-submission checks, designed to be used before writing any report to prevent invalid submissions and improve efficiency.
bugcrowd-reporting
Bugcrowd-specific reporting tactics complement report-writing, covering VRT category search-and-fallback, manual severity override, and a severity-request paragraph. It also includes OOS-clause rebuttal templates for issues like rate limiting on auth-flow endpoints and user enumeration with sensitive PII.
cloud-iam-deep
A Cloud IAM red-team attack chain across AWS, Azure, and GCP, focusing on external exploitation and post-credential-discovery privilege analysis. It covers IAM enumeration, STS/AssumeRole chaining, Azure Managed Identity abuse, GCP service account JSON abuse, IMDSv1/v2 attacks, and K8s ServiceAccount token exfiltration.
enterprise-vpn-attack
This skill provides an attack matrix for external SSL VPN/remote-access appliances (Cisco ASA, Fortinet FortiGate, Citrix NetScaler, Palo Alto GlobalProtect, Pulse Secure, SonicWall, F5 Big-IP). It covers version fingerprinting, CVEs (2018-2026), default credentials, configuration disclosure, and pre-authentication exploits like RCE/SSRF/path-traversal.
hunt-ato
Account takeover (ATO) taxonomy outlining 9 distinct paths, including password reset flaws, email change without re-authentication, OAuth account-link CSRF, MFA bypass, session fixation, and JWT manipulation.
hunt-business-logic
A skill for hunting business logic vulnerabilities, built from 12 public bug bounty reports. It covers issues like coupon-race-stacking, negative-quantity price tampering, decimal/fraction price-field overflow, client-side checkout amount trust, price-per-unit mass-assignment, and archived-price swap.
hunt-cloud-misconfig
Identifies and exploits cloud/infrastructure misconfigurations across AWS, GCP, and Azure, such as public storage buckets, exposed services, and leaked credentials.
hunt-csrf
Skill for hunting CSRF vulnerabilities, developed from 15 public bug bounty reports including modern variants.
hunt-llm-ai
Identify LLM/AI feature bugs like prompt injection, indirect injection, exfiltration via tool-use, and ASCII smuggling, covering patterns such as direct injection in user input and indirect injection through model-read documents.
hunt-ntlm-info
This skill identifies NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange servers. It captures anonymous NTLM Type-2 challenges to leak sensitive internal network details and AD timestamps, often indicating lazy provisioning via default hostnames.