Explore skills
4,856 skills found
Category alert
Get new DevOps e Infra skills every Monday
hunt-saml
This skill detects SAML/SSO attacks, such as XML Signature Wrapping (XSW1-XSW8), NameID comment injection, signature stripping, and key confusion, which exploit vulnerabilities in SAML assertion and signature processing.
offensive-osint
An operational arsenal for authorized external red-team and bug-bounty reconnaissance. It provides concrete probes, wordlists, regexes, dorks, and curl one-liners for subdomain enumeration, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365), cloud bucket enumeration (S3/GCS/Azure), CDN/WAF bypass, origin discovery, and vendor fingerprinting.
hunt-sharepoint
This skill hunts on-prem Microsoft SharePoint Server farms (2013/2016/2019/Subscription Edition) to discover vulnerabilities. It performs anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass, and exploits specific CVEs, including those in end-of-life systems.
hunt-ssrf
A skill designed to hunt for SSRF vulnerabilities, developed from 15 public bug bounty reports. It covers various types including AWS, GCP, and Azure metadata SSRF, as well as DNS rebinding SSRF.
hunt-subdomain
A skill for hunting subdomain vulnerabilities, built from 15 public bug bounty reports. It includes modern provider fingerprints for services like Microsoft Azure DevOps, Zendesk, Vercel, and AWS, detailing specific takeover methods.
osint-methodology
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments, covering a 5-stage recon pipeline, 29 asset types, severity rubric, confidence workflows, time budgeting, and asset-level triage.
redteam-mindset
Red-team operator discipline involves mindset corrections that distinguish offensive testing from defensive WAPT. This approach, developed from authorized red-team work, addresses how conservative defaults can lead to missed findings. Apply it at the start of any red-team engagement and whenever you feel stuck on a defended target.
vmware-vcenter-attack
This document outlines the VMware vSphere/vCenter Server external attack matrix, covering version fingerprinting, a chain of high-impact CVEs (including unauthenticated file upload, RCE, SSTI, and APT-exploited vulnerabilities), default credentials, SSO configuration disclosure, and vmdir LDAP enumeration.
report-writing
This skill assists in writing bug bounty reports for platforms like H1, Bugcrowd, Intigriti, and Immunefi, offering templates, impact-first writing, CVSS 3.1 scoring, and a pre-submit checklist. Use it after validating a finding and before submission, remembering to prove all claims.
supply-chain-attack-recon
External reconnaissance for software supply-chain attack surfaces, identifying risks like package-namespace squatting, dependency-confusion, GitHub Actions injection, and CI/CD exposure. This skill is for reconnaissance and identification only, not offensive actions such as package publishing or typosquat attacks.
ctf-crypto
Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block cipher weaknesses.
ctf-forensics
Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files