All authors

Claude Skills by 26zl
github.com/26zl510 skills6 installs902 views
- Implementing Continuous Security Validation With BasDeploy Breach and Attack Simulation tools to continuously validate securityVotes: 0GitHub stars: 65
- Implementing Data Loss Prevention With Microsoft Purview'Implements data loss prevention policies using Microsoft Purview toVotes: 0GitHub stars: 65
- Implementing Deception Based Detection With CanarytokenDeploy and monitor Canary Tokens via the Thinkst Canary API for deception-basedVotes: 0GitHub stars: 65
- Implementing Delinea Secret Server For Pam'Implements Delinea Secret Server for privileged access management (PAM)Votes: 0GitHub stars: 65
- Implementing Device Posture Assessment In Zero Trust'Implementing device posture assessment as a zero trust access controlVotes: 0GitHub stars: 65
- Implementing Devsecops Security Scanning'Integrates Static Application Security Testing (SAST), Dynamic ApplicationVotes: 0GitHub stars: 65
- Implementing Digital Signatures With Ed25519Ed25519 is a high-performance digital signature algorithm using the EdwardsVotes: 0GitHub stars: 65
- Implementing Dmarc Dkim Spf Email SecuritySPF, DKIM, and DMARC form the three pillars of email authentication.Votes: 0GitHub stars: 65
- Implementing Dragos Platform For Ot Monitoring'Deploy and configure the Dragos Platform for OT network monitoring,Votes: 0GitHub stars: 65
- Meme Coin AuditMeme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, MCP-driven red-flag scanning (grep/run_pipeline over contract source), and real exploit examples from 2...Votes: 0GitHub stars: 65
- Offensive Active DirectoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trus...Votes: 0GitHub stars: 65
- Offensive Advanced RedteamPractical advanced red team operations guide: OPSEC discipline, C2 infrastructure design, living-off-the-land techniques, lateral movement, persistence, data exfiltration, and evading modern defenses. Use for planning advanced red team engagements or understanding APT TTPs. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Ai SecurityAI/LLM security offensive checklist: prompt injection, jailbreaking, model extraction, training data poisoning, adversarial inputs, LLM-assisted attack automation, and AI system reconnaissance. Use when assessing AI/ML systems, red-teaming LLMs, or researching AI attack vectors. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Basic ExploitationWeek 5 exploit development curriculum. Foundational exploitation techniques: controlling EIP/RIP, ROP chain construction, ret2libc, shellcode injection, heap spraying, bypass techniques for ASLR/NX/stack canaries. Use when building initial PoCs or understanding classic exploitation primitives. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Bluetooth BleBluetooth Low Energy (BLE) attack methodology \u2014 GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devi...Votes: 0GitHub stars: 65
- Offensive Bluetooth ClassicBluetooth Classic (BR/EDR) attack methodology \u2014 device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth \u2264 4.0 BR/EDR) \u2014 common in legacy car kits, industrial sensors, older medical device...Votes: 0GitHub stars: 65
- Offensive Bug IdentificationSystematic bug identification methodology: source code review patterns, black-box testing strategies, taint analysis, dangerous function hunting, data flow tracing, and automated scanning setup. Use for code audits, bug bounty triage, or building vulnerability identification pipelines. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Business LogicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surfa...Votes: 0GitHub stars: 65
- Offensive CloudCloud security attack methodology for AWS, Azure, and GCP: credential harvesting (IMDS, ~/.aws, env vars, CI secrets, instance roles), enumeration (pacu, ScoutSuite, Prowler, ROADtools, gcp_enum), privilege escalation (IAM PassRole, AssumeRole chains, Lambda/Functions flips, Azure Owner-on-self, GCP serviceAccountTokenCreator), persistence (IAM keys, AAD app registration, GCP svc account keys, EventBridge/Logic Apps backdoors), data exfiltration (S3/Blob/GCS, snapshot share, RDS/CosmosDB/Clou...Votes: 0GitHub stars: 65
- Offensive Crash AnalysisWeek 4 exploit development curriculum. Crash triage and analysis methodology: WinDbg/GDB analysis, ASAN/MSAN output interpretation, exploitability assessment, register/stack trace reading, root cause identification. Use when analyzing crash dumps, assessing exploitability, or understanding fuzzer-generated crashes. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Deauth DisassocDeauthentication and disassociation attacks against 802.11 networks \u2014 targeted single-client deauth for handshake capture, broadcast deauth for DoS (with authorization), action-frame attacks bypassing 802.11w (PMF), beacon flooding, mdk4 / aireplay-ng tooling, and rate-limit / PMF-aware operation. Use to coerce client reconnection (handshake capture, evil-twin roaming), as targeted DoS, or to test PMF posture. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive DeserializationInsecure deserialization attack checklist: identifying deserialization sinks, Java/PHP/.NET/Python deserialization exploitation, ysoserial gadget chains, magic method abuse, and detection evasion. Use when testing deserialization endpoints or developing deserialization exploits. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Edr EvasionEDR evasion offensive checklist: hook unhooking (user/kernel), direct syscalls, PPID spoofing, process injection variants, AMSI bypass, ETW patching, memory encryption, and behavior-based evasion. Use when planning EDR bypass during red team engagements or researching AV/EDR evasion techniques. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Evil TwinEvil Twin / KARMA / Mana access point methodology \u2014 rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe response, Mana selective probe response, captive portal phishing, deauth-driven client coercion to attacker AP, MAC randomization defeat via PNL leak analysis, post-association MITM (DNS, ARP, transparent proxy), credential capture for portal/web/SMB, and detection-evasion tactics. Use to coerce client devices onto an attacker-controlled AP, interce...Votes: 0GitHub stars: 65
- Offensive Exploit Dev CourseFull exploit development course roadmap and syllabus: weekly topics, recommended reading, lab setup, and learning path from vulnerability classes through advanced exploitation. Use to structure exploit dev training or onboard new researchers. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Exploit DevelopmentExploit development operational guide: environment setup, debugging workflow, PoC development lifecycle, writing reliable exploits, using pwntools/pwndbg, heap exploitation techniques, and weaponization considerations. Use when actively developing exploits or setting up an exploit dev environment. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Fast CheckingSpeed-optimized offensive checklist for rapid assessment: quick-win vulnerability patterns, fast recon shortcuts, automated scanner configurations, and triage shortcuts. Use for time-boxed assessments, CTF-speed engagements, or initial rapid surface mapping. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive File UploadFile upload vulnerability checklist: MIME type bypass, extension bypass, magic byte manipulation, path traversal in filenames, stored XSS via SVG/HTML upload, server-side processing attacks, and race conditions. Use for assessing file upload endpoints in web app pentests or bug bounty. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Fuzzing CourseWeek 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing, and triage/deduplication. Use when setting up fuzz campaigns, selecting harness strategies, or triaging fuzzer output. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive FuzzingPractical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage. Use when setting up or running fuzz campaigns against any target: file parsers, network protocols, kernel drivers, EDR engines, embedded firmware, or language runtimes. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive GraphqlGraphQL security testing checklist: introspection abuse, batching attacks, query depth/complexity DoS, field suggestion enumeration, IDOR via GraphQL, injection through arguments, authorization bypass. Use when assessing GraphQL endpoints in web app tests or bug bounty. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive IdorIDOR (Insecure Direct Object Reference) testing checklist: object ID enumeration, horizontal/vertical privilege escalation, GUID predictability, indirect references via hashes, chained IDOR, and API endpoint IDOR. Use for web app pentests and bug bounty IDOR discovery. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Initial AccessInitial access techniques checklist: phishing (spear/smishing), credential stuffing, exposed service exploitation, supply chain attacks, watering hole, VPN/RDP brute force, public-facing application exploitation. Maps to MITRE ATT&CK TA0001. Use when planning initial access phases of red team engagements. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive IotIoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off), firmware acquisition (vendor portals, OTA capture, flash dump, binwalk extraction), firmware analysis (filesystem mounting, binary triage, hardcoded secrets, default credential discovery), bootloader attacks (U-Boot console, secure-boot bypass, fault injection), runtime attacks on embedded Linux/RTOS (busybox CVEs, MTD writes, /dev/mem), wireless protoc...Votes: 0GitHub stars: 65
- Offensive JwtJWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256\u2192HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting auth bypass via token manipulation, or evaluating JWT implementation security in web or mobile apps. Use only for authorized security researc...Votes: 0GitHub stars: 65
- Offensive Keylogger ArchLow-level keylogger architecture design: kernel driver hooks (WH_KEYBOARD_LL, SetWindowsHookEx), ETW-based input capture, user-mode vs kernel-mode approaches, stealth techniques, and data exfiltration. Use for understanding input capture mechanisms, EDR evasion research, or malware architecture analysis. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Krack FragattacksKRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) \u2014 key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when assessing legacy supplicants, embedded clients, or vendors with poor patch cadence. Use only...Votes: 0GitHub stars: 65
- Offensive Lorawan Sub GhzLoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology \u2014 LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR / Flipper Zero workflows, signal analysis with Inspectrum / Universal Radio Hacker, and reconstruction of proprietary packet formats. Use for LoRaWAN deployments (smart cities, ass...Votes: 0GitHub stars: 65
- Offensive MitigationsSecurity mitigation reference and bypass catalog: ASLR, DEP/NX, RELRO, stack canaries, CFI, sandboxing, seccomp. Covers both detection of enabled mitigations and known bypass techniques. Use when assessing target hardening or planning exploit mitigation bypasses. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive MobileMobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL b...Votes: 0GitHub stars: 65
- Offensive OauthOAuth 2.0 attack checklist: authorization code interception, redirect_uri bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Open RedirectOpen redirect vulnerability checklist: parameter identification, bypass techniques (URL encoding, double slashes, CRLF injection, protocol handlers), chaining with OAuth/SSRF, and impact escalation paths. Use for web app testing and bug bounty open redirect discovery. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Osint MethodologyStructured OSINT methodology framework: target definition, source selection, collection workflows, data correlation, timeline reconstruction, and reporting. Use to guide systematic OSINT campaigns or teach OSINT methodology. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive OsintComprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tra...Votes: 0GitHub stars: 65
- Offensive Parameter PollutionHTTP parameter pollution (HPP) checklist: duplicate parameter injection, backend vs frontend parsing differences, WAF bypass via HPP, server-side vs client-side HPP, and practical exploitation patterns. Use when testing web applications for parameter handling flaws. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive Race ConditionRace condition (TOCTOU) testing checklist: identifying timing windows, Burp Suite Turbo Intruder, Last-Byte sync technique, rate limit bypass, double-spend attacks, and concurrent request exploitation. Use for web app race condition testing or bug bounty time-of-check-to-time-of-use bugs. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive RceRemote Code Execution testing checklist: OS command injection, SSTI-to-RCE, deserialization RCE, file upload RCE, XXE with SSRF to RCE, RCE via dependency confusion, and CVE-based RCE patterns. Use for web app pentests and bug bounty RCE discovery. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive ReportingPenetration test and red team report writing methodology: executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, scope, narrative, reproduction, impact, remediation, references), CVSS v3.1/v4.0 scoring with vector justification, OWASP risk rating, evidence hygiene (redacting credentials, hashing client data, time-stamping actions), screenshot and PoC artifact management, finding chain narratives, scope/limitations/assumptions, ...Votes: 0GitHub stars: 65
- Offensive Request SmugglingHTTP request smuggling checklist: CL.TE, TE.CL, TE.TE variants, detection with timing and differential responses, WAF bypass, cache poisoning, credential hijacking, and request smuggling via HTTP/2. Use when testing reverse proxy/load balancer configurations. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65
- Offensive ShellcodeShellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode loaders, evading AV/EDR detection, or converting PE files to shellcode. Covers null byte avoidance, API hashing, encoder/decoder patterns, staged vs stageless payloads, Windows PEB traversal, and cross-platform shellcode techniques. Use only for authorized security research, training, or assessment.Votes: 0GitHub stars: 65