All authors

Claude Skills by ajtazer
github.com/ajtazer207 skills4 installs326 views
- Ad Acl AbuseYou are helping a penetration tester exploit misconfigured Active DirectoryVotes: 0GitHub stars: 2
- Ad Ad DiscoveryYou are helping a penetration tester enumerate an Active Directory domain andVotes: 0GitHub stars: 2
- Ad Ad PersistenceYou are helping a penetration tester establish persistent access in ActiveVotes: 0GitHub stars: 2
- Ad Adcs Access And RelayYou are helping a penetration tester exploit ADCS through template/CA accessVotes: 0GitHub stars: 2
- Ad Adcs PersistenceYou are helping a penetration tester establish persistence through AD CSVotes: 0GitHub stars: 2
- Ad Adcs Template AbuseYou are helping a penetration tester exploit misconfigured AD CS certificateVotes: 0GitHub stars: 2
- Ad Auth Coercion RelayYou are helping a penetration tester force remote systems to authenticateVotes: 0GitHub stars: 2
- Ad Credential DumpingYou are helping a penetration tester extract credentials from ActiveVotes: 0GitHub stars: 2
- Ad Gpo AbuseYou are helping a penetration tester exploit writable Group Policy ObjectsVotes: 0GitHub stars: 2
- Ad Kerberos DelegationYou are helping a penetration tester exploit Kerberos delegation misconfigurationsVotes: 0GitHub stars: 2
- Ad Kerberos RoastingYou are helping a penetration tester perform Kerberoasting (extracting TGSVotes: 0GitHub stars: 2
- Ad Kerberos Ticket ForgingYou are helping a penetration tester forge Kerberos tickets for domainVotes: 0GitHub stars: 2
- Ad Pass The HashYou are helping a penetration tester use credential material (NTLM hashes,Votes: 0GitHub stars: 2
- Ad Sccm ExploitationYou are helping a penetration tester enumerate and exploit MicrosoftVotes: 0GitHub stars: 2
- Ad Trust AttacksYou are helping a penetration tester enumerate and exploit Active DirectoryVotes: 0GitHub stars: 2
- Hunt Ntlm InfoNTLM info disclosure is a Medium-severity finding when chained to context — the leak itself is intentional protocol behavior (RFC-compliant NTLMSSP challenge), but on internet-exposed enterprise infrastructure it provides exact reconnaissance for the next stage of an attack. Highest-value targets:Votes: 0GitHub stars: 2
- Hunt Llm AiLLM bugs are only worth reporting when they cross a trust boundary you can prove — an OOB callback, a verbatim-reproducible secret, a cross-tenant record, or code execution. A model 'saying something bad once' is confabulation, not a vulnerability. Read the False-Positive Gate before claiming anything.Votes: 0GitHub stars: 2
- Hunt Rag Vectorhunt-llm-ai already owns *session-scoped* indirect injection — a hidden instruction in oneVotes: 0GitHub stars: 2
- Offensive Ai SecurityAI/LLM security offensive checklist: prompt injection, jailbreaking, model extraction, training data poisoning, adversarial inputs, LLM-assisted attack automation, and AI system reconnaissance. Use when assessing AI/ML systems, red-teaming LLMs, or researching AI attack vectors.Votes: 0GitHub stars: 2
- Cloud Iam DeepCloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account ass...Votes: 0GitHub stars: 2
- Hunt Cloud Misconfigcurl -s 'https://TARGET-NAME.s3.amazonaws.com/?max-keys=10'Votes: 0GitHub stars: 2
- M365 Entra AttackMicrosoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates. Built from authorized red-team work where ROPC spray surfaced pre-existing lockouts and CA-blocked credentials, plus real-time external attacker activity correlation. Use for any M365/Entra credential attack, password spray, user enumeration...Votes: 0GitHub stars: 2
- Network Container EscapesYou are helping a penetration tester escape from a containerized environment orVotes: 0GitHub stars: 2
- Offensive CloudCloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, gcp_enum), privilege escalation paths (IAM PassRole, AssumeRole chains, Lambda/Functions privilege flips, Azure Owner-on-self, GCP serviceAccountTokenCreator), persistence techniques (IAM user/key creation, AAD app registration, GCP svc account key creation, Event...Votes: 0GitHub stars: 2
- Offensive K8s AttacksKubernetes cluster attack techniques covering the full attack lifecycle from initial foothold in a pod to cluster-wide compromise. Covers service account token theft and impersonation, RBAC misconfiguration exploitation including wildcard permissions and privilege escalation via role binding, direct etcd access for secret extraction, kubelet API abuse on port 10250 and read-only port 10255, pod escape via hostPID hostNetwork and hostPath volume mounts, Kubernetes secrets enumeration and decod...Votes: 0GitHub stars: 2
- Okta AttackOkta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives (kits, FastPass abuse, OIDC redirect_uri tampering), MFA enumeration, post-compromise admin API surface. Many enterprise orgs use Okta instead of (or alongside) Entra ID. Distinct endpoints, distinct rate-limiting, distinct factor flows. Use...Votes: 0GitHub stars: 2
- Vmware Vcenter AttackVMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-21972 vRealize unauth file upload, CVE-2021-21985 vSAN plugin RCE, CVE-2022-22954 Workspace ONE SSTI, CVE-2023-20887 Aria RCE, CVE-2024-37085 ESXi AD bypass, CVE-2023-34048 vCenter DCERPC OOB write APT-exploited), default credentials, SSO configuration disclosure, vmdir LDAP enumeration, ESXi Open SLP RCE history. ONLY for vCenter / Workspace ONE / Aria instances exposed to the...Votes: 0GitHub stars: 2
- Credential Password SprayingYou are helping a penetration tester perform password spraying againstVotes: 0GitHub stars: 2
- Hunt Forgot Password1. POST to the forgot-password endpoint with a clearly invalid email (e.g. nonexistent@fakedomain12345.com) — record the response body, status code, and lengthVotes: 0GitHub stars: 2
- Post Exploit Credential RecoveryYou are helping a penetration tester with offline credential and file cracking.Votes: 0GitHub stars: 2
- Meme Coin AuditMeme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, and real exploit examples from 2024-2025. Use for any token audit, rug pull assessment, meme coin secur...Votes: 0GitHub stars: 2
- Offensive Crypto AttacksSystematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern padbuster automation), ECB mode exploitation including block cut-and-paste and byte-at-a-time decryption, hash length extension attacks against SHA1/SHA256/MD5-based MACs using HashPump, RSA vulnerabilities including small public exponent, common modulus, Bl...Votes: 0GitHub stars: 2
- Web3 AuditSmart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.Votes: 0GitHub stars: 2
- CtfYou are orchestrating a penetration test using Claude Code agent teams. YouVotes: 0GitHub stars: 2
- Evasion Av Edr EvasionYou are helping a penetration tester bypass AV/EDR that is blocking payloadVotes: 0GitHub stars: 2
- Offensive Anti ForensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact remov...Votes: 0GitHub stars: 2
- Offensive Edr EvasionEDR evasion offensive checklist: hook unhooking (user/kernel), direct syscalls, PPID spoofing, process injection variants, AMSI bypass, ETW patching, memory encryption, and behavior-based evasion. Use when planning EDR bypass during red team engagements or researching AV/EDR evasion techniques.Votes: 0GitHub stars: 2
- Offensive Keylogger ArchLow-level keylogger architecture design: kernel driver hooks (WH_KEYBOARD_LL, SetWindowsHookEx), ETW-based input capture, user-mode vs kernel-mode approaches, stealth techniques, and data exfiltration. Use for understanding input capture mechanisms, EDR evasion research, or malware architecture analysis.Votes: 0GitHub stars: 2
- Offensive MitigationsSecurity mitigation reference and bypass catalog: ASLR, DEP/NX, RELRO, stack canaries, CFI, sandboxing, seccomp. Covers both detection of enabled mitigations and known bypass techniques. Use when assessing target hardening or planning exploit mitigation bypasses.Votes: 0GitHub stars: 2
- Offensive Waf BypassWAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.Votes: 0GitHub stars: 2
- Offensive Windows BoundariesWindows security boundary taxonomy and attack surface enumeration: kernel/user boundary, sandbox boundaries (LPAC, AppContainer), COM/RPC boundaries, hypervisor boundary, trust level transitions. Use when planning privilege escalation paths, sandbox escapes, or understanding Windows security architecture.Votes: 0GitHub stars: 2
- Offensive Windows MitigationsDeep-dive on Windows exploit mitigations: ASLR, DEP/NX, CFG, CET/Shadow Stack, SEHOP, Heap Guard, ACG, Arbitrary Code Guard. Covers both the protection mechanism and known bypass techniques. Use when researching Windows exploit mitigations, planning bypass strategies, or understanding protection depth.Votes: 0GitHub stars: 2
- Offensive Basic ExploitationWeek 5 exploit development curriculum. Foundational exploitation techniques: controlling EIP/RIP, ROP chain construction, ret2libc, shellcode injection, heap spraying, bypass techniques for ASLR/NX/stack canaries. Use when building initial PoCs or understanding classic exploitation primitives.Votes: 0GitHub stars: 2
- Offensive Bug IdentificationSystematic bug identification methodology: source code review patterns, black-box testing strategies, taint analysis, dangerous function hunting, data flow tracing, and automated scanning setup. Use for code audits, bug bounty triage, or building vulnerability identification pipelines.Votes: 0GitHub stars: 2
- Offensive Crash AnalysisWeek 4 exploit development curriculum. Crash triage and analysis methodology: WinDbg/GDB analysis, ASAN/MSAN output interpretation, exploitability assessment, register/stack trace reading, root cause identification. Use when analyzing crash dumps, assessing exploitability, or understanding fuzzer-generated crashes.Votes: 0GitHub stars: 2
- Offensive DeserializationInsecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/phpggc/ysoserial.net, ObjectInputStream and BinaryFormatter sink identification, pickle __reduce__ RCE, phar:// wrapper abuse, Jackson polymorphic typing, Json.NET TypeNameHandling, ViewState tampering, node-serialize IIFE injection, Ruby Marshal.load and YAML.load gadgets, framework-specific chains for Spring/Hibernate/Laravel/Symfony, modern attack surface...Votes: 0GitHub stars: 2
- Offensive Exploit Dev CourseFull exploit development course roadmap and syllabus: weekly topics, recommended reading, lab setup, and learning path from vulnerability classes through advanced exploitation. Use to structure exploit dev training or onboard new researchers.Votes: 0GitHub stars: 2
- Offensive Exploit DevelopmentExploit development operational guide: environment setup, debugging workflow, PoC development lifecycle, writing reliable exploits, using pwntools/pwndbg, heap exploitation techniques, and weaponization considerations. Use when actively developing exploits or setting up an exploit dev environment.Votes: 0GitHub stars: 2
- Offensive Fast CheckingSpeed-optimized offensive checklist for rapid assessment: quick-win vulnerability patterns, fast recon shortcuts, automated scanner configurations, and triage shortcuts. Use for time-boxed assessments, CTF-speed engagements, or initial rapid surface mapping.Votes: 0GitHub stars: 2
- Offensive Fuzzing CourseWeek 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing, and triage/deduplication. Use when setting up fuzz campaigns, selecting harness strategies, or triaging fuzzer output.Votes: 0GitHub stars: 2