All authors

Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repo753 skills0 installs1,069 views
- Detecting Stuxnet Style Attacks'Detects sophisticated cyber-physical attacks that follow the StuxnetVotes: 0GitHub stars: 67
- Detecting Supply Chain Attacks In Ci Cd'Scans GitHub Actions workflows and CI/CD pipeline configurations forVotes: 0GitHub stars: 67
- Detecting Suspicious Oauth Application ConsentDetect risky OAuth application consent grants in Azure AD / MicrosoftVotes: 0GitHub stars: 67
- Detecting Suspicious Powershell ExecutionHunt for suspicious PowerShell execution (T1059.001) such as encoded commands,Votes: 0GitHub stars: 67
- Detecting T1003 Credential Dumping With EdrDetect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAMVotes: 0GitHub stars: 67
- Detecting T1055 Process Injection With SysmonDetect process injection techniques (T1055) - including DLL injection, processVotes: 0GitHub stars: 67
- Detecting T1548 Abuse Elevation Control MechanismDetect abuse of elevation control mechanisms (T1548), including Windows UACVotes: 0GitHub stars: 67
- Detecting Typosquatting Packages In Npm Pypi'Detects typosquatting attacks in npm and PyPI package registries byVotes: 0GitHub stars: 67
- Detecting Wmi PersistenceDetect WMI event subscription persistence (MITRE T1546.003) by analyzing SysmonVotes: 0GitHub stars: 67
- Eradicating Malware From Infected SystemsSystematically map and remove malware, backdoors, and attacker persistenceVotes: 0GitHub stars: 67
- Evaluating Threat Intelligence Platforms'Evaluates and selects Threat Intelligence Platform (TIP) products basedVotes: 0GitHub stars: 67
- Executing Active Directory Attack Simulation'Executes authorized attack simulations against Active Directory environmentsVotes: 0GitHub stars: 67
- Executing Phishing Simulation Campaign'Executes authorized phishing simulation campaigns to assess an organization''sVotes: 0GitHub stars: 67
- Executing Red Team Engagement PlanningBuild the foundational red team engagement plan - scope definition, RulesVotes: 0GitHub stars: 67
- Executing Red Team Exercise'Run a stealthy, MITRE ATT&CK-mapped adversary emulation against an organization''sVotes: 0GitHub stars: 67
- Exploiting Active Directory Certificate Services Esc1Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1Votes: 0GitHub stars: 67
- Exploiting Active Directory With BloodhoundBloodHound is a graph-based Active Directory reconnaissance tool thatVotes: 0GitHub stars: 67
- Exploiting Api Injection VulnerabilitiesTests API parameters, headers, and request bodies for injection flaws — SQL injection, NoSQL injection, OS command injection, LDAP injection, and SSRF — by crafting payloads tailored to the target backend to extract data, execute commands, or reach internal services, mapped to OWASP API8:2023 and API7:2023 SSRF. Use when performing SQLi, NoSQL injection, command injection, or SSRF testing against APIs, or assessing API input validation.Votes: 0GitHub stars: 67
- Exploiting Bgp Hijacking Vulnerabilities'Analyzes and simulates BGP hijacking scenarios in authorized lab environmentsVotes: 0GitHub stars: 67
- Exploiting Broken Function Level AuthorizationTests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path manipulation, and parameter tampering. Use when testing whether low-privilege users can invoke admin API functions or otherwise escalate privileges via function-level access control gaps.Votes: 0GitHub stars: 67
- Exploiting Broken Link HijackingDiscovers and exploits broken link hijacking by spidering a site (Burp Suite Spider, Scrapy, curl scraping), extracting referenced external scripts/domains, and checking DNS/CNAME records and domain registration status for expired or unclaimed resources an attacker could register. Use for subdomain takeover testing, supply-chain review of third-party scripts, or bug bounty hunting for hijackable external resources.Votes: 0GitHub stars: 67
- Exploiting Constrained Delegation AbuseExploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4U2Proxy and impersonate privileged users. Use during authorized Active Directory penetration tests or red-team engagements for lateral movement and privilege escalation after finding an account trusted for constrained delegation.Votes: 0GitHub stars: 67
- Exploiting Deeplink Vulnerabilities'Tests and exploits deep link (URL scheme and App Link) vulnerabilitiesVotes: 0GitHub stars: 67
- Exploiting Excessive Data Exposure In ApiTests APIs for excessive data exposure (OWASP API3:2023) by intercepting raw API responses and comparing them against what the UI actually renders, looking for leaked PII, internal identifiers, debug data, or business-sensitive fields the frontend filters but the API still transmits. Use when auditing REST or mobile-app APIs for over-fetching, response filtering bypass, or unintended data leakage in endpoint responses.Votes: 0GitHub stars: 67
- Exploiting Http Request SmugglingDetects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length disabled), the HTTP Request Smuggler extension, and smuggler.py. Use during authorized tests of multi-tier architectures behind a reverse proxy, load balancer, or CDN to find desync flaws and bypass front-end controls.Votes: 0GitHub stars: 67
- Exploiting Idor VulnerabilitiesIdentifies and exploits Insecure Direct Object Reference (IDOR) vulnerabilities by manipulating object identifiers (numeric IDs, UUIDs, slugs) in API requests and URLs, using Burp Suite proxy history, Intruder, and the Authorize extension to test object-level authorization across sessions. Use during authorized penetration tests or bug bounty work to validate that CRUD endpoints and multi-tenant applications enforce per-object access control.Votes: 0GitHub stars: 67
- Exploiting Insecure Data Storage In Mobile'Identifies and exploits insecure local data storage vulnerabilitiesVotes: 0GitHub stars: 67
- Exploiting Insecure DeserializationIdentifying and exploiting insecure deserialization vulnerabilities inVotes: 0GitHub stars: 67
- Exploiting Ipv6 Vulnerabilities'Identifies and exploits IPv6-specific vulnerabilities including SLAACVotes: 0GitHub stars: 67
- Exploiting Jwt Algorithm Confusion AttackExploits JWT algorithm confusion where the server's verification library trusts the alg named in the token header, by switching RS256 to HS256 (signing with the RSA public key as HMAC secret), setting alg to none, or injecting kid/jku/x5u headers to supply an attacker-controlled key. Use when testing RS256 JWT auth for algorithm downgrade, alg:none bypass, or key-confusion signature forgery.Votes: 0GitHub stars: 67
- Exploiting Kerberoasting With ImpacketPerforms Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/AES-encrypted hashes offline to recover service account credentials. Use during authorized Active Directory penetration tests or red-team engagements for credential access against service accounts via Kerberos ticket-granting-service requests.Votes: 0GitHub stars: 67
- Exploiting Mass Assignment In Rest ApisDiscovers and exploits mass assignment (autobinding) in REST APIs by injecting unexpected or hidden parameters (e.g. role, isAdmin, plan) into create/update requests, using Burp Suite Intruder, Arjun, and param-miner to find bindable fields on ORM-backed endpoints (Rails, Django, Laravel, Spring). Use when testing REST APIs for privilege escalation or authorization bypass via unintended parameter binding.Votes: 0GitHub stars: 67
- Exploiting Ms17 010 Eternalblue VulnerabilityDetects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's ms17_010_eternalblue/ms17_010_psexec modules for exploitation. Use during authorized red-team engagements or penetration tests against legacy Windows environments with unpatched SMBv1 to gain remote code execution.Votes: 0GitHub stars: 67
- Exploiting Nopac Cve 2021 42278 42287Exploits the noPac Active Directory privilege-escalation chain (CVE-2021-42278Votes: 0GitHub stars: 67
- Exploiting Nosql Injection VulnerabilitiesDetects and exploits NoSQL injection vulnerabilities in MongoDB, CouchDB,Votes: 0GitHub stars: 67
- Exploiting Oauth MisconfigurationIdentifying and exploiting OAuth 2.0 and OpenID Connect misconfigurationsVotes: 0GitHub stars: 67
- Exploiting Prototype Pollution In JavascriptDetects and exploits JavaScript prototype pollution vulnerabilitiesVotes: 0GitHub stars: 67
- Exploiting Race Condition VulnerabilitiesDetects and exploits race condition (TOCTOU) vulnerabilities in webVotes: 0GitHub stars: 67
- Exploiting Server Side Request ForgeryIdentifying and exploiting SSRF vulnerabilities to access internal services,Votes: 0GitHub stars: 67
- Exploiting Smb Vulnerabilities With Metasploit'Identifies and exploits SMB protocol vulnerabilities using MetasploitVotes: 0GitHub stars: 67
- Exploiting Sql Injection Vulnerabilities'Identifies and exploits SQL injection vulnerabilities in web applicationsVotes: 0GitHub stars: 67
- Exploiting Sql Injection With SqlmapDetecting and exploiting SQL injection vulnerabilities using sqlmap toVotes: 0GitHub stars: 67
- Exploiting Template Injection VulnerabilitiesDetects and exploits Server-Side Template Injection (SSTI) vulnerabilitiesVotes: 0GitHub stars: 67
- Exploiting Type Juggling VulnerabilitiesExploits PHP type juggling vulnerabilities caused by loose (==) comparisonVotes: 0GitHub stars: 67
- Exploiting Vulnerabilities With Metasploit FrameworkUses the Metasploit Framework (msfconsole and its exploit, auxiliary,Votes: 0GitHub stars: 67
- Exploiting Websocket VulnerabilitiesTesting WebSocket implementations for authentication bypass, cross-siteVotes: 0GitHub stars: 67
- Exploiting Zerologon Vulnerability Cve 2020 1472Exploits the Zerologon vulnerability (CVE-2020-1472) in the NetlogonVotes: 0GitHub stars: 67
- Extracting Browser History ArtifactsExtracts and analyzes browser history, cookies, cache, downloads, andVotes: 0GitHub stars: 67
- Extracting Config From Agent Tesla RatExtracts embedded configuration from Agent Tesla RAT samples, includingVotes: 0GitHub stars: 67
- Extracting Credentials From Memory DumpExtracts cached credentials, password hashes, Kerberos tickets, andVotes: 0GitHub stars: 67