All authors

Claude Skills by Miosa-osa
github.com/Miosa-osa276 skills9 installs363 views
- Offensive Tls AttacksComprehensive methodology for auditing and exploiting TLS/SSL implementations and misconfigurations across network services and mobile applications. Covers protocol downgrade attacks including POODLE (CVE-2014-3566) against SSLv3 CBC padding, DROWN (CVE-2016-0800) cross-protocol attack leveraging SSLv2 export ciphers to decrypt TLS sessions, and FREAK (CVE-2015-0204) forcing RSA export-grade key exchange. Addresses BEAST (CVE-2011-3389) exploiting CBC IV predictability in TLS 1.0, CRIME (CVE-...Votes: 0GitHub stars: 76
- Offensive ToctouTime-of-Check / Time-of-Use (TOCTOU) race condition exploitation methodology across binary, kernel, filesystem, web, and container layers. Covers symbolic-link races (open/access/stat split), file-descriptor races, fopen/realpath traversal races, /proc and procfs races, FUSE-backed slow-fs races to widen the window, ptrace and signal races, kernel double-fetch / userspace pointer races, container/runc/symlink escape primitives, kubernetes admission/authz TOCTOU, web auth-vs-authz TOCTOU, JWT-...Votes: 0GitHub stars: 76
- Offensive Vuln ClassesExploit development curriculum covering core vulnerability classes with real-world CVE case studies: stack/heap buffer overflows, use-after-free, integer overflows, format strings, type confusion, and race conditions. Use when learning or teaching vuln classes, researching specific CVE patterns, or building exploit dev knowledge.Votes: 0GitHub stars: 76
- Offensive Waf BypassWAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.Votes: 0GitHub stars: 76
- Offensive Wifi ReconWi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and structured airspace data capture for downstream attacks. Use at the start of any wireless engagement to build the target map before active attacks; covers 2.4 GHz, 5 GHz, and 6 GHz (...Votes: 0GitHub stars: 76
- Offensive WifiWireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802....Votes: 0GitHub stars: 76
- Offensive Windows BoundariesWindows security boundary taxonomy and attack surface enumeration: kernel/user boundary, sandbox boundaries (LPAC, AppContainer), COM/RPC boundaries, hypervisor boundary, trust level transitions. Use when planning privilege escalation paths, sandbox escapes, or understanding Windows security architecture.Votes: 0GitHub stars: 76
- Offensive Windows MitigationsDeep-dive on Windows exploit mitigations: ASLR, DEP/NX, CFG, CET/Shadow Stack, SEHOP, Heap Guard, ACG, Arbitrary Code Guard. Covers both the protection mechanism and known bypass techniques. Use when researching Windows exploit mitigations, planning bypass strategies, or understanding protection depth.Votes: 0GitHub stars: 76
- Offensive Windows PrivescComprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\\SYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using JuicyPotato, PrintSpoofer, GodPotato, SweetPotato, and RoguePotato; service misconfigurations including unquoted service paths, weak service DACLs, writable service binaries, and insecure service creation permissions; AlwaysInstallElevated MSI...Votes: 0GitHub stars: 76
- Offensive Wpa EnterpriseWPA/WPA2/WPA3-Enterprise (802.1X / EAP) attack methodology — EAP method identification (PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, EAP-GTC, EAP-PWD, EAP-FAST), evil-twin RADIUS attacks with eaphammer for credential capture, MSCHAPv2 challenge-response cracking, EAP-TLS client certificate theft paths (DPAPI, NDES, AD CS auto-enrollment), supplicant validation bypass (missing server cert validation, missing CN pinning, BYOD misconfigurations), and post-capture pivots into AD via cracked domain credentia...Votes: 0GitHub stars: 76
- Offensive Wpa2 PskWPA/WPA2-PSK attack methodology — four-way handshake capture via targeted deauthentication, PMKID attacks (no client required), hcxdumptool / hcxpcapngtool conversion to hashcat hc22000 format, GPU-accelerated cracking with dictionary, mask, and rule-based attacks, vendor default-PSK generators (UPC, Sky, BT, etc.), 802.11r FT key cracking, opportunistic key cache analysis, and signal-level optimization. Use when the in-scope network is WPA/WPA2 Personal — the most common consumer/SMB encrypt...Votes: 0GitHub stars: 76
- Offensive Wpa3 SaeWPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377, 13456), SAE auth flooding for AP CPU exhaustion, Hash-to-Element (H2E) timing analysis, group downgrade, and 6 GHz / Wi-Fi 6E spec implications (PMF mandatory, no transition mode allowed). Use when target advertises WPA3-SAE or WPA3-Personal/Enterprise, or operates in 6 GHz where WPA3 + PMF are required by spec.Votes: 0GitHub stars: 76
- Offensive WpsWPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default even when WPS attacks have been known for over a decade.Votes: 0GitHub stars: 76
- Offensive XssCross-Site Scripting testing checklist: stored/reflected/DOM/blind XSS discovery, polyglot payloads, CSP bypass, XSS filter bypass, event handler injection, DOM clobbering, mutation XSS, and impact escalation (session hijack, phishing, keylogging). Use for web app XSS testing and bug bounty.Votes: 0GitHub stars: 76
- Offensive XxeXML External Entity injection testing checklist: classic XXE, blind XXE (out-of-band), XXE via file upload (SVG/docx), XXE in SOAP/REST, error-based XXE, XInclude attacks, and XXE filter bypass. Use for web app XXE testing and bug bounty.Votes: 0GitHub stars: 76
- Offensive Z WaveZ-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting Z-Wave smart home devices (door locks, sensors, garage controllers) — common in mid-2010s smart home deployments still in production.Votes: 0GitHub stars: 76
- Offensive Zigbee Thread MatterZigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, KillerBee toolkit, Touchlink commissioning abuse with the well-known transport key, replay/injection attacks, Zigbee Cluster Library command abuse for door locks and bulbs, Thread network credential theft, Matter commissioning chain analysis, and 6LoWPAN/IPv6 routing exploitation. Use when targeting smart-home or commercial mesh deployments, Zigbee-based door ...Votes: 0GitHub stars: 76
- Opsec Operational DisciplineOperational security for offensive engagements: OPSEC level tiers (silent/covert/loud) with detection-event budgets, cooldown and jitter mechanics, traffic blending, log sanitization, IOC tracking, abort-recommendation logic, and cleanup-on-completion. Use when planning how noisy an engagement should be, tuning scan/exploit pacing to avoid detection, responding to detection events during an engagement, or sanitizing logs and reports before delivery. Derived from the T3MP3ST platform's OPSEC c...Votes: 0GitHub stars: 76
- Osint MethodologyStructured OSINT methodology framework: target definition, source selection, collection workflows, data correlation, timeline reconstruction, and reporting. Covers sock-puppet OpSec, cryptocurrency and L2 tracing, image/video geolocation, chronolocation (shadow/astronomical/satellite), threat-actor investigation with attribution discipline, RU/CN-specific pivots, people and social-media investigation, infrastructure OSINT, Telegram/WeChat, case management, and synthetic-media verification. Us...Votes: 0GitHub stars: 76
- Redteam Multi Agent OrchestrationMulti-agent red-team campaign orchestration: mission intake with authorization gates, planner/executor separation, objective decomposition into innocuous worker queries, strict-majority verdict adjudication with mandatory cite-checks, and crash-safe mission recovery with idempotent actions. Use when coordinating multiple agents on an offensive-security engagement, structuring a red-team campaign across specialist operators, designing planner-worker splits for restricted models, or building re...Votes: 0GitHub stars: 76
- Redteam Report GenerationEngagement report generation for red-team and pentest work: severity-ordered finding sections with verification status badges, evidence snippets with type labels, CVE/CWE cross-references, remediation guidance, mission metadata (status, phases, timestamps), markdown escaping for safe report rendering, and best-effort report writing that never breaks the engagement. Use when writing the final report for a security engagement, structuring findings for delivery, or generating status reports from...Votes: 0GitHub stars: 76
- Sandbox TriageTriage suspicious files with static metadata and bounded scanning, and distinguish malware detonation from safe application attack labs. Use for sandbox triage, suspicious attachments, YARA scanning or malware analysis preparation.Votes: 0GitHub stars: 76
- Siem OperationsValidate SIEM ingestion, parsing, alert routing and retention with synthetic canaries and timestamp evidence. Use for SIEM operations, missing events, alert pipeline outages, duplicate events or detection delivery checks.Votes: 0GitHub stars: 76
- Threat HuntingInvestigate a testable cyber defense hypothesis across host, identity and network evidence. Use for threat hunting, hidden persistence, unusual logins or finding adversary behavior without an existing alert.Votes: 0GitHub stars: 76
- Threat ModelingBuild a concrete cyber defense threat model from assets, data flows and trust boundaries, then map controls to attack simulations and verification. Use for threat modeling, architecture security, abuse cases or designing defenses before deployment.Votes: 0GitHub stars: 76
- Vulnerability ManagementPrioritize vulnerabilities using exact affected versions, reachable exposure and known exploitation, then patch and retest with rollback. Use for vulnerability management, patch prioritization, KEV matching, dependency risk or verifying a security fix.Votes: 0GitHub stars: 76