All authors

Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146962 skills2 installs1,412 views
- Misc TechniquesProvides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game theory, unusual sandboxVotes: 0GitHub stars: 4
- OsintOSINT kategorisi SKILL.md — Kullanıcı araştırması, sosyal medya, subdomain keşfi araçları kurma rehberiVotes: 0GitHub stars: 4
- Osint TechniquesProvides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknowVotes: 0GitHub stars: 4
- Persona TrackingOSINT kişi araştırması — sosyal medya, EXIF, bcrypt crack, geolocationVotes: 0GitHub stars: 4
- PwnPwn/Binary kategorisi SKILL.md — BOF, ROP, kernel exploit araçları kurma rehberiVotes: 0GitHub stars: 4
- Buffer Overflow RopStack buffer overflow + ROP chain ile kontrol akışı ele geçirme — NX etkin, canary yok senaryoları için eksiksiz tarifVotes: 0GitHub stars: 4
- Format Stringprintf format string ile arbitrary read/write — GOT overwrite, libc leak, RCEVotes: 0GitHub stars: 4
- Heap ExploitGlibc heap exploitation — tcache poisoning, unsorted bin leak, IO_FILE FSOPVotes: 0GitHub stars: 4
- Kernel Pwn BasicsLinux kernel pwn temelleri — char device exploitation, ret2usr, KPTI/SMEP/SMAP bypass, modprobe_path overwrite, privesc primitivesVotes: 0GitHub stars: 4
- Pwn TechniquesProvides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs,Votes: 0GitHub stars: 4
- Remote PwnRemote binary exploitation — pwntools remote(), socket yönetimi, interactive shellVotes: 0GitHub stars: 4
- Ret2libcNX açık, ASLR varsa libc leak + system("/bin/sh") zinciriVotes: 0GitHub stars: 4
- Seccomp Sandbox EscapeSECCOMP filter analizi ve bypass — yasaklı syscall'lar etrafında ORW shellcode, open+sendfile, openat2, io_uring teknikleriVotes: 0GitHub stars: 4
- Srop AttackSigreturn Oriented Programming (SROP) — sigreturn syscall ile tüm registerları tek payload'da kontrol etme; gadget kıtlığında ROP alternatifiVotes: 0GitHub stars: 4
- RevRev kategorisi SKILL.md — Binary analysis, disassembly, symbolic execution araçları kurma rehberiVotes: 0GitHub stars: 4
- Android Apk AnalysisAndroid APK reverse engineering — apktool, jadx, Frida dynamic instrumentation, native .so analizi, root/SSL bypassVotes: 0GitHub stars: 4
- Anti Debug ObfuscationAnti-debug bypass ve obfuscation çözme — ptrace, UPX, PRNG, packer tespitiVotes: 0GitHub stars: 4
- Elf Static AnalysisELF binary statik analiz — file, strings, objdump, readelf, nm, Ghidra workflowVotes: 0GitHub stars: 4
- Reverse TechniquesProvides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, game clients, malwarVotes: 0GitHub stars: 4
- Z3 Constraint SolvingZ3 SMT solver ile CTF constraint çözme — byte equations, hash collision, validator bypassVotes: 0GitHub stars: 4
- WebWeb kategorisi SKILL.md — SQLi, XSS, SSRF tarayıcı ve exploit araçları kurma rehberiVotes: 0GitHub stars: 4
- DeserializationInsecure deserialization — Python pickle, Java, PHP object injection ile RCEVotes: 0GitHub stars: 4
- Graphql AttacksGraphQL saldırıları — introspection, aliased query batching, rate limit bypassVotes: 0GitHub stars: 4
- Http Request SmugglingHTTP Request Smuggling — frontend/backend HTTP parser uyumsuzluğunu sömürerek auth bypass, cache poisoning, internal endpoint erişimiVotes: 0GitHub stars: 4
- Jwt Web BypassWeb uygulamalarında JWT bypass — alg:none, CVE-2022-39227, SSRF zinciriVotes: 0GitHub stars: 4
- Prototype PollutionJavaScript prototype pollution — Object.prototype'u kirleterek auth bypass, RCE, XSS gadget chains (server-side Node.js ve client-side)Votes: 0GitHub stars: 4
- Race ConditionsWeb race condition exploitation — TOCTOU, single-packet attack, limit overrun, parallel race testingVotes: 0GitHub stars: 4
- Sqli ExploitationSQL injection — error-based, blind boolean, time-based ve UNION tekniklerini kapsar; CTF'te login bypass, veri çekme ve flag okumak için tam otomatik exploit şablonları içerirVotes: 0GitHub stars: 4
- Ssrf Ssti ChainSSRF → SSTI zinciri ile RCE — Flask/Jinja2, Thymeleaf, FreeMarker şablonlarıVotes: 0GitHub stars: 4
- Web TechniquesProvides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, reqVotes: 0GitHub stars: 4
- CybersecurityFETIH Siber Güvenlik Ana Orkestratörü — 912+ skill ile tüm siber güvenlik alanlarını kapsar. Tehdit avı, zararlı yazılım analizi, dijital adli bilişim, olay müdahalesi, bulut güvenliği, ağ güvenliği, web uygulama güvenliği, API güvenliği, sızma testi, red team, SOC operasyonları, OT/ICS güvenliği ve daha 25+ alt kategori. ljagiello/ctf-skills ve Eyadkelleh/awesome-claude-skills-security entegre edildi.Votes: 0GitHub stars: 4
- Ai Ml TechniquesProvides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network analysis, LoRA adaptVotes: 0GitHub stars: 4
- Detecting Ai Model Prompt Injection Attackstespit etme (s) prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structuralVotes: 0GitHub stars: 4
- Implementing Llm Guardrails For SecurityImplements input and output validation guardrails for LLM-powered applications to prevent prompt injection, data leakage, toxic content generation, and hallucinated outputs. Builds a securityVotes: 0GitHub stars: 4
- Llm Security TestingComprehensive LLM security testing: bias detection, data leakage, prompt injection, jailbreak, alignment testing, adversarial promptsVotes: 0GitHub stars: 4
- Detecting Api Enumeration Attackstespit etmeand prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier access patterns and authorization failures.Votes: 0GitHub stars: 4
- Detecting Broken Object Property Level Authorizationtespit etmeand test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.Votes: 0GitHub stars: 4
- Detecting Shadow Api EndpointsDiscover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.Votes: 0GitHub stars: 4
- Exploiting Api Injection VulnerabilitiesTests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers,Votes: 0GitHub stars: 4
- Exploiting Broken Function Level AuthorizationTests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them.Votes: 0GitHub stars: 4
- Exploiting Excessive Data Exposure In ApiTests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responsesVotes: 0GitHub stars: 4
- Exploiting Jwt Algorithm Confusion AttackExploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. TheVotes: 0GitHub stars: 4
- Implementing Api Abuse Detection With Rate LimitingImplement API abuse Tespit using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.Votes: 0GitHub stars: 4
- Implementing Api Gateway Security ControlsImplements security controls at the API gateway layer including authentication enforcement, rate limiting, request validation, IP allowlisting, TLS termination, and threat protection. The engineerVotes: 0GitHub stars: 4
- Implementing Api Key Security ControlsImplements secure API key generation, storage, rotation, and revocation controls to protect API authentication credentials from leakage, brute force, and abuse. The engineer designs API keyVotes: 0GitHub stars: 4
- Implementing Api Rate Limiting And ThrottlingImplements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion,Votes: 0GitHub stars: 4
- Implementing Api Schema Validation SecurityImplement API schema validation using OpenAPI specifications and JSON Schema to enforce input/output contracts and prevent injection, data exposure, and mass assignment attacks.Votes: 0GitHub stars: 4
- Implementing Api Security Posture ManagementImplement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.Votes: 0GitHub stars: 4
- Implementing Api Security Testing With 42crunchImplement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.Votes: 0GitHub stars: 4
- Implementing Api Threat Protection With ApigeeImplement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.Votes: 0GitHub stars: 4