Skill Claude CodeCodex
BEC and AiTM incident-response skill for suspicious sign-ins, mailbox abuse, forwarding, inbox rules, session theft, token replay, consent abuse, and secondary phishing.
Skill Claude CodeCodex
BEC and AiTM incident-response skill for suspicious sign-ins, mailbox abuse, forwarding, inbox rules, session theft, token replay, consent abuse, and secondary phishing.
Skill Claude CodeCodex
Static malware reverse-engineering and threat-intelligence triage for unknown files, Windows EXE/PE binaries, scripts, archives, ISOs, JavaScript, PowerShell, documents, and unpacked payloads. Use when a user provides a sample path, hash, filename, or file and asks whether it is malicious, benign, suspicious, contains…
Skill Claude CodeCodex
Defensive incident-response companion for Microsoft Entra ID, Microsoft 365, Defender, and mixed identity or endpoint incidents. Use for sign-in triage, public-IP enrichment, initial scoping, containment planning, and analyst-ready notes.
Skill Claude CodeCodex
Incident-response reporting skill for decision-ready summaries, timelines, containment records, executive handoff, remediation plans, and unresolved evidence gaps.
Skill Claude CodeCodex
Focused authorization assessment for access control, IDOR, BOLA, BFLA, RBAC, object ownership, function authorization, tenant isolation, and horizontal or vertical privilege escalation. Uses paired roles, alternate objects, methods, and controls to prove boundaries safely.
Skill Claude CodeCodex
Authentication and authorization security assessment for sessions, tokens, MFA, account takeover, IDOR, BOLA, BFLA, privilege escalation, tenant isolation, and identity boundary validation. Hands off to recon, input/protocol, access-control deep dive, exploit, or reporting workflows when those become the owner phase.
Skill Claude CodeCodex
Business logic and workflow abuse assessment for state-machine manipulation, race conditions, replay, quota abuse, order-of-operations flaws, delegated execution abuse, and unauthorized state transitions. Hands off to recon, input/protocol, exploit, or reporting workflows when those become the owner phase.
Skill Claude CodeCodex
Manual vulnerability research skill for finding advisories, downloading affected and fixed artifacts, diffing patches, confirming root cause, and writing reliable reports across products and technologies.
Skill Claude CodeCodex
CVE and vulnerability research skill for exact CVE lookup, product/version applicability, exploit maturity, KEV/PoC status, source ranking, contradiction handling, and non-destructive validation guidance.
Skill Claude CodeCodex
Evidence structuring and report synthesis for confirmed findings, severity ranking, remediation guidance, executive summaries, technical appendices, and unresolved evidence gaps. Hands off to live validation workflows when proof is incomplete.
Skill Claude CodeCodex
Deterministic exploit execution and payload control from validated primitives. Use for exploit implementation, payload hardening, chaining confirmed weaknesses, post-exploitation proof, controlled impact demonstration, reliability notes, and rollback or containment planning.
Skill Claude CodeCodex
Azure, Microsoft 365, Microsoft Graph, and Entra ID operator skill using the current Azure CLI session and az rest for scoped read, list, create, update, delete, and evidence collection tasks.
Skill Claude CodeCodex
Controlled lab skill for Hack The Box, CTF, and private lab workflows from reconnaissance, enumeration, vulnerability research, exploitation, foothold, and privilege escalation through evidence consolidation.
Skill Claude CodeCodex
Support skill for HackTricks technique research, payload ideas, bypasses, prerequisites, caveats, and edge-case behavior across web, network, cloud, and application security topics. Use as owner only when research is the current blocker.
Skill Claude CodeCodex
Input validation and protocol manipulation assessment for injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, and payload mutation. Hands off to authz, business-logic, exploit, or reporting workflows when those become the owner phase.
Skill Claude CodeCodex
Authenticated LinkedIn OSINT helper using local cookies.txt and bundled scripts for people, company, role, certification, post, and network-context research.
Skill Claude CodeCodex
Outbound interaction and OOB validation for SSRF callbacks, blind XSS beacons, webhook abuse, XXE/OOB behavior, DNS/HTTP/HTTPS callback correlation, asynchronous server-side interaction proof, and egress validation.
Skill Claude CodeCodex
Reconnaissance and attack-surface mapping for endpoint discovery, asset inventory, service enumeration, technology fingerprinting, control-plane surfaces, trust boundaries, and prioritized next tests.
Skill Claude CodeCodex
Shodan CLI-only search workflow for query design, filter selection, count/stats validation, and search-result retrieval through /root/.local/bin/shodan.
Skill Claude CodeCodex
Web application logic mapper for spidering, crawling, hidden API discovery, workflow mapping, state-machine analysis, route relationships, and handoff targets for authz, business logic, XSS, input/protocol, OOB, CVE, exploit, or reporting workflows.
Skill Claude CodeCodex
Authorized web enumeration for one or many websites or web applications, including live-target normalization, HTTP and TLS fingerprinting, technology and platform identification, virtual-host discovery, crawling, JavaScript and API endpoint extraction, focused directory and sensitive-file discovery, CMS-specific…
Skill Claude CodeCodex
XSS assessment skill for reflected XSS, stored XSS, DOM XSS, blind XSS, CSP bypass, WAF bypass, source-to-sink analysis, browser context validation, safe payload design, and evidence collection.