hypnguyen1209

60 mods across 2 repositories, 368 stars between them.

malware-analysis

49

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing).

351 15d ago A 65 tokens original MIT

mobile-pentest

50

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE.

351 15d ago B 59 tokens original MIT

network-attack

51

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay (CVE-2025-33073), TUN pivoting (Ligolo-ng/Chisel), MitM, network-service RCE (CVE-2024-38077), WPA2/WPA3 wireless.

351 15d ago B 87 tokens original MIT

opsec-discipline

52

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or feeding captured traffic to the model) — to decide detection footprint, cleanup, and secret redaction first.

351 15d ago A 49 tokens original MIT

privesc-linux

53

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LDPRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe, GameOver(lay)), service misconfig (PwnKit, Looney Tunables), container/namespace escape.

351 15d ago B 84 tokens original MIT

privesc-windows

54

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel EoP + BYOVD (CVE-2025-29824), token-rights abuse, LSASS/SAM/DPAPI credential harvesting.

351 15d ago A 81 tokens original MIT

recon-osint

55

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover, multi-cloud/Azure tenant recon, GitHub secret dorking, breach/infostealer credential intel, CVE prioritization (EPSS/KEV).

351 15d ago A 74 tokens original MIT

red-team-ops

56

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when running a full red-team engagement end-to-end — initial access, persistence, privilege escalation, defense evasion, C2 infrastructure, EDR bypass, living-off-the-land.

351 15d ago B 41 tokens original MIT

reverse-engineering

57

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when reverse-engineering a binary or firmware — static triage + decompilation (Ghidra/IDA/Binary Ninja), dynamic instrumentation (GDB/Frida 17/angr), anti-reversing & packer bypass, OLLVM/VM deobfuscation, UEFI/BIOS RE & Secure Boot research, patch-diffing for n-days.

351 15d ago A 81 tokens original MIT

scope-discipline

58

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when about to send a request to, scan, enumerate, exploit, or otherwise interact with any host, IP, URL, or asset — before the first packet reaches a target.

351 15d ago A 40 tokens original MIT

shellcode-dev

59

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when writing position-independent shellcode or a loader — PEB walking, API hashing, null-byte avoidance, encoders, loaders, PE-to-shellcode conversion, cross-platform shellcode.

351 15d ago A 41 tokens original MIT

threat-hunting

60

hypnguyen1209/offensive-claude

Skill Claude CodeCodex

Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation.

351 15d ago A 73 tokens original MIT