MingyiSecLab

60 mods across 1 repository, 11 stars between them.

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction.

11 2mo ago C 55 tokens original Apache-2.0

container

50

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Container / Kubernetes attack category — pod escape, RBAC abuse, runtime CVE exploitation, socket-mount escape. Routing skill: identify the surface (pod-internal RCE vs API-level vs build-pipeline), then load the matching sub-skill.

11 2mo ago A 53 tokens original Apache-2.0

container-cve

51

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

High-impact container-runtime CVE catalog — runC Leaky Vessels (CVE-2024-21626/-23651/-23652/-23653), CVE-2022-0185 (FUSE/legacy-fs), CVE-2019-5736 (runC binary replace), CRI-O Dirty COW analogs, Kubernetes API server CVE-2019-11247 (custom-resource RBAC bypass). Fingerprint → match → exploit.

11 2mo ago A 102 tokens original Apache-2.0

docker-socket-mount

52

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Docker / containerd socket mounted into a container → host RCE. Common in CI runners, GitOps controllers (ArgoCD, Flux), and 'Docker-in-Docker' setups. Single-command escape via docker run --rm --privileged -v /:/host alpine chroot /host.

11 2mo ago B 67 tokens original Apache-2.0

k8s-pod-escape

53

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Kubernetes pod escape to node — privileged container abuse, hostPath mount escape, hostPID/hostIPC, capability misuse (SYSADMIN, SYSPTRACE), runC CVE chains. Pivots from RCE-in-pod to full node compromise.

11 2mo ago A 60 tokens original Apache-2.0

k8s-rbac-abuse

54

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Kubernetes RBAC privilege escalation paths — ClusterRole/Role enumeration via kubectl auth can-i --list, abuse of pods/exec, pods/portforward, secrets get, escalate verb, bind verb, impersonate verb, system:masters group abuse, ServiceAccount token theft and reuse.

11 2mo ago B 68 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

GCP service account impersonation chain — IAM roles/iam.serviceAccountTokenCreator, roles/iam.serviceAccountUser, actAs on Cloud Functions / Cloud Run / Compute Engine. Pivot from low-priv SA to org-admin via chained impersonation.

11 2mo ago F 64 tokens original Apache-2.0

imds-pivot

56

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Pivot from SSRF or RCE to cloud Instance Metadata Service (IMDS) — extract IAM role creds, instance identity, user-data secrets.

11 2mo ago C 34 tokens original Apache-2.0

k8s-pivot

57

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Kubernetes attack playbook — service-account token theft, RBAC abuse, pod escape, hostPath mount abuse, kube-api-server pivoting.

11 2mo ago A 35 tokens original Apache-2.0

s3-takeover

58

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Detect and claim dangling S3 buckets referenced by subdomains (CNAME → s3 hostnames where bucket no longer exists).

11 2mo ago A 31 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

11 2mo ago A 31 tokens original Apache-2.0

contracts

60

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Smart contract audit lane — Solidity/EVM pattern scanner, Slither ingestion, Foundry PoC generation, DeFi attack playbooks.

11 2mo ago A 29 tokens original Apache-2.0