ShulkwiSEC

60 mods across 1 repository, 21 stars between them.

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write) and need to convert it into code execution by targeting GOT, hooks, IOFILE vtable, exitfuncs, TLSdtorlist, modprobepath, .finiarray, or C++ vtables.

21 1mo ago B 80 tokens copy · 100% MIT

auth-bypass

50

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Bypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from linear/incremental cookies, SQL injection on login forms, PHP unserialize() boolean type juggling (b:1 payload), and credential transport over HTTP. Detectable…

21 1mo ago A 80 tokens original MIT

auth-sec

51

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

21 1mo ago A 46 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

21 1mo ago A 43 tokens copy · 100% MIT

authz-bypass

54

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Test horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=, EventID=), and special header injection (X-Original-URL, X-Rewrite-URL, X-Forwarded-For, X-Remote-IP, X-Client-IP with 127.0.0.1/localhost/RFC1918 values). Tools…

21 1mo ago A 110 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Bypass antivirus and Endpoint Detection & Response solutions during red team operations using payload obfuscation, process injection, AMSI bypass, ETW patching, and custom loaders. Use this skill when AV/EDR is blocking your payloads, tooling, or post-exploitation activities. Covers shellcode encryption, syscall-based…

21 1mo ago A 93 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Penetration test AWS cloud environments for misconfigurations, privilege escalation, data exposure, and lateral movement. Use this skill when assessing AWS accounts for security weaknesses including S3 bucket misconfigurations, IAM policy flaws, EC2 metadata exploitation, Lambda function abuse, and cross-account…

21 1mo ago B 75 tokens original MIT

aws-cognito-abuse

57

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Exploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege escalation via custom attributes to access broader AWS infrastructure.

21 1mo ago A 44 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Identify and exploit misconfigured Identity and Access Management (IAM) permissions within Amazon Web Services (AWS) to escalate privileges. Use this skill to move from a low-privileged compromised IAM user/role (e.g., via SSRF) to full AdministratorAccess by abusing AssumeRole, PassRole, inline policies, or resource…

21 1mo ago C 80 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Exploit Server-Side Request Forgery (SSRF) vulnerabilities to extract AWS IAM credentials from the Instance Metadata Service version 2 (IMDSv2). This skill details how to bypass the token requirement of IMDSv2 by chaining HTTP verbs (PUT then GET) if the SSRF vulnerability allows full control over the request headers…

21 1mo ago C 84 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Exploit Server-Side Request Forgery (SSRF) vulnerabilities on Amazon Web Services (AWS) EC2 instances to access the highly sensitive Instance Metadata Service (IMDS). Circumvent basic protections and extract temporary IAM access keys, escalating privileges comprehensively across the AWS Cloud environment.

21 1mo ago B 68 tokens original MIT