Suzu-Testing

61 mods across 1 repository, 3 stars between them.

internal-ad-pentest

25

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Active Directory and internal network penetration testing for AD enumeration, Kerberos abuse, relay attacks, ADCS exploitation, lateral movement, domain dominance, and MSSQL attacks in domain environments.

3 7d ago A 43 tokens original MIT

jwt-pentest

26

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides JSON Web Token attack testing with algorithm confusion, signature bypass, header injection, and secret brute force techniques. Use when Bearer tokens, Authorization headers with eyJ prefix, or JWT cookies are observed during web or API testing.

3 7d ago A 51 tokens original MIT

ldap-pentest

27

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides LDAP directory service penetration testing. Use when port 389 or 636 is discovered during scanning or when LDAP/Active Directory is identified.

3 7d ago A 33 tokens original MIT

lfi-pentest

28

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides local and remote file inclusion testing with traversal payloads, PHP wrappers, log poisoning, and LFI-to-RCE chains. Use when parameters like page, file, include, or path accept filenames or traversal sequences.

3 7d ago A 50 tokens original MIT

linux-pentest

29

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Linux penetration testing for privesc, persistence, container host escape, SUID/capabilities abuse, cron, kernel exploits, and post-ex on Linux sessions.

3 7d ago B 39 tokens original MIT

macos-pentest

30

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides macOS penetration testing when ROE includes macOS endpoints. Covers privesc, TCC bypass, keychain abuse, sandbox escape, launch daemon abuse, dylib hijacking, and XPC/Mach service abuse on Intel and Apple Silicon.

3 7d ago A 57 tokens original MIT

memcache-pentest

31

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Memcached in-memory cache penetration testing. Use when port 11211 is discovered during scanning or when Memcached is identified on a target.

3 7d ago A 35 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Central reference for pentest methodology, cross-cutting cheatsheets, reverse shells, file transfer, hash cracking, network discovery, and common tool syntax. Use during recon, threat modeling, post-exploit, and reporting when any domain skill needs quick operational references.

3 7d ago A 58 tokens original MIT

mobile-pentest

33

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Android and iOS application penetration testing including static/dynamic analysis, Frida hooking, certificate pinning bypass, and common mobile vulns. Use when ROE includes Android, iOS, or hybrid mobile app testing.

3 7d ago A 50 tokens original MIT

msf-exploit-chain

34

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Orchestrates Metasploit Cursor Harness MCP tools through recon, module check, exploit, handler, session, and post-exploitation phases. Use when running msfsearchmodules, msfrunexploit, msfrunauxiliarymodule, payload generation, or session management with ROE enforcement in this project.

3 7d ago A 69 tokens original MIT

msf-harness

35

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Master guide for using the Metasploit Cursor Harness MCP server. Use when starting an engagement, choosing between MCP and shell, setting up ROE, or understanding the tool surface. Read this first before any Metasploit work.

3 7d ago A 51 tokens original MIT

msf-post

36

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Post-exploitation workflow using Metasploit MCP. Use when interacting with active sessions, running post modules, harvesting credentials, collecting loot, or cleaning up sessions.

3 7d ago C 36 tokens original MIT

msf-recon

37

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Reconnaissance workflow using Metasploit MCP read tools. Use when mapping targets, searching for exploit modules, correlating services with vulnerabilities, or querying the Metasploit database.

3 7d ago A 41 tokens original MIT

nfs-pentest

38

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides NFS network file system penetration testing. Use when port 2049 is discovered during scanning or when NFS is identified on a target.

3 7d ago B 35 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides NoSQL injection testing with operator-based auth bypass, blind extraction, JavaScript injection, and MongoDB-specific payloads. Use when MongoDB backend, JSON body with operators ($gt, $ne, $regex), or NoSQL error messages are observed during web testing.

3 7d ago A 63 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Routes pentest tasks to the correct harness skill based on engagement type, target platform, discovered services, or vulnerability class. Use when choosing which skill to load for a specific testing scenario.

3 7d ago A 43 tokens original MIT

pentest-workflow

41

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Orchestrates PTES-aligned phases, gates, and subgates for pentest engagements. Each subgate links to a skill the agent must load and execute. Use when starting an engagement, advancing phases, completing subgates, or when the user asks about workflow, gates, checkpoints, or pentest methodology structure.

3 7d ago A 71 tokens original MIT

persistence-pentest

42

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides persistence mechanism research and documentation for Windows, Linux, and RDP. Use during post-exploit when ROE authorizes persistence testing, or to document options without deployment.

3 7d ago B 41 tokens original MIT

pivoting-pentest

43

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides network pivoting and tunneling including SSH tunnels, chisel, ligolo-ng, proxychains, Meterpreter routing, and port forwarding during post-exploitation. Use when reaching unreachable in-scope subnets from a foothold host.

3 7d ago A 54 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides prompt injection testing with direct/indirect injection, jailbreak techniques, tool abuse, and system prompt extraction. Use when LLM chatbot features, AI-powered search, or text generation from user input are discovered.

3 7d ago C 49 tokens original MIT

rdp-pentest

45

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Remote Desktop Protocol penetration testing. Use when port 3389 is discovered during scanning or when RDP service is identified on a target.

3 7d ago A 34 tokens original MIT

red-team-evasion

46

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides OPSEC, EDR evasion, and defensive control bypass including AMSI, AppLocker, ETW patching, process injection, PPID spoofing, and living-off-the-land techniques. Use before noisy actions or when encountering AV/EDR controls.

3 7d ago A 59 tokens original MIT

reporting-pentest

47

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides vulnerability report writing and finding documentation including severity rating, evidence standards, and report structure. Use during report phase (SG6) and when structuring harness evidence into client deliverables.

3 7d ago A 43 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides HTTP request smuggling testing with CL.TE, TE.CL, TE.TE, and H2 downgrade detection and exploitation. Use when front/back-end proxy chains or HTTP/2 downgrade scenarios are suspected in the target architecture.

3 7d ago A 53 tokens original MIT