Guides SMB/CIFS service penetration testing. Use when port 445 or 139 is discovered during scanning or when SMB file sharing is identified on a target.
Guides server-side request forgery testing with internal network probes, cloud metadata abuse, protocol smuggling, and filter bypass techniques. Use when the application fetches URLs, webhooks, PDFs, image proxies, or imports content from user-supplied addresses.
Guides server-side template injection testing with engine identification probes, RCE payloads per template engine, and tplmap automation. Use when template delimiters appear in output, template engine errors surface, or user input is rendered inside server-side templates.
Guides file upload vulnerability testing with extension bypass, content-type manipulation, magic byte injection, and web shell deployment. Use when file upload forms, avatar/profile uploads, or document import features are in scope.
Guides web application penetration testing aligned with OWASP/WSTG methodology. Use for attack surface mapping, vuln class routing, auth testing, and MSF delivery after web-based initial access. Payload details live in tier-3 vuln skills.