A guide for comparing patched and unpatched software to infer what vulnerability a security update fixed. It then describes how to create a proof of concept, meaning a small demonstration that triggers the issue.
An authorized penetration-testing toolkit that gives an AI agent access to more than 20 tools for checking networks and web applications for security weaknesses.
A tool and workflow for identifying the software, services, versions, and TLS details behind HTTP targets. It uses fingerprints as clues that should be checked against actual responses or certificates.
A bug-bounty and security-response workflow for finding and reporting vulnerabilities in authorized websites, APIs, and applications. Bug bounty programs pay researchers for responsibly disclosing qualifying security flaws.
A workflow for turning a known memory bug in a compiled program into a working exploit. It focuses on binaries, Linux kernel drivers, and remote environments where a local proof may fail.
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together…
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it…
A method for understanding custom virtual machines written in JavaScript, including interpreters that run a small instruction language inside a web page. It helps identify their instructions and runtime behavior.
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
★not rated 2 25d agoA34 tokens
copy · 100%MIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: