Guides AI and LLM application security testing including prompt injection, system prompt extraction, tool/function abuse, MCP server testing, and data exfiltration via LLM features. Use for chatbots, agents, and AI-integrated apps.
Guides binary exploitation including stack overflow, ROP, format strings, heap basics, pwntools, and GDB analysis. Use when engagement ROE explicitly authorizes custom exploit development beyond Metasploit modules.
Guides blockchain and smart contract security testing with reentrancy, flash loan, and access control analysis using Slither and EVM tooling. Use when auditing Solidity contracts, DeFi protocols, EVM dApps, or Web3 signing workflows in engagement scope.
Guides cloud penetration testing for AWS, Azure, and GCP enumeration, credential abuse, metadata SSRF, storage misconfigurations, IAM privilege escalation, and cloud lateral movement from web or internal footholds.
Guides OS command injection testing with shell metacharacter probes, blind exfiltration, filter bypass, and OS-specific syntax. Use when inputs reach shell commands such as ping, nslookup, file conversion, or when shell metacharacters alter application behavior.
Guides container and DevOps penetration testing for Docker escape, Kubernetes abuse, CI/CD pipeline secrets, package manager poisoning, and secrets enumeration from footholds or exposed services.
Guides database penetration testing for MSSQL, MySQL, PostgreSQL, MongoDB, Redis, and Elasticsearch. Use when database ports are open, SQL injection yields DB access, or linked-server abuse is suspected.
Guides insecure deserialization testing with format identification, language-specific gadget chains, and ysoserial/phpggc tooling. Use when Java, .NET, PHP, Python, or Ruby serialized objects appear in cookies, headers, APIs, or base64-encoded parameters including ViewState.
Guides digital forensics methodology for disk images, memory dumps, pcaps, and artifact analysis. Use when analyzing evidence to support incident response, malware triage, or pentest finding validation.
Guides GraphQL injection and authorization testing with introspection, field enumeration, batch attacks, and nested query abuse. Use when GraphQL endpoints, introspection, or query syntax are discovered.
Guides network and service penetration testing after port discovery. Provides port-to-skill routing, per-service quick reference, and general enumeration methodology for services with and without dedicated harness skills.
Guides hardware and physical access penetration testing with UART/JTAG/SPI analysis, firmware extraction, and logic analyzer techniques. Use when engagement ROE includes firmware extraction, debug interface access, or physical device compromise.
Guides Insecure Direct Object Reference testing with ID manipulation, parameter pollution, and horizontal/vertical privilege escalation techniques. Use when predictable IDs in URLs, sequential numbers, UUIDs, or authorization bypass indicators appear.
Guides initial access techniques including external attack surface mapping, credential abuse, phishing delivery chains, and client-side payload planning. Use during external engagement phases before exploitation.
Guides Active Directory and internal network penetration testing for AD enumeration, Kerberos abuse, relay attacks, ADCS exploitation, lateral movement, domain dominance, and MSSQL attacks in domain environments.
Guides JSON Web Token attack testing with algorithm confusion, signature bypass, header injection, and secret brute force techniques. Use when Bearer tokens, Authorization headers with eyJ prefix, or JWT cookies are observed during web or API testing.
Guides local and remote file inclusion testing with traversal payloads, PHP wrappers, log poisoning, and LFI-to-RCE chains. Use when parameters like page, file, include, or path accept filenames or traversal sequences.
Guides Linux penetration testing for privesc, persistence, container host escape, SUID/capabilities abuse, cron, kernel exploits, and post-ex on Linux sessions.
Guides macOS penetration testing when ROE includes macOS endpoints. Covers privesc, TCC bypass, keychain abuse, sandbox escape, launch daemon abuse, dylib hijacking, and XPC/Mach service abuse on Intel and Apple Silicon.
Central reference for pentest methodology, cross-cutting cheatsheets, reverse shells, file transfer, hash cracking, network discovery, and common tool syntax. Use during recon, threat modeling, post-exploit, and reporting when any domain skill needs quick operational references.
★not rated 3 9d agoA58 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: