wgpsec/AboutSecurity

Everything for pentest. | A penetration testing knowledge base that captures security methodologies in an AI Agent-executable format.

This repository also configures its own agents. See what AboutSecurity tells them →

1.7kStars on the repository
200Mods indexed here, across every type
6d agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

php-framework-audit

49

wgpsec/AboutSecurity

Skill Claude CodeCodex

A PHP source-code audit focused on the security rules and common mistakes of specific web frameworks. It covers Laravel, ThinkPHP, WordPress, Symfony, Yii2, and CodeIgniter.

not rated 1.7k +7 6d ago A 145 tokens

php-frontend-audit

50

wgpsec/AboutSecurity

Skill Claude CodeCodex

A PHP source-code audit for security problems in browser-facing behavior and HTTP responses. It covers XSS, CSRF, open redirects, CRLF injection, and unsafe session or cookie handling.

not rated 1.7k +7 6d ago A 116 tokens

php-injection-audit

51

wgpsec/AboutSecurity

Skill Claude CodeCodex

A PHP source-code security audit for finding injection vulnerabilities, where untrusted input is treated as code or a query.

not rated 1.7k +7 6d ago A 112 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A PHP source-code security audit for serialization, XML, and template-injection risks.

not rated 1.7k +7 6d ago A 119 tokens

ctf-ai-ml

53

wgpsec/AboutSecurity

Skill Claude CodeCodex

An AI and machine-learning security guide for capture-the-flag (CTF) challenges involving attacks on models or their supporting systems.

not rated 1.7k +7 6d ago A 120 tokens

ctf-crypto

54

wgpsec/AboutSecurity

Skill Claude CodeCodex

A cryptography attack guide for capture-the-flag (CTF) challenges involving encrypted data or weak encryption designs.

not rated 1.7k +7 6d ago A 114 tokens

ctf-flag-hunting

55

wgpsec/AboutSecurity

Skill Claude CodeCodex

A search guide for finding flags in capture-the-flag (CTF) challenges after access to a target has been gained.

not rated 1.7k +7 6d ago A 92 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A verification workflow for checking suspected flags in capture-the-flag (CTF) security challenges before submission.

not rated 1.7k +7 6d ago A 152 tokens

ctf-forensics

57

wgpsec/AboutSecurity

Skill Claude CodeCodex

A digital-forensics and signal-analysis guide for capture-the-flag (CTF) challenges involving collected computer evidence.

not rated 1.7k +7 6d ago B 100 tokens

ctf-malware

58

wgpsec/AboutSecurity

Skill Claude CodeCodex

A malware-analysis guide for capture-the-flag (CTF) challenges involving suspicious software, scripts, or network traffic.

not rated 1.7k +7 6d ago A 105 tokens

ctf-misc

59

wgpsec/AboutSecurity

Skill Claude CodeCodex

A collection of techniques for solving miscellaneous capture-the-flag security challenges that do not fit common categories such as web or cryptography.

not rated 1.7k +7 6d ago A 98 tokens

ctf-osint

60

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to open-source intelligence (OSINT) for capture-the-flag (CTF) challenges, where clues come from publicly available information.

not rated 1.7k +7 6d ago A 90 tokens

ctf-pwn

61

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to exploiting binary programs in capture-the-flag (CTF) challenges, including ELF and PE executable files and network services.

not rated 1.7k +7 6d ago A 97 tokens

ctf-reverse

62

wgpsec/AboutSecurity

Skill Claude CodeCodex

A reverse-engineering guide for capture-the-flag (CTF) challenges, where an unknown program is examined to discover how it works.

not rated 1.7k +7 6d ago A 95 tokens

ctf-solve

63

wgpsec/AboutSecurity

Skill Claude CodeCodex

A coordinator for solving capture-the-flag (CTF) challenges when the challenge type is not yet known.

not rated 1.7k +7 6d ago A 83 tokens

ctf-source-audit

64

wgpsec/AboutSecurity

Skill Claude CodeCodex

A source-code auditing guide for capture-the-flag (CTF) challenges, where the vulnerable code is deliberately included in places such as repositories, backups, or environment leaks.

not rated 1.7k +7 6d ago A 112 tokens

ctf-web-methodology

65

wgpsec/AboutSecurity

Skill Claude CodeCodex

A general method for solving web-based capture-the-flag (CTF) security challenges, which are deliberately built with clues and exploitable weaknesses.

not rated 1.7k +7 6d ago A 76 tokens

ctf-web-recon

66

wgpsec/AboutSecurity

Skill Claude CodeCodex

A reconnaissance guide for web-based capture-the-flag (CTF) challenges, which are intentionally designed applications with clues and weaknesses.

not rated 1.7k +7 6d ago A 87 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to acquiring and examining disk evidence, including full disk images and hash checks, from both forensic and anti-forensic perspectives.

not rated 1.7k +7 6d ago C 79 tokens

emergency-response

68

wgpsec/AboutSecurity

Skill Claude CodeCodex

An incident-response method for investigating suspected compromises on Linux and Windows systems. It covers signs such as backdoors, malware, unusual processes, accounts, network connections, startup items, scheduled tasks, logs, and rootkits.

not rated 1.7k +7 6d ago D 82 tokens

log-evasion

69

wgpsec/AboutSecurity

Skill Claude CodeCodex

A collection of Sigma rule examples for detecting suspicious activity in Windows logs. Sigma is a portable format for describing log-detection rules, including process injection, credential dumping, lateral movement, persistence, log clearing, and PowerShell use.

not rated 1.7k +7 6d ago A 63 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method covering both memory forensics and ways attackers try to avoid memory-based detection. Memory forensics examines a dump of a computer's active memory, including with Volatility3.

not rated 1.7k +7 6d ago B 84 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for examining C2 source code and detection rules from YARA, Sigma, and Snort. C2 means command and control: a channel used to operate software on another machine.

not rated 1.7k +7 6d ago A 97 tokens

evasion-research

72

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for researching security repositories on GitHub and extracting Loader, C2, and detection-evasion code patterns into a local knowledge base. GitHub is a platform where developers publish and collaborate on source code.

not rated 1.7k +7 6d ago A 82 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: