Skill Claude CodeCodex
A PHP source-code audit focused on the security rules and common mistakes of specific web frameworks. It covers Laravel, ThinkPHP, WordPress, Symfony, Yii2, and CodeIgniter.
Everything for pentest. | A penetration testing knowledge base that captures security methodologies in an AI Agent-executable format.
This repository also configures its own agents. See what AboutSecurity tells them →
Skill Claude CodeCodex
A PHP source-code audit focused on the security rules and common mistakes of specific web frameworks. It covers Laravel, ThinkPHP, WordPress, Symfony, Yii2, and CodeIgniter.
Skill Claude CodeCodex
A PHP source-code audit for security problems in browser-facing behavior and HTTP responses. It covers XSS, CSRF, open redirects, CRLF injection, and unsafe session or cookie handling.
Skill Claude CodeCodex
A PHP source-code security audit for finding injection vulnerabilities, where untrusted input is treated as code or a query.
Skill Claude CodeCodex
A PHP source-code security audit for serialization, XML, and template-injection risks.
Skill Claude CodeCodex
An AI and machine-learning security guide for capture-the-flag (CTF) challenges involving attacks on models or their supporting systems.
Skill Claude CodeCodex
A cryptography attack guide for capture-the-flag (CTF) challenges involving encrypted data or weak encryption designs.
Skill Claude CodeCodex
A search guide for finding flags in capture-the-flag (CTF) challenges after access to a target has been gained.
Skill Claude CodeCodex
A verification workflow for checking suspected flags in capture-the-flag (CTF) security challenges before submission.
Skill Claude CodeCodex
A digital-forensics and signal-analysis guide for capture-the-flag (CTF) challenges involving collected computer evidence.
Skill Claude CodeCodex
A malware-analysis guide for capture-the-flag (CTF) challenges involving suspicious software, scripts, or network traffic.
Skill Claude CodeCodex
A collection of techniques for solving miscellaneous capture-the-flag security challenges that do not fit common categories such as web or cryptography.
Skill Claude CodeCodex
A guide to open-source intelligence (OSINT) for capture-the-flag (CTF) challenges, where clues come from publicly available information.
Skill Claude CodeCodex
A guide to exploiting binary programs in capture-the-flag (CTF) challenges, including ELF and PE executable files and network services.
Skill Claude CodeCodex
A reverse-engineering guide for capture-the-flag (CTF) challenges, where an unknown program is examined to discover how it works.
Skill Claude CodeCodex
A coordinator for solving capture-the-flag (CTF) challenges when the challenge type is not yet known.
Skill Claude CodeCodex
A source-code auditing guide for capture-the-flag (CTF) challenges, where the vulnerable code is deliberately included in places such as repositories, backups, or environment leaks.
Skill Claude CodeCodex
A general method for solving web-based capture-the-flag (CTF) security challenges, which are deliberately built with clues and exploitable weaknesses.
Skill Claude CodeCodex
A reconnaissance guide for web-based capture-the-flag (CTF) challenges, which are intentionally designed applications with clues and weaknesses.
Skill Claude CodeCodex
A guide to acquiring and examining disk evidence, including full disk images and hash checks, from both forensic and anti-forensic perspectives.
Skill Claude CodeCodex
An incident-response method for investigating suspected compromises on Linux and Windows systems. It covers signs such as backdoors, malware, unusual processes, accounts, network connections, startup items, scheduled tasks, logs, and rootkits.
Skill Claude CodeCodex
A collection of Sigma rule examples for detecting suspicious activity in Windows logs. Sigma is a portable format for describing log-detection rules, including process injection, credential dumping, lateral movement, persistence, log clearing, and PowerShell use.
Skill Claude CodeCodex
A method covering both memory forensics and ways attackers try to avoid memory-based detection. Memory forensics examines a dump of a computer's active memory, including with Volatility3.
Skill Claude CodeCodex
A method for examining C2 source code and detection rules from YARA, Sigma, and Snort. C2 means command and control: a channel used to operate software on another machine.
Skill Claude CodeCodex
A method for researching security repositories on GitHub and extracting Loader, C2, and detection-evasion code patterns into a local knowledge base. GitHub is a platform where developers publish and collaborate on source code.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: