web-vuln-scan
145Skill Claude CodeCodex
A strategy for deeply scanning one known web application for security vulnerabilities. It combines software fingerprinting, automated checks, and manual testing.
Everything for pentest. | A penetration testing knowledge base that captures security methodologies in an AI Agent-executable format.
This repository also configures its own agents. See what AboutSecurity tells them →
Skill Claude CodeCodex
A strategy for deeply scanning one known web application for security vulnerabilities. It combines software fingerprinting, automated checks, and manual testing.
Skill Claude CodeCodex
A guide to placing and checking a webshell, which is a hidden server-side script used to run commands through a website.
Skill Claude CodeCodex
A guide to using a command-line webshell after it has already been uploaded to a server. A webshell is a server-side script that accepts commands through web requests.
Skill Claude CodeCodex
A methodology for testing WebSocket security. WebSockets are long-lived browser-to-server connections used to exchange messages in real time over ws:// or wss://.
Skill Claude CodeCodex
A methodology for testing XSLT injection, where attacker-controlled XML stylesheets alter how data is transformed. XSLT is commonly used to convert XML into HTML or other output formats.
Skill Claude CodeCodex
A methodology for testing cross-site scripting, where attacker-controlled input runs as code in another user's browser. It covers reflected, stored, and DOM-based XSS in places such as searches, comments, forms, and URL parameters.
Skill Claude CodeCodex
A methodology for testing XML External Entity injection, a vulnerability where an XML parser processes attacker-controlled references to external files or services. It covers XML inputs in APIs, SOAP, uploads such as DOCX or SVG, and JSON-to-XML conversions.
Skill Claude CodeCodex
A set of rules for making penetration testing more focused and efficient. It addresses blind enumeration, blocked tools, long-running scans, and repeated brute-force attempts.
Skill Claude CodeCodex
A checklist for deciding whether a CTF challenge is complete and its flag has been found. CTFs are security puzzles where participants exploit weaknesses to retrieve hidden text called a flag.
Skill Claude CodeCodex
Penetration testing evaluation checklist for the decision Agent. Evaluates whether a pentest has sufficiently covered all attack surfaces, determines task completion, and provides specific feedback on uncovered areas.
Skill Claude CodeCodex
A guide to navigating local collections of wordlists, payloads, and proof-of-concept code used in penetration testing. These resources are stored under /pentest.
Skill Claude CodeCodex
A guide for organizing the overall process of a penetration test. It focuses on assessment order and strategy rather than teaching individual exploit techniques.
Skill Claude CodeCodex
A guide for writing formal penetration-testing and red-team assessment reports. It covers report structure, CVSS risk ratings, vulnerability descriptions, and remediation advice.
Skill Claude CodeCodex
A guide to examining the software inside embedded devices such as routers, cameras, and industrial equipment. Firmware is the low-level software that runs these devices.
Skill Claude CodeCodex
A guide to abusing permissions in Active Directory, Microsoft's system for managing users and computers on a network. It covers dangerous access rules that can let one account take control of another account, computer, or service.
Skill Claude CodeCodex
A guide to abusing Kerberos delegation in Active Directory. Kerberos is the system Windows domains use to authenticate users and services; delegation can allow one service to act as another user.
Skill Claude CodeCodex
A guide to attacking an Active Directory domain, the Windows system that manages identities and computers across an organization. It covers the main stages from discovering domain information to gaining higher privileges.
Skill Claude CodeCodex
A guide to keeping access to Windows hosts and Active Directory after gaining administrator control. Active Directory is Microsoft's system for managing users, computers, and permissions across a network.
Skill Claude CodeCodex
A guide to attacking trust relationships between Active Directory domains and forests. A trust is a configured relationship that lets identities from one domain or forest access another.
Skill Claude CodeCodex
A guide to abusing Active Directory Certificate Services, the Windows system that issues digital certificates for identity and encryption. It covers misconfigured certificate authorities and certificate templates.
Skill Claude CodeCodex
A guide to credential spraying, where one password is tried against many accounts, unlike brute force, which tries many passwords against one account.
Skill Claude CodeCodex
A guide to moving from one database to other databases or internal services. It covers PostgreSQL, MySQL, and Microsoft SQL Server features that can connect across systems.
Skill Claude CodeCodex
A guide to attacking Microsoft Exchange, the email server platform used by many organizations. It covers attacks against web mail, administration interfaces, exposed services, and mail data.
Skill Claude CodeCodex
A guide to discovering hosts, ports, services, and important systems inside a private network, then mapping the network topology. A topology map shows how systems and network segments are connected.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: