wgpsec/AboutSecurity

Everything for pentest. | A penetration testing knowledge base that captures security methodologies in an AI Agent-executable format.

This repository also configures its own agents. See what AboutSecurity tells them →

1.7kStars on the repository
200Mods indexed here, across every type
8d agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

web-vuln-scan

145

wgpsec/AboutSecurity

Skill Claude CodeCodex

A strategy for deeply scanning one known web application for security vulnerabilities. It combines software fingerprinting, automated checks, and manual testing.

not rated 1.7k +7 8d ago A SkillSpector: pass 98 tokens

webshell-deploy

146

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to placing and checking a webshell, which is a hidden server-side script used to run commands through a website.

not rated 1.7k +7 8d ago D 105 tokens

webshell-management

147

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to using a command-line webshell after it has already been uploaded to a server. A webshell is a server-side script that accepts commands through web requests.

not rated 1.7k +7 8d ago B 99 tokens

websocket-attack

148

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing WebSocket security. WebSockets are long-lived browser-to-server connections used to exchange messages in real time over ws:// or wss://.

not rated 1.7k +7 8d ago A SkillSpector: pass 68 tokens

xslt-injection

149

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing XSLT injection, where attacker-controlled XML stylesheets alter how data is transformed. XSLT is commonly used to convert XML into HTML or other output formats.

not rated 1.7k +7 8d ago A SkillSpector: warn 148 tokens

xss-methodology

150

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing cross-site scripting, where attacker-controlled input runs as code in another user's browser. It covers reflected, stored, and DOM-based XSS in places such as searches, comments, forms, and URL parameters.

not rated 1.7k +7 8d ago A SkillSpector: pass 112 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing XML External Entity injection, a vulnerability where an XML parser processes attacker-controlled references to external files or services. It covers XML inputs in APIs, SOAP, uploads such as DOCX or SVG, and JSON-to-XML conversions.

not rated 1.7k +7 8d ago A SkillSpector: warn 117 tokens

efficiency-rules

152

wgpsec/AboutSecurity

Skill Claude CodeCodex

A set of rules for making penetration testing more focused and efficient. It addresses blind enumeration, blocked tools, long-running scans, and repeated brute-force attempts.

not rated 1.7k +7 8d ago A SkillSpector: pass 82 tokens

judge-ctf

153

wgpsec/AboutSecurity

Skill Claude CodeCodex

A checklist for deciding whether a CTF challenge is complete and its flag has been found. CTFs are security puzzles where participants exploit weaknesses to retrieve hidden text called a flag.

not rated 1.7k +7 8d ago A SkillSpector: pass 95 tokens

judge-pentest

154

wgpsec/AboutSecurity

Skill Claude CodeCodex

Penetration testing evaluation checklist for the decision Agent. Evaluates whether a pentest has sufficiently covered all attack surfaces, determines task completion, and provides specific feedback on uncovered areas.

not rated 1.7k +7 8d ago A SkillSpector: pass 40 tokens

local-resources

155

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to navigating local collections of wordlists, payloads, and proof-of-concept code used in penetration testing. These resources are stored under /pentest.

not rated 1.7k +7 8d ago A SkillSpector: pass 83 tokens

red-team-assessment

156

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide for organizing the overall process of a penetration test. It focuses on assessment order and strategy rather than teaching individual exploit techniques.

not rated 1.7k +7 8d ago A SkillSpector: pass 86 tokens

report-generate

157

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide for writing formal penetration-testing and red-team assessment reports. It covers report structure, CVSS risk ratings, vulnerability descriptions, and remediation advice.

not rated 1.7k +7 8d ago A SkillSpector: pass 58 tokens

firmware-analysis

158

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to examining the software inside embedded devices such as routers, cameras, and industrial equipment. Firmware is the low-level software that runs these devices.

not rated 1.7k +7 8d ago D 118 tokens

ad-acl-abuse

159

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to abusing permissions in Active Directory, Microsoft's system for managing users and computers on a network. It covers dangerous access rules that can let one account take control of another account, computer, or service.

not rated 1.7k +7 8d ago A SkillSpector: warn 63 tokens

ad-delegation-attack

160

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to abusing Kerberos delegation in Active Directory. Kerberos is the system Windows domains use to authenticate users and services; delegation can allow one service to act as another user.

not rated 1.7k +7 8d ago A SkillSpector: warn 80 tokens

ad-domain-attack

161

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to attacking an Active Directory domain, the Windows system that manages identities and computers across an organization. It covers the main stages from discovering domain information to gaining higher privileges.

not rated 1.7k +7 8d ago A SkillSpector: warn 91 tokens

ad-persistence

162

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to keeping access to Windows hosts and Active Directory after gaining administrator control. Active Directory is Microsoft's system for managing users, computers, and permissions across a network.

not rated 1.7k +7 8d ago A SkillSpector: warn 117 tokens

ad-trust-attack

163

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to attacking trust relationships between Active Directory domains and forests. A trust is a configured relationship that lets identities from one domain or forest access another.

not rated 1.7k +7 8d ago A SkillSpector: warn 70 tokens

adcs-certipy-attack

164

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to abusing Active Directory Certificate Services, the Windows system that issues digital certificates for identity and encryption. It covers misconfigured certificate authorities and certificate templates.

not rated 1.7k +7 8d ago A SkillSpector: warn 96 tokens

cred-spray

165

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to credential spraying, where one password is tried against many accounts, unlike brute force, which tries many passwords against one account.

not rated 1.7k +7 8d ago C 70 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to moving from one database to other databases or internal services. It covers PostgreSQL, MySQL, and Microsoft SQL Server features that can connect across systems.

not rated 1.7k +7 8d ago A SkillSpector: pass 135 tokens

exchange-attack

167

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to attacking Microsoft Exchange, the email server platform used by many organizations. It covers attacks against web mail, administration interfaces, exposed services, and mail data.

not rated 1.7k +7 8d ago A SkillSpector: warn 191 tokens

internal-recon

168

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to discovering hosts, ports, services, and important systems inside a private network, then mapping the network topology. A topology map shows how systems and network segments are connected.

not rated 1.7k +7 8d ago A SkillSpector: warn 74 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: