本文へ移動
cccskills

スキルを探す

1.2万 件 ・ 人気順

概要と使いどころ

External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, default credentials, configuration-disclosure paths, pre-auth RCE/SSRF/path-traversal exploits where applicable. Built from authorized-engagement Cisco ASA testing plus 2024-2026 enterprise VPN CVE landscape. Use whenever the target's perimeter exposes any SSL VPN appliance or remote-access gateway — these are the most common initial-access points in 2024-2026 actor TTPs.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypass), IPC / Intent redirection, WebView vulnerabilities (JavaScriptInterface, file:// access), Firebase/AWS/Azure misconfiguration leakage, mobile API testing, biometric/Face ID/Touch ID bypass, app-cloning and runtime patching, and mobile malware/RAT analysis primitives. Use for mobile pentest, bug bounty mobile triage, or app-store reconnaissance.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

hunt-rce

無料

Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

End-to-end iOS red-team pipeline — IPA acquisition (App Store extraction, TestFlight, enterprise/ad-hoc sideload), class-dump/Hopper/Ghidra static analysis, Info.plist + entitlements + Keychain secret extraction, App Transport Security (ATS) misconfig + certificate-pinning bypass (frida-ios-dump, objection, SSL Kill Switch 2), URL-scheme / Universal Link hijack, exported-service enumeration, Frida runtime instrumentation. Companion to apk-redteam-pipeline for the iOS side of a mobile app catalogue. Use when target has an iOS app (App Store listing, TestFlight link, enterprise MDM distribution), when an IPA URL is found hosted on a web server, or when post-recon mentions 'iOS app' / 'mobile app' in scope alongside an Apple developer account.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Detect VM/sandbox escape vulnerabilities in packages using node:vm, simpleeval, or custom sandboxes that can be bypassed to achieve code execution.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

WAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again whenever feeling stuck or considering 'stopping' on a defended target. The single most important skill to load when scope is 'external red team' not 'bug bounty / WAPT'.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external attacker locked multiple new accounts during a single test session. Use when (a) running ANY active engagement against a monitored target, (b) a previously-confirmed finding stops reproducing, (c) baseline timing shifts unexpectedly, or (d) you notice response patterns changing during testing.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

legacy

無料

You are orchestrating a penetration test. Your job is to take a target,

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation ...

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing use the bug-bounty skill. Workflow it covers — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass...

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Cross-cutting methodology for the CVE-hunting pipeline (ported from find-cve-agent): when a bug is design-vs-real, false-positive avoidance, version checking before reporting, responsible disclosure norms, acceptance-rate expectations per vuln class, vulnerability chaining playbook, known false-positive patterns, maintainer-response patterns, secure-pattern reference (what NOT to flag), and a self-criticism checklist to run before claiming a finding. Use this alongside the cve-hunter/cve-exploiter/cve-validator agents and the /cve-hunt pipeline — load it whenever judging if a finding is real, worth reporting, or already fixed.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern padbuster automation), ECB mode exploitation including block cut-and-paste and byte-at-a-time decryption, hash length extension attacks against SHA1/SHA256/MD5-based MACs using HashPump, RSA vulnerabilities including small public exponent, common modulus, Bleichenbacher PKCS1v1.5 padding oracle, and Coppersmith's method for partial key recovery. Addresses weak PRNG exploitation targeting time-seeded generators and Mersenne Twister MT19937 state recovery from observed outputs, timing side-channel attacks against comparison operations, nonce reuse in AES-GCM leading to authentication key recovery, and key derivation weaknesses including insufficient iteration counts and missing salts. Primary tooling includes padbuster, RsaCtfTool, hashpump, and PyCryptodome for building c...

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

fp-check

無料

Systematic false positive elimination for security findings. 6-gate verification, 13-item checklist, devil's advocate questioning. MANDATORY before any CVE submission.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Detect decompression bomb vulnerabilities where compressed input can expand to exhaust memory, targeting buffer-based decompression without size limits.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

ctf

無料

You are orchestrating a penetration test using Claude Code agent teams. You

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, and real exploit examples from 2024-2025. Use for any token audit, rug pull assessment, meme coin security review, or pre-investment due diligence.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

AI/LLM security offensive checklist: prompt injection, jailbreaking, model extraction, training data poisoning, adversarial inputs, LLM-assisted attack automation, and AI system reconnaissance. Use when assessing AI/ML systems, red-teaming LLMs, or researching AI attack vectors.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Detect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新