本文へ移動
cccskills

「masvs」の検索結果

17 件 ・ 関連度順

概要と使いどころ

Android and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments

日本語の概要は準備中です。原文の説明を表示しています。

Masriyan/Claude-Code-CyberSecurity-Skill4712026年9月8日 更新

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Use when the user mentions 'mobile security,' 'iOS security,' 'Android security,' 'mobile audit,' 'mobile pentest,' 'MASVS,' 'MASTG,' 'certificate pinning,' 'jailbreak detection,' 'root detection,' 'deeplink,' 'URL scheme,' 'app transport security,' 'keychain,' 'keystore,' 'mobile reverse engineering,' or has a mobile app to review.

日本語の概要は準備中です。原文の説明を表示しています。

briiirussell/cybersecurity-skills4152026年5月27日 更新

红队渗透 / 攻防 — 受授权的红队作业者 + 渗透测试工程师 + 攻击型安全顾问的认知操作系统 (侦察 OSINT / 外网渗透 / 内网 AD 渗透 BloodHound + Kerberoasting + ADCS 利用 + 横向移动 / Web 应用渗透 OWASP WSTG / 移动 OWASP MASTG / 云渗透 AWS Azure GCP IAM 路径 + 容器逃逸 + K8s / C2 操作 Cobalt Strike Sliver Mythic Havoc + OPSEC / 初始访问 + AV EDR 绕过 (仅授权场景) / 无线 RF / 物理社工 / 报告与整改 / 框架 MITRE ATT&CK + D3FEND + PTES + OSSTMM + NIST 800-115 + Kill Chain / 法律伦理 CFAA + 网络安全法 + 刑法 285 286 + 数据安全法 + GDPR + 授权书 + 范围 + 交战规则 — 不含 黑产 / 未授权攻击 / 大规模 exploitation / 供应链投毒 / 未授权 DoS — 这是 重罪 + 行业封杀 + 律师吊销, 本 skill 严守 authorized-only 边界 — 也不含 蓝队 SOC + 恶意软件 即服务 / 僵尸网络 / 勒索软件作者 — 这是 cybercrime 不是 红队) (Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasion (phishing infrastructure, payload development, AV / EDR evasion, BYOVD, AMSI / ETW bypass — strictly for authorized engagements), (i) wireless / RF (WPA2/3, evil twin, Wi-Fi pivots), (j) physical / social engineering (badge cloning, pretexting, vishing — under engagement letter), (k) reporting & remediation (executive summary, technical findings, CVSS, MITRE ATT&CK mapping, retest), (l) frameworks & methodology (MITRE ATT&CK, MITRE D3FEND, PTES, OSSTMM, NIST SP 800-115, OWASP WSTG / MASTG, Cyber Kill Chain, Unified Kill Chain, Diamond Model), (m) law & ethics (CFAA US, Computer Misuse Act UK, 中国 刑法 285/286 + 网络安全法 + 数据安全法, GDPR for tested EU systems, engagement letter, scope, rules of engagement, safe harbor for bug bounty); NOT criminal hacking / 黑产 / unauthorized targeting / mass exploitation / supply-chain compromise / DoS against unconsented systems (这是 重罪 + 业内开除 + 律师执照吊销, 本 skill 严守 authorized-only 边界), NOT pure defensive blue team / SOC analyst tradecraft (是 平行学科, 仅做 边界标注 + ATT&CK 反推方向), NOT malware-as-a-service development / botnet ops / ransomware authoring (是 cybercrime 不是 红队), NOT 'ethical hacking' 在 'just curious 看看' 自我合理化的灰色操作 (违反 authorization 原则即不是 红队).) Master OS — automated mastery of Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasi

日本語の概要は準備中です。原文の説明を表示しています。

swaylq/master-skill1482026年9月6日 更新

Detects weak or misconfigured cryptography in mobile apps (Android/iOS). Trigger on: hardcoded keys, ECB mode, DES, 3DES, RC4, MD5, SHA-1, SecureRandom misuse, static IV, reused IV, Math.random, arc4random, CommonCrypto, CryptoKit, Android Keystore, SecKey, AES-ECB, RSA without OAEP, insufficient key size, predictable seed, insecure key storage, broken hash, PBKDF2 iteration count. Covers MASVS-CRYPTO-1 (algorithm choice) and MASVS-CRYPTO-2 (key management).

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Detects sensitive data stored insecurely on mobile devices (Android/iOS). Trigger on: SharedPreferences, NSUserDefaults, SQLite, Room DB, DataStore, Core Data, Keychain misconfiguration, external storage, backup exposure, plaintext files, unencrypted databases, adb backup, iCloud backup, NSFileProtection, EncryptedSharedPreferences, SQLCipher, allowBackup, FLAG_SECURE, keyboard cache, sensitive logs. Covers MASVS-STORAGE-1 (local storage) and MASVS-STORAGE-2 (exposure to unauthorized actors).

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Detects insecure network communication in mobile apps (Android/iOS). Trigger on: cleartext HTTP, TLS misconfiguration, certificate pinning bypass, hostname verification disabled, allowCleartextTraffic, NSAllowsArbitraryLoads, ATS exceptions, custom TrustManager, ALLOW_ALL_HOSTNAME_VERIFIER, TLS 1.0/1.1, weak cipher suites, certificate pinning absent, Network Security Configuration, onReceivedSslError, SSLSocket, OkHttp, NSURL, URLSession, certificate transparency, HSTS, MITM. Covers MASVS-NETWORK-1 (TLS required) and MASVS-NETWORK-2 (certificate validation).

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the Agentic Applications 2026 edition for AI/LLM. Use for security reviews, vulnerability audits, secure auth/crypto/access-control implementation, Kubernetes manifest hardening, and LLM/agent prompt-injection defense - including indirect requests like "is this login flow secure?", "review this endpoint", or "audit my pod spec".

日本語の概要は準備中です。原文の説明を表示しています。

davila7/claude-code-templates3.3万2026年10月6日 更新

Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.

日本語の概要は準備中です。原文の説明を表示しています。

dpearson2699/swift-ios-skills1,1852026年8月1日 更新

Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.

日本語の概要は準備中です。原文の説明を表示しています。

ivan-magda/swift-security-skill392026年6月17日 更新

Detects insecure platform interaction in mobile apps (Android/iOS). Trigger on: exported Activity, exported Service, exported BroadcastReceiver, Content Provider, Intent injection, deep link hijacking, WebView JavaScript enabled, JavascriptInterface, addJavascriptInterface, setJavaScriptEnabled, intent:// scheme, file:// scheme, WKWebView, WKScriptMessageHandler, UIPasteboard, URL scheme hijacking, Universal Links, PendingIntent, FLAG_IMMUTABLE, overlay attack, tapjacking, screenshot prevention, FLAG_SECURE, Broadcast sniffing, IPC data exposure. Covers MASVS-PLATFORM-1/2/3.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Detects code quality vulnerabilities in mobile apps (Android/iOS). Trigger on: SQL injection in SQLite, JavaScript injection in WebViews, intent injection, unsafe deserialization, NSKeyedUnarchiver, NSCoding, Java serialization, Parcelable, buffer overflow, JNI native code, PIE disabled, NX disabled, stack canary absent, RELRO, ARC disabled, third-party library CVE, vulnerable dependency, outdated SDK, targetSdkVersion, update enforcement missing, implicit Intent, URL loading in WebView, object persistence, memory corruption, OWASP dependency check. Covers MASVS-CODE-1/2/3/4.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Detects authentication and biometric bypass vulnerabilities in mobile apps (Android/iOS). Trigger on: BiometricPrompt, LocalAuthentication, LAContext, evaluatePolicy, CryptoObject, Android Keystore, Secure Enclave, kSecAccessControlBiometryCurrentSet, userAuthenticationValidityDurationSeconds, confirmCredentials, biometric fallback, PIN bypass, passive authentication, enrolled biometrics detection, Frida hook auth, jailbreak bypass, TouchID, FaceID, fingerprint. Covers MASVS-AUTH-1/2/3.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Detects weak reverse engineering and tampering protections in mobile apps (Android/iOS). Trigger on: root detection bypass, jailbreak detection bypass, Frida detection, debugger detection, anti-debugging, ptrace, sysctl, emulator detection, code obfuscation absent, debug symbols present, get-task-allow, ProGuard disabled, R8 disabled, string encryption, integrity check, file tampering, repackaging, dynamic instrumentation, runtime hook, Magisk hide, Magisk, frida-server, objection bypass, signing verification, apk resign. Covers MASVS-RESILIENCE-1/2/3/4.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Assess mobile applications with static and dynamic analysis aligned to OWASP MASTG and MASVS.

日本語の概要は準備中です。原文の説明を表示しています。

0x-Professor/Agent-Skills-Hub112026年2月27日 更新

Reviews mobile security across Flutter, native Android, native iOS, React Native and Kotlin Multiplatform using OWASP MASVS. Covers credential storage, secrets, transport, deep links, WebViews, logging and platform implementations of shared KMP contracts. Use for security audits, auth/token handling, pentest findings or release hardening.

日本語の概要は準備中です。原文の説明を表示しています。

wrsilva/reis-mobile72026年9月24日 更新

Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.

日本語の概要は準備中です。原文の説明を表示しています。

JordanCoin/ios-skills-collection62026年9月10日 更新

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences analysis, or mobile data leakage assessment.

日本語の概要は準備中です。原文の説明を表示しています。

aniket2348823/Vul-Agent22026年6月9日 更新