Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CVE-2025-33073), ADCS ESC1-16 (EKUwu), ticket forgery & DCSync, dMSA BadSuccessor (CVE-2025-53779), BloodHound attack-path enumeration, domain dominance
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when red-teaming an agentic AI / LLM application — indirect & zero-click prompt injection, MCP tool poisoning, persistent memory poisoning, excessive-agency tool abuse, multi-turn jailbreaks, PyRIT/Garak/Promptfoo harnesses
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/vector poisoning, agentic/MCP exploitation (CVE-2025-54136), ML supply-chain RCE (pickle CVE-2025-32434), model extraction / membership inference / adversarial suffixes (GCG)
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution, compromised/mutable-tag actions, dependency confusion, registry worms, runner backdoors, OIDC trust abuse, SLSA/provenance
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新