elementalsouls/Claude-BugHunter
这个仓库里有 83 个技能,GitHub 星标 ★ 4,515。
- apk-redteam-pipelineEnd-to-end Android APK red-team pipeline — automated APK acquisition (Play Store
- bb-local-toolkitLocal-tooling companion to the bug-bounty orchestrator — carries the SAME comple
- bb-methodologyUse at the START of any bug bounty hunting session, when switching targets, or w
- bug-bountyComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fi
- bugcrowd-reportingBugcrowd-specific reporting tactics complementing report-writing: VRT category s
- cloud-iam-deepCloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exp
- enterprise-vpn-attackExternal SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect,
- evidence-hygieneEvidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie
- hunt-api-misconfigHunt API security misconfiguration — mass assignment, prototype pollution, HTTP
- hunt-aspnetHunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encryp
- hunt-atoHunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1
- hunt-auth-bypassHunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty r
- hunt-brute-forceHunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 k
- hunt-business-logicHunting skill for business logic vulnerabilities. Built from 12 public bug bount
- hunt-cache-poisonHunting skill for cache poison vulnerabilities. Built from 10 public bug bounty
- hunt-captcha-bypassHunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from
- hunt-cicdHunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_re
- hunt-clickjackingHunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attack
- hunt-cloud-misconfigHunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObj
- hunt-corsHunt CORS Misconfiguration — origin-reflection with credentials, null-origin tru
- hunt-csrfHunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports
- hunt-deserializationHunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injec
- hunt-dispatchSkill-set loader for /hunt orchestrator. Fingerprints the target, picks the righ
- hunt-domHunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via
- hunt-exceptional-conditionsHunt mishandling of exceptional conditions — feed an endpoint malformed/unexpect
- hunt-file-uploadHunt file upload bugs — RCE via webshell, XSS via SVG/HTML, SSRF via XXE in DOCX
- hunt-fintech-graphqlHunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfe
- hunt-forgot-passwordHunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patter
- hunt-graphqlHunting skill for graphql vulnerabilities. Built from 12 public bug bounty repor
- hunt-grpcHunt gRPC vulnerabilities — server reflection enabled (enumerate all services/me
- hunt-host-headerHunt Host Header Injection — password reset poisoning → ATO, web cache poisoning
- hunt-html-injectionHunt HTML Injection — user-supplied input is rendered as raw HTML in the respons
- hunt-http-smugglingHunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy
- hunt-idorHunting skill for idor vulnerabilities. Built from 26 public bug bounty reports.
- hunt-jwt-cryptoHunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 k
- hunt-k8sHunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSoc
- hunt-laravelHunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true expos
- hunt-ldapHunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-c
- hunt-lfiHunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal
- hunt-llm-aiHunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration vi
- hunt-mfa-bypassHunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive e
- hunt-miscHunting skill for misc vulnerabilities. Built from 225 public bug bounty reports
- hunt-nextjsHunt Next.js specific vulnerabilities — Server Actions arbitrary function execut
- hunt-nodejsHunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash
- hunt-nosqliHunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), Co
- hunt-ntlm-infoHunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/
- hunt-oauthHunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports
- hunt-open-redirectHunt Open Redirect — all types including low-impact, chained to OAuth token thef
- hunt-race-conditionHunting skill for race condition vulnerabilities. Built from 12 public bug bount
- hunt-rag-vectorHunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vec
- hunt-rceHunting skill for rce vulnerabilities. Built from 67 public bug bounty reports.
- hunt-samlHunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Asserti
- hunt-sessionHunt Session Management vulnerabilities — session fixation (no regeneration on l
- hunt-shadow-apiHunt shadow / zombie / undocumented API surface (OWASP API9 Improper Inventory M
- hunt-sharepointHunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem f
- hunt-source-leakHunt source code and build artifact leakage — JavaScript source maps (.js.map) r
- hunt-spa-apiDiscover a single-page-app's hidden backend API from its public JS bundle, then
- hunt-springbootHunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, l
- hunt-sqliHunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports
- hunt-ssrfHunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports
- hunt-sstiHunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (S
- hunt-subdomainHunting skill for subdomain takeover vulnerabilities. Includes modern provider f
- hunt-tls-networkHunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak c
- hunt-websocketHunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing
- hunt-xssHunting skill for xss vulnerabilities. Built from 174 public bug bounty reports.
- hunt-xxeHunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports i
- ios-redteam-pipelineEnd-to-end iOS red-team pipeline — IPA acquisition (App Store extraction, TestFl
- m365-entra-attackMicrosoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS co
- meme-coin-auditMeme coin and token security audit — rug pull detection (honeypot, hidden mint,
- mid-engagement-ir-detectionMethodology for detecting client SOC patches, attacker activity, and security-st
- offensive-osintOperational arsenal for authorized external red-team and bug-bounty recon. Concr
- okta-attackOkta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple
- osint-methodologyComprehensive OSINT methodology for external red-team operations and authorized
- recon-scope-triageTriage ASM/recon output for ownership before testing — separate the target's rea
- redteam-mindsetRed-team operator discipline — the mindset corrections that separate offensive t
- redteam-report-templateClient-facing red-team deliverable format — codifies the Subject / Observations
- report-writingBug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates,
- security-arsenalSecurity payloads, bypass tables, wordlists, gf pattern names, always-rejected b
- supply-chain-attack-reconExternal recon for software supply-chain attack surface — package-namespace squa
- triage-validationFinding validation before writing any report — 7-Question Gate (all 7 questions)
- vmware-vcenter-attackVMware vSphere / vCenter Server external attack matrix — version fingerprinting,
- web2-reconWeb2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder),
- web3-auditSmart contract security audit — 10 DeFi bug classes (accounting desync, access c
想一次拿到这个仓库的全部技能?
本站把开放许可(MIT / Apache 等)的仓库按整仓打包整理到网盘,点一下转存到你自己的网盘。许可未声明的仓库只给原始仓库链接,不打包。