hypnguyen1209/offensive-claude
这个仓库里有 37 个技能,GitHub 星标 ★ 367。
- active-directory-attackUse when attacking a Windows Active Directory domain — Kerberos roasting/delegat
- advanced-redteam
- ai-agent-redteamUse when red-teaming an agentic AI / LLM application — indirect & zero-click pro
- ai-securityUse when attacking an AI/ML system or model — prompt injection & jailbreaks (Cre
- browser-exploitationUse when building a client-side browser exploit — V8/JSC JIT type confusion to r
- cicd-supply-chainUse when attacking or auditing a CI/CD pipeline or software supply chain — pwn r
- cloud-securityUse when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS
- coding-masteryUse when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust
- container-k8s-escapeUse when breaking out of a container or escalating inside Kubernetes — runc/Buil
- crypto-analysisUse when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA n
- edr-evasionUse when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect sys
- engagement-flowUse when starting, planning, or running a multi-phase pentest or red-team engage
- engagement-memoryUse when recalling prior techniques at recon/weaponize, or recording a confirmed
- exploit-developmentUse when turning a memory-corruption bug into a working PoC — stack/ROP, glibc h
- finding-disciplineUse when about to record, claim, rate the severity of, or report any security fi
- incident-responseUse when responding to or forensically investigating an incident — triage acquis
- keylogger-arch
- malware-analysisUse when reverse-engineering or detecting malware — static triage + capa/YARA-X,
- mobile-pentestUse when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning &
- network-attackUse when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS,
- opsec-disciplineUse when about to take any outward or offensive action (request, payload, persis
- privesc-linuxUse when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE
- privesc-windowsUse when escalating privileges on a Windows host — SeImpersonate Potato chains (
- recon-osintUse when mapping a target's external attack surface or gathering OSINT — subdoma
- red-team-opsUse when running a full red-team engagement end-to-end — initial access, persist
- reverse-engineeringUse when reverse-engineering a binary or firmware — static triage + decompilatio
- scope-disciplineUse when about to send a request to, scan, enumerate, exploit, or otherwise inte
- shellcode-devUse when writing position-independent shellcode or a loader — PEB walking, API h
- threat-huntingUse when hunting threats or engineering detections — ATT&CK Detection-Strategies
- threat-model-disciplineUse when starting an engagement, before exploitation, or whenever the attack sur
- using-offensive-claudeUse when starting any offensive-security engagement or task — establishes how to
- vulnerability-analysisUse when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern t
- web-pentestUse when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-me
- windows-boundariesUse when crossing a Windows security boundary or escaping a sandbox — kernel/use
- windows-mitigations-bypassUse when bypassing a Windows exploit/platform mitigation — ASLR/DEP/CFG/XFG/CET,
- wireless-rfUse when the target has a non-Wi-Fi radio attack surface — Bluetooth/BLE (GATT,
- writing-offensive-skillsUse when creating or editing a skill in this offensive-claude repo — for the SKI
想一次拿到这个仓库的全部技能?
本站把开放许可(MIT / Apache 等)的仓库按整仓打包整理到网盘,点一下转存到你自己的网盘。许可未声明的仓库只给原始仓库链接,不打包。