All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- Attack Prototype PollutionJavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitationVotes: 0GitHub stars: 2,182
- Attack Race ConditionRace condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flawsVotes: 0GitHub stars: 2,182
- Attack Rate Limit BypassRate limit bypass testing — XFF rotation, case variation, method switching, header manipulationVotes: 0GitHub stars: 2,182
- Attack Request SmugglingHTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypassVotes: 0GitHub stars: 2,182
- Attack SsrfServer-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniquesVotes: 0GitHub stars: 2,182
- Attack SstiServer-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template enginesVotes: 0GitHub stars: 2,182
- Attack Subdomain TakeoverSubdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitationVotes: 0GitHub stars: 2,182
- Attack WebsocketWebSocket security testing — CSWSH, message injection, auth bypass, origin validationVotes: 0GitHub stars: 2,182
- Attack XxeXML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsingVotes: 0GitHub stars: 2,182
- Aws PostexploitAWS post-exploitation — 92 programs for full kill chain from recon to cleanup via AWS CLIVotes: 0GitHub stars: 2,182
- Azure PostexploitAzure/Entra ID post-exploitation — 154 programs for tenant compromise, CIS compliance, identity attacks, data exfiltration, and M365 abuseVotes: 0GitHub stars: 2,182
- Bun File IoUse this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.Votes: 0GitHub stars: 2,182
- Ci AssessmentREAD-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chainVotes: 0GitHub stars: 2,182
- Cicd AttacksCI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLabVotes: 0GitHub stars: 2,182
- Cloud AssessmentMulti-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checksVotes: 0GitHub stars: 2,182
- Ebpf AttackseBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on LinuxVotes: 0GitHub stars: 2,182
- Gcp PostexploitGCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDKVotes: 0GitHub stars: 2,182
- K8s AssessmentREAD-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectlVotes: 0GitHub stars: 2,182
- K8s PostexploitKubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistenceVotes: 0GitHub stars: 2,182
- Kerberos AttacksKerberos protocol attack techniques and exploitationVotes: 0GitHub stars: 2,182
- Linux PostexploitLinux post-exploitation — credential harvesting, privilege escalation, persistence, lateral movement, evasion, exfiltration, and network attacks with multi-exec fallback (bash/sh/python3/perl/busybox) and stealth modes (base64/memfd/shm)Votes: 0GitHub stars: 2,182
- Llm SecurityOWASP LLM Top 10 security testing - prompt injection, system prompt leakage, excessive agency, sensitive data disclosureVotes: 0GitHub stars: 2,182
- Macos PostexploitmacOS post-exploitation — 46 programs across recon, credential harvesting, privilege escalation, persistence, evasion, monitoring, lateral movement, and exfiltrationVotes: 0GitHub stars: 2,182
- T1189 Drive By CompromiseAdversaries may gain access to a system through a user visiting a website over the normal course of browsing.Votes: 0GitHub stars: 2,182
- T1190 Exploit Public Facing ApplicationAdversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.Votes: 0GitHub stars: 2,182
- T1195 Supply Chain CompromiseAdversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.Votes: 0GitHub stars: 2,182
- T1199 Trusted RelationshipAdversaries may breach or otherwise leverage organizations who have access to intended victims.Votes: 0GitHub stars: 2,182
- T1200 Hardware AdditionsAdversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.Votes: 0GitHub stars: 2,182
- T1566.001 Spearphishing AttachmentAdversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.Votes: 0GitHub stars: 2,182
- T1566.002 Spearphishing LinkAdversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.Votes: 0GitHub stars: 2,182
- T1566.003 Spearphishing Via ServiceAdversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.Votes: 0GitHub stars: 2,182
- T1566.004 Spearphishing VoiceAdversaries may use voice communications to ultimately gain access to victim systems.Votes: 0GitHub stars: 2,182
- T1566 PhishingAdversaries may send phishing messages to gain access to victim systems.Votes: 0GitHub stars: 2,182
- T1659 Content InjectionAdversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.Votes: 0GitHub stars: 2,182
- T1669 Wi Fi NetworksAdversaries may gain initial access to target systems by connecting to wireless networks.Votes: 0GitHub stars: 2,182
- T1195 001 Compromise SoftwareAdversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.Votes: 0GitHub stars: 2,182
- T1195 002 Compromise Software SupplyAdversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.Votes: 0GitHub stars: 2,182
- T1195 003 Compromise Hardware SupplyAdversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.Votes: 0GitHub stars: 2,182
- T1047 Windows Management InstrumentationAdversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.Votes: 0GitHub stars: 2,182
- T1053.002 AtAdversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code.Votes: 0GitHub stars: 2,182
- T1053.003 CronAdversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.Votes: 0GitHub stars: 2,182
- T1053.005 Scheduled TaskAdversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.Votes: 0GitHub stars: 2,182
- T1053.006 Systemd TimersAdversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.Votes: 0GitHub stars: 2,182
- T1053.007 Container Orchestration JobAdversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code.Votes: 0GitHub stars: 2,182
- T1053 Scheduled TaskjobAdversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.Votes: 0GitHub stars: 2,182
- T1059.001 PowershellAdversaries may abuse PowerShell commands and scripts for execution.Votes: 0GitHub stars: 2,182
- T1059.002 ApplescriptAdversaries may abuse AppleScript for execution.Votes: 0GitHub stars: 2,182
- T1059.003 Windows Command ShellAdversaries may abuse the Windows command shell for execution.Votes: 0GitHub stars: 2,182
- T1059.004 Unix ShellAdversaries may abuse Unix shell commands and scripts for execution.Votes: 0GitHub stars: 2,182
- T1059.005 Visual BasicAdversaries may abuse Visual Basic (VB) for execution.Votes: 0GitHub stars: 2,182