All authors
MustafaKemal0146 avatar

Claude Skills by MustafaKemal0146

github.com/MustafaKemal0146
960 skillsA× 817B× 97C× 26D× 12F× 80 installs250 views
Prioritizing Vulnerabilities With Cvss ScoringA

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS

securitygogit
0
4
Scanning Infrastructure With NessusB

Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating

securitygobash
0
4
Triaging Vulnerabilities With Ssvc FrameworkA

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

securitypythongo
0
4
Bug Bounty HunterA

Bug bounty hunting advisor for responsible vulnerability disclosure. Program scope analysis, testing strategies, vulnerability discovery methods.

securitypythongo
0
4
Bypassing Authentication With Forced BrowsingB

Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.

securitygojava
0
4
Exploiting Broken Link HijackingA

Discover and exploit broken link hijacking vulnerabilities by identifying references to expired domains, decommissioned cloud resources, and dead external services that can be claimed by an

securityjavascriptgo
0
4
Exploiting Http Request SmugglingA

Tespit etme and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

securitypythongo
0
4
Exploiting Idor VulnerabilitiesA

Identifying and exploiting Insecure Direct Object Reference vulnerabilities to access unauthorized resources by manipulating object identifiers in API requests and URLs.

securitygobash
0
4
Exploiting Insecure DeserializationA

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

securitypythonrust
0
4
Exploiting Mass Assignment In Rest ApisA

Discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API

securitypythongo
0
4
Exploiting Nosql Injection VulnerabilitiesB

tespit etmeand exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.

securityjavascriptpython
0
4
Exploiting Oauth MisconfigurationA

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

securityjavascriptpython
0
4
Exploiting Prototype Pollution In JavascriptA

tespit etmeand exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.

securityjavascriptgo
0
4
Exploiting Race Condition VulnerabilitiesA

tespit etmeand exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use

securitypythongo
0
4
Exploiting Server Side Request ForgeryB

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.

securityrustgo
0
4
Exploiting Sql Injection With SqlmapB

Tespit etme and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

securitypythongo
0
4
Exploiting Template Injection VulnerabilitiesC

Tespit etme and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.

securitypythongo
0
4
Exploiting Type Juggling VulnerabilitiesA

Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion

securitypythongo
0
4
Exploiting Websocket VulnerabilitiesC

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.

securitypythonrust
0
4
Implementing Devsecops Security ScanningA

Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines using open-source tools. Covers

securitypythongo
0
4
Implementing Runtime Application Self ProtectionA

Dağıt: Runtime Application Self-Protection (RASP) agents to tespit etmeand block attacks from within application runtime, covering OpenRASP integration, attack pattern Tespit, and security policy

securitypythongo
0
4
Implementing Web Application Logging With ModsecurityA

Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack Tespit, and implement custom SecRules

securitygosql
0
4
Performing Blind Ssrf ExploitationA

tespit etmeand exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.

securitypythongo
0
4
Performing Clickjacking Attack TestA

Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.

securityjavascriptpython
0
4
Performing Content Security Policy BypassA

Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations, JSONP endpoints, unsafe directives, and policy injection techniques.

securityjavascriptgo
0
4
Performing Csrf Attack SimulationA

Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.

securityjavascriptpython
0
4
Performing Directory Traversal TestingC

Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.

securitygophp
0
4
Performing Fuzzing With AflplusplusA

Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments

securitygosql
0
4
Performing Graphql Security AssessmentA

Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.

securitypythongo
0
4
Performing Http Parameter Pollution AttackA

Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end

securitypythonrust
0
4
Performing Second Order Sql InjectionA

tespit etmeand exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

securitypythonrust
0
4
Performing Security Headers AuditA

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

securitygophp
0
4
Performing Subdomain Enumeration With SubfinderA

Enumerate subdomains of target domains using ProjectDiscovery's SubBul:er passive reconnaissance tool to map the attack surface during security assessments.

securityrustgo
0
4
Performing Supply Chain Attack SimulationA

Simulate and tespit etmesoftware supply chain attacks including typosquatting Tespit via Levenshtein distance, dependency confusion testing against private registries, package hash verification

securitypythonrust
0
4
Performing Web Application Firewall BypassA

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack

securityjavascriptgo
0
4
Performing Web Cache Deception AttackA

Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.

securitygobash
0
4
Performing Web Cache Poisoning AttackA

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

securityjavascriptgo
0
4
Seclists FuzzingA

SecLists-based security testing skill

securitypythongo
0
4
Sqli Test GeneratorA

Generate SQL injection test payloads for authorized security testing. Database-specific payloads for MySQL, PostgreSQL, MSSQL, Oracle.

securitygosql
0
4
Testing Api Security With Owasp Top 10A

Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.

securitygobash
0
4
Testing Cors MisconfigurationA

Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.

securitypythonrust
0
4
Testing For Broken Access ControlA

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

securitygobash
0
4
Testing For Business Logic VulnerabilitiesA

Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can Detect.

securitypythonrust
0
4
Testing For Email Header InjectionB

Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam

securityrustgo
0
4
Testing For Host Header InjectionA

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

securityjavascriptgo
0
4
Testing For Json Web Token VulnerabilitiesA

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass

securitypythongo
0
4
Testing For Open Redirect VulnerabilitiesA

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

securityjavascriptpython
0
4
Testing For Sensitive Data ExposureB

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

securityjavascriptgo
0
4
Testing For Xml Injection VulnerabilitiesB

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

securitypythongo
0
4
Testing For Xss Vulnerabilities With BurpsuiteA

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

securityjavascriptrust
0
4