All authors
NoorQureshi avatar

Claude Skills by NoorQureshi

github.com/NoorQureshi
206 skillsA× 186B× 11C× 4D× 2F× 30 installs22 views
Crypto Rsa AttacksA

Break RSA when parameters or padding are weak — recover plaintext or the private key from a public key and ciphertext. Load when you meet RSA in auth/tokens/TLS/custom crypto and have (n, e) + a ciphertext. Signals: a public key or n/e/c values, small exponent e=3, "textbook RSA", a JWT signed RS256 with a suspicious key, RsaCtfTool, factordb, close/shared primes, key you can't verify.

ai-agentspythongo
0
20
Defense Ad DefenseA

Detect and harden against Active Directory attacks — Kerberoasting, AS-REP roasting, DCSync, ADCS abuse, and delegation/relay. Load for "detect kerberoasting", "harden AD", "AD monitoring", "did someone DCSync us", or defending a domain. The defensive counterpart to the ad-* offensive skills.

ai-agentsgosecurity
0
20
Defense Cloud DetectionA

Detect and respond to attacks in cloud control planes — credential abuse, IMDS theft, persistence, and privilege escalation — from audit logs. Load for "detect cloud attacks", "CloudTrail/GuardDuty", "someone used our keys", AWS/Azure/GCP monitoring, or cloud IR. The defensive counterpart to the cloud-* offensive skills.

ai-agentsrustgo
0
20
Defense Detection EngineeringA

Build detections as a repeatable pipeline, not one-off alerts. Load for "improve our detections", "detection as code", "reduce false positives", "measure ATT&CK coverage", or turning a red-team finding into durable blue-team coverage. Complements defense-detection-sigma (the rule format).

ai-agentsrustgo
0
20
Defense Detection SigmaA

Write portable detections as Sigma rules and map them to MITRE ATT&CK, then convert to your SIEM. Load for blue-team/detection-engineering tasks: "write a detection", "sigma rule", "alert on", turning an offensive technique or an incident into a repeatable detection.

ai-agentsrustgo
0
20
Defense Dfir TriageA

First-response DFIR triage: scope an incident, collect volatile evidence, and find attacker activity on Linux/Windows. Load on "incident", "we got breached", "investigate this host", "IOCs", suspected compromise, or forensic triage. Signals: alert to investigate, suspicious host, "what happened".

ai-agentsgobash
0
20
Defense Hardening BaselineA

Turn offensive findings into concrete hardening — the fix side of each vuln class, plus config baselines. Load for blue-team/remediation tasks, "how do we fix/prevent", secure config review, or writing the remediation section of a report. Signals: "harden", "remediation", "secure baseline", "prevent".

securityrustsql
0
20
Defense Incident ResponseA

Run an incident end to end — detect, scope, contain, eradicate, recover, learn. Load for "we've been breached", "incident response", "contain this host", "we found malware/an intrusion", or to build an IR plan. Complements defense-dfir-triage (evidence collection) with the response process around it.

ai-agentsrustgo
0
20
Defense Log AnalysisA

Hunt for attacker activity in logs — auth, web, cloud, endpoint — with concrete queries and what to look for. Load for blue-team log/SIEM hunting, "analyze these logs", "find the attack", triage of auth/web/cloud logs, or building hunts. Signals: log files/SIEM, "what happened", IOC hunting.

ai-agentsgoshell
0
20
Defense Malware TriageA

Safely triage a suspicious file or process — is it malicious, what does it do, and what IOCs does it yield — with static then dynamic analysis. Load for "is this file malware", "analyze this binary/script/document", "suspicious process on a host", or extracting IOCs for hunting/detection.

ai-agentsgo
0
20
Defense Network DetectionA

Detect attacker activity in network telemetry — C2 beaconing, DNS tunnelling, data exfil, and lateral movement. Load for "detect C2", "find beaconing", "network monitoring / NSM", "suspicious traffic", or building Zeek/Suricata coverage. The defensive counterpart to the offensive network/pivoting skills.

ai-agentsgogit
0
20
Defense Purple TeamA

Run a purple-team exercise — emulate specific attacker techniques and validate detection/response end to end. Load for "purple team", detection validation, ATT&CK coverage testing, "can we detect X", or turning red-team findings into blue-team improvements. Signals: detection gaps, ATT&CK mapping, control testing.

ai-agentstesting
0
20
Defense Threat HuntingA

Hunt for intrusions no alert fired on — hypothesis-driven, ATT&CK-guided searching across EDR and logs. Load for "threat hunt", "are we compromised", "hunt for <technique>", proactive blue-team work, or turning threat intel into a hunt. Complements detection engineering: hunts find the gaps, then become detections.

ai-agentsgo
0
20
Defense Threat ModelingA

Threat-model a system or feature (STRIDE + attack trees) to find design-level risk before code. Load on "threat model", a new design/architecture review, security design questions, or planning controls. Signals: architecture diagram, data-flow, "what could go wrong", pre-build security.

ai-agentsrustgo
0
20
Exploit ChainingA

Combine low/medium findings into one high-impact exploit chain, and amplify demonstrated impact. Load when you have several small bugs, a "so what?" finding, on "chain", "escalate impact", or building the narrative for a report. Signals: self-XSS + CSRF, open-redirect + OAuth, IDOR + info-leak, SSRF + metadata.

ai-agentsgo
0
20
Exploit Memory CorruptionA

Turn a memory-corruption bug in a native binary into code execution — stack overflows, format strings, and ROP against modern mitigations. Load when you control input to a compiled program and it crashes or misbehaves: a network daemon, a thick client, a setuid/SUID helper, or extracted firmware. Signals: segfault on long/`%n` input, a crash with control of a register, no source, checksec output, "exploit this binary/service".

ai-agentsgoc++
0
20
Exploit Poc DevelopmentA

Turn a known/1-day vulnerability or a raw bug into a working, reliable PoC for an authorized target. Load when a CVE/advisory needs weaponizing, a public PoC needs adapting, or "write an exploit/PoC". Signals: a versioned service with a known CVE, a crash/primitive to develop, searchsploit hits.

ai-agentspythongo
0
20
Mobile Android AssessmentA

Assess an Android app (static + dynamic). Load when the target is an APK/AAB, a mobile bug-bounty scope, or "test the android app". Signals: .apk file, Java/Kotlin/Smali, AndroidManifest.xml, exported components, WebViews, hardcoded secrets, Frida/objection.

ai-agentsrustgo
0
20
Mobile Cert Pinning BypassA

Bypass TLS certificate pinning so you can proxy a mobile app's traffic. Load when a proxy shows no/broken traffic, you see SSL handshake failures in logs, OkHttp CertificatePinner, TrustKit, or "the app won't connect through Burp". Android/iOS.

ai-agentsrustgo
0
20
Mobile Deeplink AbuseA

Abuse deep links / custom URL schemes / intents for redirect, token theft, and reaching internal screens. Load on custom schemes (myapp://), App Links/Universal Links, exported activities, or "open in app". Signals: intent-filters in the manifest, WebView loading deep-link params, OAuth redirect via a custom scheme.

ai-agentsjavascriptrust
0
20
Mobile Ios AssessmentA

Assess an iOS app (static + dynamic). Load when the target is an IPA / iOS app, an iOS bug-bounty scope, or "test the iOS app". Signals: .ipa, Info.plist, Swift/Obj-C, Keychain, URL schemes, ATS exceptions, Frida/objection on a jailbroken device.

ai-agentsrustgo
0
20
Mobile WebviewA

Exploit insecure mobile WebViews — JS-bridge abuse, file access, and XSS→native. Load when an app renders web content in a WebView/WKWebView, exposes a JS bridge, or loads attacker-influenced URLs. Signals: addJavascriptInterface, WKScriptMessageHandler, loadUrl, file:// access, deep-link → WebView.

ai-agentsjavascriptgo
0
20
Network Appliance AttacksA

Offensively test perimeter appliances and VPN crypto — IKE/IPsec aggressive mode, transform/DH enumeration, safe firmware/version inference for FortiGate / PAN-OS / Cisco ASA / Citrix feeding CVE applicability, TLS-version posture, and NTLM Type-2 info leaks. Load when an edge firewall, VPN, or load balancer is in scope. Signals: UDP 500/4500, ports 4433/10443/443 on an appliance, "SSL-VPN"/"Global Protect"/"Pulse"/"NetScaler" banners, Check Point SIC (18190/18191).

ai-agentsgotesting
0
20
Network Credential CrackingB

Crack hashes and handshakes captured during an engagement — identify the format, pick the right hashcat/john mode, and run wordlist + rules. Load when you've recovered a hash, ticket, or handshake and need the plaintext. Signals: bcrypt $2b$/PBKDF2/sha512crypt $6$, NTLM/NetNTLMv2, Kerberos $krb5tgs$/$krb5asrep$, WPA2 .22000, a leaked DB hash column, "what hashcat mode".

ai-agentsgogit
0
20
Network Ntlm RelayA

Coerce and relay NTLM authentication for lateral movement and privilege escalation (relay to SMB, LDAP, ADCS). Load in an AD network with a foothold, on "NTLM relay", "responder", "coerce", no/absent SMB signing, or PetitPotam/PrinterBug. Signals: LLMNR/NBT-NS traffic, SMB signing off, MS-RPRN/EFSRPC.

ai-agentsgo
0
20
Network Password SprayingA

Low-and-slow credential attacks against exposed auth surfaces — spray one password across many users, and stuff known breach creds — without locking accounts. Load on a login portal or service auth with valid usernames: OWA/O365/Entra, VPN, Citrix, SSH, RDP, SMB, LDAP, or a web login. Signals: a harvested user list, "AzureAD"/"outlook", 401/403 on auth, lockout policy known.

ai-agentsgoazure
0
20
Network Pivoting TunnelingA

Pivot into internal networks from a foothold — tunnels, port-forwards, and proxychains. Load when a host has a second NIC / reaches an internal subnet you can't hit directly, on "pivot", "internal network", "double-hop", after a foothold in a multi-host lab.

ai-agentsrustgo
0
20
Network Service AttacksA

Attack non-web network services surfaced by recon. Load when nmap shows services like SMB (445), RPC (135), LDAP (389), SNMP (161), NFS (2049), SMTP (25), FTP (21), RDP (3389), databases (3306/5432/1433/6379/27017). Signals: open non-HTTP ports, service+version banners.

ai-agentsgodatabase
0
20
Payloads File TransfersA

Move files on/off a target when there's no shared drive — upload tools (linpeas, nc, exploits), pull loot back, and do it through a pivot or when wget/curl are missing. Load when you need to get a file to or from an authorized host. Signals: "transfer a file", "upload linpeas", "no wget/curl", "get the file off the box", certutil/bitsadmin/impacket-smbserver, exfil over a tunnel.

ai-agentspythongo
0
20
Payloads Reverse ShellsA

Get a reliable reverse (or bind) shell and upgrade it to a real interactive TTY. Load the moment you have code execution and need a shell back — RCE confirmed, a command-injection sink, an upload that runs, a webshell, a cron/service you control. Signals: "reverse shell", "get a shell", "nc listener", "shell is dumb / no tab completion", "which payload", stabilize/upgrade a shell.

ai-agentspythongo
0
20
Payloads Waf BypassA

Bypass WAFs/filters blocking your payloads. Load when a payload that should work is blocked, you see 403/406/429 or "request blocked", Cloudflare/Akamai/Imperva/AWS-WAF/ModSecurity, or a filter strips keywords. Signals: works locally but blocked on target, generic block pages.

ai-agentsgosql
0
20
Payloads Xss PolyglotsA

Context-breaking XSS polyglots and per-context payloads that fire across HTML/attribute/JS/ URL sinks in one shot. Load when confirming XSS fast, unsure of the injection context, or a single test payload should cover many contexts. Signals: reflected input, XSS triage, "polyglot".

ai-agentsjavascriptgo
0
20
Privesc ArsenalF

One line: Linux + Windows local privilege-escalation tool arsenal for authorized engagements. Trigger signals: "privesc", "got a shell", "escalate", "root", "SYSTEM", initial access gained but not root. Authorized, in-scope targets only.

ai-agentspythongo
0
20
Privesc EnumerationF

Systematic post-foothold host enumeration and credential/loot hunting on Linux and Windows — build situational awareness and find the lead that escalates or moves laterally. Load the moment you land a shell and think "now what?". Signals: fresh foothold, low-priv user, "enumerate the box", "situational awareness", hunting configs/history/creds, before running exploit tooling.

ai-agentsgophp
0
20
Privesc Linux GtfobinsA

Linux privilege escalation via sudo rules, SUID/SGID binaries, and capabilities using GTFOBins techniques. Load with a Linux shell needing root, on `sudo -l` output, SUID/`getcap` findings, or "escalate on Linux". Signals: allowed sudo commands, SUID binaries, file capabilities, cron/PATH abuse.

ai-agentspythongo
0
20
Privesc Windows TokensA

Windows privilege escalation via token impersonation privileges — SeImpersonate/SeAssignPrimaryToken (the Potato family) and related token abuse to SYSTEM. Load with a Windows shell as a service/web account, on "SeImpersonate", "whoami /priv", IIS/MSSQL service context, or "got a shell on Windows".

ai-agentsgoshell
0
20
Recon ArsenalC

One line: port/host/service discovery tool arsenal for authorized engagements. Pack in trigger signals so it auto-loads: "new target", "enumerate", "scan", an in-scope target, open-port lists needing deeper enum. Authorized, in-scope targets only.

ai-agentsrustgo
0
20
Recon Cloud AssetsA

Discover an organization's cloud footprint — buckets, blobs, apps, IP ranges, and services across AWS/GCP/Azure. Load during recon on a company target, on "cloud recon", finding storage/assets, or before cloud testing. Signals: an org name/domain in scope, assets on cloud CDNs, wildcard program.

ai-agentsgoaws
0
20
Recon Content DiscoveryA

Discover hidden paths, endpoints, params, and JS-exposed routes on a web target. Load after a live host is found, on "dirbust/content discovery/fuzzing", or when mapping an app's real surface. Signals: a single web host to deep-map, SPA with API calls, /api, JS bundles.

ai-agentsjavascriptgo
0
20
Recon Dns AnalysisA

Deep DNS analysis for attack surface — record mining, zone transfers, DNSSEC/NSEC walking, and dangling records. Load during recon, on "DNS", a domain in scope, or hunting takeovers/origin IPs. Signals: a root domain, CNAMEs, MX/TXT/SPF, NS servers, subdomains to resolve.

ai-agentsgorails
0
20
Recon Github Code LeaksB

Find secrets and internal detail an organisation leaked to public code — GitHub/GitLab repos, gists, and commit history. Load during recon of a named org, on "github dorks", "leaked secrets", "find API keys", or when employees/repos are in scope. Signals: a company GitHub org, developer usernames, an internal domain to grep for.

securitygoaws
0
20
Recon Js AnalysisA

Mine JavaScript for endpoints, params, secrets, and hidden functionality. Load on SPAs, heavy JS apps, after crawling, or "analyze the JS". Signals: bundled JS (webpack/main.*.js), API calls in JS, source maps, /static/js, front-end frameworks.

ai-agentsjavascriptgo
0
20
Recon OsintA

Passive OSINT to expand attack surface without touching the target: dorks, code/secret leaks, Shodan/Censys, cloud assets, employees. Load at recon start, on "OSINT", "google/github dorks", "shodan", or gathering intel on an org. Signals: org name, root domain, "find leaks/exposed".

ai-agentsgotesting
0
20
Recon Subdomain EnumA

Enumerate subdomains and live hosts to build the attack surface for a bug-bounty program or external assessment. Load at engagement start, on "recon", a root domain in scope, "find subdomains", or before content discovery. Signals: wildcard scope (*.target.com), a program scope list, a new external target.

ai-agentsrustgo
0
20
Recon Techstack FingerprintingA

Passively identify a target's full technology stack — frontend framework, backend runtime, server, CMS, CDN/WAF, cloud, and versions — from public signals, then route to the right attack skills and CVEs. Load at the start of a web/API assessment, when choosing which techniques apply, or when "what is this built with / what CVEs match". Signals: a new domain in scope, unknown stack, "fingerprint", "what framework", version-to-CVE matching.

ai-agentsgophp
0
20
Reporting Bug Bounty WriteupA

Turn a confirmed finding into a triage-friendly bug-bounty report (HackerOne/Bugcrowd) with correct severity and clean evidence. Load when a bug is validated and needs submitting, on "write the report", "CVSS", "severity", or before disclosure. Signals: a reproduced finding, a program's VRT/severity policy.

ai-agentsgo
0
20
Reporting Cvss ScoringA

Assign a defensible severity to a finding — build the CVSS 3.1 vector from demonstrated impact and reconcile it with the program's own scale. Load on "what severity", "CVSS", "rate this bug", or before submitting a report. Signals: a confirmed finding needing a score, a program VRT/severity policy, a severity dispute.

ai-agentsrustgo
0
20
Reporting Pentest ReportA

Structure a professional penetration-test report (engagement deliverable, not a single bug). Load at the end of a pentest, on "write the pentest report", "executive summary", "deliverable", or compiling findings for a client. Signals: engagement wrap-up, multiple findings, client report.

securitygotesting
0
20
Reporting Triage CommunicationA

Work productively with triagers after you submit — answer follow-ups, and handle duplicate, not-applicable, or severity disputes professionally. Load on "triage asked for more info", "they closed it as N/A", "dispute the severity/duplicate", or managing a report thread. Signals: a submitted report awaiting/receiving triage, a disagreement on outcome.

ai-agentsgo
0
20
Reporting Triage ValidationA

Validate a finding BEFORE you write it up — kill false positives, confirm real impact, check scope, and deduplicate. Load after a candidate bug and before reporting-bug-bounty-writeup or reporting-pentest-report. Signals: "I think I found", "is this reportable", a scanner hit, a reflected value, a 500 error, an open redirect, a CORS wildcard, "should I submit this".

ai-agentsgo
0
20