All authors
NoorQureshi avatar

Claude Skills by NoorQureshi

github.com/NoorQureshi
206 skillsA× 186B× 11C× 4D× 2F× 30 installs22 views
Web Ssrf Gopher Redis RceF

Turn a server-side request (SSRF) into RCE by speaking the Redis protocol over gopher:// to an internal, unauthenticated Redis — write a cron job, an SSH key, or a webshell. Load when: SSRF is confirmed (URL fetch, webhook, PDF/URL preview, image proxy) AND an internal Redis/6379 (or similar line-protocol service) is reachable. Authorized targets only.

ai-agentsgophp
0
20
Web SsrfA

Discover and escalate Server-Side Request Forgery. Load when the app fetches a URL you influence: webhooks, "import from URL", link/image preview, PDF/HTML render, avatar-by-URL, URL health-checks, XML/SVG parsers. Signals: params like url=, uri=, dest=, callback=, image=, feed=, or a request that reaches out on your behalf.

ai-agentsrustgo
0
20
Web SstiA

Server-Side Template Injection → RCE. Load when user input is rendered by a template engine: profile names in emails, custom reports, "hello {{name}}", error pages echoing math, Jinja2/Twig/Freemarker/Velocity/ERB/Handlebars. Signals: {{7*7}} returns 49, ${...} or #{...} evaluated, framework stack traces mentioning a templating engine.

ai-agentspythongo
0
20
Web Subdomain TakeoverA

Claim a dangling DNS record pointing to a deprovisioned service (subdomain takeover). Load after subdomain enum, on CNAMEs to cloud services, "NoSuchBucket"/"404 there isn't a GitHub Pages site here", or dangling A/CNAME. Signals: CNAME → S3/GitHub/Heroku/Azure/Fastly with a fingerprint error page.

ai-agentsrustgo
0
20
Web Testing ChecklistA

A fast, ordered checklist for testing a web application end to end — so nothing gets skipped. Load when starting on a web target, "checklist", "what should I test", methodology triage, or to confirm coverage before reporting. Signals: a new web app in scope, "am I missing anything".

ai-agentsgosql
0
20
Web Webauthn Software AuthenticatorA

Register and authenticate against a WebAuthn/FIDO2 relying party using a self-built SOFTWARE authenticator (no hardware key) when the RP requests attestation "none" (or otherwise doesn't verify attestation trust). Load when: a login is "WebAuthn/passkey/ FIDO2", endpoints like /webauthn/register|auth/begin|finish, `navigator.credentials`, and you hold (or can leak) a registration invite/enrollment token. Authorized targets only.

ai-agentspythonrust
0
20
Web WebsocketA

Attack WebSocket endpoints — CSWSH (cross-site hijacking), message tampering, and auth gaps. Load on ws:// or wss:// connections, Socket.IO, real-time chat/notifications/trading, or "websocket". Signals: Upgrade: websocket, ws handshake, JSON messages over a socket, token in the handshake.

ai-agentsrustgo
0
20
Web XssA

Find and prove Cross-Site Scripting (reflected, stored, DOM). Load when input is echoed into HTML/JS/attributes, a search/comment/profile field renders your text, a URL param appears in the response, or a sink like innerHTML/document.write is in client JS. Signals: "search=", reflected values, error pages echoing input, Angular/React dangerouslySetInnerHTML.

ai-agentsjavascriptgo
0
20
Web XxeB

XML External Entity injection → file read, SSRF, sometimes RCE. Load when the app parses XML you supply: SOAP, SAML, XML APIs, SVG/DOCX/XLSX upload, RSS import, `Content-Type: application/xml`. Signals: XML request bodies, "<?xml", SAML responses, file parsers.

ai-agentsgophp
0
20
Wireless Evil TwinA

Stand up a rogue/evil-twin access point to harvest credentials — WPA2-Enterprise PEAP-MSCHAPv2 challenge/response and captive-portal capture. Load on an authorized wireless engagement targeting WPA-Enterprise (802.1X) or a portal-based network. Signals: PEAP/EAP/802.1X, RADIUS, "enterprise Wi-Fi", eaphammer/hostapd-wpe in play, a captive portal, corporate SSID with per-user logins.

ai-agentsgorails
0
20
Wireless Wpa2 AttacksA

Attack WPA2-PSK Wi-Fi end to end — monitor mode, network discovery, handshake/PMKID capture, and offline cracking. Load on an authorized wireless engagement with a WPA2-personal network in scope. Signals: an SSID/BSSID to test, a wireless adapter in monitor mode, a captured .pcap/.22000, "crack the Wi-Fi", "capture the handshake", aircrack-ng/hcxdumptool in play.

ai-agentsgotesting
0
20
Exploit Pwn ChainA

Engineer a reliable exploit from a known memory-corruption bug — stack, heap, or kernel — taking a local crash to a stable remote exploit: ret2libc/ret2csu/one_gadget, tcache/fastbin/unsorted-bin techniques matched to the glibc version, kernel pwn against SMEP/SMAP/KASLR/KPTI, and remote stabilization (libc fingerprinting, stack alignment, recvuntil anchoring, spray sizing). Load when you have binary + bug + target environment and "local works, remote crashes". Signals: pwn, ROP, ret2libc, on...

ai-agentsgoshell
0
20
Hardware Ot IcsA

Assess OT/ICS environments — PLC, SCADA, DCS, HMI — safely and passive-first: Purdue-model zoning, industrial protocol discovery (Modbus, S7, DNP3, EtherNet/IP), mirrored-traffic analysis, and read-only verification. Load for an authorized engagement touching industrial control networks, engineering workstations, historians, or IT/OT boundaries. Signals: ports 502, 102, 44818, 20000; Modbus/S7comm banners; PLC/RTU inventory requests.

securitygogit
0
20
Hardware Radio SdrA

Authorized RF/SDR security research on non-Wi-Fi radio signals — identify a signal's frequency and modulation receive-only, demodulate and reverse the protocol, and assess replay feasibility in a shielded lab. Load for wireless remotes, key fobs, sensors, telemetry, ISM-band devices, ADS-B, or any sub-GHz/RF protocol outside classic Wi-Fi. Signals: unknown RF device in scope, 315/433/868/915 MHz, OOK/ASK/FSK captures, RTL-SDR/HackRF work.

ai-agentsrustgo
0
20
Hardware SecurityA

Discover and triage hardware debug interfaces (UART, JTAG, SWD) on an authorized embedded device — read boot logs, land a root console, interrupt the bootloader, and extract flash for offline analysis. Load when handed a physical device, PCB, or IoT/embedded target in scope, exposed test points or header pins, a serial console, U-Boot prompt, or a flash chip to dump. Signals: TX/RX/GND pads, silkscreen labels, baud-rate guessing, IDCODE enumeration.

ai-agentsgoshell
0
20
Mobile Apk ReverseD

Reverse an Android APK end-to-end — jadx/apktool unpacking, manifest and smali analysis, rebuild-sign-install patching, and Frida runtime hooks. Load when handed an .apk to understand, modify, or instrument: login/signing/risk-control logic, root or SSL-pinning checks, cert validation, embedded .so/JNI code. Signals: an APK in scope, "decompile/patch this app", smali, AndroidManifest.xml, jadx/apktool/frida/adb, System.loadLibrary, OkHttp/Retrofit.

ai-agentsrustgo
0
20
Reverse Eng Binary NinjaA

Reverse engineer in Binary Ninja — HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patching, Python API automation, and the optional MCP/HTTP bridge. Load when the user picks Binary Ninja, when its IL levels materially help data-flow analysis, or when IDA/Ghidra/radare2 results need an independent cross-check. Signals: "binaryninja", HLIL/MLIL, BinaryView scripting, Vector 35, localhost:9009 bridge.

ai-agentspythonrust
0
20
Reverse Eng DotnetA

Reverse a .NET / C# assembly — decompile, deobfuscate, debug, and IL-patch managed binaries. Load when the target is a managed PE (.exe/.dll with a CLR header), a Sharp* red-team tool (Rubeus, SharpHound, Seatbelt), a ConfuserEx/SmartAssembly/Babel/.NET-Reactor-obfuscated sample, or a .NET loader/stealer. Signals: "mscoree" / "_CorExeMain" / "mscorlib" strings, garbled Unicode class names in a decompiler, "deobfuscate this .NET", "patch/keygen a C# binary".

ai-agentsgoc#
0
20
Reverse Eng Edr AnalysisA

Reverse engineer the EDR/AV on an authorized target host, then evade it — fingerprint the product, dump its userland hook table, and assemble a matching bypass stack: ntdll unhooking, direct/indirect syscalls (Hell's/Halo's/Tartarus Gate), ETW and AMSI patching, hardware-breakpoint Blindside, call-stack spoofing, PPID spoof, sleep masks. Load for "bypass EDR", implant OPSEC against CrowdStrike/Defender/SentinelOne, or when telemetry keeps killing your payload. Signals: unhook, direct syscall,...

ai-agentspythongo
0
20
Reverse Eng GhidraA

Reverse engineer with Ghidra (GUI, headless, or ghidra-mcp) — decompile, cross-references, scripting — when there's no IDA license, for batch/CI decompilation, or as a free second opinion. Load for "decompile without IDA", bulk analysis of many samples, analyzeHeadless, Ghidra scripts (Jython/PyGhidra), or patch diffing with ghidriff. Signals: an ELF/PE needing a decompiler, "use Ghidra", headless automation, no commercial RE license.

ai-agentspythonrust
0
20
Reverse Eng Go RustA

Reverse stripped Go and Rust binaries — recover symbols from pclntab/moduledata and panic metadata, then navigate language-specific idioms. Load when a stripped ELF/PE/Mach-O shows Go or Rust runtime residue. Signals: "go.buildid", "runtime.main" / "main.main", "panic:" or "rust_begin_unwind" strings, /rustc/ or src/*.rs paths, huge static binary with no symbols, Go malware, a Rust release build.

ai-agentsrustgo
0
20
Reverse Eng IdaA

Deep reverse engineering in IDA Pro — Hex-Rays decompile, cross-references, types, patching — via the GUI or the ida-pro-mcp bridge for agent-driven analysis. Load when a PE/ELF/Mach-O/DLL/SYS needs pseudocode-grade analysis: license/serial checks, crypto or protocol recovery, a sink found during triage, malware capability mapping. Signals: "decompile this exe/dll", IDA, Hex-Rays, idapro_* tools, port 13337, .i64/.idb database, idalib.

ai-agentsrustgo
0
20
Reverse Eng JsA

Reverse front-end JavaScript end to end: trace which script fires a given request, capture a signing/encryption function's real inputs at runtime, then rebuild the algorithm locally in Node.js with evidence-driven environment shims until it reproduces the target parameter. Load when you need the *mechanism* behind client-computed params (sign, signature, _signature, X-Sign, token, encrypted bodies, anti-bot / risk-control fields), when webpack-minified or obfuscated JS hides the logic, or whe...

ai-agentsjavascriptgo
0
20
Reverse Eng MacosA

Reverse macOS Mach-O binaries and .app bundles — codesign/notarization state, entitlements, Objective-C/Swift symbol recovery, and lldb/Frida dynamic analysis. Load when the target is a Mach-O executable/dylib/framework, an .app bundle, a LaunchAgent/Daemon plist, or Apple-platform malware. Signals: "Mach-O 64-bit executable", codesign/spctl output, hardened runtime, objc_msgSend, mangled _ZN/_$s symbols, XPC service names, TCC prompts.

ai-agentsrustgo
0
20
Reverse Eng MalwareA

Fully analyze a malware sample — static, dynamic, and behavioral — including unpacking and IAT rebuild, import-table triage, anti-analysis detection and defeat, IOC extraction, and YARA/Sigma rule writing. Load when handed a suspicious PE/ELF/Mach-O/script sample to reverse beyond quick triage: packed binaries, "analyze this malware", a sandbox run that shows no behavior, or a need for durable detection. Signals: a dropped sample, a VirusTotal/MalwareBazaar hash, C2 strings, anti-VM/anti-debu...

ai-agentsrustgo
0
20
Reverse Eng Patch DiffA

Turn a vendor security patch into a working N-day: diff the patched and unpatched binaries, read the newly added safety checks back to a bug class, then write a PoC that crashes the unpatched build. Load for a CVE with a patch but no public PoC, Patch Tuesday triage (ntoskrnl / win32k / afd.sys / clfs.sys), Linux LTS backport analysis, bindiff / ghidriff / Diaphora workflows, patch diff, binary diffing to find what a patch fixed.

ai-agentsgobash
0
20
Reverse Eng ProtocolA

Reverse a custom network protocol from captured traffic or the client binary: recover the frame layout, message-type dictionary, field meanings, and state machine. Load for custom TCP/UDP binary protocols, Protobuf/gRPC without reflection, FlatBuffers/MessagePack, WebSocket/MQTT/private RPC framing, PCAP-driven format recovery, length-prefixed or TLV frames, magic bytes, CRC/checksum fields, or encrypted frame headers.

ai-agentspythongo
0
20
Reverse Eng Radare2A

Command-line binary analysis with radare2/r2 — recon, disassembly, strings/imports, cross-references, patching, diffing, and scripting, no GUI needed. Load for exe/dll/so/elf/dex/wasm CLI analysis, quick triage before committing to IDA/Ghidra, r2 batch commands (-c/-A), r2pipe scripts, or help with rabin2/rasm2/radiff2/rahash2/rax2. Signals: "use radare2/r2", terminal-only environment, radiff2 diffing, fast recon on a new sample.

ai-agentsjavascriptrust
0
20
Reverse Eng Thick ClientA

Security-test a desktop thick client end to end: map its trust boundaries, then work the local attack surface (config files, credential storage, IPC, update channel) and the network surface (proxying, certificate pinning, hidden APIs). Load for a C/S desktop app in scope — Electron, Qt, .NET WinForms/WPF, or native — an installer to audit, local config/credential storage to assess, named pipes or loopback IPC, an auto-update channel, or a client that hides admin-only API calls.

securityrustgo
0
20
Ai Sensitive Data DisclosureA

Make an LLM app disclose sensitive data it should never reveal: training-data memorization, secrets/PII in RAG context, cross-tenant leakage, conversation logs. Load when the target LLM has RAG/document access, is multi-tenant (per-user/per-org assistants), was fine-tuned on private data, or logs conversations. Signals: "ask your documents", per-org chatbots, upload a file and query it, admin/debug endpoints, conversation history in analytics.

ai-agentsgogit
0
20
Ai System Prompt LeakageB

Extract an LLM app's system prompt / hidden developer instructions — the attack map that reveals guardrails, tool definitions, internal endpoints, and planted secrets. Load when the target is a chatbot/assistant/agent with hidden instructions, refuses with policy-sounding language, names tools or functions in errors, or does RAG. Signals: "repeat your instructions", canned refusals, verbose tool-call errors, "you are a helpful assistant for <company>".

ai-agentsgorails
0
20
Automation BrowserA

Drive a real browser against an in-scope web app with Playwright / agent-browser: automated login, form and payload submission through the UI, scraping JS-rendered pages, request/response interception, and evidence screenshots. Load on "browser automation", "fill this form", "submit payload", "screenshot this page", automated login, headless crawling, or UI-driven XSS testing. Signals: Playwright, agent-browser, headless, @e1 element refs, networkidle, DOM interaction.

ai-agentsjavascriptgo
0
20
Ctf CryptoA

CTF crypto challenge playbook — read the provided encryption script like a spec, attack RSA parameter weaknesses, XOR/multi-time-pad oracles, and homemade ciphers with math tooling (z3, sympy, sage). Load when the handout is .py/.sage math, n/e/c values, or an "encryption service" on nc. Signals: "crypto" category, chall.py with Crypto.Util.number, e=3 or e=65537, "encrypted_flag", XOR with a key, nc service that encrypts your input.

ai-agentspythongo
0
20
Ctf ForensicsA

CTF forensics playbook — quick wins on pcaps, memory dumps, disk images, and stego files: binwalk carving, Wireshark object export, Volatility's five commands that solve most memory challenges, steghide/zsteg/exiftool stego battery. Load when the handout is a capture, image, or dump file. Signals: "forensics"/"stego" category, .pcap/.pcapng, .mem/.raw/.vmem, .dd/.img/.E01, a lone .png/.jpg/.wav, "incident", "suspicious traffic".

ai-agentsgonode
0
20
Ctf MethodologyA

CTF challenge triage and time management — identify the category and intended technique from the handout artifacts in the first 10 minutes, budget points vs. time, and know when to park a challenge. Load at the start of any CTF/jeopardy challenge, when handed an unknown file, URL, or "nc host port" with no context. Signals: flag{...} / CTF{...} format, challenge tarball, pwn/ web/crypto/rev/forensics/misc categories, "nc ", Docker handout, points value.

ai-agentsgophp
0
20
Ctf PwnA

CTF pwn challenge playbook — fast pwntools workflow against "nc host port" services: reproduce the remote environment locally with the provided libc/ld (patchelf, Docker), exploit format-string bugs (the CTF staple) for leaks and writes, and iterate a script from crash to flag. Load when the handout is a binary plus connection info. Signals: "pwn" category, nc host port, checksec output, provided libc.so.6/ld-linux, Dockerfile, "%p" reflections, menu-driven heap note apps.

ai-agentspythongo
0
20
Ctf RevA

CTF reversing speed-run — crack flag-check binaries fast: locate the check via strings/xrefs, bypass anti-debug and obfuscation, and solve constraint-checkers with z3 instead of manual algebra. Load when the handout is an ELF/PE/exe that asks for input or a key. Signals: "rev" category, "Enter the flag/key/password", correct/wrong messages, crackme, packed binary, anti-debug (ptrace, IsDebuggerPresent), keygen challenge.

ai-agentspythonrust
0
20
Ctf WebA

CTF web challenge playbook — the recurring shapes jeopardy web challenges take: source disclosure (.git, backups, flask debug), SSTI/SSRF in their CTF forms, PHP quirks (type juggling, wrappers, filters), cookie/JWT games, and chained primitives to read /flag. Load on any CTF challenge whose handout is a URL. Signals: "web" category, flask/werkzeug or PHP banner, /flag or flag.txt on the box, robots.txt, provided app.py/index.php source, JWT or flask session cookie.

ai-agentspythongo
0
20
Defense ForensicsA

Deep forensic artifact analysis after triage — memory dumps (Volatility 3), disk and super-timelines (Plaso), PCAP (tshark), and Windows host artifacts (Zimmerman toolset) — with hashing and chain of custody. Load when an incident moves past first response into "prove what the attacker did on this image": a memory dump to analyze, an E01/disk image, a captured pcap, or Prefetch/Shimcache/Amcache deep-dives. Signals: .dmp/.raw memory image, E01, pcap/pcapng, "analyze this dump", timeline recon...

ai-agentsrustgo
0
20
Defense Threat IntelA

Enrich IOCs, campaigns, impersonation, and scam narratives from public sources — bounded public X/Twitter collection via Xquik plus independent corroboration — and hand off a reviewable intelligence package. Load for "enrich this IOC", "is this domain in recent phishing disclosures", tracking threat-actor aliases or lookalike accounts, or prepping an intel package for threat hunting, malware triage, or IR. Signals: IOC lists (domain/IP/URL/hash/email/wallet), campaign names, phishing disclosu...

ai-agentsrustgo
0
20
Network Database SecurityA

Assess reachable database services — PostgreSQL/MySQL/MSSQL/MongoDB/Redis — for unauthenticated access, weak/default accounts, over-broad grants, and dangerous features (xp_cmdshell, COPY FROM PROGRAM, UDF, Redis file write) that turn a DB login into OS code execution. Load when recon shows 3306/5432/1433/6379/27017, leaked app config yields DB creds, or a database review is in scope. Signals: 0.0.0.0 bind, unauth Redis PONG, mysql.user host '%', FILE priv, secure_file_priv empty, xp_cmdshell.

securityrustgo
0
20
Network Email SecurityA

Email security review: dissect phishing samples (headers, URLs, attachments), assess a domain's spoofability via SPF/DKIM/DMARC alignment, recognize BEC patterns, and audit tenant anti-phishing controls incl. OAuth consent abuse. Load on phishing email analysis, .eml header review, "can this domain be spoofed", DMARC/SPF checks, or BEC investigation. Signals: Received chain, Authentication-Results, dmarc p=none, ~all vs -all, reply-to mismatch, lookalike domains.

securityrustgo
0
20
Reporting Evidence ReviewA

Pre-handoff audit of an engagement package — scope confirmed, every finding traceable to reproducible evidence, activity-log leads closed with rationale, artifact hashes intact. Load before writing the final report or handing a case to a teammate/client, on "is this ready to report", "review my engagement notes", QA of findings/ + notes.md. Signals: findings folder full, handoff, report QA, evidence chain, chain of custody.

ai-agentsgotesting
0
20
Tools ArsenalA

Cross-domain pentest tool selection — which tool for which job, and which SploitAgent skill to load for it. Load at engagement start or whenever a new surface appears and you need the right scanner/framework/wordlist. Signals: "which tool for", tool selection, arsenal, SecLists, PayloadsAllTheThings, searchsploit, "what do I scan this with".

ai-agentsrustgo
0
20
Tools Burp SuiteA

Drive Burp Suite for web/API testing — proxy history triage, Repeater, Intruder enumeration, Collaborator OOB, active scanning — manually or agent-driven through a Burp MCP extension on 127.0.0.1:9876. Load for any HTTP-target deep testing: "burp", proxy history analysis, repeater replay, intruder brute/enum, collaborator payloads, DAST scan, CSRF PoC generation, token randomness analysis. Signals: port 8080 proxy, port 9876 MCP, burpsuite, BApp MCP Server.

ai-agentsgojava
0
20
Tools CurlA

Use curl as the ground-truth HTTP client during recon and verification — browser-impersonation headers for CDN/WAF 403s, --globoff for bracket params, Windows curl.exe quirks, SPA false-200 traps. Load when bare tooling gets 403/blocked at a CDN edge, an API needs precise hand-crafted requests, or scanner output needs a clean manual repro. Signals: curl, 403 access-policy, CF-RAY, Cf-Mitigated, "bad range in position", --globoff, data-center UA blocked.

ai-agentspythongo
0
20
Tools FfufA

Fuzz web targets with ffuf for content, parameter, and vhost discovery — FUZZ keyword placement in paths, query strings, POST bodies and Host headers, matcher/filter calibration (-mc/-fs/-ac), recursion, and when to switch to feroxbuster/gobuster/dirsearch. Load when a web target needs hidden paths, files, parameters, or virtual hosts enumerated. Signals: ffuf -w FUZZ, directory brute force, gobuster dir, feroxbuster, dirsearch, raft-medium-directories, burp-parameter-names, 404 filtering.

ai-agentsrustgo
0
20
Tools HashcatC

Crack password hashes offline with hashcat (GPU) and John the Ripper (CPU) — hash-mode selection, attack modes (straight/mask/combinator/rules), the -m type table, *2john extractors, and potfile discipline. Load when loot includes hashes: NTLM/NetNTLMv2 dumps, Kerberos TGS (kerberoast), JWT secrets, /etc/shadow, zip/rar/ssh key passwords. Signals: hashcat -m, rockyou, best64.rule, $6$ hashes, unshadow, john --show, mask ?a?a?a.

securitygobash
0
20
Tools HydraA

Run online password attacks against live services with hydra and its alternatives (medusa, ncrack, patator, crowbar) — service modules, http-post-form failure strings, thread tuning, resume, and lockout avoidance. Load when scope allows credential guessing against SSH/FTP/RDP/MySQL/web login forms and offline cracking is not an option. Signals: hydra -l -P, http-post-form, ^USER^ ^PASS^, ssh:// rdp:// mysql:// targets, medusa -M, ncrack, patator, login brute force.

ai-agentsgobash
0
20
Tools Mcp BridgesA

Expose CLI security tools to an AI agent through MCP servers — mcp-kali-server generic terminal bridge, MetasploitMCP, pentestMCP Docker bundle, mcp-security-hub, single-tool nmap/nuclei servers. Load when setting up agent-driven tooling on Kali or wiring a new tool into MCP. Signals: mcpServers config, kali-server-mcp, metasploitmcp, pentestmcp, "MCP server for nmap", stdio transport, port 5000/8080/8085.

ai-agentsgoshell
0
20