
Claude Skills by ogrodev
github.com/ogrodevActivate this skill whenever the user mentions API endpoint, REST API, RESTful, GraphQL, GraphQL introspection, GraphQL mutation, gRPC, gRPC reflection, WebSocket, WebSocket upgrade, WS endpoint, API security, API fuzzing, API enumeration, API versioning, API gateway, API rate limit, JWT, JSON Web Token, bearer token, access token, refresh token, API key, OAuth, OAuth2, OIDC, OpenID Connect, PKCE, authorization code, client credentials, implicit grant, BOLA, broken object level authorization,...
Activate this skill whenever the user mentions cloud lateral movement, cloud privilege escalation, cloud post-exploitation, cloud red team, multi-cloud attack, cloud pentesting, AWS, Amazon Web Services, EC2, S3, Lambda, IAM, STS, SSM, Systems Manager, CloudTrail, GuardDuty, CloudShell, Secrets Manager, Parameter Store, RDS, ECS, EKS, Fargate, ECR, CodeBuild, CodePipeline, Glue, SageMaker, instance profile, instance metadata, EC2 role, cross-account, assume role, Azure, Entra ID, Azure AD, ma...
Activate this skill whenever the user mentions port scan, port scanning, nmap, nmap scan, masscan, rustscan, service detection, service enumeration, service fingerprinting, network scan, network scanning, network mapping, network discovery, network topology, open ports, closed ports, filtered ports, banner grabbing, banner grab, host discovery, live hosts, ping sweep, ARP scan, ARP discovery, OS fingerprinting, OS detection, operating system detection, TCP fingerprinting, SYN scan, TCP scan, ...
This skill should be used when the user mentions "brute force", "password cracking", "hydra", "hashcat", "john the ripper", "credential stuffing", "password spray", "password spraying", "hash cracking", "wordlist", "dictionary attack", "mask attack", "rainbow table", "NTLM", "NTLMv2", "bcrypt", "Kerberoast", "Kerberoasting", "AS-REP roasting", "AS-REP roast", "golden ticket", "silver ticket", "ticket attack", "kerbrute", "crackmapexec", "medusa", "patator", "ncrack", "crowbar", "online attack...
This skill should be used when the user mentions "payment", "payment gateway", "checkout", "IDOR payment", "payment bypass", "Stripe", "MercadoPago", "Binance Pay", "PIX", "PayPal", "Adyen", "Braintree", "Square", "Razorpay", "Mollie", "webhook", "payment webhook", "price manipulation", "amount tampering", "currency manipulation", "e-commerce", "shopping cart", "cart manipulation", "checkout flow", "checkout bypass", "order tampering", "refund abuse", "refund fraud", "chargeback", "race condi...
This skill should be used when the user mentions "generate report", "pentest report", "engagement report", "findings report", "executive summary", "technical report", "vulnerability report", "remediation report", "remediation plan", "retest report", "write up findings", "document findings", "report findings", "create report", "final report", "assessment report", "security report", "audit report", "CVSS score", "CVSS vector", "risk rating", "risk assessment", "severity rating", "finding writeu...
This skill should be used when the user mentions "WAF", "web application firewall", "WAF bypass", "WAF evasion", "WAF detection", "WAF fingerprint", "wafw00f", "firewall bypass", "firewall evasion", "request filtering", "request blocked", "payload blocked", "blocked by WAF", "403 forbidden", "406 not acceptable", "429 too many requests", "rate limit", "rate limiting", "IP ban", "IP block", "IP reputation", "IP blacklist", "CDN bypass", "origin IP", "origin discovery", "Cloudflare", "Cloudflar...
This skill activates when the user mentions "XSS", "cross-site scripting", "reflected XSS", "stored XSS", "DOM XSS", "blind XSS", "SQL injection", "SQLi", "blind SQLi", "union injection", "error-based injection", "time-based injection", "stacked queries", "second-order injection", "SSRF", "server-side request forgery", "cloud metadata", "IMDS", "internal service access", "IDOR", "insecure direct object reference", "broken access control", "horizontal privilege", "vertical privilege", "BOLA", ...
Activate this skill whenever the user mentions WordPress, WP, WooCommerce, WP plugin, WP theme, wp-admin, wp-content, wp-login, wp-json, wp-includes, xmlrpc, XML-RPC, wp-cron, admin-ajax, wp-config, wpscan, WordPress vulnerability, WordPress exploit, WordPress enumeration, WordPress brute force, WordPress RCE, WordPress shell upload, WordPress backdoor, WordPress privilege escalation, WordPress authentication bypass, WordPress REST API, WordPress nonce, WordPress application password, plugin ...
This skill should be used when the user mentions "new engagement", "setup engagement", "initialize workspace", "start operation", "new pentest", "setup project", "create workspace", "engagement setup", "initialize engagement", "new investigation", "start campaign", "new operation", "workspace init", "set up a new operation", "begin engagement", or discusses setting up a new offensive security engagement from scratch with target definition, plugin selection, and workspace creation.
This skill activates when the user mentions "patch analysis", "binary diff", "binary diffing", "bindiff", "BinDiff", "Diaphora", "diaphora", "radiff2", "DarunGrim", "turbodiff", "version comparison", "what changed between versions", "compare binaries", "diff binaries", "function comparison", "code delta", "patch Tuesday", "Patch Tuesday diffing", "security patch analysis", "CVE diffing", "1-day exploit", "1day", "n-day", "vulnerability discovery through diffing", "binary comparison", "patch d...
Activate this skill when the user mentions ".NET", "CLR", "managed code", "C# binary", "C# decompile", "decompile C#", "VB.NET", "F# binary", "ILSpy", "dnSpy", "de4dot", "dotPeek", ".NET Reflector", "monodis", "ilspycmd", "ilasm", "ildasm", "Cecil", "Mono.Cecil", "dnlib", ".NET Reactor", "ConfuserEx", "Dotfuscator", "SmartAssembly", "Eazfuscator", "Babel obfuscator", "Crypto Obfuscator", "Agile.NET", "Themida .NET", "deobfuscate", "deobfuscation", ".NET obfuscation", "unpack .NET", "mscoree",...
Activate this skill when the user mentions ANY of: "YARA", "YARA rules", "YARA signature", "write YARA", "detection rule", "packer detection", "packer identification", "packed binary", "UPX", "Themida", "VMProtect", "ASPack", "crypter", "obfuscated binary", "entropy", "entropy analysis", "section entropy", "high entropy", "malware family", "malware classification", "malware triage", "classify sample", "classify binary", "sample analysis", "unknown binary", "suspicious binary", "malware type",...
Activate this skill whenever the user mentions PE analysis, PE file, PE header, portable executable, Windows executable analysis, EXE analysis, DLL analysis, SYS driver analysis, OCX analysis, PE structure, PE format, PE parsing, PE triage, PE inspection, binary headers, file headers, DOS header, MZ header, COFF header, optional header, PE signature, image base, entry point, AddressOfEntryPoint, section table, section headers, section entropy, section permissions, .text section, .rdata sectio...
This skill activates when the user mentions "extract secrets", "find credentials", "hardcoded passwords", "API keys", "embedded keys", "connection strings", "tokens", "secret scanning", "credential extraction", "extract crypto keys", "private keys", "certificate extraction", "config extraction", "encryption keys", "AES key", "RSA key", "HMAC secret", "JWT secret", "bearer token", "OAuth token", "AWS access key", "Azure key", "GCP key", "cloud credentials", "database password", "admin password...
This skill should be used when the user mentions "log cleaning", "clear logs", "wipe logs", "timestomp", "timestamp manipulation", "metadata stripping", "exiftool", "mat2", "file wiping", "shred", "srm", "secure delete", "bleachbit", "memory clearing", "swap wipe", "bash history", "wtmp", "btmp", "lastlog", "auth.log", "journal", "journalctl", "forensic artifacts", "anti-forensics", "trace removal", "cover tracks", "clean up traces", "eliminate footprint", "shell history", "browser artifacts"...
Network anonymity and traffic concealment for red team operations. Use this skill whenever the user mentions "proxy chain", "proxychains", "SOCKS5", "Tor", "onion routing", "VPN", "WireGuard", "OpenVPN", "multi-hop", "IP rotation", "MAC spoofing", "MAC randomization", "macchanger", "DNS leak", "WebRTC leak", "IPv6 leak", "identity rotation", "anonymity", "traffic analysis", "traffic obfuscation", "SSH tunnel", "stunnel", "domain fronting", "DNS over HTTPS", "DoH", "DoT", "DNS privacy", "kills...
This skill should be used when the user mentions "generate report", "opsec report", "engagement report", "pentest report", "red team report", "purple team report", "security assessment", "hardening report", "compliance report", "audit report", "findings report", "evidence handling", "chain of custody", "redaction", "redact", "report delivery", "secure delivery", "debrief", "debrief prep", "post-engagement", "artifact inventory", "secure destruction", "evidence capture", "screenshot capture", ...
This skill should be used when the user mentions "harden", "hardening", "sysctl", "kernel parameters", "SSH config", "sshd_config", "firewall rules", "iptables", "nftables", "ufw", "fail2ban", "file permissions", "SUID", "SGID", "service minimization", "disable services", "auditd", "SELinux", "AppArmor", "CIS benchmark", "security baseline", "OS hardening", "attack platform", "operator machine", "Kali hardening", "disk encryption", "LUKS", "swap encryption", "encrypted swap", "secure boot", "...
This skill covers end-to-end VPS security for red team attack infrastructure. Use it when the user mentions "VPS", "virtual private server", "cloud server", "droplet", "Linode", "Vultr", "Hetzner", "DigitalOcean", "AWS EC2", "OVH", "server provisioning", "LUKS", "dm-crypt", "full disk encryption", "encrypted disk", "remote server", "C2 server", "redirector", "team server", "attack infrastructure", "infra hardening", "server teardown", "burn server", "nuke VPS", "anonymous hosting", "bulletpro...
This skill should be used when the user mentions "handoff to elliot", "pipeline to elliot", "cross-plugin", "elliot handoff", "transfer to elliot", "handoff package", "generate handoff", "build handoff", "elliot engagement", "pass to elliot", "bridge to elliot", "return flow", "elliot return", "post-exploitation return", "feed back to tyrell", "ingest from elliot", "credential handoff", "target enrichment", "intel handoff", "handoff-builder", "handoff-tracker", "finding correlation", "leak to...
This skill should be used when the user mentions "dump database", "acquire data", "download dump", "extract records", "mongodump", "elasticdump", "mongoexport", "database dump", "data extraction", "redis dump", "couch dump", or discusses safely pulling data from an open database, converting database export formats, setting extraction limits, or monitoring dump progress. It routes data acquisition through dumper.js and pipeline.js.
This skill should be used when the user mentions "Shodan", "Censys", "MongoDB exposed", "Elasticsearch open", "Redis no auth", "open database", "unauthenticated database", "exposed MongoDB", "exposed Elasticsearch", "exposed Redis", "exposed CouchDB", "exposed MySQL", "exposed PostgreSQL", "port 27017", "port 9200", "port 6379", "port 5984", "port 3306", "port 5432", "find open databases", "database hunting", "scan for databases", "internet-facing database", "no authentication database", "dat...
This skill should be used when the user mentions "hunt leaks", "find breaches", "credential leaks", "data leak", "breach database", "hunt dumps", "leak finder", "leak hunting", "discover leaks", "breached credentials", "combo list", "combolist", "credential dump", "paste site", "pastebin leak", "breach forums", "BreachForums", "Exploit.in", "RaidForums", "Telegram leaks", "leak channel", "h8mail", "dehashed", "LeakCheck", "IntelX", "Intelligence X", "breach correlation", "credential reuse", "...
This skill should be used when the user mentions "Google dork", "search operator", "inurl:", "filetype:", "intitle:", "site:", "intext:", "dork pattern", "breach forum", "BreachForums", "Exploit.in", "XSS.is", "RaidForums", "forum intelligence", "forum navigation", "seller credibility", "paste site", "Pastebin", "Ghostbin", "paste search", "paste monitoring", "Telegram leak", "Telegram channel", "Discord leak", "channel monitoring", "GitHub secrets", "GitHub scanning", "gitleaks", "trufflehog...