正在加载项目…
正在加载项目…
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissi
其他仓库内容 · 未声明插件包归属
Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resil
其他仓库内容 · 未声明插件包归属
Analyze ELF binaries for memory-corruption vulnerabilities and build proof-of-concept exploits using pwntools, checksec, and ROPgadget for buffer overflows and
其他仓库内容 · 未声明插件包归属
Detect and exploit blind Server-Side Request Forgery (SSRF) using out-of-band techniques such as Burp Collaborator DNS interactions and timing analysis, to reac
其他仓库内容 · 未声明插件包归属
Assess Bluetooth Low Energy (BLE) device security using Python's bleak asyncio library to discover nearby devices, enumerate GATT services and characteristics,
其他仓库内容 · 未声明插件包归属
Monitor for brand impersonation attacks across domains, social media, mobile apps, and dark web channels to detect phishing campaigns, fake sites, and unauthori
其他仓库内容 · 未声明插件包归属
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized
其他仓库内容 · 未声明插件包归属
Run Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database, mapping relationships such as IAM permission chains, network paths, and cross-
其他仓库内容 · 未声明插件包归属
Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations
其他仓库内容 · 未声明插件包归属
Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agent
其他仓库内容 · 未声明插件包归属
Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources wit
其他仓库内容 · 未声明插件包归属
Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection,
其他仓库内容 · 未声明插件包归属
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and pr
其他仓库内容 · 未声明插件包归属
Investigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entit
其他仓库内容 · 未声明插件包归属
Run authorized AWS penetration tests with Pacu, the open-source AWS exploitation framework, to enumerate IAM configuration, scan for privilege escalation paths,
其他仓库内容 · 未声明插件包归属
Perform forensic acquisition of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by pulling API-based remote data such as revision hist
其他仓库内容 · 未声明插件包归属
Audits container and pod configuration for escape-enabling misconfiguration using the Kubernetes Python client - privileged flags, dangerous capability grants,
其他仓库内容 · 未声明插件包归属
Harden container images by minimizing attack surface, stripping unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying
其他仓库内容 · 未声明插件包归属
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabiliti
其他仓库内容 · 未声明插件包归属
Analyze Content-Security-Policy headers and bypass them to achieve cross-site scripting by exploiting unsafe-inline/unsafe-eval, whitelisted JSONP endpoints, ba
其他仓库内容 · 未声明插件包归属
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and
其他仓库内容 · 未声明插件包归属
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as
其他仓库内容 · 未声明插件包归属
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized s
其他仓库内容 · 未声明插件包归属
Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog, enrich it with EPSS scores and CVSS metrics, and build a multi-factor prioritization eng
其他仓库内容 · 未声明插件包归属