CyberStrikeus/CyberStrike

DirSkills catalogs 51 skills from this repository, across 4 categories: AI Engineering, Automation, DevOps, Quality.

1.7K stars253 forksView on GitHub
📅
2026/07/20

AMI Age Compliance

Audit AWS AMIs to ensure they have been created within the last 90 days, a CIS benchmark compliance check for compute services.
DevOps
1.7K253
🔒
2026/07/20

AMI Encryption Check

Audits and remediates unencrypted Amazon Machine Images (AMIs) in AWS to ensure EBS snapshots are encrypted, as per CIS AWS Compute Benchmark 2.1.2. Use this skill to maintain encryption compliance for your AWS compute resources.
DevOps
1.7K253
🏷️
2026/07/20

AMI Naming Convention Compliance

Checks that all Amazon Machine Images (AMIs) in your AWS account follow your organization's naming convention, helping maintain a consistent asset inventory.
DevOps
1.7K253
🛡️
2026/07/20

AWS Approved AMI Audit

Audits Amazon EC2 instances to confirm only organization-approved AMIs are used, providing manual verification and remediation steps. Enforces consistent, secure machine images across AWS environments.
DevOps
1.7K253
🛡️
2026/07/20

AWS Lambda Admin Privileges Audit

Ensure your AWS Lambda functions don't have administrative permissions. Audit execution roles to enforce least privilege and remove overly permissive policies.
DevOps
1.7K253
🔒
2026/07/20

AWS Lambda Code Signing Compliance

Audit and enforce AWS Lambda code signing configurations to prevent deployment of unverified or tampered code. Use for security compliance and integrity verification in serverless applications.
DevOps
1.7K253
🔒
2026/07/20

AWS Lambda Least Privilege

Audits and enforces least-privilege IAM permissions for AWS Lambda functions, ensuring each function has only the minimal required access, in line with CIS benchmarks.
DevOps
1.7K253
☁️
3w ago

AWS Post-Exploitation

AWS Post-Exploitation maps 92 AWS CLI programs for reconnaissance, credential harvesting, privilege escalation, persistence, and cleanup after compromising AWS access. Use it when you need scripted post-compromise workflows in AWS.
DevOps
1.7K269
🔑
2026/07/20

AWS Secrets Manager for Lambda

Audits Lambda functions to ensure database credentials are stored and retrieved from AWS Secrets Manager, helping maintain security and enable automatic rotation.
DevOps
1.7K253
🛡️
3w ago

Active Directory Security Testing

Active Directory Security Testing lists common AD attack, privilege escalation, lateral movement, and persistence techniques with example tools and enumeration commands. Use it as a reference during authorized security assessments.
Quality
1.7K269
🛡️
2026/07/20

Active Lambda Execution Roles

Automatically audits AWS Lambda functions to verify they reference active IAM execution roles, preventing failures from deleted roles. Based on CIS AWS Foundations Benchmark control 12.7.
DevOps
1.7K253
☁️
3w ago

Azure Post-Exploitation

Azure Post-Exploitation provides Azure and Entra ID attack commands for enumeration, credential harvesting, privilege escalation, lateral movement, and persistence. Use it when assessing tenant compromise paths or abuse of M365 and identity controls.
AI Engineering
1.7K269
📁
3w ago

Bun File I/O

Bun File I/O covers the preferred file-reading, writing, scanning, and deletion patterns used in this repo. Use it when working on file operations or directory handling with Bun and node:fs helpers.
DevOps
1.7K269
🔒
3w ago

CI Assessment

CI Assessment performs read-only security checks on GitHub Actions workflows, token permissions, secrets exposure, runners, and branch protection. It also reviews dependencies and supply-chain settings from a local checkout.
DevOps
1.7K269
🛠️
3w ago

CICD Attacks

CICD Attacks describes methods for extracting secrets, injecting pipeline steps, and modifying CI/CD workflows in GitHub, Jenkins, or GitLab. Use it when assessing pipeline exposure or validating CI/CD security controls.
DevOps
1.7K269
🛡️
2026/07/20

CIS AWS Compute 10.3

Checks that AWS Elastic Beanstalk load balancers have access logs enabled, in accordance with CIS AWS Foundations Benchmark control 10.3. Use for security audits and compliance verification.
DevOps
1.7K253
🔑
2026/07/20

CIS AWS Compute 11.1 — Fargate Ephemeral Storage Encryption

Audits and enforces the use of customer-managed KMS keys for AWS Fargate ephemeral storage encryption in ECS, helping meet CIS compliance requirements and enhance data protection.
DevOps
1.7K253
🛡️
2026/07/20

CIS AWS Compute 12.1: Enable AWS Config for Lambda

This skill audits and remediates AWS Config conformance for Lambda and serverless workloads per CIS AWS Compute 12.1, ensuring compliance by deploying necessary conformance packs.
Quality
1.7K253
🔒
2026/07/20

CIS AWS Compute 12.6

Audit and remediate AWS Lambda functions to ensure they are not exposed to the public. Helps enforce CIS AWS Compute benchmark 12.6 by removing resource-based policies that allow anonymous invocation.
DevOps
1.7K253
🔒
2026/07/20

CIS AWS Compute 2.1.5

Verifies that AWS EC2 Machine Images (AMIs) are not publicly shared, preventing unauthorized access to instance data and configurations. For use in cloud security audits and CIS Benchmark compliance.
DevOps
1.7K253
🗑️
2026/07/20

CIS AWS Compute 2.11

A security rule to identify and terminate EC2 instances that have been stopped for over 90 days, helping maintain CIS compliance and reduce cloud attack surface.
DevOps
1.7K253
🔒
2026/07/20

CIS AWS Compute Encryption

Audits that communications between applications and clients in AWS SimSpace Weaver are encrypted in transit, per CIS AWS Compute benchmark 16.1. Use this skill to verify application-level encryption (e.g., TLS) for secure deployments.
DevOps
1.7K253
🔒
2026/07/20

CIS AWS Lambda Encryption

Audit and remediate AWS Lambda environment variables to ensure they are encrypted in transit, meeting CIS benchmark control 12.12. Use when securing Lambda functions against unauthorized access to sensitive data.
DevOps
1.7K253
🛡️
2026/07/14

CIS AWS RDS Regular Patching

Guides the manual process for ensuring Amazon RDS instances have auto minor version upgrades enabled and are regularly patched to reduce security vulnerabilities.
DevOps
1.2K196
🛡️
3w ago

CORS Misconfiguration Attack

CORS Misconfiguration Attack tests endpoints for risky CORS settings like origin reflection, wildcard access, null origin acceptance, and credential leakage. Use it to verify whether cross-origin requests can read sensitive data.
Quality
1.7K269
☁️
3w ago

Cloud Assessment

Cloud Assessment runs read-only security checks across AWS, Azure, and GCP using CIS-aligned audit commands. Use it to verify credentials and review IAM, storage, network, encryption, logging, DNS, and TLS settings.
Quality
1.7K269
🔍
2026/07/20

CloudWatch Lambda Insights

Verifies that Amazon CloudWatch Lambda Insights is enabled for AWS Lambda functions, providing enhanced monitoring, troubleshooting, and compliance with CIS AWS Compute benchmark 12.2.
DevOps
1.7K253
🛡️
3w ago

EBPF Attacks

EBPF Attacks documents eBPF-based post-exploitation techniques on Linux, including credential harvesting, process hiding, and traffic interception. Use it when working with kernel-level monitoring or stealth-detection workflows.
AI Engineering
1.7K269
🪵
2026/07/20

Elastic Beanstalk Log Streaming Audit

Audits AWS Elastic Beanstalk environments to verify that instance log streaming to CloudWatch is enabled, as required by CIS AWS Compute Benchmark 10.2. Use this skill to ensure compliance and persistent log collection for security monitoring.
DevOps
1.7K253
☁️
3w ago

GCP Post-Exploitation

GCP Post-Exploitation uses gcloud and metadata endpoint access to enumerate IAM, escalate privileges, exfiltrate data, and establish persistence in Google Cloud environments. Use it after compromising GCP credentials or a Compute Engine instance.
Automation
1.7K269
🛡️
3w ago

GraphQL Vulnerability Testing

GraphQL Vulnerability Testing checks GraphQL endpoints for introspection exposure, query complexity abuse, batch abuse, and authorization bypass. Use it when assessing a GraphQL API for common security flaws.
Quality
1.7K269
🕵️
3w ago

HTTP Request Smuggling

HTTP Request Smuggling tests for CL.TE, TE.CL, TE.TE, and H2.CL desyncs between front-end and back-end servers. Use it to detect request boundary confusion, confirm impact, and demonstrate cache poisoning or auth bypass.
Quality
1.7K269
🔒
2026/07/20

HTTPS on Load Balancer

Audits AWS Elastic Beanstalk load balancer listeners to verify HTTPS is enabled for encrypted connections. Use this skill for CIS AWS Compute Benchmark 10.4 compliance checks.
DevOps
1.7K253
🛡️
3w ago

Host Header Injection

Host Header Injection tests whether a web app trusts Host or related headers when building links, routing requests, or caching responses. Use it to check for password reset poisoning, cache poisoning, and routing bypass.
Quality
1.7K269
🛡️
3w ago

IDOR Automated Testing

IDOR Automated Testing checks API endpoints for insecure direct object references using two accounts with different privilege levels. Use it to test horizontal and vertical access control bypasses and compare responses.
Quality
1.7K269
🔐
3w ago

JWT Token Attack

JWT Token Attack tests JWT implementations for alg=none bypass, key confusion, claim tampering, and kid injection. Use it when checking whether a service accepts forged or modified tokens.
Quality
1.7K269
🔒
2026/07/20

Lambda Cross-Account Access Audit

Audits AWS Lambda functions for unknown cross-account access in resource-based policies, helping enforce CIS benchmark requirements and prevent unauthorized data exposure.
DevOps
1.7K253
⚙️
2026/07/20

Lambda Runtime Audit

Check AWS Lambda functions for deprecated or soon-to-be-unsupported runtime versions, ensuring compliance with best practices and security standards.
DevOps
1.7K253
🛡️
2026/07/20

Managed Platform Updates

Audits and ensures that AWS Elastic Beanstalk environments have managed platform updates enabled, following CIS AWS Compute benchmark 10.1. Use when securing Beanstalk environments to enable automatic patching during maintenance windows.
DevOps
1.7K253
🔀
3w ago

Open Redirect Testing

Open Redirect Testing identifies redirect parameters and tests them for unsafe destination handling. Use it to verify redirect, OAuth, and login-flow weaknesses that can enable phishing or token theft.
Quality
1.7K269
🛡️
3w ago

Prototype Pollution Attack

Prototype Pollution Attack outlines how to test JavaScript apps for __proto__ and constructor.prototype pollution. Use it when checking merge or parse endpoints for client-side XSS, privilege escalation, or server-side gadget chains.
Quality
1.7K269
⚔️
3w ago

Race Condition Attack

Race Condition Attack sends concurrent requests to test time-of-check-to-time-of-use flaws. Use it to probe race-prone actions like coupon redemption, transfers, duplicate creation, and rate-limit bypasses.
Quality
1.7K269
🛡️
3w ago

Rate Limit Bypass

Rate Limit Bypass tests endpoints for weak throttling and account lockout controls using header, URL, and method variations. Use it when checking login, reset, OTP, or other rate-limited flows.
Quality
1.7K269
🌐
2026/07/20

Remove Unused ENIs

Audit and delete unattached AWS Elastic Network Interfaces (ENIs) to maintain a clean environment, reduce attack surface, and avoid hitting service limits.
DevOps
1.7K253
🕵️
3w ago

SSRF Testing

SSRF Testing checks URL-handling features for server-side request forgery. Use it to probe internal resources, cloud metadata endpoints, and common filter bypasses.
Quality
1.7K269
🛡️
3w ago

Server-Side Template Injection

Server-Side Template Injection detects SSTI, fingerprints template engines, and tests for code execution in server-rendered inputs. Use it when a web app may evaluate user-controlled template syntax.
Quality
1.7K269
🕵️
3w ago

Subdomain Takeover

Subdomain Takeover identifies dangling CNAME records and fingerprints the cloud services they point to. Use it to check for takeover conditions and verify cloud storage exposure.
Quality
1.7K269
🔒
2026/07/20

Unique IAM Roles for Lambda

Ensures each AWS Lambda function has its own dedicated IAM execution role, following the Principle of Least Privilege for better security isolation. Use this skill to audit and remediate shared roles across Lambda functions.
DevOps
1.7K253
🧪
3w ago

Web Cache Poisoning

Web Cache Poisoning helps test for unkeyed headers, parameters, and normalization issues that can poison cached responses. Use it when checking whether attackers can serve altered content to other users.
Quality
1.7K269
🕸️
3w ago

WebSocket Security Testing

WebSocket Security Testing checks WebSocket endpoints for CSWSH, message injection, and authentication bypass. Use it when validating origin checks, session handling, and message handling in a WebSocket app.
Quality
1.7K269
🧩
3w ago

XXE Injection

XXE Injection tests XML parsers for external entity handling to read local files, trigger SSRF, or cause out-of-band callbacks. Use it when reviewing XML, SOAP, SVG, DOCX, or SAML inputs.
Quality
1.7K269