Browse Skills

11972 skills across 8 categories

All Skills (11972 found)

๐Ÿงจ
2026/08/17

Exploit Development

Exploit Development provides an operational guide for environment setup, debugging workflow, PoC development, writing reliable exploits, using pwntools/pwndbg, heap exploitation, and weaponization. Use it when actively developing exploits or setting up an exploit dev environment.
Automation
2.9K479
๐Ÿ›ก๏ธ
2026/08/17

Kernel Exploit Mitigations

Kernel Exploit Mitigations catalogs modern OS security mitigations like ASLR, DEP/NX, RELRO, stack canaries, CFI, sandboxing, and seccomp, along with detection methods and known bypass techniques. Use it when assessing target hardening or planning exploit mitigation bypasses.
Quality
2.9K479
โŒจ๏ธ
2026/08/17

Keylogger Architecture

Keylogger Architecture documents low-level Windows keyboard input capture techniques, including SetWindowsHookEx and ETW-based hooks, and their IOCs. Use it when researching keyloggers, EDR evasion, or malware architecture analysis.
Quality
2.9K479
๐ŸŽฏ
2026/08/17

Modern Initial Access

Modern Initial Access provides a checklist of techniques for gaining initial foothold in red team engagements, including phishing, credential attacks, exposed services, and supply chain compromise. Use it when planning attack paths mapped to MITRE ATT&CK TA0001.
Automation
2.9K479
๐Ÿ”
2026/08/17

OAuth Security Testing

OAuth Security Testing applies an OAuth 2.0 attack checklist covering redirect_uri bypass, state parameter abuse, PKCE bypass, token leakage, and scope escalation when testing web apps or bug bounty.
Quality
2.9K479
โš”๏ธ
2026/08/17

Offensive Active Directory

Offensive Active Directory provides red team attack methodology for Active Directory, covering reconnaissance, credential abuse, privilege escalation, lateral movement, persistence, ADCS abuse, and Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID, or ADCS deployments.
Quality
2.9K479
๐ŸŒฉ๏ธ
2026/08/17

Offensive Cloud

Offensive Cloud provides a cloud security attack methodology for AWS, Azure, and GCP covering credential harvesting, enumeration, privilege escalation, persistence, and exfiltration. Use when testing cloud accounts, after stealing cloud credentials, or assessing cloud posture.
DevOps
2.9K479
๐Ÿ›
2026/08/17

Offensive Fuzzing

Offensive Fuzzing teaches a structured methodology for discovering vulnerabilities using coverage-guided fuzzing with AFL++ and libFuzzer. Use it when setting up fuzz campaigns, selecting harness strategies, or triaging fuzzer output.
Quality
2.9K479
๐Ÿž
2026/08/17

Offensive Fuzzing

Offensive Fuzzing covers fuzzer selection, harness writing, corpus curation, mutation strategies, coverage measurement, and crash triage for fuzz campaigns against file parsers, network protocols, kernel drivers, EDR engines, embedded firmware, or language runtimes.
Quality
2.9K479
๐Ÿ”
2026/08/17

Offensive JWT

Offensive JWT catalogs JWT attack techniques for penetration testers, covering algorithm confusion, weak secrets, header injection, and mobile token extraction. Use it when testing JWT-based authentication or evaluating JWT implementation security in web or mobile apps.
Quality
2.9K479
๐Ÿ
2026/08/17

Offensive TOCTOU

Offensive TOCTOU provides a methodology for exploiting time-of-check/time-of-use race conditions in filesystems, kernels, web applications, and containers. Use it when auditing privileged binaries, fuzzing for race conditions, or testing concurrency bugs in orchestrators.
Quality
2.9K479
๐Ÿ’ฅ
2026/08/17

Vulnerability Classes

Vulnerability Classes covers core memory corruption classes like stack/heap overflows, use-after-free, integer overflows, format strings, type confusion, and race conditions with real-world CVE case studies. Use when learning exploit development, researching vulnerability patterns, or teaching offensive security.
Quality
2.9K479
PreviousPage 211 of 998Next