SnailSploit/Claude-Red▌
78 approved skills in this repository
offensive-edr-evasion
infrastructure
### offensive-edr-evasion - - **Skill Name**: edr-evasion - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-osint
recon
### offensive-osint - Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-dependency-confusion
supply-chain
### offensive-dependency-confusion - Deep-dive offensive methodology for dependency confusion and namespace attacks across all major package ecosystems. Covers npm scope confusi - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-race-condition
web
### offensive-race-condition - - **Skill Name**: race-condition - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-xxe
web
### offensive-xxe - - **Skill Name**: xxe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-krack-fragattacks
wireless
### offensive-krack-fragattacks - KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-bluetooth-ble
wireless
### offensive-bluetooth-ble - Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forc - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-lorawan-sub-ghz
wireless
### offensive-lorawan-sub-ghz - LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-zigbee-thread-matter
wireless
### offensive-zigbee-thread-matter - Zigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, Kille - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-oauth
auth
### offensive-oauth - - **Skill Name**: oauth-attacks - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-api-security
api
### offensive-api-security - Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-exploit-development
exploit-dev
### offensive-exploit-development - - **Skill Name**: exploit-development - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-active-directory
active-directory
### offensive-active-directory - Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), cr - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-jwt
auth
### offensive-jwt - JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parame - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-crypto-attacks
crypto
### offensive-crypto-attacks - Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding ora - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-c2-frameworks
forensics
### offensive-c2-frameworks - Command and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleabl - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-cicd-pipeline
cicd
### offensive-cicd-pipeline - Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issu - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-tls-attacks
crypto
### offensive-tls-attacks - Comprehensive methodology for auditing and exploiting TLS/SSL implementations and misconfigurations across network services and mobile appli - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-mitigations
exploit-dev
### offensive-mitigations - - **Skill Name**: security-mitigations - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-cicd-secrets
cicd
### offensive-cicd-secrets - Comprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-container-escape
container
### offensive-container-escape - Container escape and breakout techniques targeting Docker, containerd, and Podman runtimes. Covers privileged container breakout via host fi - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-crash-analysis
exploit-dev
### offensive-crash-analysis - - **Skill Name**: crash-analysis - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-fuzzing-course
fuzzing
### offensive-fuzzing-course - - **Skill Name**: fuzzing-course - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-ai-security
ai
### offensive-ai-security - - **Skill Name**: ai-security - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-initial-access
infrastructure
### offensive-initial-access - - **Skill Name**: initial-access - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-api-abuse
api
### offensive-api-abuse - Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security con - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-k8s-attacks
container
### offensive-k8s-attacks - Kubernetes cluster attack techniques covering the full attack lifecycle from initial foothold in a pod to cluster-wide compromise. Covers se - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-exploit-dev-course
exploit-dev
### offensive-exploit-dev-course - - **Skill Name**: exploit-dev-curriculum - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-anti-forensics
forensics
### offensive-anti-forensics - Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-vuln-classes
fuzzing
### offensive-vuln-classes - - **Skill Name**: vulnerability-classes - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-cloud
cloud
### offensive-cloud - Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, i - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-basic-exploitation
exploit-dev
### offensive-basic-exploitation - - **Skill Name**: basic-exploitation - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-bug-identification
fuzzing
### offensive-bug-identification - - **Skill Name**: bug-identification - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-toctou
exploit-dev
### offensive-toctou - Time-of-Check / Time-of-Use (TOCTOU) race condition exploitation methodology across binary, kernel, filesystem, web, and container layers. C - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-fuzzing
fuzzing
### offensive-fuzzing - Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-keylogger-arch
infrastructure
### offensive-keylogger-arch - - **Skill Name**: keylogger-architecture - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-iot
iot
### offensive-iot - IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off) - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-advanced-redteam
infrastructure
### offensive-advanced-redteam - Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scopi - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-shellcode
infrastructure
### offensive-shellcode - Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-indepen - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-network-attacks
network
### offensive-network-attacks - Dense description covering ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, DNS poisoning, MITM attacks, VLAN hopping, DHCP attacks, 802.1X/NAC by - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-linux-privesc
privesc
### offensive-linux-privesc - Comprehensive Linux privilege escalation methodology for offensive security engagements. Covers the full attack surface from a low-privilege - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-social-engineering
social-engineering
### offensive-social-engineering - Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements. Covers pret - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-windows-mitigations
infrastructure
### offensive-windows-mitigations - - **Skill Name**: windows-mitigations - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-windows-privesc
privesc
### offensive-windows-privesc - Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard us - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-windows-boundaries
infrastructure
### offensive-windows-boundaries - - **Skill Name**: windows-boundaries - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-data-exfiltration
post-exploitation
### offensive-data-exfiltration - Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service chan - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-phishing
social-engineering
### offensive-phishing - Phishing campaign execution methodology for authorized red team engagements. Covers end-to-end campaign lifecycle: infrastructure provisioni - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-mobile
mobile
### offensive-mobile - Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-persistence
post-exploitation
### offensive-persistence - Comprehensive persistence tradecraft for authorized red team engagements covering Windows and Linux mechanisms. Windows techniques include r - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-lateral-movement
post-exploitation
### offensive-lateral-movement - Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ti - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-osint-methodology
recon
### offensive-osint-methodology - - **Skill Name**: osint-methodology - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-supply-chain
supply-chain
### offensive-supply-chain - Comprehensive offensive methodology for software supply chain attacks covering the full kill chain from reconnaissance through exploitation. - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-graphql
web
### offensive-graphql - Offensive methodology for attacking GraphQL APIs during penetration tests and bug bounty engagements. Covers the full attack lifecycle: endp - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-request-smuggling
web
### offensive-request-smuggling - - **Skill Name**: request-smuggling - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-xss
web
### offensive-xss - - **Skill Name**: xss - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-evil-twin
wireless
### offensive-evil-twin - Evil Twin / KARMA / Mana access point methodology — rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wpa-enterprise
wireless
### offensive-wpa-enterprise - WPA/WPA2/WPA3-Enterprise (802.1X / EAP) attack methodology — EAP method identification (PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, EAP-GTC, EAP-PWD, - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-fast-checking
utility
### offensive-fast-checking - - **Skill Name**: fast-checking - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-idor
web
### offensive-idor - - **Skill Name**: idor - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-business-logic
web
### offensive-business-logic - Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process ab - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-parameter-pollution
web
### offensive-parameter-pollution - - **Skill Name**: parameter-pollution - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-ssrf
web
### offensive-ssrf - - **Skill Name**: ssrf - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-reporting
utility
### offensive-reporting - Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-file-upload
web
### offensive-file-upload - - **Skill Name**: file-upload - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-sqli
web
### offensive-sqli - SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based b - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-deserialization
web
### offensive-deserialization - Insecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/php - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-open-redirect
web
### offensive-open-redirect - - **Skill Name**: open-redirect - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-ssti
web
### offensive-ssti - Dense description covering Server-Side Template Injection across Jinja2, Twig, Freemarker, Velocity, Pebble, Smarty, Mako, Handlebars, ERB, - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-bluetooth-classic
wireless
### offensive-bluetooth-classic - Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wifi-recon
wireless
### offensive-wifi-recon - Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspa - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wps
wireless
### offensive-wps - WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, Media - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-rce
web
### offensive-rce - - **Skill Name**: rce - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-waf-bypass
web
### offensive-waf-bypass - - **Skill Name**: waf-bypass - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-deauth-disassoc
wireless
### offensive-deauth-disassoc - Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wpa3-sae
wireless
### offensive-wpa3-sae - WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wifi
wireless
### offensive-wifi - Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK han - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-z-wave
wireless
### offensive-z-wave - Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-wpa2-psk
wireless
### offensive-wpa2-psk - WPA/WPA2-PSK attack methodology — four-way handshake capture via targeted deauthentication, PMKID attacks (no client required), hcxdumptool - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.