Source

ed1s0nz/cyberstrikeai

45 skills · 1.1K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
secure-code-review 安全代码审查的专业技能和方法论
ed1s0nz/cyberstrikeai
81
2
mobile-app-security-testing 移动应用安全测试的专业技能和方法论
ed1s0nz/cyberstrikeai
64
3
ssrf-testing SSRF服务器端请求伪造测试的专业技能和方法论
ed1s0nz/cyberstrikeai
49
4
api-security-testing API安全测试的专业技能和方法论
ed1s0nz/cyberstrikeai
47
5
network-penetration-testing 网络渗透测试的专业技能和方法论
ed1s0nz/cyberstrikeai
45
6
vulnerability-assessment 漏洞评估的专业技能和方法论
ed1s0nz/cyberstrikeai
45
7
sql-injection-testing SQL注入测试的专业技能和方法论
ed1s0nz/cyberstrikeai
44
8
incident-response 安全事件响应的专业技能和方法论
ed1s0nz/cyberstrikeai
41
9
file-upload-testing 文件上传漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
40
10
cloud-security-audit 云安全审计的专业技能和方法论
ed1s0nz/cyberstrikeai
39
11
idor-testing IDOR不安全的直接对象引用测试的专业技能和方法论
ed1s0nz/cyberstrikeai
39
12
ldap-injection-testing LDAP注入漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
37
13
xss-testing XSS跨站脚本攻击测试的专业技能
ed1s0nz/cyberstrikeai
37
14
csrf-testing CSRF跨站请求伪造测试的专业技能和方法论
ed1s0nz/cyberstrikeai
36
15
security-automation 安全自动化的专业技能和方法论
ed1s0nz/cyberstrikeai
36
16
command-injection-testing 命令注入漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
35
17
business-logic-testing 业务逻辑漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
34
18
container-security-testing 容器安全测试的专业技能和方法论
ed1s0nz/cyberstrikeai
34
19
security-awareness-training 安全意识培训的专业技能和方法论
ed1s0nz/cyberstrikeai
34
20
xxe-testing XXE XML外部实体注入测试的专业技能和方法论
ed1s0nz/cyberstrikeai
34
21
deserialization-testing 反序列化漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
32
22
xpath-injection-testing XPath注入漏洞测试的专业技能和方法论
ed1s0nz/cyberstrikeai
32
23
cyberstrike-eino-demo 满?
ed1s0nz/cyberstrikeai
12
24
pentest-output-standards >- 输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。 Use when reporting findings, maintai…
ed1s0nz/cyberstrikeai
9
25
post-exploitation >- 后渗透/提权+凭据破解+密码学:反弹shell,Linux/Windows提权,横向,隧道,?
ed1s0nz/cyberstrikeai
9
26
web-attack-methods Web全栈攻击:SQLi/命令注入/SSTI/XSS/SSRF/NoSQL,认证JWT/OAuth/SAML,LFI/上传,Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS…
ed1s0nz/cyberstrikeai
9
27
attack-surface-recon 侦察/攻击面测绘:被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei,DNS地域/CDN/Nginx catch-al…
ed1s0nz/cyberstrikeai
8
28
pentest-agent-os
ed1s0nz/cyberstrikeai
8
29
active-directory-attack >- ?
ed1s0nz/cyberstrikeai
7
30
binary-mobile-reversing APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE,…
ed1s0nz/cyberstrikeai
7
31
capability-primitive-search >- 能力原语+状态空间搜索:read/write/exec/ssrf等原语凑RCE等式A-F,低危映射,正反向搜索,跨域?
ed1s0nz/cyberstrikeai
7
32
component-vuln-intel 联网情报收集:识别组件后必做CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路。Use when a framework…
ed1s0nz/cyberstrikeai
7
33
pentest-verification 验证铁律:搜索≠漏洞,confirmed Fact须证据,tentative表线索,禁止空泛推测,负结果也落库, 想象力拉满+单步验证零容忍。Use whe…
ed1s0nz/cyberstrikeai
7
34
proxy-tool-bootstrap 自找代理+工具自举:SOCKS5/HTTP/Tor换路序列,工具Python自举,字典自生成,OOB基础设施。Use when blocked by 403/429/WAF/time…
ed1s0nz/cyberstrikeai
7
35
redteam-opsec OPSEC隐蔽作战纪律:IP黑名单绕过,速率时序,流量混淆,最小足迹,反取证,渐进暴露。Use when maintaining stealth, bypassing IP…
ed1s0nz/cyberstrikeai
7
36
source-code-hunting 源码狩猎:.git泄露,危险函数grep,JS RC4解混淆,semgrep/CodeQL,trufflehog,patch diff,供应链/CI。Use when hunting source l…
ed1s0nz/cyberstrikeai
7
37
specialized-attack-playbooks >- 专题实战利用:GoEdge私钥导出,灰产CDN取证,ARP MITM,CDN→S3 STS链,宝塔+UniApp,AI IDE API反代,OCS+MinIO;含references/sc…
ed1s0nz/cyberstrikeai
7
38
unlimited-attack-scope >- 不设限原则:搜索/验证/串联/记录一切,?
ed1s0nz/cyberstrikeai
7
39
wireless-hardware-attack 无线/硬件:WiFi PMKID/WPS/Evil Twin,BLE,Zigbee,NFC,SDR,UART/JTAG/SPI,侧信道,故障注入。Use when attacking WiFi, BLE, RF…
ed1s0nz/cyberstrikeai
7
40
ai-llm-app-attack >- AI/LLM应用攻击:提示注?
ed1s0nz/cyberstrikeai
6
41
blockchain-contract-attack >- 区块链/智能合约:Etherscan,slither/mythril,重?
ed1s0nz/cyberstrikeai
6
42
cloud-attack-methods >- 云攻击:?
ed1s0nz/cyberstrikeai
6
43
initial-access-phishing 初始访问/钓鱼/社工:凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing。Use when needing initial access, phishing, AiTM, …
ed1s0nz/cyberstrikeai
6
44
pentest-blackboard CyberStrikeAI 项目黑板:跨会话 Fact 图(SQLite)+ upsert_project_fact/record_vulnerability 边渗透边记录节奏、关系边 l…
ed1s0nz/cyberstrikeai
6
45
zero-day-discovery 0day自主发现引擎:变体分析/补丁间隙/差分/Fuzzing/污点推理/N-day武器化/猎人思维。Use when public vulns not found and ne…
ed1s0nz/cyberstrikeai
6