Source

hypnguyen1209/offensive-claude

35 skills · 444 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
reverse-engineering Use when reverse-engineering a binary or firmware — static triage + decompilation (Ghidra/IDA/Binary Ninja), dynamic …
hypnguyen1209/offensive-claude
49
2
mobile-pentest Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15…
hypnguyen1209/offensive-claude
29
3
exploit-development Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/J…
hypnguyen1209/offensive-claude
22
4
web-pentest Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning…
hypnguyen1209/offensive-claude
22
5
coding-mastery Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming,…
hypnguyen1209/offensive-claude
17
6
crypto-analysis Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD…
hypnguyen1209/offensive-claude
16
7
edr-evasion Use when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect syscalls, PPID spoofing, process injecti…
hypnguyen1209/offensive-claude
16
8
recon-osint Use when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mappin…
hypnguyen1209/offensive-claude
16
9
shellcode-dev Use when writing position-independent shellcode or a loader — PEB walking, API hashing, null-byte avoidance, encoders…
hypnguyen1209/offensive-claude
16
10
network-attack Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM rel…
hypnguyen1209/offensive-claude
15
11
malware-analysis Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynami…
hypnguyen1209/offensive-claude
14
12
privesc-linux Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities …
hypnguyen1209/offensive-claude
14
13
privesc-windows Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service…
hypnguyen1209/offensive-claude
14
14
red-team-ops Use when running a full red-team engagement end-to-end — initial access, persistence, privilege escalation, defense e…
hypnguyen1209/offensive-claude
14
15
threat-hunting Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-…
hypnguyen1209/offensive-claude
14
16
vulnerability-analysis Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink…
hypnguyen1209/offensive-claude
14
17
active-directory-attack Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (…
hypnguyen1209/offensive-claude
13
18
ai-security Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG…
hypnguyen1209/offensive-claude
13
19
cloud-security Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & P…
hypnguyen1209/offensive-claude
13
20
incident-response Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility…
hypnguyen1209/offensive-claude
13
21
initial-access Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply…
hypnguyen1209/offensive-claude
13
22
ai-agent-redteam Use when red-teaming an agentic AI / LLM application — indirect & zero-click prompt injection, MCP tool poisoning, pe…
hypnguyen1209/offensive-claude
6
23
cicd-supply-chain Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution,…
hypnguyen1209/offensive-claude
6
24
finding-discipline Use when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONF…
hypnguyen1209/offensive-claude
6
25
scope-discipline Use when about to send a request to, scan, enumerate, exploit, or otherwise interact with any host, IP, URL, or asset…
hypnguyen1209/offensive-claude
6
26
threat-model-discipline Use when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the thr…
hypnguyen1209/offensive-claude
6
27
windows-boundaries Use when crossing a Windows security boundary or escaping a sandbox — kernel/user crossing (win32k/dxgkrnl UAF CVE-20…
hypnguyen1209/offensive-claude
6
28
windows-mitigations-bypass Use when bypassing a Windows exploit/platform mitigation — ASLR/DEP/CFG/XFG/CET, ACG/CIG, WDAC/App Control, ASR/AMSI/…
hypnguyen1209/offensive-claude
6
29
browser-exploitation Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, …
hypnguyen1209/offensive-claude
5
30
container-k8s-escape Use when breaking out of a container or escalating inside Kubernetes — runc/BuildKit CVEs, privileged/capability/cgro…
hypnguyen1209/offensive-claude
5
31
engagement-flow Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Cha…
hypnguyen1209/offensive-claude
5
32
engagement-memory Use when recalling prior techniques at recon/weaponize, or recording a confirmed finding at report — cross-engagement…
hypnguyen1209/offensive-claude
5
33
opsec-discipline Use when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or fe…
hypnguyen1209/offensive-claude
5
34
using-offensive-claude Use when starting any offensive-security engagement or task — establishes how to find and invoke the right skill befo…
hypnguyen1209/offensive-claude
5
35
writing-offensive-skills Use when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptio…
hypnguyen1209/offensive-claude
5