Source

mn-youssef/security-skills

16 skills · 519 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
client-side-exploitation Use when testing advanced browser-side and HTTP-layer attacks beyond basic XSS/CSRF — DOM XSS, CSP bypass, CORS misco…
mn-youssef/security-skills
35
2
file-upload-and-ssrf Use when testing file-upload handling, server-side request forgery (SSRF), and insecure deserialization — upload bypa…
mn-youssef/security-skills
35
3
pentest-reporting Use when turning security findings into a clear, actionable report — scoring severity with CVSS, writing findings wit…
mn-youssef/security-skills
35
4
recon-and-osint Use when starting an assessment and you need to discover an application's full attack surface — subdomains, hosts, en…
mn-youssef/security-skills
34
5
security-testing Use when you want to security-test, pentest, audit, or find vulnerabilities in an application you own or are authoriz…
mn-youssef/security-skills
34
6
authentication-testing Use when testing login, sessions, password reset, OAuth/OIDC/SAML/SSO, MFA, and JWTs for weaknesses that lead to acco…
mn-youssef/security-skills
33
7
access-control-testing Use when testing whether users can access data or actions they shouldn't — IDOR/BOLA, horizontal and vertical privile…
mn-youssef/security-skills
32
8
active-pentest Use when you need to actually run security tests against a running application you own or are authorized to test — th…
mn-youssef/security-skills
32
9
api-security-testing Use when testing REST, GraphQL, gRPC, or WebSocket APIs against the OWASP API Security Top 10 — object- and function-…
mn-youssef/security-skills
32
10
vulnerability-chaining Use when you have multiple findings and need to combine them into realistic end-to-end attack paths — turning several…
mn-youssef/security-skills
32
11
business-logic-testing Use when testing application-specific workflow and business-rule flaws that scanners cannot find — price/quantity/par…
mn-youssef/security-skills
31
12
secrets-management-audit Use when hunting for exposed secrets and auditing how an app you own manages them — API keys, tokens, passwords, and …
mn-youssef/security-skills
31
13
security-code-audit Use when you have application source code and want to find security vulnerabilities by reading it — covers OWASP Top …
mn-youssef/security-skills
31
14
security-hardening Use when you have a security finding (from code audit or pentest) and need to fix it correctly with secure-coding pat…
mn-youssef/security-skills
31
15
threat-modeling Use when starting a security assessment and you need to map an application's attack surface, enumerate trust boundari…
mn-youssef/security-skills
31
16
injection-testing Use when dynamically testing whether untrusted input reaches an interpreter — SQL/NoSQL injection (incl.
mn-youssef/security-skills
30