wgpsec/aboutsecurity
elasticsearch-attack
Elasticsearch 未授权访问与利用。当发现目标开放 9200/9300 端口、Elasticsearch 服务无认证、需要从 ES 获取索引数据或实现远程命令执行时使用。覆盖未授权访问、认证绕过、索引数据窃取、MVEL/Groovy 脚本…
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elastics…
3.8K installsHelp developers new to Elasticsearch get from zero to a working search experience. Guide them t…
3.3K installsAuthenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or …
3.1K installsManage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level securi…
3K installsEnable, configure, and query Elasticsearch security audit logs. Use when the task involves audi…
3K installsIngest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream pro…
3K installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 15 installs