Summary
Apache Kafka 未授权访问与利用。当发现目标开放 9092 端口、Kafka Broker 无认证、Schema Registry 或 Kafka Connect 暴露、或需要从 Kafka 窃取消息数据时使用。覆盖未授权访问、Topic 枚举与消息批量导出、Consumer Group 操作、Broker…
wgpsec/aboutsecurity
Apache Kafka 未授权访问与利用。当发现目标开放 9092 端口、Kafka Broker 无认证、Schema Registry 或 Kafka Connect 暴露、或需要从 Kafka 窃取消息数据时使用。覆盖未授权访问、Topic 枚举与消息批量导出、Consumer Group 操作、Broker…
npx skills add https://github.com/wgpsec/aboutsecurity
Apache Kafka 未授权访问与利用。当发现目标开放 9092 端口、Kafka Broker 无认证、Schema Registry 或 Kafka Connect 暴露、或需要从 Kafka 窃取消息数据时使用。覆盖未授权访问、Topic 枚举与消息批量导出、Consumer Group 操作、Broker…
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Use when Codex is already in the attack-path-analysis phase of a security scan or the user expl…
287 installsBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, …
11.9K installs>- JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, ke…
3.1K installs>- HTTP Host header injection and routing abuse playbook. Use when the application trusts the H…
2.9K installs>- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrappin…
2.9K installs>- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-R…
2.9K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master