Source

wgpsec/aboutsecurity

275 skills · 6.8K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
subdomain-deep 深度子域名挖掘,多源联合枚举。当需要最大化子域名发现覆盖率、常规 DNS 枚举结果不足、或目标使用了 CDN/通配符 DNS 时使用…
wgpsec/aboutsecurity
35
2
target-profiling 目标全景画像与攻击面分析。当需要系统性整理目标资产、生成结构化目标档案、或在多人协作渗透中需要共享目标信息时使用。侧…
wgpsec/aboutsecurity
35
3
ad-acl-abuse Active Directory ACL 滥用攻击方法论。当 BloodHound 发现 GenericAll/WriteDACL/WriteOwner/GenericWrite/ForceChangePassw…
wgpsec/aboutsecurity
34
4
ai-data-security
wgpsec/aboutsecurity
34
5
ctf-ai-ml
wgpsec/aboutsecurity
34
6
ffuf-fuzz
wgpsec/aboutsecurity
34
7
gcp-exploit GCP 云环境攻击方法论。当目标使用 Google Cloud Platform、发现 GCP Service Account/Metadata/Storage Bucket 时使用。覆盖…
wgpsec/aboutsecurity
34
8
httpx-probe 使用 httpx 进行 HTTP 探活、指纹识别和信息收集。当需要批量检测 HTTP/HTTPS 服务存活、识别 Web 技术栈、提取页面标题/状态…
wgpsec/aboutsecurity
34
9
impacket-toolkit Impacket Windows 协议工具集。当需要通过 SMB/Kerberos/WMI/DCOM/MSSQL 等 Windows 协议进行远程操作时使用。覆盖 secretsdu…
wgpsec/aboutsecurity
34
10
k8s-container-escape Kubernetes 容器逃逸与集群攻击。当目标运行在 K8s 环境中、发现 6443/10250/2379 端口、获取到 ServiceAccount Token、或已…
wgpsec/aboutsecurity
34
11
k8s-storage-exploit Kubernetes 存储与文件共享利用。当 Pod 挂载了 NFS/EFS/PV/ConfigMap/Secret、发现 /efs 或 /mnt 目录、或 mount 输出中有远…
wgpsec/aboutsecurity
34
12
mcp-security MCP (Model Context Protocol) 协议安全测试方法论。当目标环境使用 MCP Server 集成外部工具、 需要评估 MCP 工具描述安全性…
wgpsec/aboutsecurity
34
13
msf-oneshot Metasploit Framework 调用方法论(一行式 + 交互式)。当需要利用操作系统级漏洞(如 EternalBlue/MS17-010)、数据库远程漏…
wgpsec/aboutsecurity
34
14
threat-hunting-evasion 威胁猎杀原理与规避方法论。理解蓝队如何主动猎杀(Hypothesis-driven / IOC-driven / Analytics-driven),红队如何设计行为…
wgpsec/aboutsecurity
34
15
ad-delegation-attack Kerberos 委派攻击(非约束/约束/RBCD)。当 BloodHound 发现委派配置、或已获取有 SPN 的服务账号/机器账号控制权时使用。通…
wgpsec/aboutsecurity
33
16
adinfo-enum
wgpsec/aboutsecurity
33
17
ai-identity-security
wgpsec/aboutsecurity
33
18
apt-emulation APT 模拟与情报驱动红队方法论。基于已知 APT 组织的 TTP(MITRE ATT&CK)设计红队行动计划。当需要模拟特定威胁组织、设计高…
wgpsec/aboutsecurity
33
19
azure-pentesting Azure 云环境渗透测试总体方法论。当目标使用 Azure/Microsoft 365/Entra ID、发现 Azure 相关资产(Blob Storage/App Servic…
wgpsec/aboutsecurity
33
20
ccupp-password-profiler
wgpsec/aboutsecurity
33
21
cdk-escape
wgpsec/aboutsecurity
33
22
cicd-pipeline-attack CI/CD 流水线与供应链攻击方法论。当发现目标使用 GitHub Actions/Jenkins/GitLab CI/CircleCI/Terraform Cloud/Atlantis 等 …
wgpsec/aboutsecurity
33
23
cot-injection
wgpsec/aboutsecurity
33
24
cross-domain-attack-chain Web 与 AI 跨域攻击链方法论。当目标系统同时包含传统 Web 应用和 AI/LLM 组件、 需要评估 Web 漏洞对 AI 系统的影响或 AI 漏…
wgpsec/aboutsecurity
33
25
disk-forensics-evasion 磁盘取证与反磁盘取证方法论。理解蓝队如何从磁盘恢复删除文件、提取时间线、分析文件系统 artifact,以及红队如何进行反取证…
wgpsec/aboutsecurity
33
26
emergency-response 应急响应方法论。当目标主机疑似被入侵、需要排查后门/木马/异常进程/异常账户、或需要进行安全事件溯源分析时使用。覆盖 Lin…
wgpsec/aboutsecurity
33
27
exchange-attack Microsoft Exchange 邮件服务器攻击方法论。当发现 OWA(Outlook Web App) 登录页面、Exchange 管理面板、443 端口运行 Exchan…
wgpsec/aboutsecurity
33
28
fscan-scan
wgpsec/aboutsecurity
33
29
iox-proxy
wgpsec/aboutsecurity
33
30
malware-analysis-methodology 恶意软件分析方法论。当需要分析可疑二进制文件(PE/ELF/Mach-O)、内存 dump 中的恶意代码、或已知恶意软件家族样本时使用。…
wgpsec/aboutsecurity
33
31
mapcidr-cidr 使用 mapcidr 进行 CIDR 网段处理。当需要展开 CIDR 为 IP 列表、聚合 IP 为 CIDR、切片网段、IP 数量统计、打乱 IP 顺序时使…
wgpsec/aboutsecurity
33
32
oa-system-attack 国产 OA/内网系统漏洞利用。当在内网发现致远(Seeyon)、泛微(Weaver/E-cology)、用友(Yonyou/NC/U8)、蓝凌(Landray)、通达(To…
wgpsec/aboutsecurity
33
33
prompt-injection AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入…
wgpsec/aboutsecurity
33
34
prompt-leak AI/LLM 系统提示词泄露技术。当目标是基于 LLM 的应用且想获取其系统提示词、配置信息、工具列表、知识库内容时使用。AI Bug …
wgpsec/aboutsecurity
33
35
sandbox-evasion-implement 沙箱逃逸与反分析技术实现。当需要让恶意载荷绕过自动化沙箱分析(AnyRun/Cuckoo/CAPE/Joe/Windows Defender Sandbox)时使用…
wgpsec/aboutsecurity
33
36
serverless-attack Serverless/云函数安全测试与攻击。当目标涉及 AWS Lambda、腾讯云 SCF、阿里云 FC、Azure Functions 等 Serverless 服务时使…
wgpsec/aboutsecurity
33
37
ad-persistence
wgpsec/aboutsecurity
32
38
aws-iam-policy-analysis AWS IAM / Resource Policy 分析方法论。当目标涉及 AWS 云服务且提供了 IAM Policy、Resource Policy、Lambda 代码、CloudFo…
wgpsec/aboutsecurity
32
39
aws-iam-privesc
wgpsec/aboutsecurity
32
40
aws-pentesting AWS 云环境渗透测试总体方法论。当目标使用 AWS 云服务、发现 AWS 相关资产(S3 Bucket/EC2 实例/Lambda 函数/CloudFront 分…
wgpsec/aboutsecurity
32
41
aws-post-exploit AWS 后渗透与持久化专项。当已获取 AWS 高权限(Admin/PowerUser)或特定服务权限后,需要进行数据窃取、横向移动到其他账户/…
wgpsec/aboutsecurity
32
42
azure-ad-attack Azure AD / Entra ID 攻击方法论。当目标使用 Microsoft 365/Azure 云环境、发现 Azure AD 认证流程、或获取到 Azure 凭据时…
wgpsec/aboutsecurity
32
43
browser-xterm-interaction
wgpsec/aboutsecurity
32
44
c2-beacon-analysis C2 Beacon 配置提取与分析。当捕获到 Cobalt Strike/Sliver/Havoc 等 C2 框架的 Beacon 样本、内存 dump、或网络流量时使用。…
wgpsec/aboutsecurity
32
45
dirsearch-fuzz
wgpsec/aboutsecurity
32
46
gcp-pentesting GCP 云环境渗透测试总体方法论。当目标使用 Google Cloud Platform、发现 GCP 相关资产(GCS Bucket/Compute Engine/Cloud Fu…
wgpsec/aboutsecurity
32
47
githacker-git-leak
wgpsec/aboutsecurity
32
48
ioc-analysis IOC(失陷指标)分析与对抗方法论。蓝队视角:如何收集、富化、关联 IOC 进行威胁猎杀。红队视角:如何避免自身基础设施和工…
wgpsec/aboutsecurity
32
49
k8s-istio-bypass Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发…
wgpsec/aboutsecurity
32
50
k8s-sidecar-attack Kubernetes Sidecar 容器流量劫持与敏感信息窃取。当目标 Pod 存在 Istio/Envoy/Linkerd sidecar、题目提到'隐形旁观者'或'共…
wgpsec/aboutsecurity
32
Page 2 · 275 total Previous Next