Search
trilwu/secskills
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. | trilwu/ | 157 | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2 | Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. | trilwu/ | 157 | — | ~3.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 3 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 4 | Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 5 | Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 7 | Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. | trilwu/ | 157 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 8 | Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction… | trilwu/ | 157 | — | ~4k | Automated safety check: Notes | MIT | 1 mo ago |
| 9 | Triage and forensically analyze reported phishing safely — extract the raw message, read the Received chain, verify SPF/DKIM/DMARC, detect display-name and lookalike spoofing, unwrap redirects and… | trilwu/ | 157 | — | ~4.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 10 | Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 157 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of… | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 13 | Attack SAML single sign-on by decoding and tampering with signed XML assertions — XML signature wrapping (XSW1-XSW8), signature stripping, assertion and attribute tampering, NameID comment… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 14 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections… | trilwu/ | 157 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 16 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 157 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed… | trilwu/ | 157 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 19 | Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora, or ghidriff to find the changed functions, reading the added checks to recover… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. | trilwu/ | 157 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | Hunt planted webshells and backdoors across a web source tree — PHP first (also JSP, ASP, Node) — triaging a directory at scale, statically decoding obfuscation layers without ever executing the… | trilwu/ | 157 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 157 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 26 | Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule… | trilwu/ | 157 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 27 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 157 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 28 | Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and… | trilwu/ | 157 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with… | trilwu/ | 157 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. | trilwu/ | 157 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 35 | Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and… | trilwu/ | 157 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 36 | Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment… | trilwu/ | 157 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping… | trilwu/ | 157 | — | ~2.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 40 | Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the… | trilwu/ | 157 | — | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 41 | Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with… | trilwu/ | 157 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules… | trilwu/ | 157 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection… | trilwu/ | 157 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 44 | Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs… | trilwu/ | 157 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 45 | Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened… | trilwu/ | 157 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 46 | Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF… | trilwu/ | 157 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 47 | Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher… | trilwu/ | 157 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and… | trilwu/ | 157 | — | ~3.9k | Automated safety check: Notes | MIT | 1 mo ago |