Topic · Security
Best penetration testing skills, page 2
Penetration testing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | 49.Adcs Attacks Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). | ADScanPro/ | 210 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 50 | Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws | NeoTheCapt/ | 142 | — | ~2.8k | Automated safety check: Pass | No licence | 2 mo ago |
| 51 | Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts. | quillai-network/ | 129 | — | ~2.8k | Automated safety check: Pass | MIT | 6 mo ago |
| 52 | 52.Cis Controls Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection… | Sushegaad/ | 942 | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 3 days ago |
| 53 | 53.Nmap Recon Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools | CommonHuman-Lab/ | 157 | — | ~639 | Automated safety check: Pass | Unknown | today |
| 54 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 55 | Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. | ADScanPro/ | 210 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 56 | 56.Cors Testing CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 142 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 57 | Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs. | AgentSecOps/ | 220 | 1 repo | ~3.3k | Automated safety check: Notes | Unknown | 5 mo ago |
| 58 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 59 | Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field. | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | today |
| 60 | Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD). | ADScanPro/ | 210 | — | ~2.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 61 | Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs. | forefy/ | 117 | — | ~213 | Automated safety check: Pass | MIT | 3 days ago |
| 62 | 62.Csrf Testing Cross-site request forgery testing for state-changing operations | NeoTheCapt/ | 142 | — | ~791 | Automated safety check: Pass | No licence | 2 mo ago |
| 63 | 63.Cso Chief Security Officer mode. An agent skill from no-session/pstack. | no-session/ | 134 | — | ~12k | Automated safety check: Notes | MIT | 6 mo ago |
| 64 | Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. | davila7/ | 32k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | today |
| 65 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 66 | Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. | transilienceai/ | 562 | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 67 | Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently… | samugit83/ | 3k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 68 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 142 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 69 | 69.Web Sqli SQL injection detection→exploitation→proof for web apps and APIs. | s0ld13rr/ | 827 | — | ~710 | Automated safety check: Pass | MIT | 5 days ago |
| 70 | Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening. | davila7/ | 32k | 4 repos | ~1.3k | Automated safety check: Pass | MIT | today |
| 71 | Subdomain and DNS enumeration workflow using subfinder, amass, dnsenum, fierce, theharvester, gau, and waybackurls | CommonHuman-Lab/ | 157 | — | ~858 | Automated safety check: Pass | Unknown | today |
| 72 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 73 | How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 74 | Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the… | samugit83/ | 3k | — | ~855 | Automated safety check: Pass | MIT | today |
| 75 | Working on the HTTP capture proxy and its replay/fuzz path: the egress guard that stops the proxy becoming an SSRF pivot, why it checks the resolved IP, and keeping capture off the scan's critical… | samugit83/ | 3k | — | ~771 | Automated safety check: Pass | MIT | today |
| 76 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 142 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 77 | A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. | ADScanPro/ | 210 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 78 | Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. | bbartling/ | 172 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 79 | Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 8 days ago |
| 80 | Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | RightNow-AI/ | 18k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 81 | 81.Web Recon Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f | CommonHuman-Lab/ | 157 | — | ~907 | Automated safety check: Pass | Unknown | today |
| 82 | 82.Recon Nmap Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~4.6k | Automated safety check: Notes | Unknown | 5 mo ago |
| 83 | Automated SQL injection detection and exploitation tool for web application security testing. | AgentSecOps/ | 220 | 1 repo | ~3.2k | Automated safety check: Pass | Unknown | 5 mo ago |
| 84 | 84.Dora Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. | Sushegaad/ | 942 | 1 repo | ~6.9k | Automated safety check: Pass | MIT | 3 days ago |
| 85 | Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 86 | Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry… | mukul975/ | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 87 | Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 88 | Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 89 | Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 90 | Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent… | mukul975/ | 34k | — | ~1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 91 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 92 | Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T… | openocta/ | 166 | — | ~6.3k | Automated safety check: Notes | MIT | 3 mo ago |
| 93 | 93.Web Vuln Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles | CommonHuman-Lab/ | 157 | — | ~896 | Automated safety check: Pass | Unknown | today |
| 94 | Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 95 | Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 96 | Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38