Topic · Security
Best penetration testing skills, page 4
Penetration testing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 156 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 146 | Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 147 | Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. | trilwu/ | 156 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 148 | Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. | trilwu/ | 156 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 149 | 149.Trust Attacks Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. | blacklanternsecurity/ | 286 | — | ~4.5k | Automated safety check: Notes | GPL-3.0 | 9 days ago |
| 150 | 150.Hack Entry P0 primary router and operating doctrine for HackSkills. | yaklang/ | 2.4k | — | ~4.7k | Automated safety check: Notes | MIT | 24 days ago |
| 151 | Coordinate a PCI DSS penetration-testing and CDE-scoping readiness assessment across methodology, scope, segmentation, execution evidence, remediation, and retesting. | cyberful/ | 134 | — | ~895 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 152 | Security architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 153 | HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning | NeoTheCapt/ | 140 | — | ~982 | Automated safety check: Pass | No licence | 2 mo ago |
| 154 | 154.Source Analysis Frontend source code analysis for hidden routes, API endpoints, and secrets | NeoTheCapt/ | 140 | — | ~3k | Automated safety check: Pass | No licence | 2 mo ago |
| 155 | 155.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 140 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 156 | 156.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 140 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 157 | Subdomain discovery via subfinder, DNS brute-force, and passive sources | NeoTheCapt/ | 140 | — | ~1.7k | Automated safety check: Notes | No licence | 2 mo ago |
| 158 | 158.User Enumeration Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference | NeoTheCapt/ | 140 | — | ~2.9k | Automated safety check: Pass | No licence | 2 mo ago |
| 159 | 159.Web Recon Enumerate web technologies, headers, endpoints, and metadata from a target | NeoTheCapt/ | 140 | — | ~770 | Automated safety check: Pass | No licence | 2 mo ago |
| 160 | 160.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 140 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 161 | 161.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 140 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 162 | Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context. | cyberful/ | 134 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 163 | Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk. | cyberful/ | 134 | — | ~829 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 164 | 164.Cyberful Operate Cyberful as an authorized application-security control room. | cyberful/ | 134 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0-only | 1 mo ago |
| 165 | 165.Av Edr Evasion Bypass antivirus and EDR detection for payload delivery during exploitation. | blacklanternsecurity/ | 286 | — | ~5.4k | Automated safety check: Notes | GPL-3.0 | 9 days ago |
| 166 | Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. | automateyournetwork/ | 674 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 167 | Custom nmap scans with arbitrary flags, plus scan history retrieval and management. | automateyournetwork/ | 674 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 168 | Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP. | automateyournetwork/ | 674 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 169 | Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. | ArabelaTso/ | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 170 | Assess AI-system risk from architecture, intended use, affected actors, model limitations, data lineage, autonomy, human oversight, monitoring, and failure consequences. | cyberful/ | 134 | — | ~566 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 171 | 171.Naabu Portscan 使用 naabu 进行高速端口扫描。当需要对目标主机/网段进行端口发现、存活检测时使用。naabu 是 ProjectDiscovery 出品的快速端口扫描器,支持 SYN/CONNECT/UDP 扫描,性能远超 nmap,支持批量目标、CDN 排除、nmap 集成。任何涉及端口扫描、端口发现、主机存活检测、网段探测的场景都应使用此技能。如果 naabu 结果不足再降级用 nmap | wgpsec/ | 1.8k | — | ~812 | Automated safety check: Notes | No licence | 4 days ago |
| 172 | 172.Nmap Scan 使用 nmap 进行端口扫描和服务识别。当需要对目标进行精细端口扫描、服务版本探测、操作系统指纹识别、NSE 脚本漏洞扫描时使用。nmap 是最经典的网络扫描器,支持 SYN/TCP/UDP/ACK 等多种扫描模式,内置 600+ NSE 脚本。任何涉及端口扫描、服务识别、漏洞脚本扫描、操作系统指纹的场景都应使用此技能。速度不如 naabu,但功能远超 naabu | wgpsec/ | 1.8k | — | ~652 | Automated safety check: Notes | No licence | 4 days ago |
| 173 | Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts | NeoTheCapt/ | 140 | — | ~5.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 174 | OS command injection detection, exploitation, and filter bypass | NeoTheCapt/ | 140 | — | ~754 | Automated safety check: Pass | No licence | 2 mo ago |
| 175 | File upload vulnerability testing — webshells, bypass, path traversal | NeoTheCapt/ | 140 | — | ~1.6k | Automated safety check: Pass | No licence | 2 mo ago |
| 176 | 176.Idor Testing Insecure direct object reference testing for broken access control | NeoTheCapt/ | 140 | — | ~793 | Automated safety check: Pass | No licence | 2 mo ago |
| 177 | Information disclosure detection — error messages, files, headers, debug endpoints | NeoTheCapt/ | 140 | — | ~1.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 178 | 178.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 140 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |
| 179 | 179.Nmap Expert Expert-level Nmap skill for network reconnaissance, port scanning, service detection, and security assessment. | theneoai/ | 183 | — | ~4.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 180 | Elite Security Engineer skill with deep expertise in application security, cloud security architecture, penetration testing, Zero Trust implementation, threat modeling (STRIDE), and compliance… | theneoai/ | 183 | — | ~2.1k | Automated safety check: Pass | MIT | 4 mo ago |
| 181 | 181.Security Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan | vibeeval/ | 531 | — | ~807 | Automated safety check: Pass | MIT | 1 mo ago |
| 182 | API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0… | FerroxLabs/ | 608 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 183 | 183.Devops Engineer Becomes a senior DevOps engineer who designs and implements CI/CD pipelines, infrastructure as code, monitoring systems, and deployment strategies. | FerroxLabs/ | 608 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34