Penetration testing framework for exploit development, vulnerability validation, and authorized security assessments using Metasploit Framework.
Ethical security testing methodology - 5-phase pipeline, OWASP checklist, proof levels, structured findings
Mobile application pentest — Android/iOS, MASTG/MASVS, Frida/Objection dynamic analiz, sertifika pinning bypass, IPC test advisory.
Network reconnaissance and port scanning using Naabu, hping3, and complementary tools
Operator OPSEC + evidence handling — operator identity hygiene, source IP design, burner infrastructure, evidence chain of custody, log retention advisory.
Yetkili penetration testing engagement orchestrator — scope declaration, OPSEC tagging, evidence handling disiplini.
Open Source Intelligence gathering and attack surface management for external reconnaissance.
Pentest especializado para pfSense CE e Plus — cobre todas as superfícies de ataque a partir da rede externa e interna, mapeado ao PTES e ao código-fonte real do pfSense
Privilege escalation methodology — Linux + Windows + container escape advisory. LinPEAS/WinPEAS analizi, SUID/capability abuse, kernel exploit secimi.
Reconnaissance ve enumeration advisory — Nmap/Nessus/Nikto/BloodHound output parsing, attack surface prioritization, next-step onerisi.
Coordinate autonomous pentest skills with dependency enforcement, deconfliction, and emergency stop controls.
Penetration test rapor yazimi — executive summary, technical writeup, CVSS scoring, remediation roadmap advisory.
Social engineering pentest methodology — phishing strategy, pretexting, vishing senaryosu, awareness training advisory. Live phishing operation YOK.
DISA STIG (Security Technical Implementation Guide) audit + GPO remediation + keep-open justification advisory.
Threat modeling — STRIDE, DREAD, attack tree, data flow diagram, MITRE ATT&CK Navigator integration. Triggers on threat model, STRIDE, DREAD, attack tree, DFD, data flow diagram,…
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL…
Web application security testing methodology — OWASP Top 10, SSRF, IDOR, auth bypass, injection sinifi advisory. Burp/ZAP cikti analizi.
Wireless network pentest — WPA/WPA2/WPA3, evil twin, 802.1X enterprise, Bluetooth advisory. Triggers on wireless pentest, WiFi, WPA2, WPA3, PMKID, evil twin, deauth, Aircrack,…
AI-powered pentesting terminal UI with 4 modes (Assist, Agent, Crew, Interact) and RAG knowledge system.
Enumerating and attacking FreeIPA domains during authorized engagements — anonymous and authenticated LDAP
Testing rsync daemon services (default port 873) for unauthenticated module listing and access, weak/default credentials and brute force, arbitrary file read/download and…
Run an AWS Security Agent penetration test against a live web application — registers and verifies the target domain, exercises the supplied endpoints with the managed Security…
Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic…
Server intelligence layer for RunCloud-managed Linux servers. Use when the user mentions Perch, /perch_*, RunCloud, nginx-rc, server intelligence, server diagnosis, WordPress site…
Identify and eliminate host-device synchronizations in PyTorch code. Detects sync points (.item(), .cpu(), boolean indexing, torch.tensor on CUDA), classifies false vs true…
Plan and record bounded dynamic analysis of Apple binaries using supported LLDB, Xcode, Instruments, unified logging, Simulator, physical-device, macOS VM, or research-device…
Observe suspicious content in a disposable, instrumented environment. Use when execution, process ancestry, file changes, persistence, network behavior, configuration decryption,…
Analyze a suspicious artifact for capabilities without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or embedded payloads…
Generate clear, accurate performance reports for investment portfolios with benchmarks, attribution, and risk dashboards.
Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised
Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust
Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound,
Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations,
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy,
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security
Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify
Uses Postman to perform structured API security testing by building collections that test for OWASP API Security
Simulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy
Develop and apply a multi-factor asset criticality scoring model to weight vulnerability prioritization based
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,
Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments
Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library.
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions,
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting
Perform comprehensive cloud asset inventory and relationship mapping using Cartography to build a Neo4j security
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations,
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and
Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and
Docker Bench for Security is an open-source script that checks dozens of common best practices around deploying