Open Source Intelligence gathering and attack surface management for external reconnaissance.
Pentest especializado para pfSense CE e Plus — cobre todas as superfícies de ataque a partir da rede externa e interna, mapeado ao PTES e ao código-fonte real do pfSense
Privilege escalation methodology — Linux + Windows + container escape advisory. LinPEAS/WinPEAS analizi, SUID/capability abuse, kernel exploit secimi.
Reconnaissance ve enumeration advisory — Nmap/Nessus/Nikto/BloodHound output parsing, attack surface prioritization, next-step onerisi.
Coordinate autonomous pentest skills with dependency enforcement, deconfliction, and emergency stop controls.
Penetration test rapor yazimi — executive summary, technical writeup, CVSS scoring, remediation roadmap advisory.
Social engineering pentest methodology — phishing strategy, pretexting, vishing senaryosu, awareness training advisory. Live phishing operation YOK.
DISA STIG (Security Technical Implementation Guide) audit + GPO remediation + keep-open justification advisory.
Threat modeling — STRIDE, DREAD, attack tree, data flow diagram, MITRE ATT&CK Navigator integration. Triggers on threat model, STRIDE, DREAD, attack tree, DFD, data flow diagram,…
Web application security testing methodology — OWASP Top 10, SSRF, IDOR, auth bypass, injection sinifi advisory. Burp/ZAP cikti analizi.
Wireless network pentest — WPA/WPA2/WPA3, evil twin, 802.1X enterprise, Bluetooth advisory. Triggers on wireless pentest, WiFi, WPA2, WPA3, PMKID, evil twin, deauth, Aircrack,…
AI-powered pentesting terminal UI with 4 modes (Assist, Agent, Crew, Interact) and RAG knowledge system.
Enumerating and attacking FreeIPA domains during authorized engagements — anonymous and authenticated LDAP
Testing rsync daemon services (default port 873) for unauthenticated module listing and access, weak/default credentials and brute force, arbitrary file read/download and…
Simulates bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized environments
Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library.
Analyze and bypass Content Security Policy implementations to achieve cross-site scripting by exploiting misconfigurations,
Execute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service
Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions,
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength.
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting
Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session
Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces,
Kerberoasting is a post-exploitation technique that targets service accounts in Active Directory by requesting
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration,
Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries,
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps
GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing
Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device
Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with
Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener
Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions
Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE,
Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials,
Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak
Römisches Recht: Personae Status Und Familie. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Steuerberater: personalakten lohnsteuer geheimnis - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Römisches Recht: Pfandrecht Pignus Hypotheca. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Phrack magazine article analysis, binary exploitation, vulnerability research, exploit development, Use-After-Free (UAF), heap exploitation, ROP chain, GDB debugging, pwntools,…
Use picocom to interact with IoT device UART consoles for pentesting operations including device enumeration, vulnerability discovery, bootloader manipulation, and gainin — from…
Modularny framework do pism procesowych na poziomie kancelaryjnym. Pipeline: W1 (rama + CLAIM-VALIDATION + RED-TEAM) → W1.2d-PRE (MOD-DOKUMENT-ANOMALIE) → W2 (projekt + executive…
Adversarial code review for a Plot branch / commit set / PR. Reads code with red-team eyes — bad-faith input, hidden coupling, rotted comments, stale spec, principle violations…
Adversarial design review for a Plot proposal BEFORE implementation. Reads a SPEC change / DECISIONS entry draft / plan file / verbal proposal with red-team eyes — unstated…
Adversarially re-review a PM artifact, recommendation, or AI-generated critique that already exists. Use as a second pass after another skill (pm-evaluator, pm-prd-drafter,…
Post-exploitation — privilege escalation (Windows Potato/UAC/SUID/sudo), credential access (LSASS/SAM/Responder/spray), and lateral movement (Pass-the-Hash/WMI/tunneling).
Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
Erkennt postfaktische oder pseudoempirische Muster in zivilrechtlicher Argumentation und zwingt zur Trennung von Tatsache, Wertung, Normzweck, Lebenserfahrung und Beweis.
Wirtschaftsprüfer: praesentation im aufsichtsrat - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Römisches Recht: Praetorisches Edikt. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
PrALR: Falsche Behauptungen über Geltung, Modernität, Liberalität oder Norminhalt des PrALR entlarven. — from Klotzkette/claude-fuer-deutsches-recht
PrALR: OCR-Halluzinationen, falsch gelesene Paragraphen und Scheinfundstellen im PrALR erkennen. — from Klotzkette/claude-fuer-deutsches-recht
PrALR: Normnavigator jede PrALR-Norm als Karte erschließen mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Textzeugenvergleich 1794 1804 Ausgabe und OCR mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Erster Teil Titel 4 Willenserklärungen und Verträge mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Erster Teil Titel 5 Verträge allgemein Form und Auslegung mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Erster Teil Titel 6 Unerlaubte Handlungen und Versehen mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Erster Teil Titel 7 Gewahrsam Besitz und Eigentumsverfolgung mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
PrALR: Erster Teil Titel 8 Erwerb Eigentum bewegliche Sachen mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.