754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0
3650 matches across 16 categories. Click a row to expand file-level details.
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …implementing-gcp-binary-authorization/scripts/agent.py | 137 | |
| LOW | …-identity-verification-for-zero-trust/scripts/agent.py | 101 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 234 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 340 | |
| LOW | …lware-hash-enrichment-with-virustotal/scripts/agent.py | 108 | |
| LOW | …g-gcp-organization-policy-constraints/scripts/agent.py | 145 | |
| LOW | …gcp-organization-policy-constraints/scripts/process.py | 112 | |
| LOW | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 189 | |
| LOW | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 419 | |
| LOW | …ng-just-in-time-access-provisioning/scripts/process.py | 220 | |
| LOW | …ing-honeypot-for-ransomware-detection/scripts/agent.py | 98 | |
| LOW | …g-honeypot-for-ransomware-detection/scripts/process.py | 240 | |
| LOW | …g-honeypot-for-ransomware-detection/scripts/process.py | 222 | |
| LOW | …lementing-aws-security-hub-compliance/scripts/agent.py | 88 | |
| LOW | …g-threat-actor-ttps-with-mitre-attack/scripts/agent.py | 33 | |
| LOW | …g-threat-actor-ttps-with-mitre-attack/scripts/agent.py | 52 | |
| LOW | …threat-actor-ttps-with-mitre-attack/scripts/process.py | 301 | |
| LOW | …tracting-credentials-from-memory-dump/scripts/agent.py | 72 | |
| LOW | …ills/analyzing-linux-system-artifacts/scripts/agent.py | 48 | |
| LOW | …ills/analyzing-linux-system-artifacts/scripts/agent.py | 106 | |
| LOW | …ills/analyzing-linux-system-artifacts/scripts/agent.py | 207 | |
| LOW | …core-for-vulnerability-prioritization/scripts/agent.py | 46 | |
| LOW | …re-for-vulnerability-prioritization/scripts/process.py | 52 | |
| LOW | …001-information-security-management/scripts/process.py | 163 | |
| LOW | …s/hunting-for-dns-tunneling-with-zeek/scripts/agent.py | 29 | |
| LOW | …hunting-for-dns-tunneling-with-zeek/scripts/process.py | 33 | |
| LOW | …scanning-infrastructure-with-nessus/scripts/process.py | 396 | |
| LOW | …scanning-infrastructure-with-nessus/scripts/process.py | 143 | |
| LOW | …scanning-infrastructure-with-nessus/scripts/process.py | 225 | |
| LOW | …ing-anomalous-authentication-patterns/scripts/agent.py | 123 | |
| LOW | …mplementing-patch-management-workflow/scripts/agent.py | 216 | |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 277 | |
| LOW | …nting-mobile-application-management/scripts/process.py | 41 | |
| LOW | …/performing-jwt-none-algorithm-attack/scripts/agent.py | 132 | |
| LOW | …ills/performing-service-account-audit/scripts/agent.py | 58 | |
| LOW | …ls/performing-service-account-audit/scripts/process.py | 83 | |
| LOW | …ls/performing-service-account-audit/scripts/process.py | 110 | |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 54 | |
| LOW | …ting-for-process-injection-techniques/scripts/agent.py | 52 | |
| LOW | …ing-vulnerabilities-with-cvss-scoring/scripts/agent.py | 75 | |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 309 | |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 128 | |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 271 | |
| LOW | …ilding-patch-tuesday-response-process/scripts/agent.py | 74 | |
| LOW | …ilding-patch-tuesday-response-process/scripts/agent.py | 104 | |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 72 | |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 90 | |
| LOW | …t-modeling-with-owasp-threat-dragon/scripts/process.py | 45 | |
| LOW | …ting-network-deception-with-honeypots/scripts/agent.py | 86 | |
| LOW | …ementing-immutable-backup-with-restic/scripts/agent.py | 106 | |
| LOW | …ementing-immutable-backup-with-restic/scripts/agent.py | 228 | |
| LOW | …ementing-immutable-backup-with-restic/scripts/agent.py | 353 | |
| LOW | …ing-wireless-network-penetration-test/scripts/agent.py | 55 | |
| LOW | …lls/securing-api-gateway-with-aws-waf/scripts/agent.py | 136 | |
| LOW | …forming-log-source-onboarding-in-siem/scripts/agent.py | 135 | |
| LOW | …rming-log-source-onboarding-in-siem/scripts/process.py | 99 | |
| LOW | …ls/analyzing-indicators-of-compromise/scripts/agent.py | 142 | |
| LOW | …ing-for-unusual-service-installations/scripts/agent.py | 49 | |
| LOW | …ing-for-unusual-service-installations/scripts/agent.py | 167 | |
| LOW | …ersary-infrastructure-tracking-system/scripts/agent.py | 54 | |
| 898 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …-identity-verification-for-zero-trust/scripts/agent.py | 30 | def assess_authentication_methods(auth_config): |
| LOW | …-identity-verification-for-zero-trust/scripts/agent.py | 62 | def assess_conditional_access(policies_path): |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 91 | def assess_conditional_access(policies: list) -> dict: |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 292 | def generate_identity_maturity_report(config: dict) -> dict: |
| LOW | …rming-malware-hash-enrichment-with-virustotal/SKILL.md | 291 | def generate_enrichment_report(hash_report, behavior, network, yara_data): |
| LOW | …ng-cobaltstrike-malleable-c2-profiles/scripts/agent.py | 36 | def parse_profile_with_dissect(profile_path): |
| LOW | …g-gcp-organization-policy-constraints/scripts/agent.py | 45 | def audit_baseline_compliance(org_id): |
| LOW | …g-gcp-organization-policy-constraints/scripts/agent.py | 89 | def check_resource_location_constraint(org_id): |
| LOW | …g-gcp-organization-policy-constraints/scripts/agent.py | 101 | def generate_terraform_policies(org_id, constraints=None): |
| LOW | …g-gcp-organization-policy-constraints/scripts/agent.py | 129 | def generate_compliance_report(findings): |
| LOW | …gcp-organization-policy-constraints/scripts/process.py | 187 | def generate_compliance_report(audit_results, org_id): |
| LOW | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 361 | def run_firmware_security_audit(): |
| LOW | …ting-just-in-time-access-provisioning/scripts/agent.py | 63 | def audit_standing_privileges(privileges_path): |
| LOW | …mplementing-dragos-platform-for-ot-monitoring/SKILL.md | 176 | def generate_siem_integration_config(self, siem_type: str = "splunk"): |
| LOW | …ing-dragos-platform-for-ot-monitoring/scripts/agent.py | 77 | def generate_monitoring_config(): |
| LOW | …g-broken-function-level-authorization/scripts/agent.py | 54 | def test_privilege_escalation(base_url, low_priv_token, endpoints=None): |
| LOW | …ing-honeypot-for-ransomware-detection/scripts/agent.py | 98 | def detect_ransomware_indicators(watch_dir, window_seconds=60): |
| LOW | …ing-honeypot-for-ransomware-detection/scripts/agent.py | 142 | def generate_honeypot_share_config(share_name="FinanceArchive", share_path="/srv/honeypot"): |
| LOW | …lementing-aws-security-hub-compliance/scripts/agent.py | 108 | def create_compliance_insight(hub_client, name, group_by_attr, severity_filter=None): |
| LOW | …s/analyzing-dns-logs-for-exfiltration/scripts/agent.py | 29 | def extract_registered_domain(fqdn): |
| LOW | …nting-api-security-posture-management/scripts/agent.py | 11 | def discover_apis_from_traffic(log_path): |
| LOW | …nting-api-security-posture-management/scripts/agent.py | 94 | def check_api_security_controls(apis, spec_path=None): |
| LOW | …lls/detecting-pass-the-ticket-attacks/scripts/agent.py | 63 | def detect_cross_host_ticket_reuse(events): |
| LOW | …lls/detecting-pass-the-ticket-attacks/scripts/agent.py | 90 | def detect_anomalous_tgs_volume(events, threshold=50): |
| LOW | …ills/analyzing-linux-system-artifacts/scripts/agent.py | 155 | def check_systemd_persistence(evidence_root): |
| LOW | …ills/analyzing-linux-system-artifacts/scripts/agent.py | 207 | def find_suspicious_tmp_files(evidence_root): |
| LOW | …uilding-identity-governance-lifecycle-process/SKILL.md | 582 | def generate_remediation_plan(self, orphaned_accounts): |
| LOW | …identity-governance-lifecycle-process/scripts/agent.py | 126 | def generate_lifecycle_report(token): |
| LOW | …g-epss-score-for-vulnerability-prioritization/SKILL.md | 148 | def prioritize_vulnerabilities(scan_results_csv, output_csv): |
| LOW | …core-for-vulnerability-prioritization/scripts/agent.py | 46 | def prioritize_vulnerabilities(cve_scores, epss_threshold=0.1, percentile_threshold=0.9): |
| LOW | …001-information-security-management/scripts/process.py | 511 | def generate_compliance_dashboard(self) -> dict: |
| LOW | …ls/implementing-endpoint-dlp-controls/scripts/agent.py | 26 | def scan_file_for_sensitive_data(file_path): |
| LOW | …s/hunting-for-dns-tunneling-with-zeek/scripts/agent.py | 55 | def analyze_domain_statistics(entries): |
| LOW | …ing-role-mining-for-rbac-optimization/scripts/agent.py | 27 | def build_user_permission_matrix(assignments): |
| LOW | …ing-role-mining-for-rbac-optimization/scripts/agent.py | 106 | def calculate_optimization_metrics(user_matrix, candidate_roles): |
| LOW | …ls/conducting-cloud-incident-response/scripts/agent.py | 109 | def aws_list_attacker_resources(username, events): |
| LOW | …ls/conducting-cloud-incident-response/scripts/agent.py | 119 | def aws_check_all_regions_instances(): |
| LOW | …s/detecting-anomalous-authentication-patterns/SKILL.md | 397 | def detect_behavioral_anomalies(event, baseline): |
| LOW | …s/detecting-anomalous-authentication-patterns/SKILL.md | 458 | def isolation_forest_anomaly_detection(df): |
| LOW | …s/detecting-anomalous-authentication-patterns/SKILL.md | 566 | def calculate_auth_risk_score(user, alerts, baseline): |
| LOW | skills/implementing-patch-management-workflow/SKILL.md | 116 | def get_windows_pending_patches(): |
| LOW | skills/implementing-patch-management-workflow/SKILL.md | 139 | def get_linux_pending_patches(): |
| LOW | …-patch-management-workflow/references/api-reference.md | 46 | def get_tenable_missing_patches(scan_id): |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 220 | def generate_compliance_report(summary: dict, compliance_df: pd.DataFrame, |
| LOW | …menting-mobile-application-management/scripts/agent.py | 40 | def get_app_protection_policies(base_url, token): |
| LOW | …menting-mobile-application-management/scripts/agent.py | 84 | def audit_protection_policies(policies): |
| LOW | skills/performing-jwt-none-algorithm-attack/SKILL.md | 159 | def craft_privilege_escalation(self, role_field: str = "role", |
| LOW | skills/performing-jwt-none-algorithm-attack/SKILL.md | 222 | def test_empty_signature_variants(self) -> list: |
| LOW | …ills/performing-service-account-audit/scripts/agent.py | 28 | def discover_ad_service_accounts(self): |
| LOW | …ls/performing-service-account-audit/scripts/process.py | 162 | def _check_password_never_expires(self): |
| LOW | …figuring-aws-verified-access-for-ztna/scripts/agent.py | 16 | def list_verified_access_instances(session): |
| LOW | …figuring-aws-verified-access-for-ztna/scripts/agent.py | 32 | def list_verified_access_groups(session): |
| LOW | …figuring-aws-verified-access-for-ztna/scripts/agent.py | 48 | def list_verified_access_endpoints(session): |
| LOW | …guring-aws-verified-access-for-ztna/scripts/process.py | 48 | def permit_group_with_device_trust(self, group: str, min_score: int = 50) -> str: |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 145 | def test_path_variation_bypass(base_endpoint, token): |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 242 | def test_account_rotation_bypass(login_endpoint, target_password_list): |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 272 | def test_parameter_pollution_bypass(endpoint): |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 294 | async def distributed_rate_limit_test(endpoint, total_requests=1000, concurrency=50): |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 31 | def detect_rate_limit_headers(url, auth_header=None): |
| LOW | …ting-for-process-injection-techniques/scripts/agent.py | 74 | def detect_remote_thread_injection(events): |
| 801 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …rming-malware-hash-enrichment-with-virustotal/SKILL.md | 142 | except Exception as e: |
| LOW | …rming-malware-hash-enrichment-with-virustotal/SKILL.md | 237 | except Exception as e: |
| LOW | …lware-hash-enrichment-with-virustotal/scripts/agent.py | 81 | except Exception as e: |
| LOW | …curity-information-sharing-with-stix2/scripts/agent.py | 131 | except Exception as e: |
| LOW | …curity-information-sharing-with-stix2/scripts/agent.py | 143 | except Exception as e: |
| LOW | …nting-api-security-posture-management/scripts/agent.py | 104 | except Exception: |
| LOW | …s/detecting-anomalous-authentication-patterns/SKILL.md | 146 | except Exception: |
| LOW | …ing-anomalous-authentication-patterns/scripts/agent.py | 63 | except Exception: |
| LOW | …ing-anomalous-authentication-patterns/scripts/agent.py | 102 | except Exception: |
| LOW | …ing-anomalous-authentication-patterns/scripts/agent.py | 140 | except Exception: |
| LOW | …ing-anomalous-authentication-patterns/scripts/agent.py | 178 | except Exception: |
| LOW | …mplementing-patch-management-workflow/scripts/agent.py | 143 | except Exception: |
| LOW | …/performing-jwt-none-algorithm-attack/scripts/agent.py | 86 | except Exception as e: |
| LOW | …/performing-jwt-none-algorithm-attack/scripts/agent.py | 115 | except Exception as e: |
| LOW | …/performing-jwt-none-algorithm-attack/scripts/agent.py | 121 | except Exception: |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 178 | except Exception: |
| LOW | skills/performing-api-rate-limiting-bypass/SKILL.md | 316 | except Exception: |
| MEDIUM | skills/performing-api-rate-limiting-bypass/SKILL.md | 298 | def make_request(session, request_num): |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 50 | except Exception as e: |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 67 | except Exception: |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 88 | except Exception: |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 114 | except Exception: |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 167 | except Exception: |
| LOW | …s/performing-api-rate-limiting-bypass/scripts/agent.py | 192 | except Exception: |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 172 | except Exception as e: |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 190 | except Exception as e: |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 208 | except Exception as e: |
| LOW | …ls/detecting-attacks-on-scada-systems/scripts/agent.py | 93 | except Exception as e: |
| LOW | …ls/detecting-attacks-on-scada-systems/scripts/agent.py | 125 | except Exception as e: |
| LOW | …ls/detecting-attacks-on-scada-systems/scripts/agent.py | 150 | except Exception as e: |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 69 | except Exception as e: |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 86 | except Exception as e: |
| LOW | …omalies-in-industrial-control-systems/scripts/agent.py | 49 | except Exception as e: |
| LOW | …omalies-in-industrial-control-systems/scripts/agent.py | 127 | except Exception as e: |
| MEDIUM | …ementing-immutable-backup-with-restic/scripts/agent.py | 388 | print("Error: --source required for backup") |
| MEDIUM | …ementing-immutable-backup-with-restic/scripts/agent.py | 418 | print("Error: --bucket required for Object Lock configuration") |
| MEDIUM | …ementing-immutable-backup-with-restic/scripts/agent.py | 431 | print("Error: --source required for full pipeline") |
| LOW | …lls/securing-api-gateway-with-aws-waf/scripts/agent.py | 73 | except Exception as e: |
| LOW | …lls/securing-api-gateway-with-aws-waf/scripts/agent.py | 90 | except Exception as e: |
| LOW | …forming-log-source-onboarding-in-siem/scripts/agent.py | 71 | except Exception as e: |
| LOW | …ing-for-unusual-service-installations/scripts/agent.py | 84 | except Exception: |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 268 | except Exception: |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 282 | except Exception as exc: |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 651 | except Exception as exc: |
| LOW | …enting-runtime-security-with-tetragon/scripts/agent.py | 37 | except Exception as e: |
| LOW | skills/performing-kerberoasting-attack/scripts/agent.py | 41 | except Exception as e: |
| LOW | skills/performing-kerberoasting-attack/scripts/agent.py | 59 | except Exception as e: |
| LOW | skills/performing-kerberoasting-attack/scripts/agent.py | 86 | except Exception as e: |
| LOW | skills/performing-kerberoasting-attack/scripts/agent.py | 143 | except Exception as e: |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 111 | except Exception as e: |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 217 | except Exception as e: |
| LOW | …zing-packed-malware-with-upx-unpacker/scripts/agent.py | 187 | except Exception as e: |
| LOW | …lls/deploying-ransomware-canary-files/scripts/agent.py | 211 | except Exception as e: |
| LOW | …lls/deploying-ransomware-canary-files/scripts/agent.py | 253 | except Exception as e: |
| LOW | …lls/deploying-ransomware-canary-files/scripts/agent.py | 276 | except Exception as e: |
| LOW | …lls/deploying-ransomware-canary-files/scripts/agent.py | 487 | except Exception as e: |
| LOW | …lementing-pci-dss-compliance-controls/scripts/agent.py | 55 | except Exception as e: |
| LOW | …lementing-pci-dss-compliance-controls/scripts/agent.py | 214 | except Exception: |
| LOW | …ming-endpoint-forensics-investigation/scripts/agent.py | 26 | except Exception as e: |
| LOW | …ming-endpoint-forensics-investigation/scripts/agent.py | 38 | except Exception as e: |
| 616 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 28 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 30 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 106 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 108 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 181 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 183 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 286 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 288 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 324 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 326 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 381 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 383 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 415 | # --------------------------------------------------------------------------- |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 417 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 166 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 168 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 501 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 503 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 689 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 691 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 40 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 42 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 252 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 254 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 315 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 317 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 582 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 584 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 785 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 787 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 813 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 815 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 104 | # --------------------------------------------------------------------------- |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 106 | # --------------------------------------------------------------------------- |
| MEDIUM | …lementing-llm-guardrails-for-security/scripts/agent.py | 29 | # --------------------------------------------------------------------------- |
| MEDIUM | …lementing-llm-guardrails-for-security/scripts/agent.py | 31 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 28 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 30 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 35 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 37 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1027 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1029 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1234 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1236 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 167 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 169 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 470 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 472 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 619 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 621 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 730 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 732 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 898 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 900 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1361 | # --------------------------------------------------------------------------- |
| MEDIUM | …g-post-quantum-cryptography-migration/scripts/agent.py | 1363 | # --------------------------------------------------------------------------- |
| MEDIUM | …etecting-command-and-control-over-dns/scripts/agent.py | 51 | # --------------------------------------------------------------------------- |
| MEDIUM | …etecting-command-and-control-over-dns/scripts/agent.py | 53 | # --------------------------------------------------------------------------- |
| MEDIUM | …etecting-command-and-control-over-dns/scripts/agent.py | 125 | # --------------------------------------------------------------------------- |
| MEDIUM | …etecting-command-and-control-over-dns/scripts/agent.py | 127 | # --------------------------------------------------------------------------- |
| 162 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …plementing-gcp-binary-authorization/scripts/process.py | 11 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 10 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 11 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 12 | |
| LOW | …dentity-verification-for-zero-trust/scripts/process.py | 15 | |
| LOW | …gcp-organization-policy-constraints/scripts/process.py | 11 | |
| LOW | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 13 | |
| LOW | …ng-just-in-time-access-provisioning/scripts/process.py | 10 | |
| LOW | …g-honeypot-for-ransomware-detection/scripts/process.py | 19 | |
| LOW | …g-threat-actor-ttps-with-mitre-attack/scripts/agent.py | 11 | |
| LOW | …re-for-vulnerability-prioritization/scripts/process.py | 13 | |
| LOW | …re-for-vulnerability-prioritization/scripts/process.py | 15 | |
| LOW | …re-for-vulnerability-prioritization/scripts/process.py | 15 | |
| LOW | …re-for-vulnerability-prioritization/scripts/process.py | 16 | |
| LOW | …001-information-security-management/scripts/process.py | 11 | |
| LOW | …001-information-security-management/scripts/process.py | 12 | |
| LOW | …g-role-mining-for-rbac-optimization/scripts/process.py | 13 | |
| LOW | …g-role-mining-for-rbac-optimization/scripts/process.py | 16 | |
| LOW | …g-role-mining-for-rbac-optimization/scripts/process.py | 17 | |
| LOW | …scanning-infrastructure-with-nessus/scripts/process.py | 24 | |
| LOW | …mplementing-patch-management-workflow/scripts/agent.py | 14 | |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 18 | |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 20 | |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 21 | |
| LOW | …lementing-patch-management-workflow/scripts/process.py | 23 | |
| LOW | …nting-mobile-application-management/scripts/process.py | 13 | |
| LOW | …nting-mobile-application-management/scripts/process.py | 15 | |
| LOW | …ls/performing-service-account-audit/scripts/process.py | 10 | |
| LOW | …guring-aws-verified-access-for-ztna/scripts/process.py | 9 | |
| LOW | …guring-aws-verified-access-for-ztna/scripts/process.py | 10 | |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 19 | |
| LOW | …g-vulnerabilities-with-cvss-scoring/scripts/process.py | 21 | |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 19 | |
| LOW | …ding-patch-tuesday-response-process/scripts/process.py | 20 | |
| LOW | …ing-wireless-network-penetration-test/scripts/agent.py | 11 | |
| LOW | …rming-log-source-onboarding-in-siem/scripts/process.py | 9 | |
| LOW | …rming-log-source-onboarding-in-siem/scripts/process.py | 10 | |
| LOW | …rming-log-source-onboarding-in-siem/scripts/process.py | 11 | |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 9 | |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 12 | |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 21 | |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 22 | |
| LOW | …ing-tls-certificate-transparency-logs/scripts/agent.py | 22 | |
| LOW | …ting-runtime-security-with-tetragon/scripts/process.py | 14 | |
| LOW | …ting-runtime-security-with-tetragon/scripts/process.py | 15 | |
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 9 | |
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 10 | |
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 11 | |
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 12 | |
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 16 | |
| LOW | …menting-zero-trust-dns-with-nextdns/scripts/process.py | 13 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 21 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 120 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 120 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 121 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 122 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 122 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 123 | |
| LOW | …lls/performing-kerberoasting-attack/scripts/process.py | 124 | |
| LOW | …ming-alert-triage-with-elastic-siem/scripts/process.py | 9 | |
| 501 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| HIGH | …tracting-credentials-from-memory-dump/scripts/agent.py | 146 | if not username or username == "(null)": |
| HIGH | …mplementing-cloud-workload-protection/scripts/agent.py | 82 | "ls -la /dev/tcp 2>/dev/null; ls -la /proc/*/fd 2>/dev/null | grep socket | head -20", |
| HIGH | …ng-agentless-vulnerability-scanning/scripts/process.py | 105 | out, _ = self._exec(client, "ss -tlnp 2>/dev/null || netstat -tlnp 2>/dev/null") |
| HIGH | …everse-engineering-ios-app-with-frida/scripts/agent.py | 58 | var SSLSetPeerDomainName = Module.findExportByName(null, 'SSLSetPeerDomainName'); |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 23 | if (name.indexOf("Auth") !== -1 || name.indexOf("Crypto") !== -1 || |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 24 | name.indexOf("Token") !== -1 || name.indexOf("Key") !== -1 || |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 25 | name.indexOf("Secret") !== -1 || name.indexOf("Login") !== -1) { |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 27 | results.classes.push({name: name, method_count: methods.length}); |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 29 | if (m.toLowerCase().indexOf("auth") !== -1 || m.toLowerCase().indexOf("login") !== -1) { |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 30 | results.auth_methods.push(name + " " + m); |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 32 | if (m.toLowerCase().indexOf("encrypt") !== -1 || m.toLowerCase().indexOf("decrypt") !== -1 || |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 33 | m.toLowerCase().indexOf("key") !== -1 || m.toLowerCase().indexOf("cipher") !== -1) { |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 34 | results.crypto_methods.push(name + " " + m); |
| HIGH | …erse-engineering-ios-app-with-frida/scripts/process.py | 71 | base: main.base.toString(), |
| HIGH | …-network-traffic-analysis-with-tshark/scripts/agent.py | 142 | ["tshark", "-r", pcap_path, "-Y", "tcp.flags.syn==1 && tcp.flags.ack==0", |
| HIGH | …ploiting-constrained-delegation-abuse/scripts/agent.py | 45 | "| Where-Object {$_.'msDS-AllowedToActOnBehalfOfOtherIdentity' -ne $null} " |
| HIGH | …erforming-ios-app-security-assessment/scripts/agent.py | 157 | send({type: 'keychain_error', class: classNames[kSecClasses[i]], error: e.toString()}); |
| HIGH | …erforming-ios-app-security-assessment/scripts/agent.py | 204 | if (this.url.indexOf('cydia://') !== -1 || this.url.indexOf('sileo://') !== -1) { |
| HIGH | …erforming-ios-app-security-assessment/scripts/agent.py | 212 | var fork = Module.findExportByName(null, 'fork'); |
| HIGH | …alyzing-network-traffic-for-incidents/scripts/agent.py | 45 | connections = run_tshark(pcap_path, "tcp.flags.syn==1 && tcp.flags.ack==0", |
| HIGH | …rming-dynamic-analysis-of-android-app/scripts/agent.py | 46 | results.methods.push('TrustManagerImpl.verifyChain'); |
| HIGH | …rming-dynamic-analysis-of-android-app/scripts/agent.py | 54 | results.methods.push('OkHostnameVerifier.verify'); |
| HIGH | skills/detecting-stuxnet-style-attacks/scripts/agent.py | 45 | ["tshark", "-r", pcap_path, "-Y", "modbus || s7comm", |
| HIGH | …menting-privileged-access-workstation/scripts/agent.py | 76 | "Select-Object DisplayName,Publisher,InstallDate | Where-Object {$_.DisplayName -ne $null} | " |
| HIGH | …forming-lateral-movement-with-wmiexec/scripts/agent.py | 90 | "dcerpc.cn_bind_uuid == 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57 || tcp.port == 135 || dcom", |
| HIGH | …ls/performing-packet-injection-attack/scripts/agent.py | 144 | print("Tests: syn, xmas, null, flags, spoof, land, frag, icmp, all") |
| HIGH | …plementing-aws-nitro-enclave-security/scripts/agent.py | 216 | "commands": ["cat /etc/nitro_enclaves/allocator.yaml 2>/dev/null || echo 'NOT_FOUND'"] |
| HIGH | …-hardware-security-key-authentication/scripts/agent.py | 434 | const displayName = document.getElementById('reg-display').value || username; |
| HIGH | …-hardware-security-key-authentication/scripts/agent.py | 487 | body: JSON.stringify({username: username || null}) |
| HIGH | …-hardware-security-key-authentication/scripts/agent.py | 487 | body: JSON.stringify({username: username || null}) |
| HIGH | …-hardware-security-key-authentication/scripts/agent.py | 512 | b64encode(assertion.response.userHandle) : null, |
| HIGH | …yzing-persistence-mechanisms-in-linux/scripts/agent.py | 46 | ["bash", "-c", "for u in $(cut -d: -f1 /etc/passwd); do crontab -l -u $u 2>/dev/null && echo \"__USER:$u\"; done |
| HIGH | …ng-authenticated-vulnerability-scan/scripts/process.py | 94 | _, stdout, stderr = client.exec_command("id && uname -a", timeout=10) |
| HIGH | …lyzing-network-traffic-with-wireshark/scripts/agent.py | 123 | stdout, _, rc = run_tshark(pcap_path, '-Y "icmp && frame.len > 100" -T fields -e ip.src -e ip.dst -e frame.len') |
| HIGH | …lyzing-network-traffic-with-wireshark/scripts/agent.py | 143 | '-Y "http && tcp.port != 80 && tcp.port != 443 && tcp.port != 8080" ' |
| Severity | File | Line | Snippet |
|---|---|---|---|
| HIGH | …rming-malware-hash-enrichment-with-virustotal/SKILL.md | 193 | batch_enrich("YOUR_API_KEY", "hashes.txt", "enrichment_results.csv") |
| HIGH | …mplementing-dragos-platform-for-ot-monitoring/SKILL.md | 220 | api_key="your-api-key", |
| HIGH | …ills/implementing-zero-trust-dns-with-nextdns/SKILL.md | 303 | curl -H "X-Api-Key: your-api-key" \ |
| HIGH | …ills/implementing-zero-trust-dns-with-nextdns/SKILL.md | 307 | curl -H "X-Api-Key: your-api-key" \ |
| HIGH | …ills/implementing-zero-trust-dns-with-nextdns/SKILL.md | 311 | curl -H "X-Api-Key: your-api-key" \ |
| HIGH | …ero-trust-dns-with-nextdns/references/api-reference.md | 7 | Header: X-Api-Key: <your-api-key> |
| HIGH | skills/extracting-iocs-from-malware-samples/SKILL.md | 229 | VT_API_KEY = "your_api_key" |
| HIGH | skills/analyzing-malicious-url-with-urlscan/SKILL.md | 73 | Header: API-Key: your-api-key |
| HIGH | …malicious-url-with-urlscan/references/api-reference.md | 10 | API-Key: YOUR_API_KEY |
| HIGH | …elationships-with-malpedia/references/api-reference.md | 10 | Authorization: apitoken YOUR_API_KEY |
| HIGH | …s/performing-ot-vulnerability-scanning-safely/SKILL.md | 243 | api_key="your-api-key-here", |
| HIGH | …s/performing-network-forensics-with-wireshark/SKILL.md | 142 | -H "x-apikey: YOUR_API_KEY" | python3 -c " |
| HIGH | …s/performing-threat-hunting-with-elastic-siem/SKILL.md | 188 | -H "Authorization: ApiKey YOUR_API_KEY" \ |
| HIGH | …pply-chain-vulnerabilities/references/api-reference.md | 12 | Header: apiKey: <your-api-key> |
| HIGH | …eat-intelligence-platforms/references/api-reference.md | 8 | -H "Authorization: YOUR_API_KEY" -H "Accept: application/json" |
| HIGH | …eat-intelligence-platforms/references/api-reference.md | 12 | -H "Authorization: YOUR_API_KEY" -H "Content-Type: application/json" \ |
| HIGH | …eat-intelligence-platforms/references/api-reference.md | 17 | -H "Authorization: YOUR_API_KEY" -H "Accept: application/json" \ |
| HIGH | …eat-intelligence-platforms/references/api-reference.md | 21 | curl "https://misp.example.com/feeds/index.json" -H "Authorization: YOUR_API_KEY" |
| HIGH | …zing-email-headers-for-phishing-investigation/SKILL.md | 161 | -H "Key: YOUR_API_KEY" -H "Accept: application/json" | python3 -m json.tool |
| HIGH | …for-phishing-investigation/references/api-reference.md | 82 | -H "Key: YOUR_API_KEY" \ |
| HIGH | …rrelating-threat-campaigns/references/api-reference.md | 8 | -H "Authorization: YOUR_API_KEY" -H "Content-Type: application/json" \ |
| HIGH | …rrelating-threat-campaigns/references/api-reference.md | 13 | -H "Authorization: YOUR_API_KEY" -H "Content-Type: application/json" \ |
| HIGH | …rrelating-threat-campaigns/references/api-reference.md | 18 | -H "Authorization: YOUR_API_KEY" -H "Accept: application/json" |
| HIGH | …rrelating-threat-campaigns/references/api-reference.md | 22 | -H "Authorization: YOUR_API_KEY" -H "Content-Type: application/json" \ |
| HIGH | …ills/collecting-threat-intelligence-with-misp/SKILL.md | 83 | misp = PyMISP('https://misp.local', 'YOUR_API_KEY', ssl=False) |
| HIGH | …ills/collecting-threat-intelligence-with-misp/SKILL.md | 125 | misp = PyMISP('https://misp.local', 'YOUR_API_KEY', ssl=False) |
| HIGH | …cting-threat-intelligence-with-misp/scripts/process.py | 16 | python process.py --url https://misp.local --key YOUR_API_KEY --action collect |
| HIGH | …cting-threat-intelligence-with-misp/scripts/process.py | 17 | python process.py --url https://misp.local --key YOUR_API_KEY --action export --format stix2 |
| HIGH | …cting-threat-intelligence-with-misp/scripts/process.py | 18 | python process.py --url https://misp.local --key YOUR_API_KEY --action feeds --enable-defaults |
| HIGH | …kens-for-network-intrusion/references/api-reference.md | 112 | console = canarytools.Console(domain="yourcompany", api_key="YOUR_API_KEY") |
| HIGH | …lligence-sharing-with-misp/references/api-reference.md | 16 | key="YOUR_API_KEY", |
| HIGH | …ath-analysis-with-xm-cyber/references/api-reference.md | 14 | --api-key YOUR_API_KEY \ |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | skills/extracting-credentials-from-memory-dump/SKILL.md | 61 | vol -f /cases/case-2024-001/memory/memory.raw windows.pslist | grep -i lsass |
| LOW | …g-epss-score-for-vulnerability-prioritization/SKILL.md | 41 | - Python 3.9+ with `requests`, `pandas`, `matplotlib` |
| LOW | …ing-infrastructure-with-nessus/references/workflows.md | 61 | |
| LOW | …lls/performing-arp-spoofing-attack-simulation/SKILL.md | 181 | ```bash |
| LOW | …ills/implementing-zero-trust-dns-with-nextdns/SKILL.md | 201 | |
| LOW | …lls/analyzing-windows-lnk-files-for-artifacts/SKILL.md | 81 | ```bash |
| LOW | …figuring-identity-aware-proxy-with-google-iap/SKILL.md | 281 | # Add IAP audit config to policy.json: |
| LOW | skills/performing-security-headers-audit/SKILL.md | 81 | |
| LOW | skills/performing-security-headers-audit/SKILL.md | 221 | # COEP: Cross-Origin-Embedder-Policy: require-corp |
| LOW | …erforming-web-application-scanning-with-nikto/SKILL.md | 101 | # 5 - Remote File Retrieval - Inside Web Root |
| LOW | skills/performing-directory-traversal-testing/SKILL.md | 41 | - **curl**: For manual testing of traversal payloads |
| LOW | …lls/exploiting-race-condition-vulnerabilities/SKILL.md | 41 | |
| LOW | …lls/exploiting-race-condition-vulnerabilities/SKILL.md | 161 | threads = [threading.Thread(target=synchronized_request) for _ in range(20)] |
| LOW | skills/performing-ssl-stripping-attack/SKILL.md | 101 | # 1. Intercepting HTTP responses containing HTTPS links |
| LOW | skills/performing-ssl-stripping-attack/SKILL.md | 141 | # 2. No padlock icon visible |
| LOW | skills/performing-second-order-sql-injection/SKILL.md | 41 | |
| LOW | skills/testing-for-host-header-injection/SKILL.md | 101 | # Poison cache with modified Host header |
| LOW | skills/testing-for-host-header-injection/SKILL.md | 161 | |
| LOW | …nting-device-posture-assessment-in-zero-trust/SKILL.md | 121 | |
| LOW | …nting-device-posture-assessment-in-zero-trust/SKILL.md | 141 | # } |
| LOW | skills/exploiting-sql-injection-with-sqlmap/SKILL.md | 41 | - **Browser with proxy**: Firefox with FoxyProxy for intercepting requests |
| LOW | skills/performing-binary-exploitation-analysis/SKILL.md | 321 | break *main |
| LOW | skills/deploying-tailscale-for-zero-trust-vpn/SKILL.md | 281 | |
| LOW | skills/performing-web-cache-deception-attack/SKILL.md | 141 | ``` |
| LOW | …erforming-cloud-penetration-testing-with-pacu/SKILL.md | 101 | ```bash |
| LOW | …rming-log-analysis-for-forensic-investigation/SKILL.md | 41 | ## Workflow |
| LOW | …s/detecting-ntlm-relay-with-event-correlation/SKILL.md | 501 | # Local Policies > Security Options > |
| LOW | skills/hunting-for-dcom-lateral-movement/SKILL.md | 81 | |
| LOW | skills/hunting-for-dcom-lateral-movement/SKILL.md | 561 | ```powershell |
| LOW | …-source-intelligence-gathering/references/workflows.md | 181 | # Glassdoor: Target Corporation technology stack |
| LOW | …-source-intelligence-gathering/references/workflows.md | 201 | # Google Street View: |
| LOW | skills/performing-web-cache-poisoning-attack/SKILL.md | 81 | ``` |
| LOW | skills/recovering-from-ransomware-attack/SKILL.md | 61 | # - Recovery workstations (10.99.0.10-20) |
| LOW | skills/testing-for-broken-access-control/SKILL.md | 41 | - **ffuf**: For discovering hidden endpoints that may lack access controls |
| LOW | skills/testing-for-broken-access-control/SKILL.md | 81 | # Burp > Extender > BApp Store > Search "Authorize" > Install |
| LOW | …/performing-memory-forensics-with-volatility3/SKILL.md | 81 | |
| LOW | …ls/performing-web-application-firewall-bypass/SKILL.md | 41 | |
| LOW | …s/performing-network-forensics-with-wireshark/SKILL.md | 41 | ## Workflow |
| LOW | skills/performing-file-carving-with-foremost/SKILL.md | 41 | ## Workflow |
| LOW | …/hunting-for-defense-evasion-via-timestomping/SKILL.md | 81 | |
| LOW | skills/exploiting-broken-link-hijacking/SKILL.md | 141 | # Verify if referenced packages still exist |
| LOW | skills/testing-for-email-header-injection/SKILL.md | 41 | |
| LOW | …lls/testing-for-open-redirect-vulnerabilities/SKILL.md | 121 | |
| LOW | skills/detecting-lateral-movement-in-network/SKILL.md | 121 | # | stats count dc(ComputerName) as unique_hosts by TargetUserName, IpAddress |
| LOW | skills/detecting-lateral-movement-in-network/SKILL.md | 261 | sudo zeekctl deploy |
| LOW | skills/detecting-lateral-movement-in-network/SKILL.md | 301 | # Timeline analysis: map the attack path |
| LOW | skills/detecting-lateral-movement-in-network/SKILL.md | 321 | |
| LOW | skills/detecting-lateral-movement-in-network/SKILL.md | 341 | |
| LOW | skills/exploiting-http-request-smuggling/SKILL.md | 241 | ``` |
| LOW | …nting-application-whitelisting-with-applocker/SKILL.md | 201 | # 1. Create a publisher rule (if signed) or path rule (if unsigned) |
| LOW | skills/exploiting-ipv6-vulnerabilities/SKILL.md | 81 | sudo mitm6 -d example.com -i eth0 |
| LOW | …rforming-wifi-password-cracking-with-aircrack/SKILL.md | 81 | # Identify the target network parameters: |
| LOW | …/exploiting-prototype-pollution-in-javascript/SKILL.md | 101 | // jQuery $.html() gadget: |
| LOW | …esting-for-xss-vulnerabilities-with-burpsuite/SKILL.md | 141 | # In Intruder > Options > Grep - Match: |
| LOW | …esting-for-xss-vulnerabilities-with-burpsuite/SKILL.md | 161 | # - setTimeout() / setInterval() with string args |
| LOW | skills/testing-for-sensitive-data-exposure/SKILL.md | 101 | |
| LOW | skills/testing-for-sensitive-data-exposure/SKILL.md | 181 | |
| LOW | skills/testing-for-sensitive-data-exposure/SKILL.md | 221 | # pip install git-dumper |
| LOW | …loiting-zerologon-vulnerability-cve-2020-1472/SKILL.md | 101 | # Performing authentication attempts... |
| LOW | skills/performing-api-fuzzing-with-restler/SKILL.md | 61 | # Verify installation |
| 53 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | index.json | 1 | {"version":"1.1.0","generated_at":"2026-05-30T09:32:08Z","repository":"https://github.com/mukul975/Anthropic-Cybersecuri |
| MEDIUM | …dentity-verification-for-zero-trust/scripts/process.py | 293 | """Generate a comprehensive identity maturity assessment.""" |
| MEDIUM | …ls/analyzing-uefi-bootkit-persistence/scripts/agent.py | 362 | """Run a comprehensive set of chipsec security modules.""" |
| MEDIUM | …identity-governance-lifecycle-process/scripts/agent.py | 127 | """Generate comprehensive identity governance report.""" |
| MEDIUM | …/extracting-browser-history-artifacts/scripts/agent.py | 159 | """Generate comprehensive browser forensics report.""" |
| MEDIUM | …ementing-immutable-backup-with-restic/scripts/agent.py | 328 | """Generate comprehensive backup status report.""" |
| MEDIUM | …ing-for-unusual-service-installations/scripts/agent.py | 147 | """Run comprehensive service installation threat hunt.""" |
| MEDIUM | …ing-tls-certificate-transparency-logs/scripts/agent.py | 694 | """Generate a comprehensive CT monitoring report.""" |
| MEDIUM | …ting-runtime-security-with-tetragon/scripts/process.py | 233 | """Generate a comprehensive security report.""" |
| MEDIUM | …nting-google-workspace-admin-security/scripts/agent.py | 142 | """Run comprehensive Google Workspace security audit.""" |
| MEDIUM | skills/securing-serverless-functions/scripts/agent.py | 128 | """Run comprehensive serverless security audit.""" |
| MEDIUM | …certificate-transparency-for-phishing/scripts/agent.py | 150 | """Generate comprehensive CT monitoring report.""" |
| MEDIUM | skills/profiling-threat-actor-groups/scripts/agent.py | 50 | """Build a comprehensive profile for a specific threat actor group.""" |
| MEDIUM | …asswordless-auth-with-microsoft-entra/scripts/agent.py | 146 | """Run comprehensive passwordless authentication audit.""" |
| MEDIUM | …oss-prevention-with-microsoft-purview/scripts/agent.py | 240 | """Generate comprehensive DLP compliance report.""" |
| MEDIUM | …ng-cloudflare-access-for-zero-trust/scripts/process.py | 176 | """Generate comprehensive audit report.""" |
| MEDIUM | …ills/implementing-zero-trust-in-cloud/scripts/agent.py | 157 | """Run comprehensive zero trust assessment.""" |
| MEDIUM | …detecting-port-scanning-with-fail2ban/scripts/agent.py | 196 | """Generate comprehensive Fail2ban security report.""" |
| MEDIUM | …-supply-chain-security-with-in-toto/scripts/process.py | 167 | """Generate a comprehensive verification report.""" |
| MEDIUM | skills/detecting-wmi-persistence/scripts/agent.py | 162 | """Generate comprehensive WMI persistence hunt report.""" |
| MEDIUM | …ecuring-azure-with-microsoft-defender/scripts/agent.py | 135 | """Generate a comprehensive security posture report.""" |
| MEDIUM | …etecting-bluetooth-low-energy-attacks/scripts/agent.py | 502 | """Generate comprehensive BLE security assessment report.""" |
| MEDIUM | …tion-based-detection-with-canarytoken/scripts/agent.py | 156 | """Run comprehensive Canarytoken deployment audit.""" |
| MEDIUM | …g-kubernetes-etcd-security-assessment/scripts/agent.py | 131 | """Run comprehensive etcd security assessment.""" |
| MEDIUM | …entitlement-review-with-sailpoint-iiq/scripts/agent.py | 86 | """Generate a comprehensive entitlement review report.""" |
| MEDIUM | …g-analysis-for-forensic-investigation/scripts/agent.py | 161 | """Generate a comprehensive forensic log analysis report.""" |
| MEDIUM | …-open-source-intelligence-gathering/scripts/process.py | 375 | """Generate comprehensive OSINT report.""" |
| MEDIUM | …ing-dark-web-monitoring-for-threats/scripts/process.py | 139 | """Generate comprehensive dark web monitoring report.""" |
| MEDIUM | …unting-for-startup-folder-persistence/scripts/agent.py | 238 | """Run comprehensive startup persistence threat hunt.""" |
| MEDIUM | …ng-microsegmentation-for-zero-trust/scripts/process.py | 234 | """Generate comprehensive microsegmentation report.""" |
| MEDIUM | …rforming-soc2-type2-audit-preparation/scripts/agent.py | 673 | """Generate a comprehensive audit readiness report.""" |
| MEDIUM | …ing-memory-forensics-with-volatility3/scripts/agent.py | 117 | """Run comprehensive memory analysis and generate report.""" |
| MEDIUM | …ged-access-management-with-cyberark/scripts/process.py | 304 | """Generate comprehensive PAM audit report.""" |
| MEDIUM | …tecting-serverless-function-injection/scripts/agent.py | 477 | """Generate comprehensive serverless injection detection report.""" |
| MEDIUM | …/implementing-alert-fatigue-reduction/scripts/agent.py | 112 | """Build comprehensive alert fatigue reduction report.""" |
| MEDIUM | …erforming-ios-app-security-assessment/scripts/agent.py | 514 | """Generate comprehensive iOS security assessment report.""" |
| MEDIUM | …ming-network-forensics-with-wireshark/scripts/agent.py | 194 | """Generate comprehensive network forensics report.""" |
| MEDIUM | …lls/implementing-siem-use-case-tuning/scripts/agent.py | 125 | """Generate comprehensive tuning report with recommendations.""" |
| MEDIUM | …performing-file-carving-with-foremost/scripts/agent.py | 103 | """Build a comprehensive evidence catalog of carved files.""" |
| MEDIUM | skills/detecting-rootkit-activity/scripts/agent.py | 173 | """Generate comprehensive rootkit detection report.""" |
| MEDIUM | …detecting-lateral-movement-in-network/scripts/agent.py | 178 | """Generate comprehensive lateral movement detection report.""" |
| MEDIUM | …rming-cloud-log-forensics-with-athena/scripts/agent.py | 572 | """Run all forensic queries and compile a comprehensive report.""" |
| MEDIUM | …s/implementing-gcp-vpc-firewall-rules/scripts/agent.py | 135 | """Run a comprehensive firewall audit.""" |
| MEDIUM | …sbom-for-supply-chain-vulnerabilities/scripts/agent.py | 509 | """Generate a comprehensive vulnerability analysis report.""" |
| MEDIUM | …eploying-software-defined-perimeter/scripts/process.py | 216 | """Generate comprehensive SDP deployment report.""" |
| MEDIUM | …-gcp-security-assessment-with-forseti/scripts/agent.py | 144 | """Generate a comprehensive GCP security assessment report.""" |
| MEDIUM | …/analyzing-golang-malware-with-ghidra/scripts/agent.py | 201 | """Generate comprehensive Go malware analysis report.""" |
| MEDIUM | …-hardware-security-module-integration/scripts/agent.py | 154 | """Run comprehensive HSM compliance audit.""" |
| MEDIUM | …s/performing-malware-triage-with-yara/scripts/agent.py | 118 | """Generate comprehensive triage report.""" |
| MEDIUM | …detecting-network-anomalies-with-zeek/scripts/agent.py | 266 | """Generate comprehensive Zeek network analysis report.""" |
| MEDIUM | …menting-privileged-access-workstation/scripts/agent.py | 132 | """Run comprehensive PAW compliance audit.""" |
| MEDIUM | …-active-directory-forest-trust-attack/scripts/agent.py | 178 | """Run comprehensive forest trust security audit.""" |
| MEDIUM | skills/performing-ransomware-response/scripts/agent.py | 189 | """Generate comprehensive ransomware incident report.""" |
| MEDIUM | …ing-zscaler-private-access-for-ztna/scripts/process.py | 242 | """Generate comprehensive ZPA audit report.""" |
| MEDIUM | …ntity-federation-with-saml-azure-ad/scripts/process.py | 152 | """Generate comprehensive federation health report.""" |
| MEDIUM | …/performing-sqlite-database-forensics/scripts/agent.py | 176 | """Generate comprehensive forensic analysis report.""" |
| MEDIUM | …erforming-sqlite-database-forensics/scripts/process.py | 158 | """Generate comprehensive forensic analysis report.""" |
| MEDIUM | …ng-active-directory-with-bloodhound/scripts/process.py | 321 | """Generate comprehensive analysis report.""" |
| MEDIUM | …nalyzing-android-malware-with-apktool/scripts/agent.py | 162 | """Run comprehensive APK malware analysis.""" |
| MEDIUM | …-beyondcorp-zero-trust-access-model/scripts/process.py | 284 | """Generate a comprehensive BeyondCorp compliance report.""" |
| 30 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …loiting-kerberoasting-with-impacket/scripts/process.py | 158 | # Check if privileged |
| LOW | …ulti-factor-authentication-with-duo/scripts/process.py | 156 | # Check if denials happened within a short window |
| LOW | …-malware-behavior-with-cuckoo-sandbox/scripts/agent.py | 199 | # Check if argument is a report JSON path |
| LOW | …ing-insecure-data-storage-in-mobile/scripts/process.py | 86 | # Check if database is encrypted |
| LOW | …g-post-quantum-cryptography-migration/scripts/agent.py | 702 | # Check if connection succeeded with the specified group |
| LOW | …g-for-command-and-control-beaconing/scripts/process.py | 172 | # Check if beaconing threshold met |
| LOW | …etecting-bluetooth-low-energy-attacks/scripts/agent.py | 384 | # Check if Secure Connections flag is not set |
| LOW | …lls/hunting-for-dcom-lateral-movement/scripts/agent.py | 261 | # Check if DCOM is enabled |
| LOW | …teral-movement/scripts/detect_dcom_lateral_movement.py | 165 | # Check if this might be interactive (less suspicious) or DCOM (more suspicious) |
| LOW | …ementing-ransomware-backup-strategy/scripts/process.py | 262 | # Check if restore test is recent enough |
| LOW | …orming-soc2-type2-audit-preparation/scripts/process.py | 326 | # Display results |
| LOW | …s/detecting-dll-sideloading-attacks/scripts/process.py | 93 | # Check if DLL is a known sideloading target |
| LOW | …s/detecting-dll-sideloading-attacks/scripts/process.py | 95 | # Check if loaded from non-standard path |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 216 | # Check if event data flows into this sink |
| LOW | …g-dcsync-attack-in-active-directory/scripts/process.py | 74 | # Check if this is a legitimate domain controller |
| LOW | …-soar-playbook-with-palo-alto-xsoar/scripts/process.py | 111 | # Check if preceding task is manual |
| LOW | …rologon-vulnerability-cve-2020-1472/scripts/process.py | 100 | # Check if Netlogon is accessible |
| LOW | …-phishing-reporting-button-workflow/scripts/process.py | 137 | # Check if it's a known simulation |
| LOW | …-decoy-files-for-ransomware-detection/scripts/agent.py | 126 | # Check if file was renamed with ransomware extension |
| LOW | …detecting-container-escape-attempts/scripts/process.py | 329 | # Print results |
| LOW | …tecting-process-hollowing-technique/scripts/process.py | 183 | # Check if process path is from unexpected location |
| LOW | …g-business-email-compromise-with-ai/scripts/process.py | 155 | # Check if first-time sender to this recipient |
| LOW | …g-business-email-compromise-with-ai/scripts/process.py | 167 | # Check if request type is unusual for sender |
| LOW | …g-spearphishing-simulation-campaign/scripts/process.py | 336 | # Check if domain resolves |
| LOW | …ng-for-living-off-the-land-binaries/scripts/process.py | 399 | # Output results |
| LOW | …d-team-c2-infrastructure-with-havoc/scripts/process.py | 227 | # Check if domain is too new (WHOIS-based heuristic) |
| LOW | …menting-sigstore-for-software-signing/scripts/agent.py | 231 | result = run_cosign(["env"]) # Check if rekor-cli is better |
| LOW | …mplementing-usb-device-control-policy/scripts/agent.py | 22 | # Check if USBGuard is installed and running |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | skills/performing-jwt-none-algorithm-attack/SKILL.md | 91 | # Output: {'sub': '1234567890', 'name': 'John Doe', 'role': 'user', 'iat': 1516239022} |
| LOW | …second-order-sql-injection/references/api-reference.md | 48 | {"id": 1, "username": "admin", "email": "admin@example.com"}, |
| LOW | …second-order-sql-injection/references/api-reference.md | 49 | {"id": 2, "username": "' UNION SELECT 1,2,3--", "email": "test@test.com"} |
| LOW | skills/exploiting-mass-assignment-in-rest-apis/SKILL.md | 72 | -d '{"username":"testuser","email":"test@test.com","role":"admin"}' |
| LOW | …rce-intelligence-gathering/references/api-reference.md | 16 | python agent.py social --name "John Doe" |
| LOW | …ing-dark-web-monitoring-for-threats/scripts/process.py | 15 | python process.py --org "Acme Corp" --domains acme.com,acme.io --check-credentials |
| LOW | …ing-dark-web-monitoring-for-threats/scripts/process.py | 16 | python process.py --org "Acme Corp" --check-ransomware |
| LOW | …ing-dark-web-monitoring-for-threats/scripts/process.py | 17 | python process.py --org "Acme Corp" --full-scan --output report.json |
| LOW | …nting-gdpr-data-protection-controls/scripts/process.py | 466 | "data_subject_name": "Jane Doe", |
| LOW | skills/testing-for-email-header-injection/SKILL.md | 148 | -d '{"to":["test@test.com","attacker@evil.com"],"subject":"Test","body":"Test"}' |
| LOW | skills/testing-for-email-header-injection/SKILL.md | 153 | -d '{"to":"test@test.com","subject":"Test","body":"{{constructor.constructor(\"return process.env\")()}}"}' |
| LOW | …ls/testing-for-email-header-injection/scripts/agent.py | 103 | def test_contact_form(self, endpoint="/contact", base_email="test@test.com"): |
| LOW | …ls/testing-for-email-header-injection/scripts/agent.py | 119 | def test_json_api(self, endpoint, base_email="test@test.com"): |
| LOW | …ls/testing-for-email-header-injection/scripts/agent.py | 142 | def test_smtp_commands(self, endpoint, field_name="email", base_email="test@test.com"): |
| LOW | …lls/exploiting-jwt-algorithm-confusion-attack/SKILL.md | 181 | modifications={"role": "admin", "sub": "admin@example.com"}) |
| LOW | …-authentication-with-fido2/references/api-reference.md | 11 | user: { id: userId, name: "user@example.com", displayName: "User" }, |
| LOW | skills/testing-api-security-with-owasp-top-10/SKILL.md | 179 | -d '{"email":"test@test.com","password":"wrong"}' \ |
| LOW | …esting-api-security-with-owasp-top-10/scripts/agent.py | 44 | resp = requests.post(url, json={"email": "test@test.com", "password": f"wrong{i}"}, |
| LOW | skills/testing-jwt-token-security/SKILL.md | 60 | # Output: {"sub":"1234567890","name":"John Doe","iat":1516239022} |
| LOW | skills/testing-jwt-token-security/SKILL.md | 86 | PAYLOAD=$(echo -n '{"sub":"1234567890","name":"John Doe","role":"admin","iat":1516239022}' | base64 | tr -d '=' | tr '+/ |
| LOW | …implementing-browser-isolation-for-zero-trust/SKILL.md | 62 | organization="Acme Corp", |
| LOW | …r-isolation-for-zero-trust/references/api-reference.md | 13 | organization="Acme Corp", |
| LOW | …r-isolation-for-zero-trust/references/api-reference.md | 260 | python agent.py --action demo --org "Acme Corp" --output report.json |
| LOW | skills/performing-privacy-impact-assessment/SKILL.md | 67 | data_controller="Acme Corp", |
| LOW | …-privacy-impact-assessment/references/api-reference.md | 13 | organization_name="Acme Corp", |
| LOW | …-privacy-impact-assessment/references/api-reference.md | 26 | data_controller="Acme Corp", # Controller name |
| LOW | …-privacy-impact-assessment/references/api-reference.md | 236 | python agent.py --action demo --org "Acme Corp" --output report.json |
| LOW | …-middle-phishing-detection/references/api-reference.md | 55 | "mailboxOwner": "user@example.com", |
| LOW | …ls/testing-for-business-logic-vulnerabilities/SKILL.md | 148 | -d '{"cart_id": "abc123", "shipping_address": "123 Main St"}' \ |
| LOW | …ls/testing-for-business-logic-vulnerabilities/SKILL.md | 256 | -d '{"email":"test@test.com","password":"Test1234!","role":"admin"}' \ |
| LOW | …testing-api-for-mass-assignment-vulnerability/SKILL.md | 296 | 2. Register another user with injected role: `POST /api/v1/register {"name":"Admin","email":"admin@example.com","passwor |
| LOW | …s/performing-web-application-penetration-test/SKILL.md | 191 | {"orderId":10452,"customerName":"Jane Smith","email":"jane@...","address":"123 Main St"} |
| LOW | …ential-access-with-lazagne/references/api-reference.md | 184 | "Login": "admin@example.com", |
| LOW | …ng-broken-object-property-level-authorization/SKILL.md | 62 | "name": "John Doe", |
| LOW | …implementing-gdpr-data-subject-access-request/SKILL.md | 252 | requester_name="John Doe", |
| LOW | …implementing-gdpr-data-subject-access-request/SKILL.md | 268 | data_subject="John Doe", |
| LOW | …ata-subject-access-request/references/api-reference.md | 74 | | `search_identifiers` | `dict` | required | Key-value pairs to search for (e.g., `{"email": "user@example.com"}`) | |
| LOW | skills/testing-mobile-api-authentication/SKILL.md | 143 | -d '{"email":"test@test.com","password":"pass"}' | jq -r '.token') |
| LOW | …testing-api-authentication-weaknesses/scripts/agent.py | 170 | {"username": "admin@example.com", "password": "wrong"}) |
| LOW | …r-spearphishing-indicators/references/api-reference.md | 57 | result, _, _ = spf.check2(ip="1.2.3.4", sender="user@example.com", helo="mail.example.com") |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 540 | # Step 1: Enumerate functions |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 545 | # Step 2: Get event source mappings |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 548 | # Step 3: Scan code for injection patterns |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 564 | # Step 4: Audit layers |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 567 | # Step 5: Detect privilege escalation paths |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 570 | # Step 6: Check CloudTrail for suspicious modifications |
| LOW | …tecting-serverless-function-injection/scripts/agent.py | 573 | # Step 7: Check function URL security |
| LOW | …plementing-aws-nitro-enclave-security/scripts/agent.py | 467 | # Step 3: Audit IAM roles |
| LOW | …plementing-aws-nitro-enclave-security/scripts/agent.py | 474 | # Step 4: Search CloudTrail events |
| LOW | …plementing-aws-nitro-enclave-security/scripts/agent.py | 477 | # Step 5: Validate attestation document if provided |
| LOW | …plementing-aws-nitro-enclave-security/scripts/agent.py | 447 | # Step 1: Find enclave-enabled instances |
| LOW | …plementing-aws-nitro-enclave-security/scripts/agent.py | 450 | # Step 2: Audit KMS key policies |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1398 | # Step 1: Register DSAR |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1416 | # Step 2: PII Discovery |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1442 | # Step 3: Data Mapping |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1447 | # Step 4: Exemption Review |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1458 | # Step 5: Response Generation |
| LOW | …ting-gdpr-data-subject-access-request/scripts/agent.py | 1477 | # Step 6: Mark complete |
| Severity | File | Line | Snippet |
|---|---|---|---|
| HIGH | …ing-tls-certificate-transparency-logs/scripts/agent.py | 0 | insert into alerts (alert_type, severity, domain, details, certificate_id) values (?, ?, ?, ?, ?) |
| HIGH | …ing-tls-certificate-transparency-logs/scripts/agent.py | 0 | insert into alerts (alert_type, severity, domain, details, certificate_id) values (?, ?, ?, ?, ?) |
| HIGH | …ing-tls-certificate-transparency-logs/scripts/agent.py | 0 | insert into alerts (alert_type, severity, domain, details, certificate_id) values (?, ?, ?, ?, ?) |
| HIGH | …ng-for-json-web-token-vulnerabilities/scripts/agent.py | 0 | decode jwt header and payload without verification. |
| HIGH | skills/testing-api-authentication-weaknesses/SKILL.md | 0 | decode jwt header and payload without verification. |
| HIGH | …testing-api-authentication-weaknesses/scripts/agent.py | 0 | decode jwt header and payload without verification. |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | …eploying-active-directory-honeytokens/scripts/agent.py | 120 | # Create the honeytoken account |
| MEDIUM | …eploying-active-directory-honeytokens/scripts/agent.py | 257 | # Create the GPO folder structure in SYSVOL |
| MEDIUM | …eploying-active-directory-honeytokens/scripts/agent.py | 266 | # Create the Groups.xml with a fake cpassword |
| MEDIUM | …eploying-active-directory-honeytokens/scripts/agent.py | 294 | # Create a matching real AD account (disabled or with different password) |
| MEDIUM | …ting-browser-isolation-for-zero-trust/scripts/agent.py | 817 | # Create a session (which evaluates all policies) |
| MEDIUM | …rming-deception-technology-deployment/scripts/agent.py | 65 | content += f"# This file is a decoy. Any access triggers a security alert.\n" |
| MEDIUM | …s/testing-mobile-api-authentication/scripts/process.py | 136 | # Create a JWT with expired timestamp (modifying payload) |
| MEDIUM | …fuzz-testing-in-cicd-with-aflplusplus/scripts/agent.py | 33 | # Create a minimal seed if none provided |
| Severity | File | Line | Snippet |
|---|---|---|---|
| HIGH | index.json | 1 | {"version":"1.1.0","generated_at":"2026-05-30T09:32:08Z","repository":"https://github.com/mukul975/Anthropic-Cybersecuri |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …lls/performing-red-team-with-covenant/scripts/agent.py | 131 | def execute_task(self, grunt_id, task_name, parameters=None): |