Database
Browse 6,168 skills across 448 packs and 38 categories
forensic-readiness
139LForensic log retention assessment, evidence preservation, and attack traceability
incident-response
203LIR handoff quality assessment, playbook review, and communication evaluation
siem-coverage
143LSIEM coverage assessment, log source gaps, and detection blind spot analysis
threat-hunting
185LProactive threat hunting methodology with hypothesis-driven search techniques
container-security
156LContainer image hygiene, Kubernetes RBAC, and pod security assessment
edr-visibility
126LEDR and antivirus coverage gap analysis and blind spot detection
local-privilege
146LLocal privilege escalation testing including SUID, sudo abuse, and service misconfiguration
os-hardening
143LOS hardening assessment for Linux and Windows systems against CIS benchmarks
scheduled-task-abuse
160LCron job and scheduled task abuse risk assessment and service hijacking
software-inventory
142LSoftware inventory anomaly detection, shadow IT discovery, and EOL software identification
exploitability-confirmation
135LExploitability confirmation and false positive reduction methodology
impact-verification
143LImpact verification, blast radius estimation, and business consequence assessment
poc-execution
139LControlled proof-of-concept execution and safe vulnerability validation
post-exploitation-mapping
156LPost-exploitation risk mapping including pivot paths and persistence mechanisms
vulnerability-assessment
164LCVE matching, version risk analysis, and misconfiguration detection methodology
ad-security
156LActive Directory trust review, Kerberos assessment, and delegation risk analysis for authorized assessments
iam-policy-review
163LIAM policy analysis and least privilege assessment for authorized security assessments
mfa-coverage
154LMFA coverage assessment and bypass risk detection for authorized security assessments
privilege-escalation
167LPrivilege escalation path detection in cloud and enterprise environments for authorized assessments
role-trust-boundaries
156LRole trust boundaries, cross-account access, and federation security review for authorized assessments
secret-management
162LSecret sprawl detection, key rotation assessment, and vault configuration review for authorized assessments
attribution-support
47LAlias clustering, language patterns, infrastructure reuse, and confidence-rated attribution
decentralized-threat-research
45LP2P abuse monitoring, wallet-linked fraud, smart contract risk, and cross-platform correlation
domain-correlation
46LCorrelate domains, certificates, IPs, and ASNs across adversary campaigns
incident-enrichment
47LTransform raw security alerts into actor hypotheses, motives, next steps, and containment guidance
osint-fusion
48LMerge public web, breach data, passive DNS, social graph, and code repository intelligence
endpoint-visibility
129LEndpoint visibility gap analysis, rogue device detection, and EDR coverage assessment for internal networks
lateral-movement
117LLateral movement path analysis, credential relay, and pivot detection for authorized internal network assessments
legacy-protocol-risk
120LLegacy protocol risk assessment for SMBv1, LLMNR, NetBIOS, Telnet, and other deprecated services
segmentation-review
133LNetwork segmentation validation, VLAN hopping, firewall rule review, and micro-segmentation testing
trust-relationships
110LDomain trust enumeration, shared service abuse, and cross-boundary attack path analysis for authorized assessments
app-transport
154LApp transport security assessment, certificate pinning validation, HSTS enforcement, and TLS configuration review
local-storage
157LMobile local storage security review, keychain/keystore assessment, and sensitive data exposure detection
mobile-api-testing
184LMobile API interception, proxy configuration, request manipulation, and backend API security testing
reverse-engineering
164LAPK and IPA decompilation, binary analysis, obfuscation review, and tampering detection assessment
token-persistence
161LMobile token persistence analysis, session management review, and authentication state security
host-discovery
123LHost availability detection and network segmentation mapping for authorized security assessments
network-exposure
137LExposure validation and firewall rule assessment for authorized security assessments
port-scanning
123LPort discovery and service detection with nmap for authorized security assessments
protocol-identification
140LProtocol fingerprinting and unusual service detection for authorized security assessments
traffic-analysis
144LPacket capture interpretation, cleartext detection, and traffic analysis with tcpdump and Wireshark
tunneling-validation
139LSecure tunneling validation, proxy path review, and VPN configuration checks for authorized assessments
credential-attacks
44LCredential attack techniques for authorized assessments including password spraying, Kerberoasting, NTLM relay, and credential dumping
defense-evasion-testing
44LTesting detection coverage through AMSI bypass, process injection, and living-off-the-land techniques for detection validation
initial-access
44LInitial access techniques for authorized penetration tests including phishing, exposed services, and credential attacks
lateral-movement-techniques
44LLateral movement techniques for authorized assessments including pass-the-hash, WMI, PSExec, and RDP pivoting
payload-development
45LCustom payload development for authorized assessments including AV/EDR testing and C2 framework usage
persistence-analysis
45LPersistence mechanism testing for authorized assessments covering scheduled tasks, registry keys, services, and DLL side-loading
privilege-escalation-techniques
45LWindows and Linux privilege escalation techniques for authorized penetration testing including kernel exploits, misconfigurations, and token abuse
ad-attack-paths
45LActive Directory attack path analysis using BloodHound, Certify, and Rubeus for authorized security assessments
attack-infrastructure
44LAttack infrastructure setup including redirectors, domain fronting assessment, and phishing infrastructure for authorized engagements
c2-framework
44LCommand and control framework setup and operation for authorized penetration tests with OPSEC considerations
cloud-exploitation
44LCloud exploitation techniques for authorized assessments covering metadata abuse, SSRF to cloud, and IAM role assumption
debrief-retesting
46LClient debrief methodology, remediation validation, retest procedures, and knowledge transfer for penetration testing engagements
report-writing
45LProfessional penetration test report writing covering executive summary, technical findings, risk ratings, and remediation guidance
engagement-planning
47LRules of engagement definition, scope documentation, authorization validation, and legal compliance for penetration testing
external-pentest
45LExternal network penetration testing methodology aligned with PTES for authorized security assessments
internal-pentest
44LInternal network penetration testing and assumed breach methodology for authorized security assessments
physical-pentest
44LPhysical penetration testing methodology including access control bypass, tailgating assessment, and social engineering for authorized engagements
purple-team
44LPurple team exercise methodology for cooperative adversary simulation and detection validation in authorized engagements